# How access and privacy fit together

Understand the boundaries around family and academy information.

Type: Explanation

For: All users and academy owners

Before you start: Consult the applicable published privacy policy and agreement for legal commitments.

Reviewed: 2026-09-16

## Access has a purpose

An academy holds operational records about its participants, families and staff. Access follows academy membership, role, scope and verified relationships. A guardian can see permitted linked-participant records; a staff member does not automatically see every family or payroll record.

Private notes, pickup permissions and financial evidence have specific purposes. Put sensitive information in its intended restricted workflow rather than a broad notice, lesson summary or public enrolment description.

## Exports and deletion are workflows

An export creates another copy that the recipient must protect. Deletion requests require identity checks and may be affected by legal retention or holds. Leaving an academy, deleting a personal account and closing an academy are different requests.

Technical access controls are not a claim of independent certification. Owners still need clear operating policies, staff training and lawful use of the information they collect. Review applicable legal documents before a live rollout.

## Related guides

- [Request an export or account deletion](https://kelab.app/docs/privacy-requests.md)
- [Roles, relationships and permissions](https://kelab.app/docs/roles-access.md)
- [Record care, arrival and authorised pickup](https://kelab.app/docs/care-pickup.md)
- [Protect your account and manage access](https://kelab.app/docs/security.md)
