WylariWylari

Data Processing Addendum

Last updated: July 20, 2026

This Data Processing Addendum (“DPA”) forms part of, and is subject to, the Terms & Conditions (the “Terms”) between Willow Peak Digital, LLC (“we,” “us,” “our,” the “Processor”) and the customer that uses Wylari (the “Customer,” the “Controller”). It describes how we process the personal data that the Customer stores in Wylari (the “Service”) on the Customer’s behalf. If there is a conflict between this DPA and the Terms regarding the processing of Customer Personal Data, this DPA controls.

This document is a plain-language template provided for convenience; it is not legal advice. You are responsible for confirming it fits your obligations.

1. Definitions

Customer Personal Data” means personal data the Customer or its users enter into the Service about children, parents/guardians, authorized pickups, and staff, which we process on the Customer’s behalf. “Controller,” “Processor,” “Data Subject,” “processing,” and “personal data” have the meanings given under applicable data-protection law. “Sub-processor” means a third party we engage to help provide the Service that processes Customer Personal Data.

2. Roles & scope

For Customer Personal Data, the Customer is the Controller and Willow Peak Digital, LLC is the Processor, processing that data only to provide and support the Service. The subject matter, duration, nature and purpose of the processing, the types of personal data, and the categories of data subjects are set out in Annex A. This DPA does not apply to information we handle as a controller (for example, a provider’s own account and billing details, or emails of people who opt in to hear from us), which is governed by our Privacy Policy.

3. Customer responsibilities

4. Our obligations as Processor

We will:

5. Sub-processors

The Customer authorizes us to engage the sub-processors listed in Annex B to help provide the Service. We remain responsible for their performance of the applicable obligations in this DPA and will impose data-protection terms on them that are no less protective than those in this DPA. If we add or replace a sub-processor that processes Customer Personal Data, we will update Annex B and notify the Customer (for example, through the Service or by email); if the Customer reasonably objects on data-protection grounds, we will work in good faith to address the concern, and if we cannot, the Customer may stop using the affected feature or terminate as provided in the Terms.

6. Data-subject requests

Because the Customer is the Controller, requests from parents, guardians, staff, or other individuals to access, correct, or delete their information should be handled by the Customer. If we receive such a request directly, we will, where lawful, direct the individual to the relevant Customer and reasonably assist the Customer in responding, including through the tools available in the Service.

7. Personal-data breaches

If we become aware of a breach of security leading to the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of or access to Customer Personal Data, we will notify the Customer without undue delay and provide information reasonably available to us to help the Customer meet its own notification obligations. Our notification is not an acknowledgement of fault or liability. We will make commercially reasonable efforts to notify the Customer without undue delay after becoming aware of a confirmed breach affecting Customer Personal Data.

8. Return & deletion

The Customer may export Customer Personal Data available through the Service during the term. On termination, and on the Customer’s request within a reasonable period, we will delete or return Customer Personal Data, after which we will delete remaining copies — except for data we must retain to comply with law or that is preserved as part of the recordkeeping described in our Privacy Policy (for example, attendance and check-in records that childcare-licensing rules require to be kept). Retained data remains protected under this DPA for as long as we hold it.

9. Data location

The Service and Customer Personal Data are hosted on servers located in the United States. By using the Service, the Customer instructs us to process and store Customer Personal Data in the United States and by the sub-processors in Annex B. The Customer is responsible for ensuring it may lawfully allow this given the location of its data subjects.

10. Records & audits

We will make available to the Customer information reasonably necessary to demonstrate our compliance with this DPA. Given the nature of the Service and our size, audits will consist of us responding to the Customer’s reasonable written questions and providing available documentation; on-site audits are not offered.

11. Liability & term

Each party’s liability under this DPA is subject to the limitations and exclusions of liability in the Terms. This DPA takes effect when the Customer accepts the Terms and continues for as long as we process Customer Personal Data. Sections that by their nature should survive termination will survive.

Questions about this DPA: privacy@wylari.com.

Annex A — Details of processing

Subject matterProvision of the Wylari childcare-management Service to the Customer.
DurationThe term of the Customer’s account, plus any retention period described in the Privacy Policy or required by law.
Nature & purposeHosting, storing, organizing, displaying, transmitting, and otherwise processing Customer Personal Data as needed to operate the Service’s features (attendance/kiosk, communication, parent portal, progress records, meals, documents, payment record-keeping, and staff tools).
Categories of data subjectsChildren in the Customer’s care; their parents/guardians and authorized pickups; and the Customer’s staff.
Types of personal data Children: name, preferred name, date of birth, photos, allergies, medications, immunization and health notes, general notes, and custom fields.
Guardians & pickups: names, contact details (email, phone), relationship, and check-in PINs.
Attendance: check-in/out times and actor, drawn signatures, health-screening answers, and (only if remote check-in is enabled and used) approximate device location at check-in.
Content & records: messages, announcements, daily updates, progress observations/photos, meal plans, documents and acknowledgements, and tuition/fee record entries.
Staff: name, role, work email, and PIN.
Special-category / sensitive dataMay include children’s health-related information (allergies, medications, immunizations) that the Customer chooses to record.

Annex B — Approved sub-processors

Sub-processorPurposeData processedLocation
HostingerCloud hosting of the Service and its databaseAll Customer Personal DataUnited States
Backblaze B2Encrypted cloud object storage of uploaded media & backupsUploaded files including children's photos and signatures (Customer Personal Data)United States
Email delivery (our mail server / email provider)Sending account and notification emails (e.g., sign-in links, alerts)Recipient email address and message contentUnited States
Browser push services (e.g., Google, Apple, Mozilla)Delivering push notifications a user has opted intoPush subscription identifier and notification contentGlobal
LemonSqueezySubscription payment processing (when paid plans are active)Provider account & billing details — not children/family recordsUnited States / Global
MailerLiteMarketing emails to people who opt in (e.g., beta/launch interest)Email addresses of opted-in contacts — not children/family recordsUnited States / Global
Google Analytics (Google LLC)Aggregate page/usage analytics on the staff-facing app & public pagesUsage, event, and device metadata — not children/family recordsUnited States / Global
Microsoft Clarity (Microsoft Corp.)Heatmaps & masked session-behavior analytics on the staff-facing app & public pagesMasked interaction metadata — not children/family recordsUnited States / Global

We will keep this list current and notify the Customer of changes as described in Section 5.

Annex C — Technical & organizational security measures

These measures may evolve as the Service improves, provided the overall level of protection is not reduced.