Template notice: this document is a template and should be reviewed by a qualified lawyer before it is relied upon.
Privacy Policy
Last updated: 1 October 2026
Your trust matters to us — especially because EarlyCare looks after information about young children. This policy explains, in plain language, how we handle personal information.
1. Who we are
NgeZha EarlyCare ("EarlyCare", "we", "us") is a management platform for crèches, daycares and preschools in any country, operated by NgeZha Tech Group, a company based in Zimbabwe. It is available on the web at earlycare.ngezhagroup.co.zw and as a mobile app.
When a school ("the School") uses EarlyCare to record information about its children, parents, guardians and staff, the School decides why and how that information is used and is the data controller. We process that information on the School's behalf, as a data processor, and only on its instructions.
For information about the people who sign up for and manage a school account (for example the administrator's name and email, and billing details), we are the data controller.
2. Scope of this policy
This policy explains what personal information EarlyCare collects, why, how it is protected, how long it is kept and what rights you have. It applies to our website, web application and mobile app.
It is written to meet the Cyber and Data Protection Act [Chapter 12:07] of Zimbabwe (2021) and the principles of the EU General Data Protection Regulation (GDPR). Schools outside Zimbabwe are also protected by their own national laws — for example South Africa's POPIA, Kenya's Data Protection Act, Nigeria's NDPA or the UK GDPR — and we will support schools in meeting them.
3. Information we collect
We collect only what a school needs to run its day-to-day operations. Depending on how a school uses EarlyCare, this may include:
- School account information: school name, logo, address, contact details, the sections it runs and its subscription details.
- Staff information: name, email address, phone number, role and the classes they are assigned to.
- Children's information: name, date of birth, gender, section and class, guardians, authorised pick-up people, emergency contacts, allergies, medical and dietary notes provided by the parent, attendance, daily care records (feeding, naps, nappy changes, mood), learning assessments and — only where the school and parent allow it — photos.
- Parent and guardian information: name, relationship to the child, phone number, email address and, where the school requires it, a national ID number.
- Fee and payment records: invoices, amounts, currency, payment method (for example bank transfer, card, PayPal, mobile money, cash, or EcoCash, InnBucks and O'mari in Zimbabwe), proof-of-payment images uploaded by parents, receipts and credits.
- Subscription billing: if you pay your EarlyCare subscription by card, card details are handled by our payment provider and are never stored on our servers.
- Technical information: sign-in records, device and browser type, error reports and security logs needed to keep the service working and safe.
4. What we do not collect
We follow a strict data-minimisation approach, which is especially important because EarlyCare holds information about young children.
- We do not request or collect location data.
- We do not access your phone's contacts.
- The camera is used only when you choose to take a profile photo or photograph a document (such as a proof of payment). We do not use the microphone.
- We do not use advertising identifiers and there is no advertising of any kind in EarlyCare.
- We do not sell, rent or trade personal information, and we do not build marketing profiles of children or parents.
5. Children's data and parental consent
Children's personal information receives extra protection. Children's personal information is encrypted, stored securely, and never shared with third parties for their own purposes. Only authorised staff and the child's own parents or guardians can access it.
EarlyCare is used by adults — school staff and parents. Children do not create accounts or use the app themselves.
Schools must obtain the consent of a parent or guardian before entering a child's information into EarlyCare, and must tell parents how the information will be used. Parents may ask the school, or us, at any time what information is held about their child.
Each child has privacy settings controlled by the school together with the parent: photo sharing is off by default, and sharing of daily reports with that child's parents is on by default. Data exports are available to the school administrator and to the child's parents.
6. How we use information
We use personal information only to:
- provide EarlyCare's features to the school, its staff and parents (attendance, daily records, fees, receipts, reports, messages and printing);
- send service emails and notifications, such as invoices, receipts, payment confirmations and subscription reminders;
- manage the school's subscription and billing;
- provide support when you contact us;
- keep the service secure, prevent abuse and investigate problems;
- meet our legal obligations.
We never use personal information for advertising, and we do not use children's information to train artificial intelligence models.
7. Legal bases for processing
Where data protection law requires a legal basis, we (or the School, as controller) rely on: performance of a contract (providing the service the School subscribed to); consent (for example a parent's consent to register their child and to share photos); legitimate interests (keeping the service secure and improving it, balanced against your rights); and legal obligation (for example keeping financial records).
8. AI features
EarlyCare includes an optional AI assistant that helps staff draft reports, announcements and summaries. AI features only process information when a staff member actively uses them, and only the information needed for that request is sent.
Every AI output is clearly labelled "AI Generated — Please Review" and is saved only after a staff member reviews and accepts it. The AI never makes medical or safeguarding decisions.
AI requests are processed by Anthropic, our AI provider, under terms that prohibit using that data to train its models.
10. Subprocessors and international transfers
We use the following trusted service providers ("subprocessors") to run EarlyCare:
- Supabase — database, authentication and secure file storage.
- Vercel — website and application hosting.
- Resend — delivery of transactional emails such as invoices and receipts.
- Upstash — rate limiting and short-lived caching to protect the service from abuse.
- Anthropic — AI processing, only when staff use AI features, with every output reviewed by a person before it is saved.
Some of these providers store or process data outside the country where your school is based. Where that happens we rely on contractual safeguards (such as standard contractual clauses) and providers that apply strong security standards, as required by the Cyber and Data Protection Act and other applicable data-protection laws. We will update this list before adding a new subprocessor.
11. Google Play Families policy
Our mobile app complies with the Google Play Families policy and the Google Play User Data policy. The app contains no ads and no third-party advertising or analytics SDKs that track children, collects only the data needed for its features, discloses that data collection in its store listing, and relies on parental consent for children's data.
12. How we protect information
We use layered security measures, including:
- Encryption of data in transit (HTTPS/TLS) and at rest.
- Row-level security in the database, so each school's data is isolated from every other school and every request is checked against the user's school and role.
- Private file storage: photos and documents are never public and are shown only through short-lived signed links.
- Strong passwords, optional multi-factor authentication and rate limiting on sign-in.
- Audit logs of sensitive actions, such as data exports, deletions and payment approvals.
- Automatic daily backups with point-in-time recovery.
No system is completely secure. If a personal data breach occurs that is likely to affect you, we will notify the affected schools and the data protection authority as required by law, without undue delay.
13. How long we keep information
We keep information only for as long as it is needed. Our retention policy is:
- Active children: kept for as long as the child is enrolled and the school's account remains active.
- Graduated children: kept for 3 years after graduation, then deleted.
- Withdrawn children: kept for 2 years after withdrawal, then deleted.
- Payment records (invoices, proofs of payment, receipts and credits): kept for 7 years to meet legal and accounting requirements.
- Audit logs: kept for 2 years.
- In-app notifications: kept for 90 days, then deleted automatically.
- Email delivery logs: kept for 6 months.
We never delete a school's data without confirmation from its administrator. If a school's subscription ends, its data is locked — not deleted — so it can be restored when the school reactivates or exported on request. Deleted data may remain in encrypted backups for a short period until those backups expire.
14. Your rights
Subject to the law, you have the right to:
- access the personal information held about you or your child;
- have inaccurate information corrected;
- have information deleted (see section 15);
- restrict or object to certain processing;
- receive a copy of your information in a portable format (schools and parents can export data from the app);
- withdraw consent at any time, where processing is based on consent;
- complain to the data protection authority in your country — for example the Postal and Telecommunications Regulatory Authority of Zimbabwe (POTRAZ) under the Cyber and Data Protection Act, the Information Regulator in South Africa, or the Information Commissioner's Office in the UK.
Because the School controls its records, we may pass your request to the School and help it respond. We will reply within the time the law requires.
15. Deletion requests
A parent or guardian can ask the school, or us, to delete their child's information completely — for example after the child has been withdrawn or has graduated. Deletion is permanent and cannot be undone, so the school administrator is asked to confirm it after a clear warning.
The audit log records who carried out a deletion and when. Records that we or the School are legally required to keep, such as payment records, are retained only for the required period and then deleted.
17. Changes to this policy
We may update this policy from time to time. We will show the new "last updated" date at the top of this page and, for significant changes, notify school administrators by email or in the app before the changes take effect.
18. Contact us
For privacy questions or to exercise your rights, contact NgeZha Tech Group at info@ngezhagroup.co.zw. Please tell us the name of the school concerned so we can help you quickly.
Related: Terms of Service