Privacy Policy

Effective 19 August 2026

Bloomffy (“we”, “us”) is a crèche management system used by childcare providers in Ireland (“your crèche”, “the customer”) to run staff daily logging, parent visibility, and Tusla compliance records. This policy explains what we do with personal data as part of providing that system. It doesn’t replace your crèche’s own privacy notice to parents and staff — ask your crèche for that if you’re a parent or staff member looking for it.

Who is the data controller

For data about children, parents/guardians, and staff, your crèche is the data controller — they decide what’s recorded and why. Bloomffy acts as a data processor, handling that data only on your crèche’s instructions and only to provide the service. If you’re a parent or staff member with a question about your own data, your crèche is the right first point of contact; we’ll support them in answering it.

For the marketing site itself (this page, the pages linked from it) and for your own account if you’re a Bloomffy customer contact, Bloomffy is the controller.

What we process

  • Child records: name, date of birth, allergies, medical and consent information, attendance, photos, and developmental notes, entered by your crèche’s staff.
  • Parent/guardian records: name, contact details, and messages sent through the parent app.
  • Staff records: name, role, room assignment, and logging activity.
  • Account and device data: login sessions, room-tablet device identifiers, and basic usage needed to run the service (e.g. sync status, error logs).

Some of this — health and allergy information especially — is special category data under GDPR. It’s processed because it’s necessary for your crèche to meet its own regulatory and safeguarding obligations, on your crèche’s instructions.

Where it’s stored, and who else sees it

Bloomffy runs on Supabase (Postgres, authentication, and file storage) as its hosting infrastructure. We use Sentry for error monitoring, so we can find and fix bugs — it may capture technical details about a crash, not a general feed of app content. Outbound email (e.g. account and notification emails) goes through a transactional email provider. We don’t sell data, and we don’t share it with anyone outside the people who need it to run the service.

Cookies

The marketing pages you’re reading now don’t set tracking or advertising cookies. Signing in anywhere in Bloomffy (staff, parent, admin, or platform accounts) sets a session cookie required to keep you signed in — that’s it.

How long we keep it

Retention is set by your crèche in line with its own regulatory recordkeeping obligations (Tusla and related requirements), not by a fixed schedule we impose. Ask your crèche’s admin for specifics on a given record.

Your rights

Under GDPR you have rights to access, correct, delete, restrict, or port your personal data, and to object to certain processing. Since your crèche is the controller for most of the data described here, start with them; we’ll assist any request they need help fulfilling. You also have the right to complain to Ireland’s Data Protection Commission (dataprotection.ie).

Contact

Questions about this policy: hello@bloomffy.com.

[Placeholder: registered legal entity name and address to be added here once incorporated — this policy will be updated before general availability.]

Talk to us