Effective Date: 1 July 2026
The Customer
(hereinafter "Customer")
and
Meadow Labs Limited, 7 Bearú Mhór, Cois Bhearú, Athy, Co. Kildare, R14 D363, Ireland
(hereinafter "Meadow")
(each a "Party" and together the "Parties")
have entered into this Data Processing Agreement (this "DPA") regarding Meadow's processing of personal data on behalf of the Customer. This DPA is effective from the date of the Agreement.
Definitions
"Agreement" means the Meadow Terms and Conditions and the Customer's Order, as amended from time to time in accordance with their terms;
"Applicable Data Protection Law" means the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the Data Protection Acts 1988 to 2018, and any guidance or codes of practice issued by the Data Protection Commission, in each case as amended from time to time;
"Authorised Sub-Processors" means the sub-processors set out in Appendix B, as amended from time to time under clause 6;
"Controller", "Processor", "Data Subject", "Personal Data", "Processing" and "Supervisory Authority" have the meanings given to them in the GDPR;
"Customer Data" means the Personal Data that the Customer or its Authorised Users enter into, upload to, or otherwise make available to Meadow through the Platform under the Agreement, including Personal Data shared with Meadow for support;
"Customer Point of Contact" has the meaning given in clause 18.3;
"Data Breach" has the meaning given in clause 10.1;
"Data Subject Request" has the meaning given in clause 9.1;
"Platform", "Authorised User", "Admin User", "Staff User", "Family User" and "Site" have the meanings given in the Agreement;
"Services" means the Platform services described in and provided under the Agreement;
"Sub-Processor" has the meaning given in clause 6.1;
"Transfer Mechanism" means the Standard Contractual Clauses approved by the European Commission Decision of 4 June 2021, as amended from time to time, the EU-U.S. Data Privacy Framework where the recipient is certified, an adequacy decision of the European Commission, or any other mechanism recognised under Applicable Data Protection Law for transfers of Personal Data outside the EEA.
Capitalised terms not defined here have the meaning given in the Agreement. Any reference to writing or written includes email.
1. Background
1.1 The Parties have entered into the Agreement, under which the Customer has engaged Meadow to provide the Services. This DPA, including its appendices, is incorporated into the Agreement by reference.
1.2 In providing the Services, Meadow will Process Customer Data for the term of this DPA. This DPA applies to every activity under the Agreement in which Meadow, its staff or its Sub-Processors Process Customer Data on the Customer's behalf.
2. Responsibilities and Instructions
2.1 The Customer is the Controller of the Customer Data and Meadow is the Processor. This DPA, and not the Meadow Privacy Policy, governs Meadow's Processing of Customer Data as Processor.
2.2 The Customer is responsible for its own compliance with Applicable Data Protection Law, including the lawfulness of the records it keeps in the Platform, of disclosing Customer Data to Meadow, and of having Meadow Process it. The Customer warrants that it is lawfully entitled to Process and disclose the Customer Data to Meadow, including any health data about children that the Child Care Act 1991 (Early Years Services) Regulations 2016 require it to hold, and that it has obtained any parental consent its own policies or the 2016 Regulations require, including for photographs and recordings of children. The Customer is responsible for its own privacy notices to families and staff, including naming Meadow as its Processor.
2.3 Meadow Processes Customer Data only on the Customer's documented instructions, unless required to do otherwise by law. The Customer's instructions are this DPA, Appendices A and C, the Agreement, and the settings and actions its Authorised Users take in the Platform. Further instructions may be given in writing during the term.
2.4 Meadow will inform the Customer without delay if, in Meadow's opinion, an instruction infringes Applicable Data Protection Law, and may suspend performance of that instruction until the Customer confirms or changes it.
2.5 Meadow's staff may access Customer Data on a limited, need-to-know basis to provide support, investigate a problem or maintain the Platform. Such access is read-only and limited to named administrators. When investigating a problem, Meadow's engineers may use AI assistants provided by the Authorised Sub-Processors listed for that purpose in Appendix B, on business terms that prohibit the provider from using Customer Data to train its models.
3. Details of Processing
3.1 The subject matter and nature of Meadow's Processing is the provision of the Services under the Agreement. The Customer and its Authorised Users decide what Customer Data enters the Platform. The purposes of Processing, the types of Customer Data and the categories of Data Subjects are set out in Appendix A.
3.2 Processing continues for the term of the Agreement and for 60 days after its termination, unless the Customer requests earlier deletion, deletes the data itself, or Appendix A specifies otherwise.
4. Security of Processing
4.1 Meadow implements the technical and organisational measures described in Appendix C to protect Customer Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access, and to ensure the ongoing confidentiality, integrity, availability and resilience of the Services.
4.2 Meadow reviews and updates these measures as risks, standards and technology change. Meadow may improve or replace a measure provided the level of protection is not reduced, and will notify the Customer of any material change. Meadow will not make a change that materially reduces the level of protection without the Customer's prior written approval.
4.3 Meadow maintains a process for regularly testing, assessing and evaluating the effectiveness of these measures.
4.4 The Customer has reviewed Appendix C and is responsible for satisfying itself that the measures are appropriate to the risk of its Processing.
5. Confidentiality
5.1 Meadow keeps Customer Data confidential. This obligation has no time limit and survives termination of the Agreement and this DPA.
5.2 Meadow grants access to Customer Data only to persons under its authority who are bound by confidentiality and only on a need-to-know basis. Meadow reviews who has access periodically and withdraws access that is no longer needed.
5.3 On request, Meadow will demonstrate that the persons concerned are bound by confidentiality.
6. Sub-Processing
6.1 The Customer gives Meadow general authorisation to engage sub-contractors that Process Customer Data on the Customer's behalf ("Sub-Processors") in accordance with this clause 6.
6.2 The Customer authorises the Sub-Processors listed in Appendix B.
6.3 Meadow will give the Customer Point of Contact at least 30 days' written notice before adding or replacing a Sub-Processor. The Customer may object in writing within 14 days of the notice on reasonable grounds relating to data protection. Meadow will consider the objection and discuss possible solutions. If no solution is reasonably possible and the Customer maintains its objection, the Customer may terminate the Agreement by giving 14 days' written notice, and will receive a refund of any prepaid fees for the period after termination. If the Customer does not terminate within that time, it is deemed to have accepted the Sub-Processor.
6.4 Where a Sub-Processor must be replaced urgently for reasons outside Meadow's reasonable control, Meadow will notify the Customer as soon as possible and the Customer may object and terminate as in clause 6.3.
6.5 Meadow will enter into a written agreement with each Sub-Processor imposing data protection obligations no less protective than this DPA, to the extent applicable to the service the Sub-Processor provides, and will restrict its access to what is necessary for that service.
6.6 Meadow remains fully liable to the Customer for the performance of each Sub-Processor's data protection obligations, within the limitations of liability in this DPA and the Agreement.
7. Location of Customer Data and Transfers Outside the EEA
7.1 Customer Data is stored in Ireland. The locations of Processing by each Authorised Sub-Processor are set out in Appendix B.
7.2 Meadow will not transfer Customer Data outside the EEA except to the Authorised Sub-Processors in Appendix B, or after following the notice and objection process in clause 6.3.
7.3 Where a transfer is to a country covered by an adequacy decision of the European Commission, no further safeguard is required.
7.4 Where a transfer is to any other country, Meadow will first carry out a transfer impact assessment and put in place an appropriate Transfer Mechanism, with supplementary measures where needed, including those in Appendix D. The Customer acknowledges that Meadow has incorporated an appropriate Transfer Mechanism into its agreements with each Authorised Sub-Processor outside the EEA.
8. Deletion, Correction or Return of Customer Data
8.1 The Customer can correct, withdraw, export and delete Customer Data itself using the Platform, including permanently deleting a child's record. Where the Customer cannot do so, Meadow will carry out the correction or deletion on the Customer's written instruction where Applicable Data Protection Law permits.
8.2 Within 60 days after termination of the Agreement, Meadow will, at the Customer's choice, return the Customer Data to the Customer in a commonly used electronic format or delete it, unless Applicable Data Protection Law requires otherwise. The Customer states its choice in writing and may change it at any time before the end of that period; if it states no choice, Meadow deletes. At the end of the period Meadow irreversibly deletes the Customer Data from live systems, after which it cannot be retrieved; backups roll off on their normal cycle within 7 days. Meadow confirms the deletion to the Customer Point of Contact in writing within 14 days of completing it. The Customer remains responsible for exporting, before the period ends, any record that Irish law requires it to retain.
9. Data Subject Requests
9.1 Where a Data Subject makes a request to Meadow to exercise rights under Applicable Data Protection Law in respect of Customer Data ("Data Subject Request"), and Meadow can identify the Customer concerned, Meadow will without undue delay refer the Data Subject to the Customer and inform the Customer.
9.2 On the Customer's instruction, Meadow will assist the Customer, to the extent reasonably possible and where the Customer cannot fulfil the request itself using the Platform, in responding to a Data Subject Request. Meadow is not liable where the Customer fails to respond completely, correctly or in time.
10. Data Breaches
10.1 Meadow will notify the Customer without undue delay, and in any event within 48 hours of becoming aware, of any accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Customer Data within Meadow's area of responsibility, including at an Authorised Sub-Processor to the extent Meadow becomes aware of it ("Data Breach"). The notice goes to the Customer Point of Contact by email and states, so far as known at the time and updated as more becomes known: the nature of the Data Breach; the categories and approximate number of Data Subjects and records concerned; the likely consequences; the measures Meadow has taken or proposes to take; and the person at Meadow to contact. Meadow will take the measures necessary to secure the Customer Data and to mitigate adverse effects on Data Subjects, and will coordinate with the Customer.
10.2 Meadow will assist the Customer, to the extent reasonably possible and where the Customer cannot do so itself, in notifying a Data Breach to the Data Protection Commission and in communicating it to affected Data Subjects, as Applicable Data Protection Law requires.
11. Data Protection Impact Assessments and Prior Consultation
11.1 On written request, and to the extent the information is available to Meadow and not otherwise available to the Customer, Meadow will provide reasonable assistance with any data protection impact assessment and any prior consultation with the Data Protection Commission that Applicable Data Protection Law requires of the Customer.
12. Audits and Inspections
12.1 On written request, Meadow will make available the information necessary to demonstrate compliance with this DPA, including Appendix C and a description of its current security measures. Such documentation is Meadow's Confidential Information.
12.2 Where the Customer reasonably concludes that the documentation is not sufficient in an individual case, the Customer may carry out an audit or inspection, itself or through an independent auditor who is not a competitor of Meadow, no more than once in any 12-month period unless a Supervisory Authority requires otherwise or there is a documented suspicion of a material breach. Audits are conducted during business hours, on at least 30 days' written notice, without disproportionately disturbing Meadow's operations, and subject to a confidentiality undertaking.
12.3 The information and documentation in clause 12.1 are provided without charge. For an audit or inspection under clause 12.2 the Customer bears its own costs and reimburses Meadow's reasonable internal costs, which will not be set at a level that discourages the Customer from exercising its audit rights. If the audit reveals a breach by Meadow of this DPA, Meadow will remedy it promptly at its own cost and refund those reimbursed costs.
13. Audit Records and Linked Services
13.1 The Platform records, on each record, who created and last changed it and when, and keeps attendance and correction history as append-only entries. These audit fields are kept for the life of the record and are visible to the Customer in the Platform. Infrastructure access and error logs are retained by Meadow's hosting providers for their standard periods, currently no longer than 90 days.
13.2 Meadow uses these records only to provide and secure the Services and to demonstrate compliance. On request supported by a legitimate reason, such as a regulatory, safeguarding or audit requirement, Meadow will provide the Customer with the relevant audit information.
13.3 If the Customer connects a third-party service to the Platform (a "Linked Service" under the Agreement), the Customer instructs Meadow to share the Customer Data needed for it with that provider, and is solely responsible for that provider's compliance with Applicable Data Protection Law. A Linked Service provider is not a Sub-Processor of Meadow.
14. Defence Support
14.1 Where a Data Subject brings a claim against the Customer in respect of Customer Data, Meadow will provide reasonable assistance to the Customer in defending it, and vice versa where a claim is brought against Meadow.
15. Term of this DPA
15.1 This DPA remains in force until 60 days after termination of the Agreement, except for obligations expressed to survive.
16. Limitation of Liability
16.1 Meadow is liable for data protection losses only where they result from Meadow failing to comply with this DPA or with its obligations as a Processor under Applicable Data Protection Law, or from an Authorised Sub-Processor failing to comply with its data protection obligations.
16.2 Each Party's total liability arising out of or in connection with this DPA is subject to the exclusions and limitations of liability in clause 15 of the Agreement.
16.3 Subject to clauses 16.1 and 16.2, each Party will indemnify the other against claims, losses, costs and regulatory fines arising from its own breach of Applicable Data Protection Law, provided the indemnified Party gives prompt notice, full information, reasonable assistance and sole control of the defence and settlement of the claim.
17. Obligations to Inform, Amendments and Data Protection Contact
17.1 If Customer Data in Meadow's control becomes subject to seizure, attachment, insolvency proceedings or a similar third-party measure, Meadow will notify the Customer without undue delay, follow the Customer's reasonable instructions to preserve confidentiality, and inform the relevant parties that the Customer is the Controller of that data.
17.2 Clause 21 of the Agreement (Amendments) applies to changes to this DPA. It does not apply to notices of new Sub-Processors, which follow clause 6.3.
17.3 Meadow has not appointed a Data Protection Officer. Data protection matters are handled by Meadow's director, reachable at james@meadowapp.ie.
18. Point of Contact
18.1 Each Party will name a point of contact for data protection matters under the Agreement and this DPA.
18.2 The Customer may contact Meadow at james@meadowapp.ie.
18.3 The Customer's point of contact is the email address of its Admin Users unless it tells Meadow otherwise ("Customer Point of Contact"). Meadow uses it to assist with Data Subject Requests, to notify Data Breaches, and to give notice of new Sub-Processors and amendments to this DPA.
19. Entire Agreement
19.1 Except as amended by this DPA, the Agreement remains in full force. If any provision of this DPA is invalid or unenforceable, the rest is unaffected.
19.2 In the event of conflict, the order of precedence is: (i) any Transfer Mechanism, (ii) Appendix D, (iii) this DPA, (iv) the Agreement.
20. Governing Law and Dispute Resolution
Clause 25 of the Agreement (Governing Law and Dispute Resolution) applies to this DPA. The competent Supervisory Authority is the Data Protection Commission, Ireland.
Appendix A: Details of Processing
The subject matter and nature of the Processing is the provision of the Services under the Agreement. The Customer decides which of the following it records.
| Type of Customer Data | Purpose of Processing on behalf of the Customer | Data Subjects |
|---|---|---|
| Basic data about a child: name, date of birth, gender, nationality, languages spoken, home address and Eircode, who the child lives with, who holds parental responsibility | So the Customer holds the record of each child that the 2016 Regulations require and can run its Sites | Children |
| Enrolment data: enquiry, waitlist, start date, room, plan and booking pattern, leave date and reason, notes | To manage places, rooms and bookings | Children; prospective children |
| Health data: allergies, penicillin tolerance, dietary needs, immunisation record, health notes, the child's doctor and their contact details, AIM support, medication administered with dose | So the Customer holds the health information the 2016 Regulations require and can care for the child safely | Children |
| Attendance data: check-in and check-out times, room moves, absences, planned departures, corrections | To keep the daily attendance record the 2016 Regulations require and to produce attendance reports | Children |
| Activity data: meals, sleep, nappies, toileting, medication, learning observations and similar, with notes | To record the child's day and share it with the family | Children |
| Funding data: ECCE and NCS registration status, the NCS CHICK reference, registration dates and hours, attendance figures used for funding returns | To help the Customer prepare its ECCE and NCS returns. Meadow submits nothing to the Early Years Hive or Pobal | Children; parents and guardians |
| Photos and video: an optional profile photo; photos and video in newsfeed posts and messages | To share the child's day with the family within the audience the Customer chooses. Staff may appear in photos | Children; staff; parents and guardians |
| Forms: answers to enrolment, consent and other forms the Customer sends to families, and public enquiry forms | To collect the information the Customer needs from families | Children; parents and guardians; prospective families |
| Family contact details: name, email, phone, relationship to the child, collection authorisation, emergency-contact status | So the Customer can reach families and know who may collect a child | Parents, guardians and other family contacts |
| Family activity in the Platform: messages with the Customer, comments and reactions on posts, RSVPs to events, form submissions, notification preferences | So the Platform's communication features work | Parents and guardians |
| Staff details: name, job title, date of birth, phone number, home room, notes entered by the Customer; daily attendance and absences; the record of which staff member recorded each entry | To keep staff records and rosters and to attribute actions in the Platform | Customer employees and workers |
| Any Customer Data shared with Meadow support | To provide support | All of the above |
| Usage data about how Authorised Users use the Platform | To operate and secure the Services and, in aggregated or pseudonymised form, to improve them | Staff users; parent users |
Meadow provides no fields for PPS numbers, ethnicity, religion, family financial details or Garda-vetting records.
Duration of Processing. The general retention period is set out in clause 3.2. The following Sub-Processor-specific periods also apply:
| Sub-Processor | Retention |
|---|---|
| Supabase | Database backups are retained for 7 days from the date of each backup |
| Sentry | Error reports are retained for 90 days |
| Intercom | Support conversations are retained for 12 months after the conversation closes |
| Google Workspace | Recordings and transcripts of calls with the Customer are retained for 12 months |
| Anthropic and OpenAI | Inputs are not used to train models and are retained only as the providers' business terms allow |
| Expo, Apple and Google | Push notification content is held only for delivery |
Appendix B: Authorised Sub-Processors
The Customer authorises the following Sub-Processors for the Processing of Customer Data under this DPA:
| Sub-Processor | Location of Processing | Service | Customer Data Processed |
|---|---|---|---|
| Supabase Inc. | Ireland (AWS eu-west-1) | Database, authentication and file storage for the Platform | All Customer Data in Appendix A. Supabase Inc. is US-based; support access is covered by the Standard Contractual Clauses and the EU-U.S. Data Privacy Framework |
| Vercel Inc. | Dublin, Ireland (eu-west-1) | Hosting of the web application and scheduled jobs | Customer Data in transit and in request logs. Vercel Inc. is US-based; Standard Contractual Clauses and Data Privacy Framework |
| BunnyWay d.o.o. (bunny.net) | Slovenia and EU storage | Video hosting and transcoding, only where the Customer enables video | Newsfeed video |
| Resend Inc. | Ireland (eu-west-1) | Sending of email: invitations, sign-in codes, message and post notifications | Names and email addresses of Authorised Users, and the content of the emails. Resend Inc. is US-based; Standard Contractual Clauses and Data Privacy Framework |
| 650 Industries Inc. (Expo), with Apple Push Notification service and Google Firebase Cloud Messaging | United States | Delivery of push notifications to the Meadow app | Push tokens and the title and preview text of notifications. Standard Contractual Clauses and Data Privacy Framework |
| Functional Software Inc. (Sentry) | EU data region | Error and crash reporting. Session replay is switched off | User identifiers and technical data, which may include fragments of Customer Data present when an error occurred. Standard Contractual Clauses and Data Privacy Framework |
| Cloudflare Inc. (Turnstile) | United States | Bot protection on public enquiry forms, where enabled | IP address and browser signals of the person completing the form. Standard Contractual Clauses and Data Privacy Framework |
| Intercom R&D Unlimited Company | Ireland (EU hosting) | Support chat and support inbox | Contact details of the person requesting support and any Customer Data they share in the conversation |
| Google Ireland Ltd. (Google Workspace) | EU and United States under Google's data processing terms | Email, calendar and Google Meet calls between Meadow and the Customer, including recordings and transcripts | Names of Staff Users and any Customer Data the Customer shares by email or on a call |
| Anthropic Ireland Ltd. (Claude) | United States | AI assistant used by Meadow's engineers when investigating a problem, on business terms with no training on inputs | Customer Data exposed to the assistant during an investigation. Standard Contractual Clauses and Data Privacy Framework |
| OpenAI Ireland Ltd. (Codex, ChatGPT) | United States | AI assistants used by Meadow's team when investigating a problem, on business terms with no training on inputs | Customer Data exposed to the assistant during an investigation. Standard Contractual Clauses and Data Privacy Framework |
Stripe processes the Customer's own billing details on Meadow's behalf as Meadow's payment processor; it does not process Customer Data about children, families or staff and is covered by the Meadow Privacy Policy.
Appendix C: Technical and Organisational Security Measures
Meadow has in place the following measures to protect Customer Data, described under the headings used in the European Commission's standard contractual clauses for processors. Meadow may improve or replace a measure as clause 4.2 provides. A fuller description of Meadow's security practices is available to the Customer on request under clause 12.1.
Pseudonymisation and encryption. All connections to the Platform are encrypted with TLS. Customer Data is encrypted at rest by the hosting providers. Photos and files are held in private storage and served only through short-lived signed links. Video is streamed with signed, expiring tokens. Records of deleted children are reduced to a pseudonymous audit entry. Usage data used to improve the Platform is pseudonymised or aggregated.
Ongoing confidentiality, integrity, availability and resilience. Each Site's data is logically separated from every other Site's, and the separation is enforced in the database itself, not only in the application. Access is denied by default and granted only by explicit permission rules. The hosting providers operate redundant power, network and climate systems in their data centres.
Ability to restore availability and access. The database is backed up daily and backups are retained for 7 days. Restores are tested. In a major incident Meadow can restore the database to a new environment within hours.
Regular testing, assessment and evaluation. Automated tests attempt to read and write data across Sites and as each role, and run before every change is deployed. Dependencies are updated regularly. Meadow reviews these measures, and who has access, at least annually and after any incident.
User identification and authorisation. Every Authorised User has a unique login; there are no shared or guest accounts. Multi-factor authentication is available to every Authorised User. Access within the Platform is role-based, with a fixed permission set per role assigned by the Customer's Admin Users; parents see only the children linked to them. Meadow's own access to provider consoles and the production database requires a named account with multi-factor authentication, is read-only, and is limited to named administrators.
Protection of data during transmission. TLS on every connection between Authorised Users, the Platform, the database and Sub-Processors. No removable media is used for Customer Data.
Protection of data during storage. Encryption at rest, private storage buckets, and daily backups held by the hosting provider in Ireland. Meadow staff devices use full-disk encryption and a password manager. No Customer Data is stored at Meadow's premises.
Physical security. Customer Data is held only in the hosting providers' data centres in Ireland, which control physical access with professional security staff, identity checks, surveillance and access logging.
Event logging. Every record carries who created and last changed it and when. Attendance records are append-only; corrections are recorded as new entries. Permanent deletion of a child's record requires a typed confirmation and a recorded reason. Infrastructure access and error logs are retained by the hosting providers for their standard periods, currently no longer than 90 days.
System configuration. Infrastructure is configured in code and reviewed before deployment. Storage is private by default. Error reporting excludes session replay.
Internal IT and security governance. Meadow's director is responsible for information security and data protection. Staff with access to Customer Data are bound by confidentiality. Access is granted on a need-to-know basis and reviewed at least annually. Meadow has data processing agreements with every Sub-Processor in Appendix B.
Certification and assurance. Meadow holds no certification of its own. Its hosting providers hold ISO 27001 and SOC 2 reports, available on request from those providers.
Data minimisation. The Platform offers only the fields a childcare service needs to meet its obligations; there are no fields for PPS numbers, ethnicity, religion, family financial details or Garda-vetting records. The Customer decides which fields it uses.
Data quality. The Customer can correct any record at any time, and every change is attributed and dated.
Limited retention. Customer Data is retained as clauses 3.2 and 8 provide. Notification history is kept for 30 days and expired invitations are cleared after 90 days.
Accountability. This DPA, Meadow's records of processing, its agreements with Sub-Processors, and the annual review of these measures.
Portability and erasure. The Customer can export its data, withdraw a child, remove a parent's access, and permanently delete a child's record from within the Platform, and receives its data back or has it deleted under clause 8.
Appendix D: Supplementary Measures for Transfers Outside the EEA
- Customer Data is encrypted in transit and at rest.
- Customer Data is stored in Ireland; Sub-Processors outside the EEA receive only the data described for them in Appendix B.
- Meadow will, to the extent permitted by law, resist any request from a public authority outside the EEA for Customer Data, use available legal mechanisms to challenge it, and notify the Customer of any binding legal demand it receives unless prohibited by law.