Data processing agreement
Version 1.0 · Last updated 30 June 2026
This Data Processing Agreement (the "DPA") sets out the terms under which Nursery Room Ltd, trading as Yenlio ("Yenlio", "we", "us", "our"), processes personal data on behalf of the Customer (the nursery, childminder, early-years provider or group using Yenlio). It forms part of, and supplements, the Terms of service between Yenlio and the Customer (the "Agreement").
This DPA reflects the UK GDPR and the Data Protection Act 2018. The Data (Use and Access) Act 2025 received Royal Assent on 19 June 2025 and amends UK data-protection law and the Privacy and Electronic Communications Regulations (PECR); we keep this DPA current with those reforms. This DPA is governed by the laws of England & Wales.
1. Parties and roles
- The Customer is the controller of the personal data it enters into and runs through the service ("Customer Personal Data"). The Customer determines the purposes and means of processing that data and the lawful basis for it.
- Nursery Room Ltd / Yenlio is the processor, processing Customer Personal Data on the Customer's behalf to provide the service.
Yenlio is a company registered in England & Wales (company number 11237964), with its registered office at 375 Bellegrove Road, Welling, Kent, DA16 3RL, United Kingdom. For any data-protection matter under this DPA, contact privacy@yenlio.app.
2. Scope
This DPA applies whenever Yenlio processes Customer Personal Data on the Customer's behalf through the service. It supplements the Agreement; where the Agreement and this DPA conflict on a data-protection matter, this DPA prevails. Yenlio's processing of data for which Yenlio is itself the controller — such as account, billing, website-enquiry, support, and security-log data — is described in our Privacy notice and is not governed by this DPA.
3. Processing instructions
Yenlio processes Customer Personal Data only on the Customer's documented instructions, including with regard to international transfers, unless required to act otherwise by law. The Agreement, this DPA, the configuration choices the Customer makes in the service, and the Customer's use of the service together constitute the Customer's documented instructions. Where the law requires Yenlio to process data beyond those instructions, we will inform the Customer of that legal requirement before processing, unless the law prohibits us from doing so on important grounds of public interest. If Yenlio considers an instruction to infringe applicable data-protection law, we will inform the Customer.
4. Subject matter and duration
- Subject matter: the provision of Yenlio, a software-as-a-service nursery-management platform, and the processing of Customer Personal Data necessary to provide it.
- Duration: for the term of the Agreement, plus the retention and deletion period described in section 12.
5. Nature and purpose of processing
Yenlio processes Customer Personal Data to provide and support the service. The nature and purpose of processing includes hosting, storing, transmitting, securing, organising, displaying and analysing data; generating staff-reviewed AI drafts and summaries; translating content; sending notifications; producing invoices; and otherwise supporting nursery operations as configured by the Customer.
6. Categories of data subjects
Depending on how the Customer uses the service, the data subjects may include:
- children;
- parents and guardians;
- emergency contacts;
- staff and customer administrators;
- visitors, where their details are entered; and
- professional contacts.
7. Categories of personal data
Depending on how the Customer uses the service, Customer Personal Data may include:
- account, profile and contact data (names, email addresses, roles, login identifiers);
- setting details (nursery/childminder name, address, registration and configuration);
- child records and care information;
- parent and guardian contact details and parental-responsibility status;
- staff user data entered by the setting;
- attendance and register data;
- observations and learning-journey entries;
- assessments and reports;
- SEND and support information where entered;
- accident and incident reports;
- medication and health records;
- consent forms and electronic signatures;
- invoices, payments and Direct Debit status;
- communications and messages;
- photos, videos and associated media metadata;
- audit logs, security logs, and device/session data; and
- AI and translation inputs and outputs where those features are enabled and used.
8. Special-category personal data
Some operational childcare records contain special-category or otherwise sensitive personal data, processed on behalf of and under the control of the Customer. This may include:
- health and medication information;
- SEND and disability-related information;
- accident and injury details;
- safeguarding-adjacent notes; and
- ethnicity, language, religion and dietary information where entered by the setting and relevant.
Yenlio applies additional safeguards to this data and processes it only as instructed by the Customer.
9. Processor obligations
Yenlio will:
- Confidentiality — ensure that personnel authorised to process Customer Personal Data are bound by appropriate confidentiality obligations.
- Security — implement appropriate technical and organisational measures to protect Customer Personal Data, as described in our Security measures. These include, where implemented, encryption in transit and at rest, role-based access controls, tenant isolation between settings, audit logging, multi-factor authentication and passkeys where available, and continuous monitoring.
- Access controls — restrict access to Customer Personal Data to authorised personnel who need it to provide or support the service.
- Data-subject rights — taking into account the nature of the processing, assist the Customer by appropriate technical and organisational measures, insofar as possible, in responding to requests from data subjects exercising their rights.
- DPIAs and prior consultation — assist the Customer in carrying out data protection impact assessments and any required prior consultation with the ICO, taking into account the nature of the processing and the information available to Yenlio.
- Breach notification — notify the Customer without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data, and provide information reasonably available to assist the Customer in meeting its own obligations (see section 13).
- Deletion or return — at the end of the provision of the service, delete or return Customer Personal Data as described in section 12.
- Demonstrating compliance — make available to the Customer the information necessary to demonstrate compliance with this DPA, and allow for and contribute to audits, including inspections, conducted by the Customer or another auditor mandated by the Customer, on reasonable notice and subject to confidentiality and security safeguards. Yenlio may satisfy audit requests in the first instance by providing relevant documentation and certifications.
10. Sub-processors
The Customer authorises Yenlio to engage the sub-processors listed on our sub-processors page to process Customer Personal Data in connection with the service. Yenlio imposes data-protection obligations on each sub-processor that are substantially the same as those in this DPA, and remains responsible to the Customer for the performance of each sub-processor's obligations.
Yenlio maintains the sub-processor page and will give notice of any intended material change concerning the addition or replacement of a sub-processor. The Customer may object to such a change on reasonable data-protection grounds by contacting privacy@yenlio.app; the parties will work in good faith to resolve the objection.
11. International transfers
Yenlio's primary hosting and storage is in the United Kingdom and Ireland/EU. Where a specialist sub-processor is used, Yenlio requires appropriate contractual, security and transfer safeguards and maintains an up-to-date sub-processor list at /subprocessors.
12. Data export, deletion and return
During the term, the Customer can access and export Customer Personal Data through the service. On termination or expiry of the Agreement, the Customer may request export and/or deletion of Customer Personal Data. Yenlio will delete or return Customer Personal Data accordingly, subject to limited backup cycles (where data is overwritten or deleted on a rolling basis) and to any retention required by law.
13. Incident handling
If Yenlio becomes aware of a personal-data breach affecting Customer Personal Data, it will notify the Customer without undue delay and cooperate in good faith to investigate, mitigate and remediate the incident. Notification will, where available, describe the nature of the breach, the likely consequences, and the measures taken or proposed. A notification is not an acknowledgement of fault or liability.
14. AI and translation
Where enabled and used, Yenlio's optional AI and translation features are provided through AI and translation processors. These processors are engaged only where the relevant feature is enabled and used.
- AI features in Yenlio are assistive only. They draft, summarise or review content to save staff time. They do not make autonomous or automated decisions, and they do not carry out profiling that produces legal or similarly significant effects on individuals. Staff review and approval remain required before any AI-assisted content is relied upon or acted on.
- Prompts and outputs are treated as Customer Personal Data where they contain personal data, and are processed under this DPA.
- Translation is convenience machine translation and may not be perfect; it is not certified human translation. Where a translation appears wrong or unclear, the original wording should be confirmed with the setting.
15. Security measures
The technical and organisational security measures Yenlio applies to Customer Personal Data are described in our Security measures, which forms part of this DPA. Yenlio may update its security measures from time to time, provided that the level of protection is not materially reduced.
16. Liability, precedence and governing law
This DPA is governed by, and subject to, the Agreement, including any limitations and exclusions of liability set out in it. In the event of a conflict between this DPA and the Agreement on data-protection matters, this DPA prevails. This DPA is governed by the laws of England & Wales.
Related documents: Terms · Privacy notice · Sub-processors · Security