Data Processing Agreement
Last updated 5 October 2026
This agreement meets the requirements of Article 28 of the UK GDPR. It applies automatically when your nursery uses ChildHive and forms part of our Terms of Service. You do not need to sign anything separately, but we are happy to provide a signed copy on request.
1. The parties and their roles
The nursery or organisation using ChildHive ("the Nursery") is the controller of the personal data it keeps in ChildHive. Forest Village Kindergarten Ltd, trading as ChildHive ("ChildHive") is the processor and processes that data only on the Nursery's behalf.
2. Details of the processing
- Subject matter and purpose: providing ChildHive nursery management software, including records, observations, invoicing, communication with parents and AI drafting features.
- Duration: for as long as the Nursery uses ChildHive, plus the deletion period in section 10.
- People whose data is processed: children, parents, carers and emergency contacts, nursery staff, and visitors recorded in the visitor log.
- Types of data: names, contact details, dates of birth, photographs, attendance, observations and development records, invoices and funding, signatures, staff rotas and certifications.
- Special category data: health information including allergies, medication, accidents and incidents, and special educational needs, and ethnic origin where a form the Nursery sends to parents asks for it.
3. ChildHive's obligations
ChildHive will:
- process the personal data only on the Nursery's documented instructions, which include these terms and the Nursery's use of ChildHive, unless the law requires otherwise;
- make sure everyone who can access the data is bound by confidentiality;
- apply the security measures in section 9;
- only use sub-processors as set out in section 6;
- help the Nursery respond to requests from individuals exercising their data rights;
- help the Nursery with data protection impact assessments and with its security and breach-reporting duties;
- delete or return the data when the service ends, as set out in section 10;
- make available the information needed to show it is meeting these obligations.
ChildHive will tell the Nursery if it believes an instruction breaks data protection law.
4. The Nursery's obligations
The Nursery is responsible for having a lawful basis to collect and use the personal data, for giving families and staff the privacy information they need, for the accuracy of the data, and for deciding who in the Nursery can access it.
5. AI processing
Where the Nursery uses AI features, the relevant photos and notes are sent to Google's paid Gemini API to produce a draft, which a member of Nursery staff must review before it is shared with a parent. The content is processed to produce the draft and is not used by Google to train its models.
6. Sub-processors
The Nursery authorises ChildHive to use the sub-processors below. ChildHive has a written contract with each one that protects the data to the same standard as this agreement, and remains responsible for their work.
| Provider | What they do | Where |
|---|---|---|
| Supabase | Database and file storage (records, photos, documents) | Ireland (EU) |
| Vercel | Hosting and running the ChildHive website and app | United States and global edge network |
| Clerk | Sign-in, accounts and two-factor authentication | United States |
| Google (Gemini API) | AI drafting of observations, reports, newsletters and label reading | United States |
| Resend | Sending emails (invoices, reminders, notifications) | United States |
| Calendly | Booking nursery viewings, where a nursery connects it | United States |
| Browser push services (Google, Apple, Mozilla) | Delivering push notifications to staff devices | United States |
ChildHive will give the Nursery at least 30 days' notice by email before adding or replacing a sub-processor. If the Nursery has a reasonable data protection objection, it can tell us and, if we cannot resolve it, cancel without penalty.
7. Transfers outside the UK
The main database and file storage are hosted in Ireland. Where a sub-processor processes data outside the UK, ChildHive makes sure the transfer is covered by UK adequacy regulations, the UK-US data bridge, or the UK International Data Transfer Addendum.
8. Personal data breaches
ChildHive will tell the Nursery without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting the Nursery's data. We will share what we know about what happened, the data affected, the likely consequences and what we are doing about it, so the Nursery can meet its own duty to report to the ICO within 72 hours where required.
9. Security measures
- Each nursery's data is logically separated, and access within a nursery is controlled by role.
- Two-factor authentication is required for admin accounts.
- Sensitive actions are recorded in an audit log.
- Data is encrypted in transit (TLS) and at rest by our hosting providers.
- Files are accessed server-side only, never directly from the browser.
- AI drafts must be reviewed by staff before reaching parents.
- Records follow retention rules, and deleted items are permanently removed after 60 days.
10. When the service ends
When the Nursery stops using ChildHive, it can ask for an export of its data. ChildHive will then delete the Nursery's personal data within 60 days, unless the law requires us to keep it. Backups held by our providers are overwritten in their normal cycle.
11. Audits
ChildHive will answer reasonable written questions about how it protects the Nursery's data. Where that is not enough to show compliance, the Nursery may carry out an audit on reasonable notice, at its own cost, no more than once a year, and in a way that does not compromise other nurseries' data.
12. General
If this agreement conflicts with the Terms of Service about personal data, this agreement wins. It is governed by the law of England and Wales. Questions about this agreement go to us on WhatsApp on +44 7445 396443.