DATA PROCESSING AGREEMENT
This Data Processing Agreement (DPA) is made on the date of last signature below between:
Parties
- ER FIRST AID LIMITED trading as Hooty a company incorporated in England and Wales under No. 11397355 whose registered office is at 5 DUCKETTS WHARF, South Street, Bishop's Stortford, Essex, CM23 3AR, England (Supplier);
- User on pressing 'I AGREE' (Customer).
(each a party and together the parties)
Background
- The Supplier is a provider of Early Years Childcare Management software via Hooty Portal. (Services).
- The parties entered into an agreement for the provision of services on date user accepts terms by pressing 'I AGREE' (Agreement).
- The parties have agreed to enter into this DPA in relation to the processing of personal data by the Supplier in the course of providing the Services. The terms of this DPA are intended to apply in addition to and not in substitution of the terms of the Agreement.
Meanings
In this DPA, the following words are defined:
- Affiliate: any entity that directly or indirectly controls, or is controlled by, or is under common control with the subject entity. 'Control' for the purposes of this definition, means direct or indirect ownership or control of more than 50% of the voting interests of the subject entity.
- Data Protection Law: all laws and regulations, including laws and regulations of the European Union, the European Economic Area and their member states, Switzerland and the United Kingdom applicable to the Processing of Personal Data under the Agreement, including, but not limited to EU Directive 95/46/EC, as transposed into domestic legislation of each Member State and as amended, replaced or superseded from time to time, including by the GDPR and laws implementing or supplementing the GDPR; and to the extent applicable, the data protection or privacy laws of any other country.
- GDPR: Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (the EU GDPR); and the EU GDPR as implemented or adopted under the laws of the United Kingdom (UK GDPR) (General Data Protection Regulation).
- International Data Transfer Agreement: The International Data Transfer Agreement issued by the Information Commissioner for parties making Restricted Transfers.
- Personnel: in relation to a party, those of its employees, workers, agents, consultants, contractors, sub-contractors, representatives or other persons employed or engaged by that party on whatever terms.
- Subprocessor: any entity (whether or not an Affiliate of the Supplier, but excluding the Supplier's Personnel) appointed by or on behalf of the Supplier to process Personal Data on behalf of the Customer under this DPA.
- Working Day: any day, other than a Saturday, Sunday, or public holiday in England and Wales.
Terms such as "Data Subject", "Processing", "Personal Data", "Controller", and "Processor", "Supervisory Authority" and "Personal Data Breach" shall have the same meaning as ascribed to them in the Data Protection Law.
Processing Customer Personal Data
For the purpose of Data Protection Law, the Customer shall be the Controller and the Supplier shall be the Processor.
The Supplier and each Supplier Affiliate shall:
- comply with all applicable Data Protection Law in the Processing of Customer Personal Data; and
- only Process Personal Data on the Customer's documented instructions, unless Processing is required by any applicable law to which the Supplier is subject (in which case, the Supplier shall, to the extent permitted by applicable law, inform the Customer of such legal requirement before undertaking the Processing).
The Supplier and each Supplier Affiliate shall take reasonable steps to ensure the reliability of Personnel who have access to the Personal Data, ensuring in each case that such Personnel is subject to a strict duty of confidentiality (whether a contractual or statutory duty) and that they Process the Personal Data in compliance with all applicable law and only for the purpose of delivering the Services under the Agreement.
Security
The Supplier will establish data security in relation to the Processing of Personal Data under this DPA. The measures to be taken must guarantee a protection level appropriate to the risk concerning confidentiality, integrity, availability and resilience of the systems. The state of the art, implementation costs, the nature, scope and purposes of the Processing, as well as the probability of occurrence and the severity of the risk to the rights and freedoms of natural persons must be taken into account. Such measures may include, as appropriate:
- the pseudonymisation and encryption of Personal Data;
- the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services;
- the ability to restore the availability and access to Personal Data in a timely manner in the event of a physical or technical incident; and
- a process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures for ensuring the security of the Processing.
In assessing the appropriate level of security, the Supplier shall take into account any risks that are presented by the Processing, in particular, from a Personal Data Breach.
The Supplier has laid down the technical and organisational measures in Schedule 2 of this DPA. Technical and organisational measures are subject to technical progress and further development. In this respect, the Processor may implement alternative adequate measures from time to time and shall notify the Customer in writing where it has done so.
Sub-Processors
The Customer authorises the Supplier and each Supplier Affiliate to appoint the Sub-processors listed in Schedule 3 (if any) and any new Sub-processors in accordance with the subsequent provisions.
With respect to each Sub-processor, the Supplier, or the Supplier Affiliate shall:
- carry out appropriate due diligence prior to the Processing by such Sub-processor to ensure that the Sub-processor is capable of providing the level of protection for Personal Data required by the terms of the Agreement and this DPA;
- enter into a written agreement with the Sub-processor incorporating terms which are substantially similar (and no less onerous) than those set out in this DPA and which meet the requirements of Article 28(3) of UK GDPR; and
- remain fully liable to the Customer for all acts or omissions of such Sub-processor as though they were its own.
Data Subject Rights
Taking into account the nature of the Processing, the Supplier and each Supplier Affiliate shall assist the Customer in implementing appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of the Customer's obligation to respond to requests for exercising Data Subjects' rights under the Data Protection Law.
The Supplier shall:
- promptly (and in any event, within 24 hours) notify the Customer if it (or any of its Sub-processors) receives a request from a Data Subject; and
- fully cooperate with and assist the Customer in relation to any request made by a Data Subject, under the Data Protection Law in respect of Personal Data Processed by the Supplier under the terms of the Agreement or this DPA.
Personal Data Breaches
The Supplier shall:
- notify the Customer without undue delay (in any event, no later than 72 hours) upon becoming aware of any Personal Data Breach affecting the Personal Data Processed by the Supplier under this DPA;
- provide sufficient information to enable the Customer to evaluate the impact of such Personal Data Breach and to meet any obligations on the Customer to report the Personal Data Breach to a Supervisory Authority and/or notify the affected Data Subjects in accordance with the Data Protection Law;
- provide the Customer with such assistance as the Customer may reasonably request; and
- cooperate with the Customer and take such reasonable commercial steps (as directed by the Customer) to assist in the evaluation, investigation, mitigation and remediation of each such Personal Data Breach.
Return and Deletion of Personal Data
Subject to the subsequent clause, the Supplier and each Supplier Affiliate shall promptly and in any event, within 30 days of the expiry or termination of the Agreement, delete or return all copies Personal Data Processed by the Supplier and/or its Sub-processors on behalf of the Customer by such means as the parties shall agree in writing.
The Supplier (and its Sub-processors) may retain Personal Data Processed under this DPA to the extent required by any applicable law to which the Supplier (or any Sub-processor) is subject and only to the extent and for such period as required by applicable law.
General Terms
- The Customer (Childcare provider) understands they are the data controller
- The supplier (ER FIRST AID LIMITED) is acting only as a processor
- The Childcare provider (Customer) Understands the Terms and conditions surrounding the deletion of their data.
- The customer agrees to the data deletion policy found in terms and conditions.
- Data is deleted on unsubscribing from the software.
- The childminder is aware they are responsible for backing up their own data.
Governing Law and Jurisdiction
This DPA will be governed by and interpreted according to the law of England and Wales and all disputes arising under the DPA (including non-contractual disputes or claims) shall be subject to the exclusive jurisdiction of the English and Welsh courts.
Reece Buckley
Director
ER FIRST AID LIMITED trading as Hooty
Date of signature: 17/02/2026