Skip to content

Data Processing Addendum

The processor agreement between Viva Longer LLC, doing business as Ashby Care, and the organization that accepts it. It forms part of the Terms of Service. Version dpa-2026-08-29.

Effective: 29 August 2026. Version: dpa-2026-08-29.

This Data Processing Addendum (“DPA”) is between the organization that accepts it (the “Center”) and Viva Longer LLC, a California limited liability company doing business as Ashby Care (“Ashby,” “Company,” “we”). It forms part of the Terms of Service (the “Terms”). If you do not agree to this DPA, do not use the Services.

This DPA is the same in every US jurisdiction. Childcare licensing rules (ratios, immunization holds, inspection packets) are not part of this DPA. They are configured in the product from the Center’s jurisdiction, not from a separate contract.

1. Parties and incorporation

The Center accepts this DPA by clickwrap at organization signup or when Ashby publishes a new version and an owner re-accepts. Electronic acceptance has the same effect as an original signature.

If this DPA conflicts with the Terms on data protection, this DPA controls.

2. Definitions

Customer Data” means personal information and other data the Center or its users submit to the Services, including child records, guardian and staff personal information, photos and video, attendance, incidents, messages, and billing identity for the Center’s subscription.

Personal Information” has the meaning given in applicable US state privacy law (including “personal information” under the CCPA/CPRA).

Services” has the meaning given in the Terms.

Subprocessor” means a third party engaged by Ashby to process Customer Data in order to provide the Services.

Capitalized terms not defined here have the meaning in the Terms.

3. Roles

State privacy laws (CCPA/CPRA and similar). Center is the Business (or controller). Ashby is a Service Provider / Processor. Ashby processes Personal Information only to provide the Services, on Center’s documented instructions, and not for Ashby’s own commercial purposes.

COPPA. Center operates the childcare program. Center is the primary operator vis-à-vis parents. Ashby provides software as a service provider to Center. Center is responsible for providing notice and obtaining verifiable parental consent. Ashby provides the screens and the audit trail. Ashby does not claim the COPPA school-authorization exception and does not warrant FERPA coverage.

Ashby never collects children’s data on its own initiative or for its own purposes (no sale, no advertising, no model training on Customer Data, no child profiling).

These two framings can both be true: COPPA operator/service-provider as to the program, and state-law processor as to the Business.

4. Details of processing

Subject matter: hosting and processing Customer Data so the Center can run roster, attendance, parent communication, billing, and related childcare-operations features.

Duration: for the subscription term and the retention/deletion periods in Section 12.

Nature and purpose: storage, retrieval, display, backup, security, support, and the processing needed to provide the Services the Center configures.

Data subjects: children enrolled at the Center; parents and guardians; Center staff and owners; emergency contacts and authorized pickup persons the Center records.

Categories of Personal Information: identifiers (name, email, phone, account IDs); commercial information (subscription billing identity, tuition tokens via Stripe); internet activity (product logs); geolocation only as coarse network data; audio/visual information (photos/video if a guardian opts in); professional information (staff roles, schedules); education or childcare records (attendance, rooms); health-related care notes and allergies the Center stores for care; inferences we do not create about children for advertising.

Sensitive / children’s data: children’s personal information, including name, date of birth, photos, and care notes, processed only to provide the Services.

5. Instructions and limitations

Ashby will:

  • Process Customer Data only to provide, maintain, secure, and support the Services, and as the Center instructs through the product or in writing.
  • Not sell or “share” Customer Data as those terms are used in the CPRA.
  • Not retain, use, or disclose Customer Data except as this DPA and the Terms allow, including as needed to comply with law.
  • Ensure persons authorized to process Customer Data are bound to confidentiality.
  • Not send children’s profiles, medical records, or photos to any AI provider. Optional draft-text features use non-child-sensitive inputs only.

The Center instructs Ashby to process Customer Data as the Center and its authorized users enter and configure it in the Services, including inviting staff and guardians and enabling optional features.

6. CPRA service-provider certification

Ashby certifies that it understands the restrictions in California Civil Code § 1798.140 applicable to service providers and will comply with them. Ashby will not combine Customer Data it receives from the Center with personal information received from or on behalf of another person, or that Ashby collects from its own interactions, except as permitted for a service provider (including to detect security incidents, to protect against fraud, or as otherwise allowed by the CPRA). The Center may take reasonable and appropriate steps to ensure Ashby uses Customer Data in a manner consistent with the Center’s obligations under the CPRA, including the audit rights in Section 15.

7. Confidentiality

Ashby will treat Customer Data as confidential and will not disclose it except to subprocessors as permitted here, to the Center’s authorized users, as the Center instructs, or as law requires. If Ashby is legally compelled to disclose Customer Data, it will notify the Center unless legally prohibited, so the Center may seek a protective order.

8. Security

Ashby maintains administrative, technical, and organizational measures appropriate to the risk, including:

  • Encryption in transit and at rest for personal information.
  • Tenant isolation so queries are scoped to the Center’s organization.
  • Least-privilege access for Ashby personnel; no casual production browsing of child records.
  • Authentication of users; role-based authorization resolved from the database.
  • Audit of access to child-sensitive records.
  • Segregation of child-sensitive data from product analytics.

No security program is perfect. The Center remains responsible for its own user access, device security, and the accuracy of the roles it assigns.

9. Subprocessors

The Center authorizes Ashby’s current subprocessors listed at ashbycare.com/legal/subprocessors. Ashby will give notice of material additions (email to the owner of record or an in-app banner). The Center may object on reasonable data-protection grounds within fifteen (15) days. If the parties cannot resolve the objection, the Center may terminate the affected Services.

Each subprocessor is bound to data-protection terms no less protective than this DPA for the data it receives. Ashby remains responsible to the Center for subprocessors’ performance of those obligations.

10. Location of processing

Customer Data is hosted in the United States (Google Cloud us-west1 for primary application data). This DPA does not authorize a transfer framework for the EEA, UK, or Switzerland. If Ashby later offers a country pack outside the United States, that pack will include a separate addendum.

11. Assistance with requests

Parents and consumers direct requests about a child’s or family’s records to the Center. Ashby will assist the Center (export, correction, deletion) so the Center can respond, in a manner consistent with the product and the law. Ashby does not become the parent’s customer-service desk for another Center’s records.

Ashby will also assist the Center, taking into account the nature of processing, with information reasonably needed for the Center’s own security, retention, and (where applicable) data-protection assessments, without giving the Center a right to browse another tenant’s data.

12. Retention and deletion

Retention follows the Center’s configured policy and the jurisdiction ruleset in the product, never shorter than a state licensing floor for that record type, and never indefinite. The clock is the longer of what is reasonably necessary for the disclosed purpose and that licensing floor.

When the Center offboards, Ashby will make Customer Data available for export, then delete it from primary systems. Backups expire on the backup cycle. “Deleted” means primary store plus backup expiry, not a promise that every cached copy on a user’s device is gone.

The Center should export records it must keep for licensing before deletion completes.

13. Incidents

Ashby will notify the Center without unreasonable delay after confirming a breach of Customer Data, with facts the Center needs to meet its own notice duties (categories of data, approximate counts, what we did, and what the Center should do next). We will not put children’s names, photos, or medical detail in the notice when a category description will do.

State attorney-general clocks and parent-notice duties are the Center’s as Business / operator. Our notice to the Center is designed so the Center can meet the shortest applicable clock. Details of our internal process are operational, not a public runbook.

14. Public websites

The Center will not upload or publish children’s personal information (including names, photos, videos, or other child-sensitive data) on any public Ashby Care site or subdomain. Ashby may remove violating content and suspend the public site. Consent to share a photo inside the authenticated parent experience is not consent to put that photo on the public internet.

15. Audits

On written request, Ashby will provide reasonable evidence of its security program (an overview of controls, not raw child records). On-site or production-data audits require a stated purpose, are logged, are limited to what is necessary, and are not a browsing right. The Center will not use audit rights to obtain another customer’s data.

16. Term

This DPA lasts for the term of the Terms and survives as needed to complete return and deletion of Customer Data.