Effective date: 1 July 2026
This page is for parents, guardians and staff of a childcare service that uses Meadow. It explains, in plain language, what Meadow does with the records your service keeps in it. It is a summary. The data-processing agreement between your service and Meadow is the binding document.
1. Who is responsible for what
Your service is the controller. It decides what to record about your child, your family and its staff, who in the service may see it, and how long to keep it. Irish law requires it to keep many of these records (in particular the Child Care Act 1991 (Early Years Services) Regulations 2016, Regulations 15, 16 and 24), and its ECCE and National Childcare Scheme funding agreements add more.
Meadow is the processor. Meadow Labs Limited (CRO 812413, 7 Bearú Mhór, Cois Bhearú, Athy, Co. Kildare, R14 D363) stores and processes those records only on your service's instructions, which are the settings and actions its authorised staff take in Meadow, under a written data-processing agreement.
Your own login is different. Your Meadow account, the notifications we send you, our website and our billing are Meadow's own responsibility and are covered by the Meadow Privacy Policy.
2. What your service can record in Meadow
Your service decides which of these it uses. Items marked health are special-category data under Article 9 GDPR.
Children
- Name, date of birth, gender, nationality, languages spoken, home address and Eircode, who the child lives with, who holds parental responsibility.
- Enrolment: enquiry, waitlist, start date, room, plan and booking pattern, leave date and reason, notes.
- Health: allergies, penicillin tolerance, dietary needs, immunisation record, health notes, the child's doctor and their contact details, AIM (Access and Inclusion Model) support, medication administered with dose.
- Daily records: check-in and check-out times, room moves, absences, planned departures, activities (meals, sleep, nappies, toileting, medication, learning observations and similar), free-text notes.
- Funding: whether the child is registered for ECCE or the National Childcare Scheme, the NCS CHICK reference, registration dates and hours, attendance figures used for funding returns.
- Photos and video: an optional profile photo, and photos or video shared in newsfeed posts and messages.
- Forms: answers to enrolment, consent and other forms the service sends to families (the questions are set by the service).
- Prospective families: enquiry and waitlist details, including how the family heard about the service.
Parents, guardians and other family contacts
- Name, email, phone, relationship to the child, whether they are authorised to collect the child, emergency-contact status.
- Messages exchanged with the service, comments and reactions on newsfeed posts, RSVPs to events, form submissions.
Service staff
- Name, job title, date of birth, phone number, home room, notes entered by the service, daily attendance, absences, and the record of which staff member recorded each entry.
Meadow has no fields for PPS numbers, ethnicity, religion, family financial details, or Garda-vetting records.
3. What Meadow does, and does not do, with it
As processor, Meadow:
- acts only on your service's instructions and the data-processing agreement;
- keeps each service's data separate from every other service's;
- gives your service the tools to honour your rights: it can correct any record, withdraw a child, remove a parent's access, delete a child record permanently (with a reason kept for audit), remove a message, and delete its whole workspace;
- tells your service without undue delay if we become aware of a personal-data breach affecting its data;
- uses only the sub-processors in section 5 and gives your service notice before adding one;
- deletes or returns your service's data when its agreement with us ends (section 6).
Meadow does not sell personal data, build profiles, use facial recognition, use children's data or photos to train any artificial-intelligence model, or send data to the Early Years Hive, Pobal or the Department of Children, Disability and Equality. Your service enters or uploads its own funding returns; Meadow only produces the figures it uses to do so.
There is no advertising inside Meadow, and no tracking for advertising purposes. Nothing your service records in Meadow is used for advertising. We do advertise Meadow itself on our public website, meadowapp.ie, which is a separate matter from the data we process for your service and is explained in our Cookie Policy.
Meadow's own staff access your service's data only to provide support, investigate a problem, or where the law requires it. Such access is read-only and limited to named administrators. When an engineer investigates a problem they may use AI assistants (Anthropic's Claude, OpenAI's Codex and ChatGPT) on business terms that bar the provider from training on our data; they are listed in section 5.
4. Photos and video of children
- Photos and video are recorded by your service's staff and shared only with the audience the staff member chooses: a room, named children, or the whole service. A parent sees only posts addressed to their child's room or to their child.
- Profile photos and message photos are stored in private storage. Every view is authorised against the viewer's permissions and served through short-lived signed links. Video, where your service has it switched on, is transcoded and streamed by an EU-based provider using signed, expiring playback tokens.
- Photos are not analysed, tagged, or used for any purpose other than showing them to the intended audience.
- Whether a child may be photographed at all is your service's decision under its own policy on photographic and recording devices, which the 2016 Regulations require it to hold together with the form of parental consent. Meadow does not photograph children and does not obtain consent on the service's behalf.
5. Who else handles it
Meadow uses a small number of providers to run the service, each under a written contract and, where they are outside the EEA, the European Commission's Standard Contractual Clauses and the EU-US Data Privacy Framework where certified:
| Provider | Role | Location |
|---|---|---|
| Supabase | Database, sign-in, file storage | Ireland |
| Vercel | Hosts the web application | Dublin, Ireland |
| Bunny.net | Video hosting and transcoding, where your service uses video | EU (Slovenia) |
| Resend | Sends email such as invitations and notifications | Ireland |
| Expo, with Apple and Google | Delivers push notifications to the app | US |
| Sentry | Error reporting; session replay is off | EU |
| Intercom | Support chat used by your service's staff; may contain what they attach | Ireland (EU hosting) |
| Anthropic and OpenAI | AI assistants used by Meadow's engineers; may see data while a problem is investigated; business terms, no training on inputs | US |
The full list, with contract and transfer details, forms part of the data-processing agreement between your service and Meadow.
6. How long it is kept
Your service decides. Meadow does not delete a service's records on its own, because Irish law sets minimum periods the service must honour, for example:
- child records, attendance, medication and incident records: at least 2 years after the child ceases to attend (2016 Regulations, Regs 15(4) and 16(2)(b));
- records and reports required under an ECCE funding agreement: 6 years after the end of the year they relate to (ECCE Funding Agreement 2025/26, clause 8.4), and other funding agreements set their own periods;
- Garda-vetting and reference records for staff: 5 years from the date the person starts (Reg 16(2)(a)). Meadow has no fields for these.
When your service's agreement with Meadow ends, we keep its data for 60 days so the service can export or ask us to return it, then delete it from live systems. Backups roll off on their normal cycle shortly after.
7. How it is protected
Every service's data is isolated by row-level security enforced in the database, so a query from one service cannot return another service's rows. Photos and files live in private storage and are served through signed, expiring links after a permission check. Data is encrypted in transit (TLS) and at rest. Access inside a service is role-based (owner, manager, senior practitioner, practitioner, parent), each with a fixed permission set. Multi-factor authentication is available to every user. Destructive actions, such as deleting a child record, require a typed confirmation and a recorded reason. Records carry who-changed-what audit fields. Attendance records are append-only; corrections are recorded as new entries.
8. Your rights, and who to ask
You have the right to ask for access to the personal data held about you or your child, to have it corrected or erased, to restrict or object to its processing, and to receive it in a portable format. A parent or guardian may exercise a child's rights on the child's behalf.
Ask your service first. It is the controller and must answer you. If you ask Meadow instead, we will pass your request to your service without delay and help it respond. We cannot act on it ourselves without the service's instruction.
You can complain to the Data Protection Commission, 21 Fitzwilliam Square South, Dublin 2, D02 RD28, www.dataprotection.ie.
9. The legal basis for these records
Your service decides the legal basis for the records it keeps, including the health information the 2016 Regulations require it to hold, and can tell you what that basis is. Meadow does not decide it.