1. Who we are
Recess is a cloud software platform used by childcare centres (our customers) to manage observations, attendance, messaging, billing estimates, and related operations. Centres are typically the primary organisation responsible for how they use the platform with families. We act as a service provider to those centres and, for some platform account data, as an APP entity in our own right.
Contact for privacy requests: use the email published by your centre, or privacy@recess.example (replace with your verified privacy mailbox before launch).
2. What we collect
Depending on how a centre uses Recess, we may process:
- Account details (name, email, role, phone)
- Child enrolment and care records (name, date of birth, room, attendance)
- Health-related information where centres record it (allergies, immunisation statements, incidents, medication notes) — treated as sensitive information
- Learning documentation (observations, photos/videos with consent, curriculum notes)
- Messages between educators and families
- Billing and payment metadata (invoices, payment method references via Stripe)
- Technical logs needed for security, reliability, and support
3. Why we collect it (APP 3 & 6)
We collect and use personal information only as needed to:
- Provide and secure the service requested by the centre
- Enable educators and families to communicate about a child's day
- Support compliance workflows centres configure (e.g. consents, WWCC, IHS tracking)
- Generate Statements of Entitlement and billing estimates when enabled
- Improve reliability (aggregated/diagnostic telemetry without unnecessary identifiers)
We do not sell personal information. We do not use health records for marketing.
4. Collection notices (APP 5)
When you enrol or enquire through Recess, you will see a collection notice explaining the purposes of collection, who may access the information, and how to request access or correction.
5. Sharing
We share personal information only:
- With the centre that holds your family relationship on the platform
- With subprocessors needed to run the service (e.g. Supabase hosting in Australia, email delivery, optional payment processing via Stripe Australia)
- When required by law or to protect safety and security
6. Storage & security (APP 11)
Childcare application data is stored in Australian infrastructure (Supabase ap-southeast-2 / Sydney) where the production project is configured as intended. Access is role-scoped. Media is delivered via short-lived signed URLs rather than public object links.
Optional AI assist features send minimised context to the model provider (for drafting: educator notes and optional first name only — not full identifying dossiers). Content translation sends the parent-facing text as written so families can read it in their preferred language. See AI features below and our internal data-sovereignty notes for centres.
7. AI features
Educators may use optional AI drafting tools (e.g. observation wording). Educators review and own published content. Parents are not shown per-card “AI drafted” labels. Live content translation (when a preferred language other than English is set) labels translations clearly with a view-original control. Directors may see an AI-narrated centre brief built only from query-derived metrics (counts), not invented figures.
Model provider: OpenAI API (default). Inputs are not used to train OpenAI models under their API terms. Rate limits apply. A longer centre-facing fact sheet is maintained for LEGAL review alongside this policy.
8. Access & correction (APP 12 & 13)
Parents can view much of their child's day-to-day information in the parent portal. For a fuller export, contact your centre; centres can fulfil requests using portfolio export and admin records. Ask your centre (or us) to correct inaccurate information.
9. Retention
Centres must retain certain records under education and care regulations (commonly 3 years after last attendance for general records; longer for some incident records; financial/CCS records typically 7 years). Recess is designed so centres can retain rather than hard-delete prematurely. Automated destruction jobs are not the launch default.
10. Notifiable Data Breaches
If we experience a data breach likely to cause serious harm, we will assess and notify the OAIC and affected individuals as required under the NDB scheme. Our internal response plan is summarised at /legal/ndb-response-plan and maintained for the operating team in docs/NDB_RESPONSE_PLAN.md.
11. Children's data
We design for children's information carefully: purpose limitation, consent for media where required, and no behavioural advertising. We will adapt further when the OAIC Children's Online Privacy Code is published.
12. Changes
We may update this policy. Material changes will be reflected on this page with an updated date. Continued use of the service after publication constitutes notice to account holders; centres should inform families when their own practices change.