Data Processing Agreement

Last updated: August 19, 2026

This Data Processing Agreement ("DPA") forms part of the Terms of Service between NestliCare LLC ("Processor", "we", "us") and your organization ("Controller", "you") and governs how we process personal data on your behalf. Sections 1–12 apply to every organization. Section 13 contains jurisdiction-specific terms that apply only where your organization is established in the named jurisdiction. This DPA is drafted in English; if it is ever presented in another language, the English version governs.

1. Definitions

"Personal Data" means any information relating to an identified or identifiable individual, including child information, parent/guardian information, and staff information entered into the Service.

"Processing" means any operation performed on Personal Data, including collection, storage, retrieval, use, disclosure, and deletion.

"Data Protection Laws" means all laws applicable to the Processing of Personal Data under this DPA, including (as applicable to you) the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection ("FADP"), South Africa’s Protection of Personal Information Act 4 of 2013 ("POPIA"), Australia’s Privacy Act 1988, Canada’s PIPEDA and provincial equivalents, and United States federal and state law including COPPA and state childcare licensing requirements.

2. Roles and Responsibilities

You (the daycare organization) are the Data Controller (in South Africa, the "responsible party"). You determine the purposes and means of processing Personal Data. NestliCare is the Data Processor (in South Africa, the "operator"). We process Personal Data only on your behalf and according to your documented instructions, including the instructions embodied in your configuration and use of the Service.

3. Data We Process

We process the following categories of Personal Data on your behalf:

  • Child information: Names, dates of birth, room assignments, allergies, dietary needs, health and immunization records you choose to store, emergency contacts, attendance records, daily activity logs, and photos uploaded by staff (where photo features are enabled for your organization).
  • Parent/guardian information: Names, email addresses, phone numbers, and messaging history.
  • Staff information: Names, email addresses, job titles, schedules, time entries, and employment-related records.

4. Purpose Limitation

We process Personal Data solely to provide the NestliCare service to you. We will not use Personal Data for any other purpose, including advertising, profiling, or selling to third parties.

5. Data Security

We implement appropriate technical and organizational measures to protect Personal Data, including:

  • Encryption of data in transit (TLS/SSL) and at rest
  • Role-based access controls ensuring users only access data they are authorized to view
  • Time-limited, signed URLs for all uploaded media — no publicly addressable storage of photos or documents
  • Secure cloud infrastructure hosted on Amazon Web Services (AWS)
  • Regular security monitoring and updates

We ensure that personnel authorized to process Personal Data are bound by confidentiality obligations.

6. Sub-Processors

You provide general authorization for us to engage the following sub-processors to provide the Service:

  • Amazon Web Services (AWS): Cloud hosting, database, and media storage (United States, us-east-2 region)
  • Cloudflare: Content delivery, security, and bot protection for our websites
  • Stripe (and Adyen, where enabled for your organization): Tuition payment processing and payouts. Payment processors act as independent controllers for the payment data they collect directly.
  • Twilio SendGrid: Transactional email delivery (notifications, invitations, receipts)
  • Apple and Google: Push notification delivery to mobile devices and browsers
  • Anthropic: AI-generated content (daily summaries, lesson drafting, admin assistant), only when your organization uses those features. AI providers may not use your data to train their models.

We remain fully liable to you for the performance of each sub-processor, and we impose data protection obligations on each sub-processor that are no less protective than those in this DPA. We will notify organization administrators (by email or in the app) before adding or replacing a sub-processor, and you may object on reasonable data protection grounds; if we cannot resolve a well-founded objection, you may terminate the affected part of the Service.

7. Data Breach Notification

In the event of a data breach affecting Personal Data, we will notify you without undue delay after becoming aware of the breach, so that you can meet any notification duties that apply to you as Controller (for example, the 72-hour supervisory-authority notification under GDPR Article 33). The notification will include what we know at the time about the nature of the breach, the categories of data affected, and the measures taken to address it, and we will update you as our investigation progresses.

8. Data Subject Rights

Taking into account the nature of the processing, we will assist you with appropriate technical and organizational measures in responding to requests from individuals (parents, staff) to exercise their rights under Data Protection Laws, including access, correction, deletion, restriction, objection, and data portability. Parents may request access to or deletion of their child’s data through you or by contacting us at [email protected]. If a data subject contacts us directly, we will refer the request to you rather than respond on your behalf, unless the law requires otherwise.

9. Data Retention and Deletion

We retain Personal Data for as long as your account is active. When your organization stops using the Service, Personal Data remains stored until you instruct us to delete it, so that it can still be exported, transferred, or reactivated, and so that records you are legally required to keep are not destroyed accidentally. Upon a verified deletion instruction from an organization owner, we will delete the organization’s Personal Data from our production systems within 90 days; backup copies then expire automatically on a rolling schedule of approximately 31 days, and copies of uploaded media files may persist in cloud storage for a period after database deletion while storage cleanup completes. We may retain data we are legally required to keep (such as financial records) and data needed to resolve disputes. You can export your records using the reporting and export tools in the Service and should do so before requesting deletion.

10. Data Ownership and Audit

You retain full ownership of all Personal Data processed through the Service. NestliCare claims no ownership rights over your data. You may export your data at any time.

On request, we will make available the information reasonably necessary to demonstrate compliance with this DPA, including our acceptance records, sub-processor list, and summaries of our security measures. Where Data Protection Laws give you a right to audit, we will first satisfy it through documentation and written responses; on-site audits require reasonable notice, occur no more than once per year absent a supervisory-authority requirement or a security incident, and are conducted at your expense.

11. Your Obligations

As the Data Controller, you are responsible for:

  • Having a lawful basis for the collection and processing of Personal Data you enter into the Service, including obtaining any consent from parents/guardians that your jurisdiction requires for the processing of their and their children’s personal data
  • Obtaining written photo/media consent from each parent or guardian before uploading photographs of their child to the Service, where photo features are enabled for your organization. You warrant that no child’s photo will be uploaded without prior parental consent on file, and that your consent records address the appearance of children in group photographs visible to other families.
  • Ensuring that data entered into the Service is accurate and lawfully collected
  • Managing user access and permissions within your organization, and promptly deactivating users who leave
  • Complying with the Data Protection Laws and childcare licensing requirements that apply to you in your jurisdiction — for example COPPA and state licensing rules in the United States, the GDPR and your national age of digital consent in the EU/EEA, the UK GDPR in the United Kingdom, and POPIA in South Africa
  • Conducting any data protection impact assessment your jurisdiction requires for your processing; on request we will provide reasonable assistance and information about the Service to support it

12. International Data Transfers

Personal Data is processed and stored in the United States. Where your organization is established in a jurisdiction that restricts international transfers, the transfer mechanisms in Section 13 for your jurisdiction apply. In case of conflict between an incorporated transfer mechanism and the rest of this DPA, the transfer mechanism prevails.

13. Jurisdiction-Specific Terms

Each part of this Section 13 applies only where your organization is established in the named jurisdiction, and supplements Sections 1–12 for that organization.

13.1 European Economic Area (GDPR)

  • This DPA constitutes the contract required by Article 28(3) GDPR. We will: process Personal Data only on your documented instructions (including with regard to international transfers); ensure confidentiality commitments (Section 5); implement Article 32 security measures (Section 5); respect the sub-processor conditions of Article 28(2) and (4) (Section 6); assist you with data subject rights (Section 8) and with your Article 32–36 obligations, including breach notification (Section 7) and data protection impact assessments (Section 11); delete or return Personal Data at the end of the provision of services (Section 9); and make available information necessary to demonstrate compliance, allowing for audits (Section 10). We will inform you immediately if, in our opinion, an instruction infringes the GDPR.
  • For transfers to the United States, the European Commission’s Standard Contractual Clauses (Decision 2021/914, Module Two: Controller to Processor) are incorporated into this DPA by reference, with you as data exporter and NestliCare LLC as data importer; Annex I is completed by Sections 3 and 6 of this DPA, Annex II by Section 5, and the optional docking clause is excluded. If the European Commission adopts an adequacy decision covering our processing (including the EU–U.S. Data Privacy Framework, where we certify), we may rely on it in place of the Clauses for so long as it remains valid.
  • You are responsible for compliance with your national implementation of the age of digital consent (GDPR Article 8) and any national rules on children’s data and images that apply to your setting.

13.2 United Kingdom

Section 13.1 applies with references to the GDPR read as references to the UK GDPR and Data Protection Act 2018. For transfers to the United States, the Standard Contractual Clauses apply as amended by the UK International Data Transfer Addendum issued by the Information Commissioner’s Office, which is incorporated by reference and prevails over the Clauses to the extent of any conflict for UK transfers.

13.3 Switzerland

Section 13.1 applies with references to the GDPR read as references to the Swiss FADP, references to the supervisory authority read as the Federal Data Protection and Information Commissioner, and the Standard Contractual Clauses adapted as required by the FDPIC’s guidance for transfers from Switzerland (including extending protection to data of legal entities to the extent the FADP requires).

13.4 South Africa (POPIA)

  • NestliCare acts as your operator under sections 20 and 21 of POPIA and this DPA is the written contract those sections require. We process Personal Data only with your authorization, treat it as confidential, and maintain the security safeguards described in Section 5, consistent with section 19 of POPIA.
  • We will notify you where there are reasonable grounds to believe that Personal Data has been accessed or acquired by an unauthorized person, so that you can meet your obligations under section 22 of POPIA.
  • You consent, and warrant that you have the authority to consent, to the transfer of Personal Data to the United States under section 72(1) of POPIA on the basis that this DPA provides an adequate level of protection that effectively upholds principles substantially similar to the conditions for lawful processing under POPIA, including provisions substantially similar to section 72 governing onward transfers.
  • Special personal information and the personal information of children are processed only as necessary to provide the Service and subject to the safeguards in this DPA; you remain responsible for obtaining the consent of a competent person under section 34–35 of POPIA for children’s data you enter into the Service.

13.5 Australia

We will handle Personal Data consistently with the Australian Privacy Principles to the extent they apply to our processing on your behalf. You acknowledge that Personal Data is disclosed to us in the United States and are responsible for the notice and consent steps APP 8 (cross-border disclosure) requires of you; this DPA constitutes the contractual measures reasonable in the circumstances to ensure the information is handled consistently with the APPs.

13.6 Canada

This DPA constitutes the contractual protection required for transfers of Personal Data to a service provider outside Canada under PIPEDA and applicable provincial legislation (including Quebec’s Act respecting the protection of personal information in the private sector, as amended by Law 25). You are responsible for any notice to individuals that Personal Data may be stored and processed in the United States.

13.7 United States

You are responsible for complying with COPPA, your state’s childcare licensing and record-keeping requirements, and any applicable state privacy laws. Where a state privacy law applies to Personal Data in the Service, we act as your "service provider" or "processor" as defined by that law, and this DPA constitutes the contract it requires: we do not sell or share Personal Data, do not retain, use, or disclose it outside our direct business relationship with you, and do not combine it with data from other sources except as the law permits.

14. Governing Law

This DPA is governed by the laws of the State of Georgia, United States, consistent with the Terms of Service, except where an incorporated transfer mechanism or a mandatory provision of your jurisdiction’s Data Protection Laws requires otherwise.

15. Contact

For questions about this DPA or our data processing practices, contact us at [email protected].

Our representative in the European Union and the United Kingdom under Article 27 GDPR / UK GDPR is Data Protection Representative Limited (trading as DataRep), 77 Camden Street Lower, Dublin, D02 XE80, Ireland. Data subjects may contact us via DataRep at [email protected] (quote "NestliCare LLC" in the subject line) or www.datarep.com/data-request; postal inquiries can go to any DataRep location in the EU/EEA or UK, marked for ‘DataRep’.

Data Processing Agreement | NestliCare