At Snapdragons Nurseries Ltd, we promise to keep your data safe and private and only use your personal information to manage your employment at Snapdragons.
Your privacy is protected by law which says that we are allowed to use personal information only if we have a proper reason to do so. This includes sharing outside of Snapdragons Nurseries Ltd. The law says we must have one of more of these reasons:
To fulfil a contract we have with you, or
When it is our legal duty, or
When it is in our legitimate interest, or
When you consent to it.
A legitimate interest is when we have a business or commercial reason to use your information. But even then, it must not unfairly go against what is right and best for you. If we rely on our legitimate interest, we will tell you what that is.
From time to time, we will need to contact you, via phone or email to provide you with nursery updates, share important news or send your monthly payslips.
The categories of employee information that we collect, hold and share include
Personal information (such as name, date of birth and address)
Characteristics (such as ethnicity, language, nationality, country of birth)
Attendance information (such as shifts worked, holiday, absences and absence reasons)
CPD information (such as training courses, supervisions and observations)
Medical information (such as allergy information)
Sensitive information (such as accident forms and disciplinaries)
Qualifications (and, where relevant, subjects taught)
Why we collect and use this information
to enable the development of a comprehensive picture of the workforce and how it is deployed
to analyse areas of development in our teams
to meet our EYFS staffing targets
to assess the quality of our services
to comply with the law regarding data sharing
to enable individuals to be paid
The lawful basis on which we use this information
We collect and use employee information under GDPR Article 6, 1b, 1c and 1f, as well as Article 9, 2a.
Collecting employee information
Whilst the majority of employee information you provide to us is mandatory, some of it is provided to us on a voluntary basis. In order to comply with the General Data Protection Regulation, we will inform you whether you are required to provide certain information to us or if you have a choice in this. Data is collected via your application form and new starter forms, as well as supervision and appraisal forms during your employment.
Storing employee data
We hold employee data for up to seven years from their end date with Snapdragons Nurseries Ltd. Unsuccessful applicant data is held for one year. Employee data is collected through Cognito Forms and initially held in a US-based datacentre, before being moved to permanent storage on a secure Microsoft-owned datacentre, hosted in the EU. Data is then removed from Cognito Forms and not stored there longer than is necessary to process the initial data.
Who we share employee information with
We routinely share employee information with:
our local authority
Ofsted
Companies we work with, including Best Practice for employee training
Sharing of employee information
We do not share information about our employees with anyone without consent unless the law and our policies allow us to do so.
Data collection requirements:
To find out more about the data collection requirements placed on us by the Department for Education, go to https://www.gov.uk/education/data-collection-and-censuses-for-schools.
Requesting access to your personal data
Under data protection legislation, individuals have the right to request access to information about them that we hold. To make a request for your personal information, or be given access to your employment records, contact the HR Manager, Nursery Manager or Nursery Data Protection Officer.
You also have the right to:
object to processing of personal data that is likely to cause, or is causing, damage or distress
prevent processing for the purpose of direct marketing
object to decisions being taken by automated means
in certain circumstances, have inaccurate personal data rectified, blocked, erased or destroyed; and
claim compensation for damages caused by a breach of the Data Protection regulations
If you have a concern about the way we are collecting or using your personal data, we request that you raise your concern with us in the first instance. Alternatively, you can contact the Information Commissioner’s Office at https://ico.org.uk/concerns/
Right to be forgotten
Under Article 17 of the GDPR individuals have the right to have personal data erased. This is also known as the ‘right to be forgotten’. The right is not absolute and only applies in certain circumstances. Whilst an employee still works for Snapdragons, the right may not be exercised, as the personal data is still necessary for the purpose for which we originally collected it for.
Authorised third parties
We use a number of authorised third-parties to provide our services. They are not permitted to use information we share with them for any other purpose.
We use third parties to assist us in processing your personal information, and we require these third parties to comply with our Privacy Policy and any other appropriate confidentiality and security measures.
Squarespace
Secure hosting of Snapdragons Nursery is essential to both us and our families. That is why we entrust Squarespace, an industry leader in secure website hosting, to protect all of our website data.
Cognito Forms
Cognito Forms provide processing of all forms on our website, allowing us to capture the information we need for your child’s registration or your job application. Their data is stored on Amazon datacentres in the United States. Data is only temporarily stored with Cognito Forms before being moved to Snapdragons’ own servers (see 8.3. Microsoft) upon verification by a manager.
Microsoft
All customer and employee data, and the servers that process this data, are securely managed by Microsoft, geo-replicated in real time to multiple datacentres in the United Kingdom and Europe. Microsoft has more security certifications than any other cloud provider. More information about these security measures can be found in the Office 365 Trust Center.
Connect Childcare
Your personal data will be input into the Connect Childcare system, which helps us manage our nurseries. Your data is held in secure data centres hosted by Memset and Amazon Web Services and can only be accessed by authorised personnel.
Intuit’s Quickbooks
Employee payroll data is stored with Intuit’s Quickbooks, which allows us to process salaries and tax deductions in accordance with the law. This data is stored in the USA. Intuit is a certified member of the Privacy Shield scheme. They certify to the EU-US Privacy Shield scheme for our use of personal data in the USA, and apply guidelines and practices to protect all personal information, including the E.U.U.S. Privacy Shield Principles.
Signable
Employee contracts are sent and submitted using Signable. Signable is based in the UK, with infrastructure in the UK. Your personal data never gets transferred outside of the EU (European Economic Area). They fully comply with GDPR. Contracts are transferred to Snapdragons’ servers (see Microsoft) once received and then removed from Signable.
Best Practice
Best Practice conducts apprenticeship training for Snapdragon Nursery. To evaluate your learning history and verify your eligibility for an apprenticeship, they require access to your name, date of birth, and postcode. If you accept an apprenticeship with Snapdragons Nursery, this information will be shared with Best Practice to carry out these verifications.
Notice of Breach of Security
We will notify you if there was a breach of your personal information. If a security breach causes an unauthorised intrusion into our system that materially affects you or your information, then we will notify you as soon as possible and later report the action we took in response.
Safeguarding Your Information
We work hard to keep your information safe and secure. We take reasonable and appropriate measures to protect personal information from loss, misuse, and unauthorised access, disclosure, alteration, and destruction, taking into account the risks involved in the processing and the nature of the personal information. We rely on Microsoft and Connect Childcare to safeguard the physical and technical security of your information, and we have documented and enforced controls to limit access to, and to protect your information.
Scope
This Privacy Policy applies to services provided by Snapdragons Nurseries Ltd (“Snapdragons Nursery”, “us” “we” or “our”). This Privacy Policy addresses information we have collected, or will collect, about or from you, via websites located at *.snapdragonsnursery.com or *.cognitoforms.com.
Changes
We may change this Privacy Policy at any time and from time to time. The most recent version of the Privacy Policy is reflected by the modification date located at the bottom. All updates and amendments are effective immediately upon notice, which we may give by any means, including, but not limited to, by posting a revised version of this Privacy Policy or other notice on the nursery website.
Questions & Concerns
Please email us at privacy@snapdragonsnursery.com if you have any questions about the privacy or accuracy of your information.
If you have a question or complaint about this Privacy Policy or our information collection practices, please contact us at privacy@snapdragonsnursery.com, contact your Nursery Manager or Data Protection Officer or write to us at the address listed below. We will investigate the matter and are committed to resolving any privacy concerns that you may have.
Snapdragons Nursery,
43 Bath Road,
Atworth,
Melksham,
Wiltshire,
SN12 8JW
01225 707009
Last modified: 14/10/2024