Data Processing Agreement
Last updated: 8 July 2026
This Data Processing Agreement ("DPA") forms part of the MinderHQ Terms of Service and applies where MinderHQ Limited (company number 17343019)("MinderHQ", the "Processor") processes personal data on behalf of a registered childminder ("you", the "Controller") who uses MinderHQ. It reflects Article 28 of the UK GDPR. By using MinderHQ to hold information about the children and parents in your care, you and MinderHQ agree to this DPA.
1. Definitions
"UK GDPR", "Data Protection Legislation", "personal data", "special category data", "processing", "controller", "processor" and "data subject" have the meanings given in the UK GDPR and the Data Protection Act 2018. "Sub-processor" means any third party engaged by MinderHQ to process personal data on your behalf.
2. Roles and scope
You are the controller of the personal data you hold about the children in your care and their parents and guardians. For that data, MinderHQ is your processorand processes it only to provide the service. For MinderHQ's own account and billing data about you, MinderHQ is the controller (see the Privacy Policy); that is not covered by this DPA. This DPA covers only MinderHQ's processing as your processor.
3. Your instructions
MinderHQ processes personal data only on your documented instructions — which include this DPA, the Terms, and your use of the product's features — and will not process it for its own purposes. If the law requires MinderHQ to process the data otherwise, it will tell you first, unless that law prohibits it. MinderHQ will tell you if, in its opinion, an instruction infringes Data Protection Legislation.
4. Confidentiality
MinderHQ ensures that anyone authorised to process your data is bound by an appropriate duty of confidentiality.
5. Security
Taking account of the state of the art, the costs of implementation and the risks to data subjects, MinderHQ implements appropriate technical and organisational measures to protect personal data — set out in Annex B. Because you may record special category data (for example a child's health, dietary, allergy or medical information), you remain responsible for identifying an appropriate condition for processing it.
6. Sub-processors
You give MinderHQ general authorisation to engage the sub-processors listed in Annex C. MinderHQ imposes data-protection obligations on each sub-processor that are equivalent to those in this DPA, and remains liable to you for their acts and omissions. MinderHQ will give you reasonable prior notice of any intended addition or replacement of a sub-processor so that you can object on reasonable data-protection grounds.
7. Assistance
Taking into account the nature of the processing and the information available to it, MinderHQ will assist you (so far as possible) to: respond to requests from data subjects; keep personal data secure; notify and communicate personal data breaches; and carry out data protection impact assessments and any prior consultation with the ICO.
8. Personal data breaches
MinderHQ will notify you without undue delay after becoming aware of a personal data breach affecting your data, and will give you the information you reasonably need to meet your own breach-notification obligations.
9. Data subject requests
You can view, export and delete the records you hold directly in the app. If MinderHQ receives a request from one of your data subjects, it will — unless legally required to respond itself — refer that person to you and help you respond.
10. Return and deletion
You can export your data from the app at any time. On the end of your subscription, or on your written request, MinderHQ will (at your choice) delete or return your personal data and delete existing copies, unless the law requires it to keep them. Note that, as a routine part of the service, diary and message photos and videos are automatically deleted after three months (see the Terms).
11. Audits
MinderHQ will make available to you the information reasonably necessary to demonstrate compliance with Article 28 UK GDPR, and will allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate — on reasonable notice, no more than once a year (unless a regulator or a breach requires otherwise), subject to confidentiality and without compromising the security of MinderHQ's other customers.
12. International transfers
MinderHQ and its sub-processors may process personal data outside the United Kingdom. Where they do, MinderHQ ensures an appropriate transfer safeguard is in place (such as UK adequacy regulations, the International Data Transfer Agreement, or the provider's standard contractual clauses). MinderHQ will not transfer your data in a way that conflicts with your instructions.
13. Liability, precedence and law
Each party's liability under this DPA is subject to the limitations and exclusions in the Terms. If there is a conflict between this DPA and the Terms on a data-protection matter, this DPA prevails. This DPA is governed by the law of England and Wales.
Annex A — Details of processing
- Subject matter: MinderHQ's provision of childminding management software to you.
- Duration: for the term of your subscription, and until your data is deleted or returned under clause 10.
- Nature and purpose: hosting and processing your records so you can run your setting — daily diary and register, learning-journey observations, accident and incident records, invoicing, parent messaging, your public website and the parent app.
- Types of personal data: names, dates of birth and attendance; diary entries and observations; photos and videos; accident and incident details; dietary, allergy, health and other special category data you choose to record; parent and guardian names and contact details; and message content.
- Categories of data subject: the children in your care, and their parents and guardians.
Annex B — Security measures
- Encryption of personal data in transit (HTTPS/TLS).
- Access controls and least-privilege access to production systems; authentication for every account.
- Card payment data is handled solely by Stripe (a PCI-DSS provider) and is never stored by MinderHQ.
- Location (GPS/EXIF) metadata is automatically stripped from photos and videos on upload, so an image can't reveal where it was taken.
- Children's media is held in private storage and served only through short-lived signed links.
- Data minimisation: diary and message photos and videos are automatically deleted after three months.
- Logging and monitoring, and regular patching of the platform and its dependencies.
Annex C — Authorised sub-processors
| Sub-processor | Purpose | Processing location |
|---|---|---|
| Supabase | Database, file/photo storage and backend hosting | EU / UK |
| Vercel | Application and website hosting, content delivery | UK / EU / US |
| Stripe | Subscription payment processing (card data) | UK / EU / US |
| Resend | Transactional and notification email | US |
| Twilio | Text-message (SMS) notifications, where used as a fallback | US |
| Apple | Push notifications to the iOS app (APNs) | US |
| Push notifications to the Android app (FCM) | US |
Locations are indicative and may change; each provider's own transfer safeguards apply as described in clause 12.
Contact
To request a signed copy, raise a data-protection question or object to a sub-processor, email privacy@minderhq.co.uk.
This is a starting template, not legal advice — please have it reviewed by a qualified solicitor before relying on it.