Updated: 2026-07-24

Data Processing Agreement (DPA) - Kindertap®

The Data Processing Agreement (DPA), or Data Processor Appointment, is the agreement whereby, pursuant to Art. 28 of the European General Data Protection Regulation (EU) 2016/679 (hereinafter the “GDPR”), the Data Controller appoints Develia S.r.l. as Data Processor for the personal data processed on its behalf through the Kindertap® platform, defining the purposes, nature, safeguards and mutual obligations.
At Kindertap® we know how sensitive the data you manage every day through our services is – that of children, families and the staff of your facilities – and that is why we devote the utmost care to ensuring its security and full compliance with the GDPR.
This DPA applies automatically, as an integral part of the Service’s Terms and Conditions, to all Customers who activate a Kindertap account, unless a different Data Processing Agreement, separately executed by the Parties, is in force between the Customer and Develia S.r.l.; in that case, the provisions of that dedicated agreement shall prevail.

Premise

Kindertap® is a software service (SaaS) developed and provided by Develia S.r.l., with registered office in Via Europa 22/B, Pove del Grappa (VI), Italy, VAT and Tax No. 04135910240 (hereinafter “Develia” or the “Data Processor”), dedicated to the management of nurseries, schools, childcare centers, playrooms and baby-parking facilities.

The party, whether an individual or a company, that activates a Kindertap account (hereinafter the “Customer” or the “Data Controller”) processes, through the platform, personal data relating to the users of its facilities (children, parents and companions) and to its employees or collaborators. In providing the Service, Develia processes such data on behalf of the Customer and therefore acts as Data Processor pursuant to Art. 28 of the GDPR.

For all processing of personal data for which Develia instead acts as an independent Data Controller (for example, data collected through the corporate website or the Service registration form), please refer to the Privacy Policy.

Clauses

  1. Parties and definitions:
    1. Data Controller: the Customer who activates a Kindertap account and determines the purposes and means of processing the personal data of Data Subjects, uploaded or collected through the Service.
    2. Data Processor: Develia S.r.l., which processes personal data on behalf of, and in accordance with the instructions of, the Data Controller, for the purposes connected with the provision of the Service.
    3. Data Subjects: the users of the Customer’s facilities (children, parents and companions) and the Customer’s employees or collaborators, whose personal data is processed by the Customer through Kindertap.
    4. This DPA forms an integral and substantial part of the Service’s Terms and Conditions and takes effect from the moment the Customer activates its Kindertap account.
  2. Subject matter and description of the processing:
    1. Develia is authorized to process, on behalf of the Data Controller, the personal data necessary to provide the following services:
      • supply of the Kindertap management software as a “Software as a Service” (SaaS) on cloud infrastructure;
      • technical support services relating to the Kindertap management software, provided remotely (remote assistance) or at the Data Controller’s premises.
    2. The nature of the operations carried out on the data is:
      • storage and protection of personal data in a cloud environment;
      • remote viewing (via remote assistance), or viewing at the Data Controller’s premises, of personal data stored at the Data Controller’s premises.
    3. The purpose(s) of the processing are:
      • configuration, management and maintenance of the cloud infrastructure for the provision of the management software;
      • technical support for the maintenance of IT services;
      • technical support at the Data Controller’s request.
    4. The personal data processed are:
      • identification data, contact data, health-related data and, where present, photographs of the users of the facilities (children, parents and companions) acquired by the Data Controller;
      • identification data, contact data and, where present, photographs of the Data Controller’s employees or collaborators.
    5. The categories of data subjects are:
      • users of the Data Controller’s facilities (children, parents and companions);
      • employees or collaborators of the Data Controller.
    6. The Data Controller shall make available to the Data Processor all the information necessary for the full and correct performance of the Service.
  3. Duration: this DPA takes effect on the date the Customer activates its Kindertap account and remains in force for the entire duration of the Service, until termination thereof in accordance with the procedures set out in the Terms and Conditions.
  4. Obligations of the Data Processor: Develia, as Data Processor, undertakes to:
    1. process the data only for the purpose(s) specified in Article 2 and for the performance of the contractual services;
    2. process the data in accordance with the documented instructions of the Data Controller referred to in Article 5 below. Should Develia consider that an instruction constitutes a breach of the GDPR or of other provisions of Union or Member State law relating to data protection, it shall immediately inform the Data Controller. Furthermore, should it be required to transfer data to a third country or an international organization under such laws, it shall inform the Data Controller in advance of this obligation, unless the applicable law prohibits such information for important reasons of public interest;
    3. ensure the confidentiality of the personal data processed under this DPA;
    4. ensure that persons authorized to process personal data under this DPA:
      1. undertake to respect confidentiality or are subject to an appropriate statutory obligation of secrecy;
      2. receive the necessary training in personal data protection;
    5. take into account, when using materials, products, applications or services, the principles of data protection by design and by default;
    6. where it engages a further Data Processor to carry out specific processing activities, inform the Data Controller in advance, clearly indicating the activities delegated and the identity of the further Processor. The Data Controller has 15 days from receipt of such information to raise objections. The further Data Processor must comply with the obligations of this DPA on behalf of, and in accordance with the instructions of, the Data Controller; Develia remains fully liable to the Data Controller for the performance of such obligations by the further Processor. The updated list of further Data Processors used by Develia is available and can be consulted by the Data Controller directly within the Kindertap platform, under the menu item Privacy/Security > Privacy Center;
    7. keep the location of the personal data processed on behalf of the Data Controller limited to the EU/EEA. The updated list of countries and cloud infrastructures where the data is stored is available and can be consulted by the Data Controller directly within the Kindertap platform, under the menu item Privacy/Security > Privacy Center;
    8. bear in mind that it is the Data Controller’s responsibility to provide Data Subjects with the information notice referred to in Articles 13-14 of the GDPR at the time the data is collected;
    9. assist, as far as possible, the Data Controller in responding to Data Subjects’ requests to exercise their rights (access, rectification, erasure, objection, restriction of processing, data portability, and the right not to be subject to automated decision-making). Should a Data Subject exercise such rights directly with Develia, Develia shall forward the request to the Data Controller at the e-mail address indicated in Article 7 of this DPA;
    10. notify the Data Controller of any personal data breach within a maximum of 24 hours of becoming aware of it, by e-mail to the Data Controller’s address. The notification shall be accompanied by all documentation useful to enable the Data Controller, if necessary, to notify the breach to the competent supervisory authority, and shall describe at least:
      1. the nature of the breach, including, where possible, the categories and approximate number of Data Subjects and personal data records concerned;
      2. the name and contact details of the point of contact where further information can be obtained;
      3. the likely consequences of the breach;
      4. the measures taken or proposed to remedy the breach and mitigate its possible adverse effects;
    11. assist the Data Controller in carrying out data protection impact assessments under Art. 35 of the GDPR and in the prior consultation with the supervisory authority under Art. 36 of the GDPR;
    12. implement a structured set of technical and organizational security measures, appropriate to the risk and periodically reviewed and updated, including in particular:
      • Security governance: information security management based on defined roles and responsibilities, periodic assessment of risks to the confidentiality, integrity and availability of personal data, structured change management for the systems and infrastructure delivering the Service, and inventory/classification of information assets according to their criticality;
      • Access control: access to systems and personal data restricted to authorized personnel only, based on the principles of least privilege and need-to-know, authentication through individual credentials with periodic rotation of administrative credentials, periodic review of granted authorizations with prompt revocation upon termination of the relationship, and detailed logging and traceability of access to, and modification of, personal data;
      • Technical and infrastructural security: pseudonymization/encryption of personal data, for both “live” copies and backup copies, data transmissions and transfers carried out through secure connections and up-to-date encryption protocols (e.g. TLS/SSL), protection of IT systems through properly configured firewalls and antivirus/anti-malware systems, periodic updating of software components, periodic vulnerability assessments and penetration tests on the systems delivering the Service with structured management of any issues identified, and cloud infrastructure hosted at data centers equipped with adequate physical and environmental security measures (access control, video surveillance, fire protection, power continuity);
      • Remote assistance connections: permitted, where necessary, only upon the Data Controller’s invitation and for the time strictly necessary to provide the support service, with supervision by personnel authorized by the Data Controller;
      • Business continuity and incident management: daily geo-redundant backup of personal data, on servers located in geographic areas different from the ordinary storage location (spread across different EU Member States), real-time data redundancy where technically feasible, active 24/7 monitoring system to analyze the operation and availability of systems and backup copies, data restoration in the event of a technical incident within 24 hours, documented security incident management procedures with subsequent analysis aimed at preventing recurrence, and a business continuity and disaster recovery plan that is periodically tested;
      • Personnel and supplier security: confidentiality obligations and periodic training on personal data protection and information security for all personnel authorized to process data, as well as selection and assessment of suppliers and further Data Processors based on adequate security and data protection guarantees;
      • Data minimization: adoption of the data minimization principle and, unless otherwise agreed, no use of Data Subjects’ real personal data in test or development environments unless duly anonymized or pseudonymized.
    13. at the end of the provision of the services, unless Italian or EU law requires their retention, destroy all personal data within 15 days of the end of the service and document the destruction in writing;
    14. communicate to the Data Controller the name and contact details of its Data Protection Officer, appointed pursuant to Art. 37 of the GDPR, and promptly notify any change thereto. Develia’s Data Protection Officer is currently IVIQUESSE Srl SB, with registered office in Via Bastia Vecchia n. 26, Castelfranco Veneto (TV), Italy, VAT No. 03605440266, who can be contacted by email at dpo or by mail/registered letter at Develia’s address indicated in Article 7 of this DPA;
    15. keep a written record of all categories of processing activities carried out on behalf of the Data Controller, including:
      1. the name and details of the Data Controller, of any further Processors and, where applicable, of the Data Protection Officer;
      2. the categories of processing carried out on behalf of the Data Controller;
      3. where applicable, transfers of personal data to a third country or international organization and the documents evidencing the existence of appropriate safeguards;
      4. as far as possible, a general description of the technical and organizational security measures adopted;
    16. make available to the Data Controller the documentation necessary to demonstrate compliance with the obligations set out in this DPA and to allow for the carrying out of reviews, including inspections, by the Data Controller or a party appointed by it, contributing to such verification activities.
  5. Documented instructions from the Data Controller: pursuant to point b) of the previous Article, Develia processes personal data in accordance with the following documented instructions from the Data Controller:
    1. the processing of personal data must be carried out in accordance with the principles of applicable data protection law;
    2. the processing of personal data must be carried out in performance of the Service’s Terms and Conditions and for the purposes relating to the provision of the services set out therein, for the time strictly necessary to achieve such purposes as well as those strictly connected and instrumental to managing related technical issues;
    3. Develia must ensure full compliance with the obligations imposed by the GDPR directly on the Data Processor, including, by way of example, the obligation to keep a record of processing activities under Art. 30(2) of the GDPR and, where required, the obligation to appoint a Data Protection Officer under Art. 37(1) of the GDPR;
    4. Develia must implement, in accordance with Art. 32 of the GDPR, technical and organizational measures to ensure an adequate level of security for the processing carried out on behalf of the Data Controller;
    5. except in cases strictly necessary for the provision of services related to the Service, Develia must not disclose or make personal data known to third parties and must adopt the organizational and technical measures necessary to ensure the utmost confidentiality of the personal data acquired and used in carrying out the activities covered by this DPA;
    6. Develia must not transfer personal data outside the European Union without the Data Controller’s prior written authorization and in compliance with the principles and conditions applicable to transfers set out in Chapter V of the GDPR;
    7. Develia must ensure that access to personal data by its staff takes place only on a need-to-know basis and that processing connected with the performance of the Service is carried out only by authorized persons acting under Develia’s authority on the basis of appropriate instructions;
    8. Develia must adopt, keep up to date and regularly assess all technical and organizational measures necessary to ensure a level of security appropriate to the risk, in accordance with Art. 32 of the GDPR.
  6. Obligations of the Data Controller: the Customer, as Data Controller, undertakes to:
    1. provide Develia with the data and information necessary for the full and correct performance of the Service;
    2. document in writing any instructions concerning the processing of data by Develia, in addition to those set out in Article 5;
    3. oversee, both in advance and throughout the processing, Develia’s compliance with the obligations set out in the GDPR;
    4. supervise the processing, including reviews and inspections carried out by Develia;
    5. implement the security measures required under Art. 32 of the GDPR for the processing for which it is an independent Data Controller.
  7. Domicile for communications:
    1. Develia S.r.l., Data Processor: Via Europa 22/B, 36020 Pove del Grappa (VI), Italy; e-mail for privacy communications: info; certified e-mail (PEC): info;
    2. the Customer, Data Controller: the e-mail address and, where applicable, the certified e-mail (PEC) address provided at Service activation or associated with its Kindertap account.
  8. Governing law – Competent court: this DPA is governed by Italian law. Any dispute arising in connection with this DPA shall fall under the exclusive jurisdiction of the Court of Vicenza, except as otherwise provided in the Terms and Conditions regarding dispute resolution.