Saplyn Data Processing Addendum
Version: August 31, 2026 · Mommalyn Inc.
This Data Processing Addendum ("DPA") is incorporated into the Saplyn Terms of Service (the "Agreement") between Mommalyn Inc., a Delaware corporation ("Saplyn"), and the customer identified in the Agreement (the "Center"), and governs Saplyn's processing of Customer Data on the Center's behalf. If this DPA conflicts with the Agreement, this DPA controls as to the processing of Customer Data.
1. Definitions
- "Customer Data" means personal data that the Center or its Authorized Users (including Family Users acting within the Center's account) submit to the Service and that Saplyn processes on the Center's behalf — including records about children, their families and households, and the Center's staff. It excludes Saplyn Account Data.
- "Saplyn Account Data" means data Saplyn processes as a controller for its own purposes: user account and authentication data, Center subscription and billing data, usage analytics, and support communications, as described in the Privacy Policy.
- "Data Protection Laws" means all U.S. federal and state privacy laws applicable to the processing of Customer Data, including the Utah Consumer Privacy Act ("UCPA") and comparable state laws.
- "Personal data," "controller," "processor," "data subject," "sale," and "targeted advertising" have the meanings given by applicable Data Protection Laws.
- "Subprocessor" means a third party Saplyn engages to process Customer Data on Saplyn's behalf.
- "Security Incident" means a confirmed breach of Saplyn's security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Data.
2. Roles and scope of processing
2.1 Roles. For Customer Data, the Center is the controller (or, where the Center itself processes on behalf of another entity, a processor) and Saplyn is the Center's processor / service provider. For Saplyn Account Data, Saplyn is the controller.
2.2 Details of processing.
- Subject matter and nature: hosting, storage, transmission, display, and analysis of Customer Data as needed to provide the childcare-management features of the Service (enrollment, attendance and check-in, daily reports and media, health and medication records, incident reports, messaging, scheduling and staffing, compliance tracking, waitlist, billing, and reporting), as configured by the Center.
- Duration: the term of the Agreement plus the wind-down period in § 9.
- Categories of data subjects: children enrolled at or applying to the Center; their parents, guardians, household members, and emergency contacts; the Center's staff and applicants; and people the Center or one of its families has invited but who have not accepted (prospective staff, a parent asked to connect an account, an adult invited into a household).
- Categories of personal data: identity and contact data; waitlist and enrollment application records (the child and applying adult's details, the program requested, the desired start date, any priority category claimed, the days and session length requested, deposit status, the language the family applied in, which of the Center's own public application links or QR codes the family arrived through, and whether the Center's emails to that family — a spot offer, a "still interested?" check-in, an automatic status update, a follow-up after a tour, the enrollment paperwork itself, the reminders that chase outstanding forms or an expiring document, or the link back to an application the family saved but never submitted — were accepted, delivered, refused or reported as spam, per recipient where more than one adult was written to — the fate of the message, never whether it was opened or clicked), including applications a family saved but never submitted, which stop being readable 14 days after they were last saved; enrollment (including conditional enrollments and the date a documentation grace period ends), attendance, and scheduling records; photos and media of children; daily care records; health-related data (allergies, dietary restrictions, medical information, immunizations, medication permissions and administration, incident reports), including documents a family returns against enrollment paperwork; developmental observations; staff employment and credential records; pending invitations into the Center or one of its households (the invited address, who sent it, what it grants, when it expires, and whether the invitation email was accepted, delivered, refused or reported as spam); family billing records (tokenized payment references only); messages and attachments; audio clips and transcripts of staff voice observations; and, where the optional billing assistant is enabled, the natural-language billing requests a director submits together with the model's structured response (retained 90 days).
2.3 Sensitive data acknowledgment. The parties acknowledge that Customer Data includes personal data concerning children and health-related information. The Center is responsible for ensuring it has the legal right — including any consents required from parents or guardians — to collect this data and to direct Saplyn to process it.
3. Saplyn's obligations
Saplyn will:
(a) process Customer Data only on the Center's documented instructions — which are: the Agreement, this DPA, the Center's and its Authorized Users' configuration and use of the Service, and any other written instructions the parties agree — unless required by law, in which case Saplyn will notify the Center unless legally prohibited;
(b) not sell Customer Data, not share it for targeted advertising, not retain, use, or disclose it outside the direct business relationship with the Center or for any purpose (including training AI models) other than providing the Service, and not combine it with personal data from other sources except as permitted for service providers under Data Protection Laws. Saplyn may de-identify Customer Data in accordance with the de-identification standards of applicable Data Protection Laws and use the resulting data — which does not identify and cannot reasonably be used to identify any Center or person — to improve the Service and produce aggregate insights; Saplyn will maintain it in de-identified form, will not attempt to re-identify it, and will contractually prohibit recipients from doing so;
(c) ensure that every person Saplyn authorizes to process Customer Data is bound by confidentiality obligations;
(d) implement and maintain the technical and organizational measures in § 5;
(e) notify the Center if Saplyn determines it can no longer meet its obligations under Data Protection Laws, in which case the Center may direct Saplyn to stop and remediate any unauthorized processing;
(f) make available information reasonably necessary to demonstrate compliance with this DPA, and allow and contribute to audits as described in § 8.
4. The Center's obligations
The Center will: (a) have a lawful basis, and all consents and notices required by Data Protection Laws and its childcare-licensing obligations, for the Customer Data it collects and instructs Saplyn to process — including parental consents for photos and media of children where required; (b) use the Service's permission, role, and household controls to limit access to Customer Data appropriately, and keep its staff and family access lists current; (c) not instruct Saplyn to process Customer Data in violation of law; (d) respond to data subjects who contact the Center directly.
5. Security measures
Saplyn maintains a written security program appropriate to the nature of Customer Data, including at minimum:
- Encryption of Customer Data in transit (TLS) and at rest (via Saplyn's infrastructure subprocessors);
- Tenant isolation: every query is scoped to the Center's organization identifier; cross-tenant access is treated as a defect of the highest severity;
- Access control: capability-based, least-privilege authorization checks enforced in the data layer on every read and write, driven by the roles and custom permissions the Center configures; the employee floor and ownership checks are enforced server-side;
- Passwordless authentication (single-use emailed magic links) with database-backed sessions that can be revoked server-side;
- Token-authorized public pages: where a family or an invited user reaches a page from an emailed link rather than a session — enrollment paperwork, an offer of a place, a household invitation, an invitation to a Center's staff or to a child's record, or an application saved before it was submitted — the link is the credential: a 192-bit token from a cryptographic random source, minted by the application rather than defaulted by the database, scoped to the single record it was issued for, and refused once that record is answered, archived, or expired. The public endpoints behind those links are rate-limited per link and per network address, and uploaded files are type-checked from their contents server-side against an allowed list before storage;
- Audit logging of meaningful writes (who, what, when) available to demonstrate accountability;
- Payment credential isolation: full card and bank account numbers are collected directly by Stripe and never transit or rest on Saplyn systems;
- Secure development: code review, automated tests over authorization logic, and staged feature rollout;
- Personnel: access to production data limited to personnel who need it, under confidentiality obligations.
- Support access: where Saplyn personnel need access to a Center's Customer Data — to set the Center up, or to investigate a problem the Center has reported — that access is granted per-Center rather than globally, requires a stated reason, expires automatically (7 days by default and no more than 30), and can be revoked at any time with immediate effect. Grant and revocation are recorded in the Center's own audit log, and every action taken under such access is attributed to it there, so the Center can distinguish what Saplyn did from what its own staff did. The Center may end any such access itself, at any time, from its own administration screens, without contacting Saplyn. Personnel without a current grant have no access to that Center's Customer Data through the Service. Support access does not extend to deleting a Center's organization or transferring its ownership.
Saplyn may update these measures from time to time, provided the overall level of protection is not materially reduced.
6. Subprocessors
6.1 The Center authorizes Saplyn to engage the subprocessors listed at Subprocessor List (also published at saplyn.co/legal/subprocessors).
6.2 Saplyn will (a) bind each subprocessor by written contract to data protection obligations no less protective than this DPA, and (b) remain responsible to the Center for each subprocessor's performance.
6.3 Changes. Saplyn will give the Center at least 15 days' notice (email or in-app) before a new subprocessor processes Customer Data. If the Center reasonably objects on data-protection grounds and the parties cannot resolve the objection within 30 days, the Center may terminate the Agreement and receive a pro-rata refund of prepaid, unused fees.
7. Assistance
7.1 Data subject requests. Taking into account the nature of the processing, Saplyn will assist the Center in responding to data subject requests (access, correction, deletion, portability) — first through the Service's own tools (profile management, data export), and otherwise through reasonable cooperation. If a data subject contacts Saplyn directly about Customer Data, Saplyn will refer them to the Center without responding substantively, except where law requires otherwise.
7.2 Retention conflicts. The parties acknowledge that childcare-licensing laws may require the Center to retain records notwithstanding a deletion request; Saplyn will follow the Center's lawful instruction in such cases.
7.3 Assessments. Saplyn will provide reasonable assistance with data protection assessments the Center is legally required to conduct, insofar as they concern Saplyn's processing.
8. Security incidents; audits
8.1 Notification. Saplyn will notify the Center without undue delay, and in any event within 72 hours, after confirming a Security Incident affecting the Center's Customer Data, and will provide (as it becomes available) the nature of the incident, categories and approximate volume of data and data subjects affected, measures taken, and a contact point. Saplyn's notification is not an admission of fault. The Center is responsible for any notices to data subjects or regulators that the law requires of the controller; Saplyn will reasonably cooperate.
8.2 Audits. No more than once per 12 months (and additionally after a Security Incident), the Center may audit Saplyn's compliance with this DPA by written questionnaire and review of Saplyn's documentation. If Data Protection Laws grant the Center a broader audit right, an independent auditor reasonably acceptable to both parties may conduct it on 30 days' notice, during business hours, under confidentiality, at the Center's expense, without access to other customers' data.
9. Deletion and return
Upon termination or expiration of the Agreement, the Center may export Customer Data through the Service's export features during the 30-day wind-down period in the Agreement. After that period, Saplyn will delete Customer Data within 60 days, except (a) copies in encrypted backups, which are deleted on the backup rotation schedule, and (b) data Saplyn must retain by law, which remains protected by this DPA and is deleted when the requirement ends. On written request, Saplyn will confirm deletion.
10. Data location
Saplyn processes Customer Data in the United States. Saplyn will not transfer Customer Data outside the United States without the Center's prior written consent.
11. General
11.1 Term. This DPA lasts as long as Saplyn processes Customer Data.
11.2 Liability. Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Agreement.
11.3 Order of precedence. This DPA controls over the Agreement as to processing of Customer Data; the Agreement controls as to everything else.
11.4 Governing law. This DPA is governed by the law governing the Agreement (Delaware), except where the Data Protection Law of another jurisdiction mandatorily applies to a specific processing obligation.