Data Processing Agreement

Last Updated: September 5, 2026

This Data Processing Agreement ("DPA") forms part of the Terms of Use between Greater Than Gravity LLC d/b/a Kiddo ("Kiddo") and the childcare organization using the Services ("Center"). It governs Kiddo’s processing of Personal Data on the Center’s behalf. Where this DPA conflicts with the Terms of Use, this DPA controls as to the processing of Personal Data.

Definitions

  • "Personal Data" means information relating to an identified or identifiable individual that Kiddo processes on the Center’s behalf through the Services, including information about children, parents, guardians, and Center staff.

  • "Processing" means any operation performed on Personal Data, including collection, storage, use, disclosure, and deletion.

  • "Applicable Privacy Law" means all privacy, data protection, and children’s-data laws applicable to a party’s processing of Personal Data, including state comprehensive privacy laws and the Children’s Online Privacy Protection Act ("COPPA") where applicable.

  • "Subprocessor" means a third party engaged by Kiddo to process Personal Data on the Center’s behalf.

  • "Security Incident" means a confirmed breach of Kiddo’s security leading to the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of or access to Personal Data.

Roles of the parties

The Center is the controller (or business) of Personal Data it submits to or collects through the Services. Kiddo is the processor (or service provider) acting on the Center’s documented instructions.

Kiddo separately acts as a controller for a limited set of data described in the Privacy Policy — Center account and billing information, and product analytics used to operate and improve the Services. This DPA does not apply to that controller-side processing.

Scope and instructions

Kiddo will process Personal Data only:

  • to provide, maintain, secure, and support the Services;

  • in accordance with the Center’s documented instructions, including the configuration choices the Center makes in the Services; and

  • as required by applicable law, in which case Kiddo will notify the Center unless legally prohibited.

Kiddo will not sell Personal Data, share it for cross-context behavioral advertising, retain or use it outside the direct business relationship with the Center, or combine it with data from other sources except as permitted by Applicable Privacy Law. Kiddo will notify the Center if it determines it can no longer meet its obligations under Applicable Privacy Law.

Advertising technologies are never applied to Personal Data. Kiddo uses advertising and conversion technologies on its public marketing website only. They are not present in the Kiddo application, and no Personal Data processed under this DPA is used for advertising, shared with any advertising platform, used to build or match audiences, or included in any offline-conversion or customer-list upload.

Nature of the data

Categories of data subjects:

Children enrolled or seeking enrollment; parents and guardians; Center staff and administrators.

Categories of Personal Data:

  • Child name, date of birth, and enrollment details;

  • Parent and guardian names, contact information, and communications;

  • Waitlist, tour, application, and enrollment records;

  • Payment records — Kiddo does not store full payment card numbers;

  • Center staff account information;

  • Health and related information about a child, where the Center collects it — including allergies, dietary restrictions and special needs recorded on an application, and requested documents such as immunization records, health forms, physician’s reports and emergency cards;

  • Documents uploaded by families in response to a Center’s document request, which may include identity documents such as birth certificates and, for Centers participating in subsidy or assistance programs, income documentation;

  • Free-text notes recorded by Center staff about a child or family.

Health and other sensitive data

Kiddo provides free-text fields, Center-configurable form fields, and a document-request feature. The Center determines what information it collects through these features, including whether to collect health information about a child. Kiddo does not require the collection of health information and does not determine what a Center asks families to provide.

Where a Center collects health or other sensitive information through the Services, Kiddo:

  • processes it solely to provide the Services to that Center, and not for analytics, marketing, model training, product development, or any other secondary purpose;

  • applies the security measures described below, including encryption in transit and at rest and role-based access controls;

  • restricts access to personnel who need it to operate or support the Services; and

  • does not disclose it except to the Center, to the Subprocessors listed below acting on Kiddo’s behalf, or where required by law.

The Center is responsible for ensuring it has a lawful basis and any required consent to collect health information about a child through the Services, for requesting only the information it needs, and for meeting any licensing, health, or recordkeeping obligations that apply to that information under state childcare regulations.

Confidentiality

Kiddo will ensure that personnel authorized to process Personal Data are bound by written confidentiality obligations and receive appropriate training. Kiddo limits access to Personal Data to personnel who need it to perform their duties.

Subprocessors

The Center authorizes Kiddo to engage Subprocessors to provide the Services. Kiddo’s current Subprocessors are:

  • Vercel Inc. – application hosting and delivery (United States)

  • Supabase, Inc. – database, storage, and authentication (United States)

  • Stripe, Inc. – payment processing (United States)

  • Twilio SendGrid – transactional and workflow email (United States)

  • Google LLC (Google Workspace) – direct email correspondence with Centers and families (United States)

  • PostHog, Inc. – product analytics, session replay, and error tracking (United States)

  • Functional Software, Inc. (Sentry) – application error monitoring (United States)

Kiddo will maintain this list and provide at least thirty (30) days’ notice before adding or replacing a Subprocessor, by updating this page and notifying the Center by email or in-app notice. If the Center reasonably objects to a new Subprocessor on data protection grounds, it may notify Kiddo within that period, and the parties will work in good faith to resolve the objection; if they cannot, the Center may terminate the affected Services without penalty for the remainder of the then-current term.

Kiddo remains responsible for its Subprocessors’ performance of the obligations in this DPA.

Security

Kiddo is a small company. It maintains technical and organizational measures appropriate to its size and to the nature of the Personal Data it processes. These currently include:

  • encryption of Personal Data in transit and at rest, as provided by our hosting and database providers;

  • role-based access controls and authentication requirements for users and personnel;

  • logical separation of each Center’s data, enforced at the database layer;

  • access to production systems limited to personnel who need it for their role; and

  • automated dependency and vulnerability scanning in our build pipeline.

Kiddo may change these measures as the Services evolve, provided it does not materially reduce the overall level of protection. Kiddo does not hold, and does not represent that it holds, any third-party security certification or audit report (such as SOC 2 or ISO 27001). Centers requiring a certified vendor should take this into account.

Security Incident notification

Kiddo will notify the Center without undue delay, and in any event within seventy-two (72) hours after confirming a Security Incident affecting that Center’s Personal Data. A Security Incident is confirmed when Kiddo has verified that one has in fact occurred; alerts, anomalies, suspected issues, and reports still under investigation do not by themselves start this period. The notification will describe, to the extent known at the time: the nature of the incident, the categories and approximate volume of Personal Data affected, the likely consequences, and the measures taken or proposed. Kiddo will provide reasonable assistance to the Center in meeting its own notification obligations. An initial notification may be supplemented as the investigation progresses.

Payment data

Payments are processed by Stripe. Cardholder data is transmitted directly to Stripe and Kiddo does not collect or store full payment card numbers. Stripe acts as an independent controller for payment data it processes.

Children’s data and COPPA

The Center is responsible for obtaining any parental consent required by COPPA or other Applicable Privacy Law before submitting a child’s Personal Data to the Services, and for providing any notices required to parents and guardians.

Kiddo does not collect Personal Data directly from children, does not permit children under 13 to create accounts, and does not use children’s Personal Data for advertising or to build advertising profiles. Kiddo processes children’s Personal Data solely to provide the Services to the Center. On the Center’s instruction, Kiddo will delete a child’s Personal Data in accordance with the Retention section below.

Data subject requests

Kiddo will, taking into account the nature of the processing, provide reasonable assistance to enable the Center to respond to requests from individuals to access, correct, delete, or restrict the use of their Personal Data. If Kiddo receives such a request directly, it will not respond substantively except to confirm receipt and direct the individual to the Center, unless legally required or instructed otherwise by the Center.

Retention, return, and deletion

Kiddo will retain Personal Data only as long as needed to provide the Services or as required by law. On termination of the Services, and on the Center’s written request, Kiddo will delete or return the Center’s Personal Data within thirty (30) days, except for data Kiddo is required to retain by law and data held in routine backups, which is purged within ninety (90) days. Backup copies remain subject to the security measures described above until they are purged.

Audits and evidence

On the Center’s reasonable written request, no more than once per twelve (12) month period, Kiddo will provide information reasonably necessary to demonstrate compliance with this DPA, including responses to a reasonable security questionnaire and copies of any third-party security assessments or certifications Kiddo then holds. The Center will treat all such information as Kiddo’s confidential information.

International transfers

Kiddo processes and stores Personal Data in the United States. All Subprocessors listed above process Personal Data in the United States.

Liability

Each party’s liability under this DPA is subject to the limitations, exclusions, and aggregate cap in the Terms of Use. Those limits apply to all claims arising out of or relating to this DPA, taken together with all claims under the Terms of Use, and are not additional to them.

This DPA does not create any separate or additional cause of action beyond those available under the Terms of Use. This DPA has no third-party beneficiaries. It is an agreement between Kiddo and the Center only; parents, guardians, children, and Center staff are not parties to it and acquire no rights to enforce it. Individuals seeking to exercise privacy rights should contact the Center, as described in the Data subject requests section above.

Order of precedence

In the event of a conflict between this DPA and the Terms of Use as to the processing of Personal Data, this DPA controls. Where a Center has signed a separate master services agreement or a negotiated data processing agreement with Kiddo, that agreement controls to the extent of any conflict.

Contact

Questions about this DPA, or to submit a request under it:

  • Email: support@kiddosoftware.com

  • Mail: Greater Than Gravity LLC dba Kiddo, 100 N Howard St Ste R, Spokane, WA 99201, USA