Data Processing Addendum
How Scanvale LLC processes personal data, including children’s data, on behalf of child care programs that use Tendroll™.
The short version
- The child care program is in control; Scanvale LLC processes data only on its instructions.
- No selling, no ads, no profiling of children, no AI training on their data.
- Encryption, per-program isolation, and restricted staff access.
- Breach notice within 72 hours of confirmation, and help notifying families.
- 30 days’ notice before new subprocessors, with a right to object.
1. Scope and parties
This Data Processing Addendum (“DPA”) forms part of the Tendroll Terms of Service between Scanvale LLC (“Processor”) and the Customer (“Controller”) and applies whenever Processor processes Customer Personal Data in providing the Service. Capitalized terms not defined here have the meanings in the Terms. If this DPA conflicts with the Terms regarding Customer Personal Data, this DPA controls.
“Customer Personal Data” means personal information in Customer Data, including Child Data. “Data Protection Laws” means all U.S. federal and state privacy, data security, and breach notification laws applicable to the processing, which may include the Children’s Online Privacy Protection Act, state student and child privacy laws, the New York SHIELD Act, and comprehensive state privacy laws, in each case as applicable.
2. Roles and instructions
Controller determines the purposes and means of processing. Processor is a service provider/processor and will process Customer Personal Data only: (a) to provide, secure, and support the Service; (b) on Controller’s documented instructions, which are the Terms, this DPA, and Controller’s configuration and use of the Service; and (c) as required by law, in which case Processor will inform Controller before processing unless the law prohibits it.
Processor will promptly tell Controller if it believes an instruction violates Data Protection Laws.
3. Processor restrictions
Processor will not:
- sell or share Customer Personal Data, or use it for targeted or cross-context behavioral advertising;
- retain, use, or disclose it for any purpose other than the business purposes in this DPA, or outside the direct business relationship with Controller;
- combine it with personal information received from other sources, except as permitted by Data Protection Laws to provide the Service;
- build profiles of children, or use Customer Personal Data to train general-purpose artificial intelligence models.
Processor certifies that it understands and will comply with these restrictions, and will notify Controller if it can no longer meet its obligations under Data Protection Laws.
4. Details of processing
| Subject matter | Provision of the Service to Controller |
|---|---|
| Duration | The subscription term, plus the export and deletion periods in Section 10 |
| Nature and purpose | Hosting, storage, retrieval, display, transmission, backup, and support of child care administrative records and communications |
| Data subjects | Children enrolled with Controller; their parents and guardians; Controller’s staff and administrators |
| Categories of data | Identifiers and contact details; attendance and check-in/out records; health check observations and incident reports entered by Controller; authorized pickup lists; staff shifts; messages and bulletin posts |
| Sensitive data | Children’s data, and any health information Controller chooses to record |
5. Confidentiality and personnel
Processor will ensure that personnel who access Customer Personal Data are bound by confidentiality obligations, are trained on data protection, and have access only as needed to provide the Service or support. Processor will not access Controller’s child records except to provide support Controller requests, to maintain and secure the Service, or as required by law.
6. Security measures
Processor will maintain reasonable administrative, technical, and physical safeguards appropriate to the sensitivity of children’s data, including at a minimum:
- encryption of data in transit (TLS 1.2 or higher) and at rest;
- logical isolation of each Controller’s data using row-level security;
- role-based access within the Service and least-privilege, multi-factor-protected access for Processor personnel to production systems;
- logging and monitoring of administrative access and security events;
- regular backups, and procedures to restore availability after an incident;
- secure development practices, dependency updates, and remediation of identified vulnerabilities;
- periodic review of these measures.
Controller is responsible for its own account security, including managing user access, using strong credentials, and removing departing staff promptly.
7. Subprocessors
Controller authorizes Processor to engage subprocessors. Processor will impose data protection terms on each subprocessor that are no less protective than this DPA and remains responsible for their performance. Current subprocessors:
| Subprocessor | Purpose | Location |
|---|---|---|
| Supabase, Inc. | Database, authentication, and file storage | United States |
| Vercel Inc. | Application and website hosting | United States |
| [Payment processor, e.g. Stripe, Inc.] | Subscription billing | United States |
| [Email / SMS provider] | Notification delivery | United States |
Processor will give at least 30 days’ notice (by email or on this page) before adding or replacing a subprocessor. Controller may object on reasonable data-protection grounds within that period; if the parties cannot resolve the objection, Controller may terminate the affected Service and receive a refund of prepaid fees for the remaining term.
8. Security incidents
Processor will notify Controller without undue delay, and in any event within 72 hours, after confirming a security incident involving unauthorized access to, or acquisition of, Customer Personal Data. The notice will describe, to the extent known, the nature of the incident, the data and individuals affected, likely consequences, and measures taken or proposed. Processor will take reasonable steps to contain and remediate the incident and will reasonably cooperate with Controller’s legally required notifications to families, staff, or regulators. Notice of an incident is not an admission of fault or liability.
9. Assistance and requests
Processor will provide features that let Controller access, correct, export, and delete Customer Personal Data, and will reasonably assist Controller in responding to requests from parents, guardians, staff, or regulators. If Processor receives a request directly from a data subject about Customer Personal Data, it will forward it to Controller and will not respond itself except to direct the requester to Controller, unless the law requires otherwise.
10. Return and deletion
Controller may export Customer Personal Data at any time during the term and for 30 days after termination. After that, Processor will delete or de-identify Customer Personal Data within 60 days, except as required by law. Data in backups will be deleted as backups are overwritten in the ordinary course, and will remain protected by this DPA until then. On written request, Processor will confirm deletion in writing.
11. Audits and information
On Controller’s reasonable written request, no more than once per year (or after a security incident), Processor will provide information reasonably necessary to demonstrate compliance with this DPA, such as a completed security questionnaire and a summary of its security measures. Any on-site audit requires 30 days’ notice, must occur during business hours, must be at Controller’s expense, and is subject to reasonable confidentiality and security conditions.
12. Legal requests
If Processor receives a subpoena, court order, or government request for Customer Personal Data, it will (unless legally prohibited) promptly notify Controller so Controller can seek a protective order, and will disclose only the minimum data legally required. Nothing in this DPA prevents Processor from reporting suspected child abuse or exploitation where required by law.
13. Liability and term
Each party’s liability under this DPA is subject to the exclusions and limitations of liability in the Terms. This DPA remains in effect for as long as Processor processes Customer Personal Data.
Questions about this DPA: support@tendroll.com.