Data processing agreement (DPA)
Last updated:
This data processing agreement (the "Agreement") forms part of the Clever Nursery terms of use. It applies as soon as the customer nursery records personal data in the app.clevernursery.com application. It is intended to meet the requirements of Article 28 of the GDPR and the UK GDPR where they apply, and the provisions of Algerian Law No. 18-07 as amended concerning processors. A signed copy can be requested at legal@clevernursery.com.
1. Parties and roles
- The Customer: the nursery (or the person running it) holding the Clever Nursery account. It is the controller: it determines the purposes and essential means of processing the data it records.
- The Processor: CIRTA AGENCY LTD, a company registered in the United Kingdom under number 15480678, 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom, publisher of Clever Nursery.
This Agreement does not cover processing for which CIRTA AGENCY LTD is itself the controller (accounts, subscription billing, security, support, marketing website), described in the privacy policy.
2. Subject matter, duration and nature
- Subject matter: providing the Customer with the Clever Nursery application for running an early-years setting.
- Duration: the period during which the Customer uses the Service, then the time needed to return and delete the data (clause 13).
- Nature of operations: hosting, storage, organisation, consultation, modification, export, backup, transmission (notifications and emails at the Customer's request), deletion.
3. Purposes
Providing the application features the Customer uses: children's and families' records, pre-registrations, classrooms, staff, attendance, daily care, activities, health, incidents, calendar and menus, family billing, expenses, communication and notifications, reports, parent space, imports, exports and backups; and the support, security and maintenance of those features.
4. Data subjects
Children enrolled or pre-registered; parents, legal guardians and other family members; people authorised to pick up children and emergency contacts; the nursery's staff and contributors; users invited by the Customer; the Customer's suppliers and contacts.
5. Categories of data
- Identification and contact details (names, dates and places of birth, sex, address, phones, emails, identification number and identity documents if the Customer records them, photos).
- Life at the nursery (enrolments, attendance, daily care, activities, notes, documents, photo and outings consents).
- Special categories: children's health data (allergies, diets, conditions, medication, blood type, doctor, vaccinations, special needs, incident reports), where the Customer records them.
- Staff data (position, contract, dates, attendance, absences, documents).
- The nursery's financial data (invoices, family payments, expenses, suppliers).
- Communication and traceability data (notifications, emails, audit log).
The Customer undertakes to enter only the data needed for its purposes and not to record data unrelated to caring for children and running the nursery.
6. The Customer's instructions
The Processor processes the data only on the Customer's documented instructions. These Terms, this Agreement and the use of the application's features by the Customer and its authorised users constitute its instructions. The Processor tells the Customer if it considers that an instruction infringes the applicable law. If the law to which it is subject requires other processing, it informs the Customer before the processing, unless the law prohibits this.
7. Confidentiality
People authorised by the Processor to process the data are bound by a duty of confidentiality. Access by the Processor's staff to the Customer's data is limited to what is needed for support, security and maintenance.
8. Security
The Processor implements the technical and organisational measures described in the annex, appropriate to the risk, in particular for health data. It adapts them as risks and techniques evolve. The Customer is responsible for the security of its own access (choice of users and roles, confidentiality of credentials, enabling two-factor authentication, protecting the exports and backups it downloads).
9. Sub-processors
The Customer gives general authorisation for the sub-processors listed on the subprocessors page. The Processor informs the Customer of any intended addition or replacement, by email or in the application, leaving a reasonable period to object (TODO — INFORMATION TO BE CONFIRMED: period). If a reasoned objection cannot be resolved, the Customer may terminate the Service. The Processor imposes equivalent data protection obligations on each sub-processor and remains liable to the Customer for their performance.
10. International transfers
The Processor is established in the United Kingdom. Application data is hosted on Contabo's infrastructure (location: TODO — CONFIRM THE CONTABO DATA CENTRE USED BY CLEVER NURSERY) and passes through Cloudflare's network. Some sub-processors are in the United States. Any transfer outside the European Economic Area, the United Kingdom or Algeria is covered by a mechanism recognised by the applicable law (adequacy decision, European Commission standard contractual clauses, UK addendum, Data Privacy Framework), or made under the conditions of Law No. 18-07 as amended.
11. Assistance to the Customer
As far as possible and taking into account the nature of the processing, the Processor helps the Customer:
- respond to data subjects' requests: the application lets the Customer view, correct, export and delete data; the Processor forwards to the Customer without delay any request it receives directly and does not answer it itself without instructions;
- ensure security, notify breaches and, where relevant, carry out a data protection impact assessment and consult the supervisory authority, by providing the information it holds.
12. Data breaches
The Processor notifies the Customer of any personal data breach affecting its data as soon as possible after becoming aware of it (maximum time: TODO — INFORMATION TO BE CONFIRMED, for example 48 hours), with the information available: nature of the breach, categories and approximate number of people and records concerned, likely consequences, measures taken or proposed, contact point. It adds information as it becomes available. The Customer, as controller, is responsible for notifying the competent authority and the people concerned where the law requires it (72 hours under the GDPR; the time limits of Law No. 18-07 as amended for the ANPDP).
13. End of processing: return and deletion
Before the Service ends, the Customer can export its data and download a full backup from the application. When the Service ends, the Processor deletes the Customer's data from the application within TODO — DEFINE THE RETENTION PERIOD, then from backups when their rotation cycle expires, unless a legal retention obligation applies. It confirms deletion in writing on request.
14. Audits
The Processor makes available to the Customer the information needed to demonstrate compliance with this Agreement (documentation, answers to security questionnaires). The Customer may, at its own expense and no more than once a year unless there is a proven breach or a request from an authority, have an audit carried out by an independent auditor bound by confidentiality, with reasonable notice of at least 30 days, without disrupting the Service or compromising other customers' data.
15. The Customer's obligations
The Customer warrants that it has a legal basis for each processing operation (especially for children's health data and photos), that it informs the data subjects, that it handles their requests, and that its instructions comply with the law that applies to it.
16. Liability, term and governing law
Each party's liability under this Agreement is governed by the terms of use, without prejudice to the rights data subjects have under the law. This Agreement ends with the Service, subject to clause 13. Governing law and jurisdiction: those of the terms of use (TODO — INFORMATION TO BE CONFIRMED). If this Agreement and the terms of use conflict on data protection, this Agreement prevails.
Annex — Technical and organisational measures
Measures in place at the date of the last update:
- Encryption in transit: HTTPS (TLS) on all connections, HSTS.
- Network: traffic routed through Cloudflare; server firewall limited to web and SSH access.
- Authentication: hashed passwords; TOTP two-factor authentication and passkeys available; one-time codes valid for 5 minutes; rate limiting; review of new nursery sign-ups.
- Access control: roles (director, office, educator, accountant, parent) checked by the server on every request; educators limited to their classrooms and parents to their children; health data never available to the accountant role; a guardian without custody receives no data about the child.
- Isolation: each nursery is a separate space; any access to another nursery is refused; this isolation is checked by automated tests on every route.
- Files: photos, documents and receipts are private and served only after an access check; file names are generated by the server; types and sizes are checked.
- Minimisation: health data and identity documents are never written to logs; no health data in notifications; analytics without record identifiers, names or amounts; automatic deletion of rejected or withdrawn pre-registrations after 12 months.
- Traceability: audit log of sensitive actions; closed incident reports cannot be edited (also enforced by the database); technical logs with a request identifier and rotation.
- Backup and portability: exports and full backup downloadable by the director, with optional AES-256 encryption.
- To be confirmed: database encryption at rest, automatic off-site server backups and their retention, monitoring and alerting, incident management procedure — TODO — INFORMATION TO BE CONFIRMED.