Saplyn Data Processing Addendum
Version: August 9, 2026 · Mommalyn Inc.
This Data Processing Addendum ("DPA") is incorporated into the Saplyn Terms of Service (the "Agreement") between Mommalyn Inc., a Delaware corporation ("Saplyn"), and the customer identified in the Agreement (the "Center"), and governs Saplyn's processing of Customer Data on the Center's behalf. If this DPA conflicts with the Agreement, this DPA controls as to the processing of Customer Data.
1. Definitions
- "Customer Data" means personal data that the Center or its Authorized Users (including Family Users acting within the Center's account) submit to the Service and that Saplyn processes on the Center's behalf — including records about children, their families and households, and the Center's staff. It excludes Saplyn Account Data.
- "Saplyn Account Data" means data Saplyn processes as a controller for its own purposes: user account and authentication data, Center subscription and billing data, usage analytics, and support communications, as described in the Privacy Policy.
- "Data Protection Laws" means all U.S. federal and state privacy laws applicable to the processing of Customer Data, including the Utah Consumer Privacy Act ("UCPA") and comparable state laws.
- "Personal data," "controller," "processor," "data subject," "sale," and "targeted advertising" have the meanings given by applicable Data Protection Laws.
- "Subprocessor" means a third party Saplyn engages to process Customer Data on Saplyn's behalf.
- "Security Incident" means a confirmed breach of Saplyn's security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Data.
2. Roles and scope of processing
2.1 Roles. For Customer Data, the Center is the controller (or, where the Center itself processes on behalf of another entity, a processor) and Saplyn is the Center's processor / service provider. For Saplyn Account Data, Saplyn is the controller.
2.2 Details of processing.
- Subject matter and nature: hosting, storage, transmission, display, and analysis of Customer Data as needed to provide the childcare-management features of the Service (enrollment, attendance and check-in, daily reports and media, health and medication records, incident reports, messaging, scheduling and staffing, compliance tracking, waitlist, billing, and reporting), as configured by the Center.
- Duration: the term of the Agreement plus the wind-down period in § 9.
- Categories of data subjects: children enrolled at or applying to the Center; their parents, guardians, household members, and emergency contacts; the Center's staff and applicants.
- Categories of personal data: identity and contact data; enrollment, attendance, and scheduling records; photos and media of children; daily care records; health-related data (allergies, dietary restrictions, medical information, immunizations, medication permissions and administration, incident reports); developmental observations; staff employment and credential records; family billing records (tokenized payment references only); messages and attachments; audio clips and transcripts of staff voice observations.
2.3 Sensitive data acknowledgment. The parties acknowledge that Customer Data includes personal data concerning children and health-related information. The Center is responsible for ensuring it has the legal right — including any consents required from parents or guardians — to collect this data and to direct Saplyn to process it.
3. Saplyn's obligations
Saplyn will:
(a) process Customer Data only on the Center's documented instructions — which are: the Agreement, this DPA, the Center's and its Authorized Users' configuration and use of the Service, and any other written instructions the parties agree — unless required by law, in which case Saplyn will notify the Center unless legally prohibited;
(b) not sell Customer Data, not share it for targeted advertising, not retain, use, or disclose it outside the direct business relationship with the Center or for any purpose (including training AI models) other than providing the Service, and not combine it with personal data from other sources except as permitted for service providers under Data Protection Laws. Saplyn may de-identify Customer Data in accordance with the de-identification standards of applicable Data Protection Laws and use the resulting data — which does not identify and cannot reasonably be used to identify any Center or person — to improve the Service and produce aggregate insights; Saplyn will maintain it in de-identified form, will not attempt to re-identify it, and will contractually prohibit recipients from doing so;
(c) ensure that every person Saplyn authorizes to process Customer Data is bound by confidentiality obligations;
(d) implement and maintain the technical and organizational measures in § 5;
(e) notify the Center if Saplyn determines it can no longer meet its obligations under Data Protection Laws, in which case the Center may direct Saplyn to stop and remediate any unauthorized processing;
(f) make available information reasonably necessary to demonstrate compliance with this DPA, and allow and contribute to audits as described in § 8.
4. The Center's obligations
The Center will: (a) have a lawful basis, and all consents and notices required by Data Protection Laws and its childcare-licensing obligations, for the Customer Data it collects and instructs Saplyn to process — including parental consents for photos and media of children where required; (b) use the Service's permission, role, and household controls to limit access to Customer Data appropriately, and keep its staff and family access lists current; (c) not instruct Saplyn to process Customer Data in violation of law; (d) respond to data subjects who contact the Center directly.
5. Security measures
Saplyn maintains a written security program appropriate to the nature of Customer Data, including at minimum:
- Encryption of Customer Data in transit (TLS) and at rest (via Saplyn's infrastructure subprocessors);
- Tenant isolation: every query is scoped to the Center's organization identifier; cross-tenant access is treated as a defect of the highest severity;
- Access control: capability-based, least-privilege authorization checks enforced in the data layer on every read and write, driven by the roles and custom permissions the Center configures; the employee floor and ownership checks are enforced server-side;
- Passwordless authentication (single-use emailed magic links) with database-backed sessions that can be revoked server-side;
- Audit logging of meaningful writes (who, what, when) available to demonstrate accountability;
- Payment credential isolation: full card and bank account numbers are collected directly by Stripe and never transit or rest on Saplyn systems;
- Secure development: code review, automated tests over authorization logic, and staged feature rollout;
- Personnel: access to production data limited to personnel who need it, under confidentiality obligations.
Saplyn may update these measures from time to time, provided the overall level of protection is not materially reduced.
6. Subprocessors
6.1 The Center authorizes Saplyn to engage the subprocessors listed at Subprocessor List (also published at saplyn.co/legal/subprocessors).
6.2 Saplyn will (a) bind each subprocessor by written contract to data protection obligations no less protective than this DPA, and (b) remain responsible to the Center for each subprocessor's performance.
6.3 Changes. Saplyn will give the Center at least 15 days' notice (email or in-app) before a new subprocessor processes Customer Data. If the Center reasonably objects on data-protection grounds and the parties cannot resolve the objection within 30 days, the Center may terminate the Agreement and receive a pro-rata refund of prepaid, unused fees.
7. Assistance
7.1 Data subject requests. Taking into account the nature of the processing, Saplyn will assist the Center in responding to data subject requests (access, correction, deletion, portability) — first through the Service's own tools (profile management, data export), and otherwise through reasonable cooperation. If a data subject contacts Saplyn directly about Customer Data, Saplyn will refer them to the Center without responding substantively, except where law requires otherwise.
7.2 Retention conflicts. The parties acknowledge that childcare-licensing laws may require the Center to retain records notwithstanding a deletion request; Saplyn will follow the Center's lawful instruction in such cases.
7.3 Assessments. Saplyn will provide reasonable assistance with data protection assessments the Center is legally required to conduct, insofar as they concern Saplyn's processing.
8. Security incidents; audits
8.1 Notification. Saplyn will notify the Center without undue delay, and in any event within 72 hours, after confirming a Security Incident affecting the Center's Customer Data, and will provide (as it becomes available) the nature of the incident, categories and approximate volume of data and data subjects affected, measures taken, and a contact point. Saplyn's notification is not an admission of fault. The Center is responsible for any notices to data subjects or regulators that the law requires of the controller; Saplyn will reasonably cooperate.
8.2 Audits. No more than once per 12 months (and additionally after a Security Incident), the Center may audit Saplyn's compliance with this DPA by written questionnaire and review of Saplyn's documentation. If Data Protection Laws grant the Center a broader audit right, an independent auditor reasonably acceptable to both parties may conduct it on 30 days' notice, during business hours, under confidentiality, at the Center's expense, without access to other customers' data.
9. Deletion and return
Upon termination or expiration of the Agreement, the Center may export Customer Data through the Service's export features during the 30-day wind-down period in the Agreement. After that period, Saplyn will delete Customer Data within 60 days, except (a) copies in encrypted backups, which are deleted on the backup rotation schedule, and (b) data Saplyn must retain by law, which remains protected by this DPA and is deleted when the requirement ends. On written request, Saplyn will confirm deletion.
10. Data location
Saplyn processes Customer Data in the United States. Saplyn will not transfer Customer Data outside the United States without the Center's prior written consent.
11. General
11.1 Term. This DPA lasts as long as Saplyn processes Customer Data.
11.2 Liability. Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Agreement.
11.3 Order of precedence. This DPA controls over the Agreement as to processing of Customer Data; the Agreement controls as to everything else.
11.4 Governing law. This DPA is governed by the law governing the Agreement (Delaware), except where the Data Protection Law of another jurisdiction mandatorily applies to a specific processing obligation.