Legal
Data Processing Agreement
Version 1.0 · Effective August 26, 2026
This agreement is between Childrens House, a company registered in South Africa ("the Operator", "we", "us"), and the school that holds an Attend account ("the Responsible Party", "the School").
It applies automatically. By using Attend, the School accepts this agreement. No signature is required and nothing needs to be requested — the protections below are in place from the moment an account is created.
A signed copy is available to any school whose own procurement requires one. Email attend@childrenshouse.co.za.
Why this agreement exists
The School records information about Children, their Guardians, and its staff in Attend. Much of that information is personal, and some of it is sensitive.
Data protection law in most countries requires a school to have a written agreement with any organization that processes personal information on its behalf. This is that agreement, and every school using Attend has it without having to ask.
It sits alongside our Terms of Service and Privacy Policy and, where they conflict on the handling of personal information, this agreement takes precedence.
1. Definitions
Terms used here have the meanings given in the Protection of Personal Information Act, 2013 ("POPIA"). Where the School is subject to the General Data Protection Regulation ("GDPR") or the UK GDPR, equivalent terms apply and are treated as interchangeable:
| This agreement | POPIA | GDPR |
|---|---|---|
| Responsible Party | Responsible Party | Controller |
| Operator | Operator | Processor |
| Personal Information | Personal Information | Personal Data |
| Data Subject | Data Subject | Data Subject |
| Sub-Operator | Operator engaged by an Operator | Sub-processor |
"Attend" means the software service provided at attendmontessori.com.
"Personal Information" means information relating to an identifiable person — or, where South African law applies, an identifiable natural or juristic person — that the School records in Attend.
2. Who decides what
The School decides. The School determines what Personal Information is recorded in Attend, why, who may access it, and how long it is kept. The School is the Responsible Party.
We act on those decisions. We process Personal Information only to provide Attend to the School, and only on the School's documented instructions. We are the Operator.
Our instructions. The School's use of Attend constitutes its instructions to us. Additional instructions may be given in writing to attend@childrenshouse.co.za.
If an instruction appears unlawful, we will tell the School promptly and may decline to act on it.
We do not use the School's Personal Information for our own purposes. We do not sell it, we do not use it for advertising, and we do not use it to train artificial intelligence models.
3. What we process
Set out in Annex 1.
4. Our obligations
We will:
a) Process only on instruction, as set out in section 2.
b) Keep it secure. We will implement and maintain the technical and organizational measures in Annex 2, and will not materially reduce them during the term.
c) Ensure our people are bound. Anyone we authorize to access the School's Personal Information is subject to a duty of confidentiality, and is granted access only to the extent their work requires.
d) Help the School meet its own obligations, including responding to Data Subject requests, carrying out impact assessments, and consulting a regulator where required.
e) Tell the School about breaches — see section 6.
f) Return or delete at the end — see section 8.
g) Make information available to demonstrate compliance with this agreement — see section 9.
5. Data Subject requests
Requests come to the School, not to us. The School holds the information and makes the decisions.
If a Data Subject contacts us directly about information the School has recorded, we will not respond on the School's behalf. We will tell them to contact their school, and notify the School promptly.
We will assist the School in responding — including by locating, exporting, correcting, or deleting information — at no charge for reasonable requests.
Attend's own export and deletion tools mean the School can handle most requests without our involvement.
6. Security breaches
If we become aware of a breach affecting the School's Personal Information, we will:
- Notify the School within 7 days of becoming aware
- Describe what happened, what information was affected, and how many Data Subjects, so far as known
- Describe the likely consequences and what we are doing about it
- Provide the information the School needs to notify its own regulator or the people affected
- Keep the School informed as we learn more
We will not delay notification to complete an investigation. An incomplete notification within 7 days is better than a complete one after.
The School is responsible for deciding whether to notify its own regulator or Data Subjects. We will support that decision but we will not make it.
7. Sub-Operators
The School authorizes us to engage Sub-Operators to provide Attend. Those currently engaged are listed in Annex 3.
Every Sub-Operator is bound by written terms imposing data protection obligations no less protective than those in this agreement.
We remain responsible to the School for a Sub-Operator's acts and omissions as if they were our own.
Changes. We will give the School at least 30 days' notice before adding or replacing a Sub-Operator. If the School reasonably objects on data protection grounds, it may tell us within that period and we will discuss it in good faith. If we cannot resolve it, the School may terminate without penalty and export its records.
8. Cross-border transfer
Attend runs on infrastructure located in the United States. Personal Information the School records is transferred there.
Where Personal Information originates in South Africa, this transfer is made on the following terms — and we require equivalent terms from every Sub-Operator:
8.1 Equivalent protection.
The Data Importer agrees to provide a level of data protection that is at least identical to the protections found in the Protection of Personal Information Act (POPIA).
8.2 Onward transfer.
The Data Importer shall not transfer personal information to any third party unless that third party enters into a binding agreement containing these exact same data protection rules.
8.3 Juristic persons.
The parties agree that for data originating from South Africa, the term "Data Subject" includes both living natural persons and existing juristic persons (companies or school boards).
8.4 Section 8.3 matters more than it may appear. South African law protects organizations as well as individuals — a school constituted as a company, trust, or Section 21 entity has rights in its own name. Many data protection regimes protect only natural persons. We extend protection to both.
8.5 Schools in the European Union. Where the School is subject to the GDPR, transfers from the School to us are made under the European Commission's Standard Contractual Clauses, Module 2 (Controller to Processor), incorporated into this agreement by reference. The School is the data exporter; we are the data importer.
8.6 Schools in the United Kingdom. Where the School is subject to the UK GDPR, the Standard Contractual Clauses in section 8.5 apply as modified by the UK International Data Transfer Addendum issued by the Information Commissioner's Office, also incorporated by reference.
8.7 Transfer Impact Assessment. South Africa does not hold an adequacy decision from the European Commission or the UK. We maintain a Transfer Impact Assessment covering South African law — including the Protection of Personal Information Act and the Regulation of Interception of Communications and Provision of Communication-Related Information Act — and make it available to any School that requires it for its own records. Contact attend@childrenshouse.co.za.
9. Audit and assurance
We will make available the information reasonably necessary to demonstrate compliance with this agreement, including:
- The security measures in Annex 2, and confirmation they remain in place
- The current Sub-Operator list and the terms binding them
- Responses to a reasonable data protection questionnaire
On-site audits. Where the School's own legal obligations require an audit, we will discuss a reasonable approach in good faith. Given the size of our operation, we would expect to satisfy most requirements through written assurance and a call rather than a physical inspection, and we will say so plainly rather than agreeing to something we cannot deliver.
Audits are limited to once in any twelve-month period, unless a regulator requires otherwise or a breach has occurred.
10. Return and deletion
During the term, the School may export its Personal Information at any time using the tools in Attend.
On termination, we retain the School's Personal Information for 90 days so it can be exported or the account reactivated. After that we delete or anonymize it.
Earlier deletion on written request, except anything we are legally required to keep.
Backups. Encrypted backups are retained for 30 days and then automatically deleted. Personal Information may persist in a backup for up to 30 days after deletion from the live service. Backups are not accessible for ordinary use and are restored only for disaster recovery.
Confirmation of deletion provided in writing on request.
11. Liability
Liability under this agreement is subject to the limitations in our Terms of Service, except where data protection law does not permit those limitations to apply.
Nothing in this agreement excludes or limits either party's liability to a Data Subject or a regulator where the law does not permit it.
12. Duration
This agreement takes effect on the date above and continues while we process Personal Information for the School. Sections 6, 8, 10 and 11 survive termination to the extent necessary.
13. General
Governing law. This agreement is governed by the laws of South Africa, and the parties submit to the jurisdiction of the South African courts. This does not deprive the School of protections under its own law where those cannot be excluded.
Changes. We may update this agreement where the law changes or our processing changes. Material changes will be notified at least 30 days in advance.
Precedence. Where this agreement conflicts with the Terms of Service on the handling of Personal Information, this agreement prevails.
Acceptance. This agreement is accepted by the School's use of Attend. It requires no signature and takes effect when an account is created.
A signed copy is available on request at attend@childrenshouse.co.za for schools whose own procurement requires one. The terms are identical.
Annex 1 — Details of processing
Subject matter. Provision of the Attend attendance and school operations service.
Duration. For as long as the School holds an Attend account, plus the retention period in section 10.
Nature and purpose. Recording daily attendance; managing records of Children, Guardians, staff, classrooms and the academic calendar; providing the School access to its own records; support.
Categories of Data Subject:
- Children enrolled at the School
- Guardians and emergency contacts recorded by the School
- Staff members of the School
- Individuals authorized by the School to use Attend
- Where South African law applies, the School itself as a juristic person
Categories of Personal Information:
| Data Subject | Information |
|---|---|
| Children | Name, date of birth, classroom, enrollment status and history, attendance records |
| Children (where the School records it) | Medical conditions, allergies, collection restrictions |
| Guardians | Name, contact details, relationship to the Child, collection permissions |
| Staff | Name, work email, role, classroom assignments, employment status |
| Users | Name, email address, authentication credentials, sign-in records, activity logs |
Special personal information. Medical conditions and allergies recorded about Children are special personal information under POPIA and a special category under the GDPR. The School is responsible for having a lawful basis for recording them. We process them only to display them to authorized staff.
Children's information. Children do not use Attend. There are no accounts for Children and we do not communicate with them. All information about a Child is entered by the School.
Frequency. Continuous during the term.
Annex 2 — Security measures
Access control
- Individual accounts; sharing prohibited by the Terms of Service
- Role-based permissions set by the School, enforced server-side
- Where the School enables it, sign-in via Google without a password held by us
- Passwords stored only as irreversible hashes; we cannot read or recover them
- Rate limiting on sign-in and password reset to resist automated guessing
Separation between schools
- Each School's information is logically separated at the database level
- A user signed in to one School cannot reach another School's records
Encryption
- In transit: encrypted connections throughout
- Backups: encrypted at rest with a key held separately from the backup store
Auditability
- Attendance records store who recorded them and when
- Later changes are recorded, attributed, and retained
- Changes to who holds access are recorded
Backup and recovery
- Daily encrypted backups, stored separately from the production platform
- 30-day retention, then automatic deletion
- Restore procedure tested
Monitoring
- Application error monitoring with personal information excluded from reports
- Platform and dependency updates maintained
Personnel
- Access limited to those who require it
- Bound by confidentiality obligations
What we do not do
- We do not collect biometric information of any kind
- We do not use the School's information for advertising, profiling, or AI training
- We do not permit Sub-Operators to use it for their own purposes
Certification. We do not currently hold SOC 2, ISO 27001, or an equivalent independent certification. We say so rather than implying otherwise.
Annex 3 — Sub-Operators
| Purpose | Sub-Operator | Location |
|---|---|---|
| Application hosting | Vercel Inc. | United States |
| Database, authentication and file storage | Supabase Inc. | United States |
| Encrypted backup storage | Cloudflare Inc. | United States |
| Transactional email | Resend | United States |
| Identity verification | Google LLC | Only where the School enables Google Sign-In |
| Error monitoring | Functional Software Inc. (Sentry) | United States |
| Website analytics and support chat | HubSpot Inc. | Marketing website only — not within Attend |
Each is bound by written terms imposing data protection obligations no less protective than this agreement, including the restrictions in section 8.
Infrastructure beneath our Sub-Operators. Some of the providers above run on infrastructure operated by others — for example, hosting and database services built on major cloud platforms. We do not contract with those platforms directly. Our agreements require each Sub-Operator to bind its own providers to obligations no less protective than these, and each publishes its own sub-processor list. We will identify the full chain for any School that asks.
Current list available at any time from attend@childrenshouse.co.za.
Addendum A — Juristic Persons
To the Attend Data Processing Agreement
Why this addendum exists
Most data protection law protects people. South African law also protects organizations.
Section 1 of the Protection of Personal Information Act, 2013 defines a data subject as "the person to whom personal information relates", and defines a person as "a natural person or a juristic person". A school constituted as a company, a trust, a Section 21 entity, or a governing body therefore holds data protection rights in its own name, separately from the rights of the individuals within it.
The European Commission's Standard Contractual Clauses do not accommodate this. They are drafted for the GDPR, under which a data subject is a natural person. Applied without modification to information originating in South Africa, they would leave a school-as-an-organization outside the protections that South African law grants it.
This addendum closes that gap.
1. Extended definition
The parties agree that for data originating from South Africa, the term "Data Subject" includes both living natural persons and existing juristic persons (companies or school boards).
2. Application
2.1 This addendum applies to all Personal Information originating in South Africa that we process on the School's behalf.
2.2 Where the School is itself a juristic person, the School is a Data Subject in respect of Personal Information relating to it, in addition to being the Responsible Party in respect of Personal Information relating to others.
2.3 Every protection in the Data Processing Agreement extends to the School as a juristic person on the same terms as it extends to natural persons — including the security measures in Annex 2, the breach notification obligation in section 6, the cross-border transfer protections in section 8, and the deletion obligations in section 10.
3. Sub-Operators
3.1 We require every Sub-Operator processing Personal Information originating in South Africa to apply the extended definition in section 1.
3.2 Where a Sub-Operator's own terms are drafted by reference to the GDPR or the Standard Contractual Clauses, and therefore contemplate only natural persons, our agreement with that Sub-Operator extends the obligation to juristic persons.
3.3 We will not engage a Sub-Operator that cannot accept this obligation for Personal Information originating in South Africa.
4. Relationship to the Standard Contractual Clauses
4.1 Where the Standard Contractual Clauses apply, this addendum supplements them. It does not vary or reduce any protection they confer.
4.2 Where the Standard Contractual Clauses and this addendum differ in scope, the wider scope applies to Personal Information originating in South Africa.
4.3 Nothing in this addendum extends South African law to information that does not originate in South Africa.
5. Incorporation
This addendum forms part of the Attend Data Processing Agreement and is accepted on the same basis.
