PwC audited · GDPR compliant

Childcare Data Security & GDPR Compliance

That's Nembørn.

Nembørn is a childcare management platform built on GDPR-compliant infrastructure, audited by PwC. All children's data, photos, messages and observations are end-to-end encrypted in transit and at rest, stored on certified European servers, and protected by two-factor authentication and facial recognition for staff access.

GDPR compliant
EU servers
AES-256 encryption
TLS 1.3
ISO 27001
Annual PwC audit

End-to-end encryption. Every message and child record protected in transit and at rest.

Flexible data hosting. Certified hosting. Servers in your country of preference.

2FA + facial recognition. Staff authenticated before accessing any child data.

Annual PwC audit. Independent security & GDPR compliance review every year.

Secure API. OAuth 2.0, rate limiting, per-organisation isolation, TLS 1.3.

Parental privacy controls. Full GDPR Art. 15, 16 & 17 rights on request.

Where is Nembørn data hosted?

All customer data is hosted on certified servers. Nembørn’s infrastructure complies with ISO 27001 standards and undergoes annual third-party security audits.

Who audits Nembørn?

Nembørn undergoes annual security and compliance audits conducted by PwC. These audits cover data handling practices, encryption standards, access control policies, and GDPR compliance across all product features. Audit reports are available to enterprise customers on request.

How is access controlled?

Staff access to Nembørn requires two-factor authentication (2FA) and optional facial recognition. Role-based permissions ensure that each staff member only sees the children and data relevant to their room or group. All login events are logged and auditable by nursery administrators.

What encryption does Nembørn use?

Nembørn uses AES-256 encryption at rest and TLS 1.3 in transit for all data. Messages between staff and parents are end-to-end encrypted. The API uses OAuth 2.0 authentication, rate limiting, and per-organisation data isolation. All API traffic is encrypted via TLS 1.3.

Data subject rights & parental privacy controls

Nembørn provides full GDPR Article 15, 16 and 17 rights — parents can request access to, correction of, or deletion of their child's data at any time. Consent workflows are built into the onboarding process for both parents and staff. Nursery administrators can manage all consent records from a single dashboard.

Legal Information

Terms and Conditions

These Terms and Conditions govern your use of this website operated by Assemble World A/S.

By accessing and using this website, you agree to be bound by these Terms and Conditions.

Purpose of the Website

This website provides general information about the products and services offered by Assemble World A/S, including the Nembørn platform.

Use of the Website

You agree to use this website only for lawful purposes and in a way that does not infringe the rights of others or restrict their use of the website.

Intellectual Property

All content on this website, including text, graphics, logos, and design elements, is the property of Assemble World A/S or its licensors and is protected by applicable intellectual property laws.

You may not reproduce, distribute, or use any content without prior written permission.

No User Accounts on the Website

This website does not require users to create an account.

Access to our software platform is provided separately and may be subject to specific agreements and terms.

Disclaimer

The information provided on this website is for general informational purposes only.

While we strive to keep the content accurate and up to date, we make no warranties or guarantees of any kind regarding its completeness, accuracy, or reliability.

Limitation of Liability

To the fullest extent permitted by law, Assemble World A/S shall not be liable for any direct or indirect damages arising from the use of, or inability to use, this website.

Third-Party Links

This website may contain links to third-party websites.

We do not control or take responsibility for the content, policies, or practices of these external websites.

Changes to These Terms

We reserve the right to update or modify these Terms and Conditions at any time.

Any changes will be effective upon publication on this page.

Governing Law

These Terms and Conditions shall be governed by and interpreted in accordance with the laws of Denmark.

Contact

If you have any questions regarding these Terms and Conditions, please contact us at:

privacy@assemble.world

Cookie Policy

This Cookie Policy explains how Assemble World A/S may use cookies and similar technologies on this website.

What Are Cookies?

Cookies are small text files stored on your device when you visit a website. They help websites function properly and may also be used to improve the user experience.

How We Use Cookies

We may use cookies to:

  • Ensure the website functions properly
  • Improve the performance and usability of the website
  • Analyze website traffic and usage

Analytics Cookies

We may use third-party analytics tools, such as Google Analytics, to understand how visitors use our website.

These tools may collect information such as pages visited, time spent on the website, browser type, device type, and general usage data.

Managing Cookies

You can manage, block, or delete cookies through your browser settings.

Please note that disabling certain cookies may affect the functionality or performance of the website.

Changes to This Cookie Policy

We may update this Cookie Policy from time to time.

Any changes will be published on this page.

Contact

If you have any questions regarding this Cookie Policy, please contact us at:

privacy@assemble.world