Data Processing Addendum
Last updated: July 20, 2026
This Data Processing Addendum (“DPA”) forms part of, and is subject to, the Terms & Conditions (the “Terms”) between Willow Peak Digital, LLC (“we,” “us,” “our,” the “Processor”) and the customer that uses Wylari (the “Customer,” the “Controller”). It describes how we process the personal data that the Customer stores in Wylari (the “Service”) on the Customer’s behalf. If there is a conflict between this DPA and the Terms regarding the processing of Customer Personal Data, this DPA controls.
1. Definitions
“Customer Personal Data” means personal data the Customer or its users enter into the Service about children, parents/guardians, authorized pickups, and staff, which we process on the Customer’s behalf. “Controller,” “Processor,” “Data Subject,” “processing,” and “personal data” have the meanings given under applicable data-protection law. “Sub-processor” means a third party we engage to help provide the Service that processes Customer Personal Data.
2. Roles & scope
For Customer Personal Data, the Customer is the Controller and Willow Peak Digital, LLC is the Processor, processing that data only to provide and support the Service. The subject matter, duration, nature and purpose of the processing, the types of personal data, and the categories of data subjects are set out in Annex A. This DPA does not apply to information we handle as a controller (for example, a provider’s own account and billing details, or emails of people who opt in to hear from us), which is governed by our Privacy Policy.
3. Customer responsibilities
- The Customer will comply with applicable data-protection laws as a Controller.
- The Customer is responsible for the accuracy of, and its right to provide, the Customer Personal Data, and for obtaining and maintaining all necessary consents and notices — including parental consent for children’s information where required (for example, under COPPA and applicable state laws) — before entering it into the Service.
- The Customer’s use of the Service, and the instructions it gives us through the Service, are its documented processing instructions to us.
4. Our obligations as Processor
We will:
- Process on instructions only. Process Customer Personal Data solely to provide and support the Service and on the Customer’s documented instructions, and not for our own purposes. We will never sell Customer Personal Data or use it for advertising.
- Confidentiality. Ensure that people authorized to process Customer Personal Data are bound by appropriate confidentiality obligations.
- Security. Implement and maintain the technical and organizational measures described in Annex C.
- Sub-processors. Engage sub-processors only as described in Section 5.
- Assistance. Taking into account the nature of the processing, provide reasonable assistance to help the Customer respond to data-subject requests and meet its own security, breach-notification, and impact-assessment obligations.
- Deletion/return. On the end of the Service, delete or return Customer Personal Data as described in Section 8.
5. Sub-processors
The Customer authorizes us to engage the sub-processors listed in Annex B to help provide the Service. We remain responsible for their performance of the applicable obligations in this DPA and will impose data-protection terms on them that are no less protective than those in this DPA. If we add or replace a sub-processor that processes Customer Personal Data, we will update Annex B and notify the Customer (for example, through the Service or by email); if the Customer reasonably objects on data-protection grounds, we will work in good faith to address the concern, and if we cannot, the Customer may stop using the affected feature or terminate as provided in the Terms.
6. Data-subject requests
Because the Customer is the Controller, requests from parents, guardians, staff, or other individuals to access, correct, or delete their information should be handled by the Customer. If we receive such a request directly, we will, where lawful, direct the individual to the relevant Customer and reasonably assist the Customer in responding, including through the tools available in the Service.
7. Personal-data breaches
If we become aware of a breach of security leading to the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of or access to Customer Personal Data, we will notify the Customer without undue delay and provide information reasonably available to us to help the Customer meet its own notification obligations. Our notification is not an acknowledgement of fault or liability. We will make commercially reasonable efforts to notify the Customer without undue delay after becoming aware of a confirmed breach affecting Customer Personal Data.
8. Return & deletion
The Customer may export Customer Personal Data available through the Service during the term. On termination, and on the Customer’s request within a reasonable period, we will delete or return Customer Personal Data, after which we will delete remaining copies — except for data we must retain to comply with law or that is preserved as part of the recordkeeping described in our Privacy Policy (for example, attendance and check-in records that childcare-licensing rules require to be kept). Retained data remains protected under this DPA for as long as we hold it.
9. Data location
The Service and Customer Personal Data are hosted on servers located in the United States. By using the Service, the Customer instructs us to process and store Customer Personal Data in the United States and by the sub-processors in Annex B. The Customer is responsible for ensuring it may lawfully allow this given the location of its data subjects.
10. Records & audits
We will make available to the Customer information reasonably necessary to demonstrate our compliance with this DPA. Given the nature of the Service and our size, audits will consist of us responding to the Customer’s reasonable written questions and providing available documentation; on-site audits are not offered.
11. Liability & term
Each party’s liability under this DPA is subject to the limitations and exclusions of liability in the Terms. This DPA takes effect when the Customer accepts the Terms and continues for as long as we process Customer Personal Data. Sections that by their nature should survive termination will survive.
Questions about this DPA: privacy@wylari.com.
Annex A — Details of processing
| Subject matter | Provision of the Wylari childcare-management Service to the Customer. |
|---|---|
| Duration | The term of the Customer’s account, plus any retention period described in the Privacy Policy or required by law. |
| Nature & purpose | Hosting, storing, organizing, displaying, transmitting, and otherwise processing Customer Personal Data as needed to operate the Service’s features (attendance/kiosk, communication, parent portal, progress records, meals, documents, payment record-keeping, and staff tools). |
| Categories of data subjects | Children in the Customer’s care; their parents/guardians and authorized pickups; and the Customer’s staff. |
| Types of personal data |
Children: name, preferred name, date of birth, photos, allergies, medications, immunization and health notes, general notes, and custom fields. Guardians & pickups: names, contact details (email, phone), relationship, and check-in PINs. Attendance: check-in/out times and actor, drawn signatures, health-screening answers, and (only if remote check-in is enabled and used) approximate device location at check-in. Content & records: messages, announcements, daily updates, progress observations/photos, meal plans, documents and acknowledgements, and tuition/fee record entries. Staff: name, role, work email, and PIN. |
| Special-category / sensitive data | May include children’s health-related information (allergies, medications, immunizations) that the Customer chooses to record. |
Annex B — Approved sub-processors
| Sub-processor | Purpose | Data processed | Location |
|---|---|---|---|
| Hostinger | Cloud hosting of the Service and its database | All Customer Personal Data | United States |
| Backblaze B2 | Encrypted cloud object storage of uploaded media & backups | Uploaded files including children's photos and signatures (Customer Personal Data) | United States |
| Email delivery (our mail server / email provider) | Sending account and notification emails (e.g., sign-in links, alerts) | Recipient email address and message content | United States |
| Browser push services (e.g., Google, Apple, Mozilla) | Delivering push notifications a user has opted into | Push subscription identifier and notification content | Global |
| LemonSqueezy | Subscription payment processing (when paid plans are active) | Provider account & billing details — not children/family records | United States / Global |
| MailerLite | Marketing emails to people who opt in (e.g., beta/launch interest) | Email addresses of opted-in contacts — not children/family records | United States / Global |
| Google Analytics (Google LLC) | Aggregate page/usage analytics on the staff-facing app & public pages | Usage, event, and device metadata — not children/family records | United States / Global |
| Microsoft Clarity (Microsoft Corp.) | Heatmaps & masked session-behavior analytics on the staff-facing app & public pages | Masked interaction metadata — not children/family records | United States / Global |
We will keep this list current and notify the Customer of changes as described in Section 5.
Annex C — Technical & organizational security measures
- Tenant isolation: each provider’s data is separated at the database level using row-level security, so one provider cannot access another’s data.
- Encryption in transit: traffic to and from the Service is encrypted using HTTPS/TLS.
- Credential protection: passwords are stored only as salted hashes; PINs are not stored in plain text.
- Authentication: optional two-factor authentication and device verification for owners and staff, and per-guardian PINs/device trust for the parent portal and kiosk.
- Access control: role-based access within each account, and access to production systems limited to authorized personnel on a need-to-know basis.
- Logging: server and security logging to help detect and investigate issues.
- Backups: routine backups of Service data to support recovery.
- Updates: we apply security updates to the Service and its infrastructure as part of normal operation.
These measures may evolve as the Service improves, provided the overall level of protection is not reduced.
