Security at NestliCare

You trust us with sensitive information about children and families. We take that responsibility seriously. Here is how we protect your data.

Encryption

All data is encrypted in transit using TLS 1.2+ and encrypted at rest on AWS infrastructure using AES-256.

Role-Based Access Controls

Every user has a defined role (owner, admin, teacher, parent) with strict permissions. Teachers only see their assigned rooms. Parents only see their own children.

Secure Infrastructure

NestliCare runs on Amazon Web Services (AWS) in the US-East-2 region. AWS maintains SOC 2, ISO 27001, and other certifications for their infrastructure.

Data Isolation

Each daycare organization's data is logically isolated. Staff and parents at one organization can never access another organization's data.

Audit Logging

Sensitive actions like settings changes, agreement acceptance, and administrative operations are logged with timestamps, user identity, and IP address for accountability.

Data Processing Agreement

Every organization signs a Data Processing Agreement (DPA) before accessing the platform. The DPA defines data ownership, processing purposes, breach notification timelines, and your right to export or delete data.

Breach Notification

In the unlikely event of a data breach, we will notify affected organizations promptly and without undue delay, with details of the scope, impact, and remediation steps.

No Data Selling

We never sell your data, and child, family, and daycare records are never shared with advertisers or used for advertising. Your data is processed solely to provide the NestliCare service.

Have a security question?

If you have questions about our security practices or want to report a vulnerability, contact us at [email protected]

Last updated: April 13, 2026

Security | NestliCare