Childcare Leadership Alliance Workforce Planning Dashboard
Workforce Planning Dashboard

Privacy Policy

Last updated 19 July 2026

1. Who we are

The Workforce Planning Dashboard (the tool, or the dashboard) is owned and maintained by YHRTK Pty Ltd, trading as Kairos HR and Your HR Toolkit (YHRTK, we, us, our). YHRTK builds, hosts, secures and maintains the platform.

The dashboard was developed in partnership with the Childcare Leadership Alliance (CLA).

When a childcare service uses the dashboard to plan its own workforce, that service decides what staff and enrolment information it enters and why. In that sense the service handles its own information through the tool, and YHRTK processes that information on the service's behalf.

For any question about this policy or about how the tool handles data, contact the Privacy Officer: privacy@yourhrtoolkit.com.au.

2. What this policy covers

This policy covers the hosted Workforce Planning Dashboard and the information a service enters or imports into it. It solely covers this tool and no other tools provided by YHRTK or CLA outside of this to services.

3. The information the tool handles

The tool is designed to hold only what it needs to plan a service's workforce. The information falls into a small number of groups.

Account information. An email address used to sign in, a stored password hash (the password itself is never stored), a display name, and sign-in timestamps.

Service information. The service's name, approval number, region, state and service type.

Staff (educator) information. For each staff member, the tool holds the staff member's name, current role, pay rate, employment start date and qualifications (including any qualification being worked toward), together with the operational detail needed to plan the workforce: employment type, hours, award and classification, visa expiry, leave balances and notes.

It also holds compliance dates such as first aid, CPR, blue card and child protection expiry so the tool can flag what is due. Each of these details is kept and used only for workforce planning: working out ratios and staffing needs, modelling service wage costs and tracking when qualifications and clearances fall due.

This use is directly related to the service's employment relationship with its staff, and aligns with the Australian Privacy Principles, under which personal information is used only for the purpose for which it was collected. A service may choose to de-identify its staff register at its own discretion. A service's records about its own current and former employees may also fall within the employee records exemption in the Privacy Act; whether that exemption applies to information handled through the tool is a matter for each service to confirm.

Children's (enrolment) information. Children are always held in de-identified form. By default a child is identified only by their initials (for example, A.S.). A service may instead choose to use an assigned Child ID (a code such as CH-1042). Either way, the tool stores a birth month and year only, together with the room and enrolment detail needed for planning. The full name and the exact date of birth (including the day of birth) are never stored.

System records. An audit log of who did what and when (which holds no plan content), and sign-in session records.

No sensitive information. No sensitive information (as defined in the Privacy Act 1988 (Cth)) is stored in the tool. The tool is not designed to collect it and its terms instruct users not to enter it. Users are asked not to type addresses, tax file numbers or similar detail into the tool, and imports are cleaned so that this information does not reach the servers (see section 5).

4. How we use the information

We use the information for one purpose: to run the workforce planning features of the dashboard. That means working out how many educators a service needs to meet ratios, showing where the gaps are, modelling a sustainable roster and its cost, and tracking compliance dates. We do not use the information for marketing, we do not sell it, and we do not use it for any purpose other than operating the tool.

By filling out the registration form your name, service name and email will be shared with the Childcare Leadership Alliance for the purposes of support to services in regional Queensland and for tracking project effectiveness.

5. How imports are treated

When a service imports a staff register or enrolment file, the tool processes the file as it is read so that unnecessary or identifying information never reaches the servers. Full child names are shortened, exact dates of birth are reduced to a birth month and year and detail the tool does not need such as addresses or tax file numbers is not carried through.

A service can also choose to de-identify its staff register on import, which shortens each staff name to initials and clears notes while keeping pay rates and qualifications so the planning components still function. Before an import, the service is asked to confirm that it has met its own consent, notification and privacy obligations.

6. Where your data is stored

The tool's database is hosted on Cloudflare in the Oceania region, and all data is encrypted at rest. The Oceania region is primarily located in Australia and may also include Cloudflare data centres elsewhere in Oceania. Across the region, the locations are:

  • Australia: Adelaide, Brisbane, Canberra, Hobart, Melbourne, Perth, Sydney
  • New Zealand: Auckland, Christchurch
  • Fiji: Suva
  • Guam: Hagåtña
  • New Caledonia: Nouméa
  • French Polynesia: Tahiti

Data does not leave the Oceania region in the ordinary course of running the tool.

The one exception is the AI features described in Section 9: when a user generates one of the AI reports, de-identified planning information is sent to the tool's AI provider for processing outside the region. Section 9 explains exactly what is and is not sent.

Cloudflare, our hosting provider, holds a SOC 2 Type II report and is certified to ISO/IEC 27001 (information security), ISO/IEC 27018 (protection of personal data in the cloud) and ISO/IEC 27701 (privacy information management). Cloudflare also handles personal information in line with the Australian Privacy Principles, including the requirements that apply when information is accessed or handled outside Australia.

7. How we keep information safe

  • Encryption: All data is encrypted at rest. If a drive were ever stolen or the storage accessed directly, the data would be unreadable without a valid login.
  • Passwords: Passwords are stored only as a secure hash, never in plain text.
  • Two step sign-in: Any user can turn on two-factor sign in, using an authenticator app or a code sent to their email. This is the strongest protection for anyone who can see sensitive information.
  • Each service sees only its own data: A user can only reach the services they belong to; access to any other service is blocked, and this is enforced on every action.
  • Role based access: A service can control what each of its users can see. For example, an assistant manager can be allowed to see the planning pages but not pay rates.
  • Privacy mode: A user presenting or working in a public space can turn on Privacy mode to blur names and pay rates on screen.
  • Internal identifiers: Records are keyed to hidden internal identifiers rather than to names in plain text.

8. Who we share information with

We do not sell information and we do not disclose it except as needed to run the tool. Two providers are involved in running the platform: Cloudflare, which hosts the database and the application (see Section 6), and Anthropic, which provides the AI features (see Section 9).

Each acts on our instructions under its own security and privacy commitments. We may also disclose information where we are required to by law.

9. How the AI features handle information

The dashboard's AI Insights Report and Gap Plan use AI to turn the planning results into insights: the workforce gaps, qualification gaps, strategies and suggested actions. The AI is part of how these features work, not a separate setting a service switches on or off. It runs automatically when a user opens or regenerates one of these reports; information is sent to the AI only at that point, and only in the de-identified form described below.

The AI captures insights: Every figure, ratio, gap and compliance date is worked out by the dashboard's own calculation engine. The AI is used only to turn those results into insights. It does not decide ratios, compliance, staffing or cost and it cannot add to or change the underlying numbers.

The information is de-identified before it is sent. Before anything is sent to the AI, the tool replaces personal detail with neutral codes and removes everything the AI does not need. Staff are referred to only as codes such as STAFF_001, never by name. The AI receives qualification levels, the qualification a person is working toward, role-relevant dates (visa expiry, and compliance dates such as first aid, CPR, blue card and child protection), and counts and gap totals.

AI Provider: The AI features are provided by Anthropic, the maker of Claude, through its commercial API. This is the one situation in which information, in the de-identified form described above, is processed outside the Oceania region, on Anthropic's infrastructure. Under Anthropic's commercial API terms, the information sent is used only to produce the tool's response and is not used to train Anthropic's models.

Storing AI drafts. To save re-sending the same request, an AI-generated draft may be held in the tool's own database on Cloudflare in the Oceania region as described in section 6.

10. What the Childcare Leadership Alliance can see

CLA's role is to support regional Queensland services. CLA only ever sees trends and de-identified data drawn from across the platform. This is used to understand where support is needed and to inform the supports CLA offers regional Queensland services. CLA does not, by default, see a service's named information or log in to a service's account.

Where a service needs in depth, one to one support, this happens only with the service's agreement and is provided in person or over a video call rather than by CLA logging directly into the service's account. A service may choose to grant CLA a user login, with permissions set by the service, but this is not the default and only applies if the service decides to set it up.

11. Responsibilities of participating services

Each participating service decides what information it puts into the tool and remains responsible for its own privacy obligations to its staff and to the families it cares for.

Notifying staff and parents. Because the tool holds staff information and de-identified enrolment information, a service should review its own privacy and data handling policies and consider whether it needs to update or issue a privacy notice to its staff and to parents before using the platform. Although the tool never stores children's full names or exact dates of birth, whether a notice to parents is required is a matter for each service to determine under its own policies and obligations.

Consent. A service is responsible for ensuring it has any consent it needs to enter staff and enrolment information into the tool.

Good data habits. A service should give each user their own login rather than sharing one, turn on two step sign-in for anyone who can see sensitive information.

12. Access, correction and your rights

A service can view and correct the information it holds in the tool at any time through its own account. The tool is not the primary record for any individual: staff and enrolment information originates in the service's own systems (for example, its enrolment records or its payroll and HR records). If a staff member or a family member wishes to access or correct their personal information, the service should deal with that request against those primary records in the first instance. Where we can assist a service in relation to information held in the tool, we will.

13. How long we keep information, return and deletion

We keep a service's information only for as long as the service uses the Workforce Planning Dashboard, unless a longer period is required by law or reasonably necessary to investigate, prevent or respond to a security incident, dispute or misuse of the tool. If a service's account is inactive for 24 consecutive months, YHRTK will treat the service as having stopped using the dashboard and will begin the return and deletion process set out below.

When a service stops using the dashboard, YHRTK will, on the service's written request or in accordance with the applicable agreement:

  • (a) make the service's information available for export or return in a reasonably usable format for 30 days after the service's access ends;
  • (b) securely delete or permanently de-identify the service's information from active systems within 30 days after the end of that 30-day export period;
  • (c) delete or permanently de-identify remaining copies held in backup systems within 90 days after deletion from active systems, unless retaining a copy is required by law; and
  • (d) on request, provide written confirmation that the deletion process has been completed.

A service may ask YHRTK to delete its information earlier. If it does, the service acknowledges that it may no longer be able to access or export that information through the dashboard.

CLA cannot direct YHRTK to delete a service's information unless CLA is authorised to do so under the agreement with that service or the service has given written authority. If CLA's program or funding arrangements end, that does not by itself give CLA a right to access, retain, return or delete a service's information.

YHRTK may retain limited audit, security and sign-in records for as long as reasonably necessary to maintain the security and integrity of the dashboard, meet legal obligations, or establish, exercise or defend legal claims. Any retained records will be protected under this policy and will not be used for unrelated purposes.

14. Changes to this policy

We may update this policy as the tool changes or as legal positions are finalised. The current version and its date appear at the top. Material changes will be communicated to CLA and to participating services.

15. Contact

For any question about this policy or about how the tool handles data, contact the Privacy officer at privacy@yourhrtoolkit.com.au.

Read the Terms of Use
Childcare Leadership Alliance · Workforce Planning Dashboard
Powered byYour HR Toolkit
Privacy Policy Terms of Use