Security at NestliCare
You trust us with sensitive information about children and families. We take that responsibility seriously. Here is how we protect your data.
Encryption
All data is encrypted in transit using TLS 1.2+ and encrypted at rest on AWS infrastructure using AES-256.
Role-Based Access Controls
Every user has a defined role (owner, admin, teacher, parent) with strict permissions. Teachers only see their assigned rooms. Parents only see their own children.
Secure Infrastructure
NestliCare runs on Amazon Web Services (AWS) in the US-East-2 region. AWS maintains SOC 2, ISO 27001, and other certifications for their infrastructure.
Data Isolation
Each daycare organization's data is logically isolated. Staff and parents at one organization can never access another organization's data.
Audit Logging
Sensitive actions like settings changes, agreement acceptance, and administrative operations are logged with timestamps, user identity, and IP address for accountability.
Data Processing Agreement
Every organization signs a Data Processing Agreement (DPA) before accessing the platform. The DPA defines data ownership, processing purposes, breach notification timelines, and your right to export or delete data.
Breach Notification
In the unlikely event of a data breach, we will notify affected organizations promptly and without undue delay, with details of the scope, impact, and remediation steps.
No Data Selling
We never sell your data, and child, family, and daycare records are never shared with advertisers or used for advertising. Your data is processed solely to provide the NestliCare service.
Have a security question?
If you have questions about our security practices or want to report a vulnerability, contact us at [email protected]
Last updated: April 13, 2026