Privacy and collection notice
How Bright Days handles information
Policy version 2026-09-v23-colour
Who is responsible
Bright Days operates this Bright Days service. Privacy enquiries, access requests and complaints can be sent to the system administrator .
Information collected
Bright Days stores account names and roles, optional profile pictures, child profiles including the selected favourite colour and assignments, weekday behaviour scores, absences, comments, averages, coins and rewards, notes and replies, uploaded documents, consent records, correction requests and security audit events. Audit events may contain usernames, IP addresses, dates, requested pages and the result of an action.
Why it is collected
The information is collected to record and review a child's progress, share authorised notes and documents, operate rewards, manage user access, respond to correction or export requests, protect the service and investigate suspected misuse or data breaches. Do not enter unrelated information into comments, notes or documents.
Who can see it
Access depends on both role and assignment to a child. Parents, teachers and stakeholders can only access children assigned to them. Notes and documents also use their selected audience. Child accounts receive a limited child-friendly view. Administrators manage users, security, retention, audits and correction requests but cannot open children's calendars, score histories, notes or documents through the site.
Storage and protection
Information, uploaded documents and profile pictures are stored on the organisation's Bright Days server. Controls include password hashing, multi-factor authentication for adult and administrator accounts, automatic account lockout, encrypted authentication secrets, child-specific authorisation and audit logging. Server administrators must also protect the IIS server, HTTPS certificates, backups and the App_Data folder.
Retention and deletion
The current live-data periods are 2555 days for scores and absences, 2555 days for documents, 2555 days for notes, and 2555 days for audit events. Only an administrator can change these settings or run a confirmed permanent-deletion process. An administrator can also permanently remove a complete child profile and its linked operational records. Deleted live records cannot be restored by Bright Days. Backup copies may remain until the organisation's protected backup retention period expires.
Access and correction
Parents can download an export for an assigned child and submit a correction request from the Data and privacy page. Users should contact the privacy contact if they cannot use the online process or wish to make a privacy complaint.
Data breaches
Suspected unauthorised access, loss or disclosure should be reported immediately to the privacy contact or system administrator. The organisation will contain the incident, preserve evidence, assess possible harm and make any legally required notifications.
Your acknowledgement
Before using Bright Days, each user is asked to confirm that they have read this notice and will only access or enter information required for their authorised role. This acknowledgement does not remove any privacy rights provided by law.