Data Processing Agreement
Last updated: June 2026
Note: This Data Processing Agreement ("DPA") forms part of the Terms of Service between Bloomily Inc. ("Processor") and the childcare center ("Controller") using our services.
1. Definitions
"Personal Data" means any information relating to an identified or identifiable natural person, including but not limited to: child information, guardian contact details, staff information, and any other data processed through the Bloomily platform.
"Processing" means any operation performed on Personal Data, including collection, recording, organization, storage, adaptation, retrieval, use, disclosure, erasure, or destruction.
"Data Subject" means the individual to whom the Personal Data relates (children, parents/guardians, or staff members).
"Sub-processor" means any third party engaged by Bloomily to process Personal Data on behalf of the Controller.
2. Scope and Purpose of Processing
Bloomily processes Personal Data solely for the purpose of providing the childcare management services described in our Terms of Service, including:
- Managing child enrollment and attendance records
- Facilitating parent-teacher communication
- Generating daily activity reports
- Processing billing and payments
- Storing and sharing photos and media
- Managing staff schedules and records
- Providing analytics and reporting to the Controller
3. Categories of Data Subjects and Personal Data
3.1 Children
- Full name and date of birth
- Classroom and enrollment information
- Medical information (allergies, medications, conditions)
- Attendance records
- Photos and videos
- Daily activity and development reports
3.2 Parents/Guardians
- Full name and contact information
- Email address and phone number
- Billing and payment information
- Communication records
- Account credentials (hashed)
3.3 Staff Members
- Full name and contact information
- Employment role and classroom assignments
- Account credentials (hashed)
- Activity logs
4. Controller Obligations
The Controller (childcare center) agrees to:
- Ensure all Personal Data is collected lawfully and with appropriate consent from Data Subjects (or their legal guardians for children)
- Provide clear privacy notices to parents and staff about how their data will be processed
- Obtain necessary consents for photo and video collection and sharing
- Not upload any Personal Data that violates applicable laws or regulations
- Respond to Data Subject requests (access, correction, deletion) and inform Bloomily when assistance is needed
5. Processor Obligations
Bloomily agrees to:
- Process Personal Data only on the Controller's documented instructions (including for the purposes in Section 2), except that Bloomily may (a) process Personal Data as required by applicable law, (b) create and use de-identified or aggregated data that excludes children's directly-identifying information and that Bloomily does not attempt to re-identify, and (c) take steps to secure, maintain, prevent fraud in, and improve the Service. Bloomily does not sell Personal Data, does not "share" it for cross-context behavioral advertising, and does not train AI models on children's personal information
- Ensure that persons authorized to process Personal Data have committed to confidentiality
- Implement appropriate technical and organizational security measures
- Assist the Controller in responding to Data Subject requests
- Notify the Controller without undue delay (within 72 hours) upon becoming aware of a Personal Data breach
- Delete or return all Personal Data upon termination of services, at the Controller's choice
- Make available information necessary to demonstrate compliance with this DPA
6. Security Measures
Bloomily maintains reasonable administrative, technical, and organizational measures designed to protect Personal Data appropriate to its nature and sensitivity:
- Encryption: Personal Data is encrypted in transit (TLS) and at rest
- Access Controls: Role-based access controls that limit access to those who need it (for example, parents see only their own children's information)
- Data Isolation: Logical separation of customer data, enforced at the database level with row-level security
- Trusted Infrastructure: Hosted on major cloud providers (Supabase / AWS, Vercel) that maintain SOC 2 Type II certifications for their infrastructure
- Backups: Personal Data is backed up on a regular basis
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. We review and improve our safeguards over time.
7. Sub-processors
The Controller authorizes Bloomily to engage the following sub-processors:
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase (AWS) | Database hosting | USA |
| Vercel | Application hosting | USA |
| Stripe | Payment processing | USA |
| Resend | Email delivery | USA |
| Twilio | SMS notifications | USA |
| PostHog | Product analytics | USA / EU |
| Sentry | Error tracking and performance monitoring | USA |
| Google Analytics | Website analytics | USA |
| HubSpot | CRM and website lead tracking | USA |
| Intercom | Live chat & customer messaging | USA |
| Mapbox | Address autocomplete | USA |
| Upstash | Rate limiting | USA |
| Calendly | Demo scheduling | USA |
| QuickBooks Online | Accounting integration | USA |
Bloomily will notify the Controller before adding or replacing sub-processors, giving reasonable time to object based on data protection grounds.
8. Data Breach Notification
In the event of a Personal Data breach, Bloomily will:
- Notify the Controller without undue delay, and in any event within 72 hours of becoming aware of the breach
- Provide details of the breach including: nature of the breach, categories and approximate number of Data Subjects affected, likely consequences, and measures taken or proposed to address the breach
- Cooperate with the Controller in investigating and remedying the breach
- Document all breaches, including remedial actions taken
9. Data Subject Rights
Bloomily will assist the Controller in fulfilling Data Subject requests including:
- Access: Providing copies of Personal Data
- Rectification: Correcting inaccurate data
- Erasure: Deleting data upon valid request
- Portability: Exporting data in a machine-readable format
- Restriction: Limiting processing in certain circumstances
The Controller is responsible for responding to Data Subject requests. Bloomily provides tools within the platform to facilitate these requests.
10. Data Retention and Deletion
During the subscription: Data is retained for the duration of the service agreement and accessible to the Controller.
Upon termination:
- The Controller may export all data within 30 days of termination
- After 30 days, Bloomily will delete all Personal Data unless legally required to retain it
- Deletion will be complete within 90 days, including backups
- Upon request, Bloomily will provide written certification of deletion
11. International Transfers
Personal Data may be transferred to and processed in the United States. For transfers from the European Economic Area (EEA), UK, or Switzerland, Bloomily relies on:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- The UK International Data Transfer Agreement (IDTA) for UK transfers
Copies of the applicable transfer mechanisms are available upon request.
12. Audits
Bloomily will make available to the Controller information necessary to demonstrate compliance with this DPA. This includes:
- SOC 2 Type II audit reports from our infrastructure providers (available upon request under NDA)
- Security questionnaire responses
- Evidence of security certifications
The Controller may conduct audits at its own expense with reasonable notice, during business hours, and subject to confidentiality obligations.
13. Liability
Each party's liability under this DPA is subject to the limitations in the Terms of Service, including the security and confidentiality super-cap set out there. Bloomily's liability for a breach of its security or confidentiality obligations is governed by that higher cap rather than the general cap.
14. Term and Termination
This DPA shall remain in effect for the duration of Bloomily's processing of Personal Data on behalf of the Controller. Upon termination of the underlying service agreement, the provisions of this DPA relating to data deletion and confidentiality shall survive.
15. US State Privacy Laws — Service-Provider and Processor Terms
For Personal Data that Bloomily processes on the Controller's behalf, Bloomily acts as a "service provider" under the California Consumer Privacy Act (CCPA) and as a "processor" under other US state privacy laws (including those of Virginia, Colorado, Connecticut, Texas, Utah, Oregon, and Montana, and others as they take effect). For that Personal Data, Bloomily:
- processes Personal Data only for the limited and specified business purposes in Section 2 and the Terms of Service, and for no other purpose;
- does not sell Personal Data and does not "share" it for cross-context behavioral or targeted advertising;
- does not retain, use, or disclose Personal Data outside the direct business relationship with the Controller, or combine it with personal information from other sources, except as the law permits;
- provides at least the same level of privacy protection the law requires of the Controller, and will notify the Controller if it determines it can no longer meet its obligations;
- grants the Controller the right to take reasonable and appropriate steps to confirm that Bloomily uses Personal Data consistently with the Controller's obligations and to stop and remediate any unauthorized use;
- assists the Controller with consumer-rights requests, security, breach notification, and data-protection assessments; and
- imposes these obligations on its sub-processors by contract.
Bloomily certifies that it understands and will comply with these restrictions.
16. Contact Information
For questions about this DPA or to report data protection concerns:
- Email: privacy@bloomily.app
- Entity: Bloomily Inc.