Legal

Data Processing Agreement

A template schools can review during procurement, covering how we process student, parent, and staff data on their behalf.

Draft — pending legal review, not yet executed

This page is a working template for discussion during procurement. It has not been reviewed by counsel and is not a signed or legally binding agreement between Little's Orbit and any school. A final DPA is reviewed and executed separately as part of your written agreement with us — please treat everything below as a draft starting point, not a commitment.

Roles

For personal data processed through the Little's Orbit platform, the school is the data controller — it decides what student, parent, and staff data is collected and why. Little's Orbit acts as the data processor, processing that data only on the school's instructions and only to provide the platform.

Categories of personal data

This DPA covers personal data the school submits or generates while using the platform, including:

  • Student identity and profile data — name, date of birth, photo, class/section
  • Parent/guardian identity and contact data — name, phone, email, relationship to student
  • Attendance records — check-in/check-out times, method, and status
  • Daily care and health-related notes — meals, naps, incidents, medical and emergency-contact details
  • Payment data — fee amounts, invoices, and payment status. Card and bank credentials are entered directly into the payment gateway's (Razorpay/Cashfree) hosted checkout and are not stored on our servers.

Subprocessors

We use the following subprocessors to operate the platform. This list reflects vendors actually integrated in our codebase today — we do not list a vendor here unless it is genuinely wired up.

  • Application hosting — Railway and/or DigitalOcean App Platform (API and database)
  • Website hosting — Vercel (this marketing site and lead forms)
  • File storage — AWS S3 or DigitalOcean Spaces, private buckets with signed URLs (photos, documents)
  • Transactional email — Brevo (notifications, receipts, account emails)
  • SMS — Twilio, where a school enables SMS notifications or OTP
  • Push notifications & phone verification — Firebase (Google)
  • Payment processing — Razorpay and/or Cashfree, where a school enables online fee payments

We will update this list as our vendor footprint changes, and schools may request advance notice of new subprocessors as part of a signed agreement.

Security measures

These are the same controls described in full on our security page:

  • Encryption at rest for sensitive fields (medical/emergency-contact details, MFA secrets, payment gateway credentials), with HTTPS/HSTS in transit
  • Role-based access control, with granular per-workflow staff permissions inside each school
  • Signed, short-lived authentication tokens (JWT, RS256-capable), with optional MFA and step-up verification for sensitive actions
  • Tamper-evident audit logging of administrative actions, staff/permission changes, payment actions, and access events
  • Nightly, verified database backups with encrypted offsite storage and regularly tested restore procedures

Little's Orbit does not currently hold SOC 2, ISO 27001, HIPAA, or any other third-party security certification, and will not claim one until it has been independently audited.

Data subject rights

Because the school is the data controller, requests from parents, guardians, or staff to access, correct, or delete their personal data should generally go to the school first. We support the school in fulfilling those requests within the platform — including record correction and deletion tools available to school admins, and assistance from us where a request needs backend support.

Breach notification

If we become aware of a security incident affecting a school's data, we will notify the affected school without undue delay and in accordance with applicable law, so the school can meet its own regulatory and parent-notification obligations.

Data retention & deletion on termination

While a school's subscription is active, data is retained to provide the service. On termination, we will make school data available for export for a reasonable transition period, after which it is deleted or anonymized, except where we are legally required to retain specific records (e.g. financial/tax records) for a longer period.

Questions

To discuss this template, request a signed DPA, or ask about our data-processing practices, reach us through the contact page.