Version 1.0 · Kinder Paradise Learning Hub
We collect the minimum data needed to run the Kinder Paradise Staff Digital Competency Framework: your name, work email address, role, location and site, plus the training, assessment, certification, compliance and escalation records the program generates about you.
No child or beneficiary personal data is stored on this platform. Practical task submissions must not contain identifying information about children.
Processing is based on your explicit consent, captured with a timestamp and policy version when you register, and on Kinder Paradise’s legitimate interest in maintaining digitally competent staff across School, Children’s Home and Day Care.
You may withdraw consent at any time by requesting account deletion from the Account & Privacy page.
Access is role-based and least-privilege: you see your own records; your Site Lead sees their site’s records; program leadership sees aggregate dashboards and drill-downs required for governance; ICT officers and administrators see what they need to run the program.
Every security-relevant action is recorded in an append-only audit log.
Access & portability: export all personal data we hold about you as JSON, self-service, at any time.
Erasure: request account deletion. An administrator will anonymise your records — direct identifiers are removed while pseudonymous aggregates needed for statutory reporting are retained.
Rectification: contact your administrator to correct inaccurate profile data.
Assessment attempts and certification history are retained for 3 years for governance reporting.
Audit logs are retained for 1 year.
Fulfilled deletion requests are anonymised within 30 days of approval.
Passwords are stored only as bcrypt hashes. Sessions use signed, httpOnly, SameSite cookies. All traffic must use HTTPS in production. Rate limiting and account lockout protect against brute force. All inputs are validated server-side, and assessment answers are scored exclusively on the server.