Legal
Data Processing Addendum
Takes effect September 27, 2026 · version 2026-09-27
The terms on which Sitterz processes personal information on behalf of a business that uses the Service. This addendum applies automatically to every account — there is nothing to sign before it takes effect.
In one line: the business decides, Sitterz executes. Sitterz processes what a business puts into its workspace only to run the Service for that business, never sells or shares it, never trains a model on it, and never uses it for anything of its own.
1. Scope and roles
This Data Processing Addendum (“DPA”) forms part of the Terms of Service between Sitterz LLC and the business that uses the Service (“Customer”). It applies automatically to every account and needs no separate signature. A Customer that requires a countersigned copy may request one at support@sitterz.com.
Customer is the controller — and, under California law, the business — for all Customer Data. Sitterz is the processor and, under California law, a service provider. Sitterz is not a third party or a contractor as those terms are defined in the CCPA.
Where this DPA conflicts with the Terms of Service as to the processing of personal information, this DPA controls. Where it conflicts with a signed order form or pilot agreement, that document controls.
Words used here
“Customer Data” has the meaning given in the Terms. “Personal information”, “personal data”, “sell”, “share”, “sensitive personal information”, “business purpose”, “consumer”, “controller”, “processor” and “service provider” have the meanings given in the applicable state privacy law. “Data Protection Law” means the privacy and data-protection laws of the United States and its states that apply to a party in connection with the Service.
Each party will comply with the Data Protection Law applicable to it in its own role. Sitterz does not undertake to comply with a law that applies to Customer as controller and not to Sitterz as processor.
2. Processing on instructions only
Sitterz will process Customer Data only on Customer's documented instructions, including as to any transfer, unless required otherwise by law — in which case Sitterz will tell Customer before processing, unless the law prohibits it.
The Terms of Service, this DPA, any order form, and Customer's use of the features and settings of the Service together constitute Customer's complete documented instructions. Any other instruction must be agreed in writing, and Sitterz may charge for work outside the ordinary operation of the Service.
Sitterz will notify Customer if, in its opinion, an instruction infringes Data Protection Law, and may decline to carry it out.
Customer is responsible for the lawfulness of the personal information it enters and of its instructions, including for giving every notice and obtaining every consent, authorisation, and release that the law requires — expressly including parental or guardian consent for information about a child and for photographs of a minor.
Customer's configuration of the Service is part of its instructions. Which features Customer enables, who it grants access to and at what permission level, which notifications it sends and to whom, what it retains and for how long, and which outside systems it connects are Customer's decisions. Sitterz gives effect to them and does not review, approve, or monitor them. Where a setting has a default, leaving it unchanged is a decision Customer has made.
3. What Sitterz will not do
Sitterz will not:
- sell Customer Data, or share it for cross-context behavioural advertising, for any consideration and under any circumstances;
- retain, use, or disclose Customer Data for any purpose other than the business purposes listed in [The business purposes Sitterz may process for](#the-business-purposes-sitterz-may-process-for), including for any commercial purpose of its own;
- retain, use, or disclose Customer Data outside the direct business relationship between Sitterz and Customer;
- combine Customer Data with personal information it receives from, or on behalf of, any other person, or collects from its own interaction with any consumer — except as expressly permitted by Data Protection Law to perform a business purpose listed below;
- use Customer Data to build or modify a profile of any individual or household;
- use Customer Data to train, fine-tune, or improve any artificial-intelligence or machine-learning model, or permit any subprocessor to do so;
- use Customer Data for advertising of any kind, or disclose it to any advertising network or data broker.
Sitterz certifies that it understands the restrictions in this section and in [The business purposes Sitterz may process for](#the-business-purposes-sitterz-may-process-for) and will comply with them.
If Sitterz determines that it can no longer meet its obligations under Data Protection Law, it will notify Customer promptly. On such notice, Customer may take reasonable and appropriate steps to stop and remediate any unauthorised use of Customer Data, and may terminate the affected part of the Service.
4. The business purposes Sitterz may process for
Sitterz processes Customer Data only for these specific business purposes, and for no others. This list is deliberately enumerated rather than cross-referenced.
- Hosting, storing, and making Customer Data available inside Customer's workspace;
- Scheduling, bookings, visits, and calendar functions;
- Client and household record-keeping, including child and pet records;
- Staff roster, availability, and document storage;
- Attendance, check-in and check-out records, and daily logs;
- Storing and displaying photographs and documents that Customer or its users upload;
- Delivering email — and, if Customer enables it, text messages — that Customer directs the Service to send;
- Invoicing, and facilitating payments made to Customer through its own payment processor account;
- Generating a starting design for Customer's own website, using only the inputs described in the AI Features Schedule;
- Publishing and serving Customer's website;
- Providing support to Customer, and diagnosing faults it reports;
- Operating, securing, supporting and improving the Service, including Sitterz's internal service and business analytics computed over Customer Data, viewed only by Sitterz platform administrators through an audited console and never disclosed in a form attributable to Customer without its written consent;
- Security monitoring, abuse and fraud prevention, and maintaining the audit record;
- Backup, disaster recovery, and business continuity;
- Complying with a legal obligation that applies to Sitterz.
5. Confidentiality of personnel
Sitterz limits access to Customer Data to personnel who need it to perform the business purposes above, applies least privilege, and binds every such person to a written duty of confidentiality that survives the end of their engagement. Sitterz trains personnel with access on their obligations under this DPA.
6. Security measures
Sitterz maintains a written information security programme with administrative, technical, and physical safeguards appropriate to the size and complexity of its business and to the sensitivity of Customer Data, aligned to the NIST Cybersecurity Framework 2.0 and the CIS Critical Security Controls.
“Aligned to” is the accurate word and is used deliberately. Sitterz holds no SOC 2 report and no security certification, and does not describe itself as compliant with, or certified against, any framework.
The measures currently in place:
| Area | Measure |
|---|---|
| Separation between customers | Every workspace table carries a row-level security policy enforced by the database on every query, not by application filtering. Access is scoped by tenant, role, and — for family and staff users — by the individual. |
| Encryption | TLS in transit. Encryption at rest through the hosting provider. Two-factor secrets encrypted with AES-GCM under a separate key. |
| Credentials | Passwords hashed with scrypt and never stored in readable form. Recovery codes stored only as hashes. Session cookies signed with HMAC-SHA256 and invalidated by an account epoch. |
| Files | Private storage, served only through short-lived signed links. Location metadata removed from images in the browser before upload. |
| Integrity | An append-only audit record of workspace actions, each entry cryptographically chained to the one before it and covered by a signed checkpoint, so tampering is detectable. |
| Access control | Role-based permissions, least privilege on production systems, two-factor authentication required for platform administrators, and an audited support-access path, including an audit record of every administrator view of a Customer's business metrics. |
| Application | Content Security Policy, browser access to camera, microphone, and location switched off at the application level, protections against server-side request forgery on outbound calls, and rate limiting on authentication paths. |
| Operations | Point-in-time database recovery, tested restores, a documented incident-response procedure, and a documented change process. |
Sitterz may update these measures from time to time provided the update does not materially reduce the overall level of security. The current version of this page is the operative description.
7. Subprocessors
Customer gives Sitterz general written authorisation to engage the subprocessors listed on the Subprocessor List, which forms part of this DPA.
Sitterz will give at least 30 days' notice before adding a subprocessor that will process Customer Data, by email to account owners and by updating that page. Customer may object on reasonable data-protection grounds within that period. If the objection cannot be resolved, Customer may terminate the affected part of the Service without penalty and receive a pro-rata refund of prepaid fees.
Sitterz imposes on every subprocessor, by written contract, data-protection obligations at least as protective as those in this DPA, including the prohibitions in What Sitterz will not do and the requirement of appropriate security. Sitterz remains fully liable to Customer for a subprocessor's performance of those obligations.
8. Helping Customer answer people who ask about their information
Taking into account the nature of the processing, Sitterz will assist Customer, by appropriate technical and organisational measures and so far as it reasonably can, to respond to requests to access, correct, delete, or obtain a copy of personal information, and to any objection or opt-out.
Sitterz will not respond substantively to a request it receives directly about Customer Data. It will forward the request to Customer within 5 business days and tell the requester who holds the record.
Where a request cannot be satisfied through the Service, Sitterz will perform the export or deletion manually and provide written confirmation of what was deleted, what was retained, and on what basis. Sitterz will begin within 10 business days of Customer's instruction, so that Customer can meet a 45-day statutory deadline.
Stated plainly: self-service export and deletion tooling does not exist in the product today. These requests are carried out by Sitterz personnel against the database, under a documented procedure, and every execution is logged. The commitment above is what Sitterz will actually do, not a description of a feature.
Sitterz will also provide, on request, the information reasonably necessary for Customer to carry out a data protection assessment or risk assessment relating to the Service.
9. Security incidents
Sitterz will notify Customer without undue delay, and in any event within 72 hours, after Sitterz confirms a security incident affecting Customer Data. The clock starts on confirmation by Sitterz's security personnel that an incident has occurred — not on the first alert, and not on a report that turns out to be a false positive.
The notification will describe, so far as then known: the nature of the incident, the categories and approximate volume of information and of individuals affected, the likely consequences, and the measures taken or proposed. Sitterz will supply further information as the investigation establishes it, and will supply facts rather than characterisations until forensics are complete.
Customer decides whether notification to individuals or to any regulator is required, and controls its content and timing. Sitterz will not notify Customer's families, staff, or any regulator about an incident affecting Customer Data without Customer's prior written consent, unless the law requires Sitterz to do so. Customer will not name Sitterz in a notification without giving Sitterz a reasonable opportunity to review it first, except where the law requires otherwise.
Sitterz will cooperate reasonably with Customer's investigation and remediation. A notification under this section is not an acknowledgement of fault or liability.
10. Audits and demonstrating compliance
Sitterz will make available to Customer the information reasonably necessary to demonstrate compliance with this DPA.
In the first instance, an audit request is satisfied by Sitterz's then-current security documentation and a completed security questionnaire, and — when one exists — an independent audit report.
Beyond that, Customer may audit once in any 12-month period, on 30 days' written notice, during business hours, at Customer's expense, under confidentiality, using an auditor who is not a competitor of Sitterz, and excluding access to any other customer's data and to shared infrastructure. An additional audit may be conducted after a confirmed security incident affecting Customer Data or where a regulator directs one.
The parties will agree the scope in advance so that an audit does not disrupt the Service.
11. Children's information
The Service holds records about children because Customer's business requires it. The following applies specifically to those records.
- Customer is the controller of every child record and determines what is collected and why.
- Customer represents and warrants that it has given every notice, and obtained every parental or guardian consent, authorisation, and release, that the law requires — before a child's information is entered and before any photograph of a minor is uploaded or shared through the Service.
- Customer will not permit any person under 18 to access the Service or to hold credentials for it, and will not use the Service to collect personal information directly from a child.
- Customer will not embed or integrate the Service into any website or online service directed to children within the meaning of 16 C.F.R. §312.2, and will tell Sitterz immediately if such use occurs.
- Sitterz does not obtain, verify, or evaluate parental consent, and provides only a place for Customer to record that it holds one.
- Sitterz does not use children's information for advertising, profiling, or AI training, and does not sell or share it under any circumstances.
Sitterz applies to children's records the retention schedule published in the Privacy Policy, and will apply a shorter period on Customer's instruction.
12. Artificial intelligence
One feature of the Service uses a third-party model, and only to generate a starting design for Customer's own website. It receives the business name, the kind of work the business does, a tone preference, and a short description the operator types.
No client record, child record, staff record, booking, invoice, message, photograph, log entry, or incident note is sent to any model. No AI feature ranks, scores, rates, matches, or assesses the suitability, quality, safety, or fitness of any individual, and no AI output is intended to be a factor in any decision about employment, engagement, assignment, compensation, discipline, or termination.
Sitterz grants no model provider the right to train on what it sends, and engaging a provider under terms that prohibit training is a condition of using it. A provider generally retains a limited amount of what it receives for its own abuse-monitoring purposes, as every provider does; that is not training. The AI Features Schedule is the full description and forms part of this DPA.
13. Return and deletion
On termination, and at any time on Customer's request, Sitterz will delete or return Customer Data at Customer's choice.
- Export remains available for 30 days after termination.
- Sitterz will delete Customer Data within 30 days after that export window closes, or sooner on Customer's instruction.
- Backups expire on their own rotation and are not restored to recover deleted data. Deletion from backups completes within 90 days.
- Sitterz will provide written confirmation of deletion on request.
Sitterz will retain, and is required to retain, records it must keep by law — including financial records and the record of agreement acceptance — and the workspace audit record, which cannot be partially deleted without destroying the integrity of the chain and is removed in full when the workspace is deleted. The Privacy Policy retention schedule sets out both.
The obligations in this section are not conditioned on anything, including Customer's payment status. Sitterz will not withhold, and has no right to withhold, Customer Data to secure payment of fees. A suspension for non-payment does not suspend Sitterz's obligations under this DPA, which continue in full for as long as Sitterz holds Customer Data.
14. Liability, and details of processing
Each party's liability under this DPA is subject to the limitations and exclusions in the Terms of Service, including the higher amount that applies to claims arising from a breach of security or privacy obligations. Nothing in this DPA limits a liability that cannot be limited by law.
Annex — details of the processing
| Item | Detail |
|---|---|
| Subject matter | Provision of the Sitterz software platform to Customer |
| Duration | The term of the Terms of Service, plus the return-and-deletion periods in Return and deletion |
| Nature and purpose | The business purposes enumerated in The business purposes Sitterz may process for |
| Categories of individuals | Customer's owners, managers, and staff; Customer's clients and the adults in their households, including parents and guardians; children in Customer's care; pets in Customer's care, and their owners' contacts; people a client names as emergency or pick-up contacts; visitors to Customer's published website |
| Types of personal information | Names, preferred names, pronouns and language as stated by the family, contact details, and postal addresses; an approximate age of a child derived from a birth year — never a full date of birth; free-text notes, care instructions, and pick-up instructions, which may contain health information a family or Customer chose to write; attendance, check-in and check-out records; daily log entries, including meals, naps, nappy and toilet changes and activities; photographs of children, pets, and visits; incident notes; uploaded documents including staff certificates; staff position, availability, and hourly rate; bookings, invoices, payment records, and payment-method display details; message content; authentication data; and IP addresses and server logs |
| Information the Service does not hold | No full date of birth for a child; no Social Security number, date of birth, home address, or bank account details for staff; no medical, allergy, medication, immunisation, or dosage field; no biometric information; no precise location of any person; no score, rating, or assessment of any person |
| Sensitive information | Account credentials, held hashed. Health information only where typed into a free-text field. Processed solely for the business purposes in The business purposes Sitterz may process for, never sold or shared, and never used for AI training. |
| Frequency | Continuous, for as long as Customer uses the Service |
| Location | United States |
| Subprocessors | As published on the Subprocessor List |
This addendum is published as part of the Sitterz launch program and has not yet been reviewed by outside counsel. Questions: support@sitterz.com. Sitterz LLC, a Colorado limited liability company, [our notice address — to be completed before launch].
Questions about this document? Email support@sitterz.com.