# CanopyKids — Data Processing Addendum (DPA)

**Template version:** 2026-07 · **Status:** Template for review by your legal counsel

This Data Processing Addendum ("DPA") supplements the CanopyKids Subscription Agreement between the school, district, or educational institution ("Customer") and CanopyKids, Inc. ("Processor") and governs the processing of Personal Data about students, staff, and parents in connection with the CanopyKids AI safety service (the "Service").

## 1. Roles
Customer is the Controller of student and staff Personal Data. Processor processes Personal Data solely on Customer's documented instructions to provide the Service, respond to support requests, and meet legal obligations.

## 2. Categories of data
- Account data: parent/educator email, display name, jurisdiction.
- Kid data: age band (not date of birth), chat prompts, AI responses, safety verdicts, rule-trace reasons.
- Operational data: session identifiers, timestamps, login IP address, user agent, error messages.

## 3. Purposes of processing
Providing the Service; enforcing safety, moderation, and rate limits; generating parent/educator dashboards and exports; billing and account administration; product security and fraud prevention.

## 4. Sub-processors
| Sub-processor | Purpose | Location |
| --- | --- | --- |
| Supabase (Lovable Cloud) | Database, auth, storage | US |
| Anthropic | LLM inference for safety and responses | US |
| Stripe | Subscription billing | US |
| Cloudflare | Edge hosting and DDoS protection | Global |

Processor will give Customer 30 days' notice before adding or replacing a sub-processor. Customer may terminate for material objection.

## 5. Security measures
Encryption in transit (TLS 1.2+) and at rest (AES-256 at the storage layer), row-level security scoping every read/write to the owning user, least-privilege service credentials, audit logging of every chat turn and safety event, and annual review of vendor security posture.

## 6. Data subject rights
Customer may access, export, correct, or delete Personal Data through the parent/educator dashboard and audit-log export. Processor will assist with data-subject requests within 30 days of a verified request.

## 7. Data retention and deletion
Chat turns, safety events, and login events are retained for the life of the account and deleted within 30 days of Customer's written deletion request or account termination, whichever is earlier. Billing records are retained as required by law.

## 8. International transfers
Where Personal Data is transferred outside the EEA/UK/Switzerland, Processor relies on the EU Standard Contractual Clauses (2021/914) and the UK IDTA.

## 9. Incident response
Processor will notify Customer without undue delay, and in any event within 72 hours, of any confirmed Personal Data breach affecting Customer data, and will cooperate with Customer's own notification obligations.

## 10. Audit
Processor will provide, once per year, a written summary of security controls and, on reasonable notice, respond to Customer security questionnaires.

## 11. Return / deletion on termination
On termination, Processor will delete or return all Customer Personal Data within 30 days, except where retention is required by law.

## 12. Governing law
This DPA is governed by the same law as the underlying Subscription Agreement.

---

**Signatures**

CanopyKids, Inc. — _________________________  Date: __________

Customer — _________________________________  Date: __________

_Questions? Email legal@canopykids.ai._
