Data protection
How we
handle data.
We build systems that hold records about children, families and staff. This page sets out how that data is treated — in plain language, because the people who have to trust us with it are not lawyers.
Who we are
Aderick LLP (UEN T26LL0888A), a limited liability partnership registered in Singapore, with its registered office at 60 Paya Lebar Road, #06-28, Paya Lebar Square, Singapore 409051.
Two different roles
This website. It sets no cookies, runs no advertising trackers and no third-party analytics. If you email us, we hold your message and your address for as long as it takes to deal with it.
Systems we build for a client. The data in them belongs to the client. They decide what is collected and why; we process it on their instructions to run and support the system. We do not sell it, mine it, or use it to train anything.
Where the data lives
On Google Cloud infrastructure via Firebase, in the Singapore region, encrypted in transit and at rest. Access is per-user and role-based: staff see the records their role requires and no more. Administrative access by us is limited to the partners and is used for support and maintenance, not routine viewing.
Children's data
Records about children are collected from and controlled by the setting that enrols them, under the consent the parent or guardian gives that setting. Photographs and video are treated as personal data: they are visible to a child's own parents and to the staff assigned to that child, and are not published anywhere public by us.
Retention
Client data is retained for as long as the client's agreement runs, plus any period they are required to keep records for by law — enrolment, employment and accounting records all carry statutory minimums. On termination we return or delete the data at the client's direction. Backups roll off on their own schedule.
Sub-processors
Google Cloud Platform and Firebase for hosting, storage, authentication and push notifications. Anything further — email delivery, payment processing — is agreed with the client before it is introduced.
Breaches
If personal data we hold is compromised, we notify the affected client without undue delay and support their notification obligations under Singapore's PDPA, Malaysia's PDPA, or whichever regime applies to them.
Your rights
If you are a parent or a member of staff at a setting that uses our software, the first point of contact is that setting — they hold the relationship and decide on access, correction and deletion requests. We support them in answering. If you would rather come to us directly, write to [email protected] and we will route it properly.
Last updated 19 September 2026.