Data Processing Agreement
Last updated August 20, 2026
MyLittleWorld Inc. ("MyLittleWorld," "Processor," "we," "us") Contact: privacy@mylittleworld.ca | Montreal, Quebec, Canada
This Data Processing Agreement ("DPA") forms part of, and is incorporated by reference into, the Terms of Service (the "Agreement") between MyLittleWorld and the licensed childcare organization that has registered for and uses the MyLittleWorld platform (the "Organization," "Controller," "you"). This DPA applies whenever MyLittleWorld processes Personal Data on the Organization's behalf in connection with the Services. Where a signed or countersigned copy of this DPA is required for the Organization's own compliance records, it is available on request to privacy@mylittleworld.ca; self-serve customers are otherwise bound by these terms upon acceptance of the Terms of Service.
1. Definitions
"Controller" means the party that determines the purposes and means of the Processing of Personal Data — here, the Organization.
"Processor" means the party that Processes Personal Data on behalf of, and under the documented instructions of, the Controller — here, MyLittleWorld.
"Personal Data" means any information relating to an identified or identifiable natural person that MyLittleWorld Processes on the Organization's behalf through the Services, including the categories described in Section 2.3.
"Data Subject" means the identified or identifiable natural person to whom Personal Data relates, including enrolled children, their parents/guardians, and the Organization's staff.
"Processing" means any operation performed on Personal Data, whether or not by automated means, including collection, recording, storage, organization, structuring, adaptation, retrieval, use, disclosure, combination, restriction, erasure, or destruction.
"Subprocessor" means any third party engaged by MyLittleWorld to Process Personal Data on MyLittleWorld's behalf in order to provide the Services, as further described in the standalone Subprocessor List.
"Data Breach" means a confirmed breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data.
"Applicable Data Protection Law" means, as applicable to the Controller and the Processing at issue: Quebec's Act respecting the protection of personal information in the private sector, as amended by Law 25; the federal Personal Information Protection and Electronic Documents Act (PIPEDA); the EU/UK General Data Protection Regulation (GDPR); and any other data protection law applicable to the Processing under this DPA.
2. Scope and Roles
2.1 Relationship of the parties. As between MyLittleWorld and the Organization, the Organization is the Controller of Personal Data submitted to or generated within the Services, and MyLittleWorld is the Processor. MyLittleWorld Processes Personal Data solely to provide, maintain, secure, and support the Services, and for no independent purpose of its own.
2.2 Data Subjects. The categories of Data Subjects whose Personal Data may be Processed under this DPA are: (a) children enrolled at the Organization; (b) parents and legal guardians of enrolled children; and (c) the Organization's staff and authorized users of the Services.
2.3 Categories of Personal Data. Depending on which features the Organization enables, Personal Data Processed may include: child profile data (name, date of birth, classroom assignment, attendance records, authorized-pickup designations, emergency contact information); health data (allergies, medications, dietary restrictions, and medical notes — a special/sensitive category of data, Processed only where the Organization enables the relevant feature and enters such data); daily report data (naps, meals, diapering/toileting, mood, and activity logs, including associated photos); photos and other media of children; guardian/parent contact information and payment/billing history; and staff employment and scheduling data.
2.4 Duration. MyLittleWorld Processes Personal Data for the duration of the Agreement, and thereafter only as necessary to comply with Section 8 (Data Return/Deletion) or a legal retention obligation.
3. Processor Obligations
3.1 Processing on instructions only. MyLittleWorld will Process Personal Data only on the Organization's documented instructions, including those embedded in the Agreement, the Organization's configuration of the Services, and any additional written instructions the Organization provides, unless Processing is otherwise required by law applicable to MyLittleWorld, in which case MyLittleWorld will inform the Organization of that legal requirement before Processing, unless the law prohibits such notice.
3.2 No independent use. MyLittleWorld will not use, sell, rent, disclose, or otherwise Process Personal Data for its own purposes, for advertising or marketing purposes unrelated to the Services, or for the benefit of any third party, other than as necessary to provide the Services or as instructed by the Organization.
3.3 Confidentiality of personnel. MyLittleWorld will ensure that personnel authorized to Process Personal Data are subject to a binding duty of confidentiality (whether contractual or statutory) and receive training appropriate to their role, and will limit access to Personal Data to personnel who require it to perform the Services (least-privilege access).
3.4 Assistance. MyLittleWorld will provide the Organization with reasonable assistance necessary to comply with the Organization's own obligations under Applicable Data Protection Law, including in relation to data protection impact assessments and consultations with supervisory or regulatory authorities, to the extent such assistance is reasonably required and relates to MyLittleWorld's Processing.
4. Security Measures
MyLittleWorld implements and maintains technical and organizational measures appropriate to the risk, including:
- Encryption of Personal Data in transit (TLS) and at rest.
- Per-organization tenant isolation enforced at the database layer through Postgres Row-Level Security, so that one Organization's data is not accessible to another.
- Password hashing using bcrypt; optional multi-factor authentication (MFA) available for staff accounts.
- Role-based access control governing what each user type can view or modify within the Services.
- Least-privilege access to production systems and data by MyLittleWorld personnel, limited to those with an operational need.
- Logging and monitoring designed to detect and respond to security incidents.
- Vendor and Subprocessor due diligence as described in Section 5.
These measures may be updated from time to time provided that any update does not materially reduce the overall level of protection.
5. Subprocessors
5.1 Authorization. The Organization provides general authorization for MyLittleWorld to engage the Subprocessors identified in the current Subprocessor List, for the purposes described therein.
5.2 Subprocessor obligations. MyLittleWorld will impose data protection obligations on each Subprocessor that are substantially consistent with those set out in this DPA, including confidentiality and security obligations, and will remain responsible to the Organization for each Subprocessor's Processing of Personal Data as if performed directly by MyLittleWorld.
5.3 Changes to Subprocessors. MyLittleWorld will provide the Organization with at least thirty (30) days' advance notice before adding a new Subprocessor or replacing an existing one, by updating the Subprocessor List and, where the Organization has subscribed to update notifications, by email. The Organization may object to a new Subprocessor on reasonable data-protection grounds by notifying privacy@mylittleworld.ca within the notice period; the parties will work in good faith to resolve the objection, failing which the Organization may terminate the affected Services as its sole remedy.
6. Assistance with Data Subject Rights
Where a Data Subject submits a request to exercise rights available under Applicable Data Protection Law (such as access, correction, deletion, or portability of Personal Data), MyLittleWorld will, taking into account the nature of the Processing: (a) promptly notify the Organization of the request if received directly by MyLittleWorld, without responding to the Data Subject except to direct them to the Organization, unless legally required to respond; and (b) provide reasonable technical and administrative assistance to enable the Organization to respond to the request within the timeframes required by Applicable Data Protection Law, including through Services functionality that allows the Organization to access, export, correct, or delete Personal Data directly.
7. Personal Data Breach Notification
7.1 Notification. MyLittleWorld will notify the Organization without undue delay, and in any event targeting no later than seventy-two (72) hours after confirming a Data Breach affecting the Organization's Personal Data, describing, to the extent then known: the nature of the Data Breach; the categories and approximate number of Data Subjects and records affected; the likely consequences; and the measures taken or proposed to address the Data Breach and mitigate its effects.
7.2 Cooperation. MyLittleWorld will cooperate with the Organization and provide information reasonably requested to enable the Organization to meet its own notification obligations to affected Data Subjects and to applicable regulators (including, as relevant, Quebec's Commission d'accès à l'information, the Office of the Privacy Commissioner of Canada, or an EU/UK supervisory authority).
7.3 No admission. Notification of, or response to, a Data Breach under this Section is not an admission of fault or liability by MyLittleWorld.
8. Data Return and Deletion on Termination
Upon termination or expiry of the Agreement, or upon the Organization's earlier written request, MyLittleWorld will, at the Organization's election, delete or return all Personal Data Processed on the Organization's behalf within ninety (90) days, except to the extent MyLittleWorld is required to retain copies under applicable law, in which case MyLittleWorld will continue to protect that Personal Data in accordance with this DPA and will limit further Processing to the purpose of that legal retention requirement.
9. Audits and Compliance Evidence
9.1 Evidence in lieu of on-site audit. Given the nature and scale of the Services, MyLittleWorld will, upon reasonable written request no more than once per calendar year (or following a Data Breach), provide the Organization with reasonable evidence of its compliance with this DPA, which may include a summary of MyLittleWorld's security practices, relevant Subprocessor certifications or attestations, and completed responses to a reasonable third-party security/privacy audit questionnaire. MyLittleWorld will not unreasonably refuse to complete such a questionnaire.
9.2 On-site or third-party audits. MyLittleWorld does not generally grant unrestricted on-site audit rights. Where the Organization has a specific regulatory obligation that cannot be satisfied through the evidence described in Section 9.1, the parties will discuss in good faith a reasonable, proportionate alternative (which may include a mutually agreed independent auditor), at the Organization's expense.
10. International Data Transfers
Personal Data Processed under this DPA may be transferred to and Processed in Canada, the United States, and other jurisdictions in which MyLittleWorld's Subprocessors operate, as identified in the Subprocessor List. MyLittleWorld will ensure that any such transfer is subject to appropriate safeguards required by Applicable Data Protection Law, which may include: (a) reliance on the Subprocessor's own certifications and contractual data protection commitments; (b) standard contractual clauses or equivalent transfer mechanisms where required for EU/UK-originating Personal Data; and (c) assessment of the destination jurisdiction's legal framework consistent with Law 25's requirements for Personal Information transferred outside Quebec, including a privacy impact assessment factor comparable to the protection that would apply in Quebec.
11. Liability
This DPA does not create a liability regime separate from, or in addition to, the liability framework (including any limitation or exclusion of liability and any liability cap) set out in the Agreement's Terms of Service. Each party's liability arising out of or in connection with this DPA is subject to the limitations and exclusions of liability set out in the Terms of Service, which are incorporated into this DPA by reference. Nothing in this Section limits liability that cannot be limited or excluded as a matter of Applicable Data Protection Law.
12. Term and Termination
This DPA takes effect on the date the Organization first agrees to the Terms of Service (or, for an executed copy, the date of countersignature) and remains in effect for as long as MyLittleWorld Processes Personal Data on the Organization's behalf under the Agreement, notwithstanding the termination of the Agreement, until such Processing ends in accordance with Section 8.
13. Governing Law
This DPA is governed by, and construed in accordance with, the laws of the Province of Quebec and the federal laws of Canada applicable therein, without regard to conflict-of-law principles. This choice of governing law does not deprive a Data Subject or Controller of protections that cannot be derogated from under Applicable Data Protection Law where such law otherwise applies.
14. Execution
Self-serve Organizations are bound by the terms of this DPA automatically upon acceptance of the Terms of Service; no separate signature is required to make this DPA effective. Where an Organization requires a signed or countersigned copy for its own internal compliance or audit records, MyLittleWorld will provide one on request to privacy@mylittleworld.ca.