CrecheFlow
MenuClose
ServicesHow it worksPricingAboutSchedule a call
Back to CrecheFlow

Data Processing Agreement

Data Processing Agreement | CrecheFlow

Version 1.0 - Effective: 16 September 2026

Relationship to the Services Agreement

This Data Processing Agreement ("DPA") supplements and is incorporated by reference into the CrecheFlow Services Agreement (the "Agreement") entered into between CrecheFlow and the Client. It reflects the requirements of Article 28 of the GDPR for processing carried out by CrecheFlow, as Processor, on behalf of the Client, as Controller. In the event of any conflict between this DPA and the Agreement regarding data processing matters, this DPA shall prevail, consistent with Section 4.2 and Section 12.4 of the Agreement.

1. Parties

Data Exporter / ControllerThe Client, as defined in the Agreement.
Data Importer / ProcessorEdita Petrauskaite, trading as CrecheFlow, a sole trader registered in Ireland (Business Name No. 785771), Scartaglen, Co. Kerry, Ireland, V93 R886.

2. Definitions

Terms used in this DPA that are defined in the Agreement (including Client Data, AcornCloud Platform, Authorised Representative, Written Instructions, Approved Output, and Hive / Pobal Hive) have the same meaning here. In addition:

TermDefinition
GDPRRegulation (EU) 2016/679, as supplemented by the Data Protection Acts 1988-2018 of Ireland.
Personal Data, Processing, Controller, Processor, Data Subject, Personal Data BreachHave the meanings given in Article 4 GDPR.
Sub-processorAny third party engaged by CrecheFlow to process Client Data on the Client's behalf in connection with the Services.
EEAThe European Economic Area.

3. Roles of the Parties

The Client is the Data Controller in respect of all personal data contained within Client Data.

CrecheFlow is the Data Processor and processes Client Data solely on behalf of, and in accordance with the documented instructions of, the Client, as set out in this DPA, the Agreement, and any Written Instructions given under the Agreement.

4. Subject Matter, Duration, Nature and Purpose of Processing

Subject matterCrecheFlow's provision of Financial Administration Services to the Client, as described in Section 2 of the Agreement.
DurationFor the term of the Agreement, and thereafter for the 30-day data export period described in Section 11.5 of the Agreement.
Nature of processingCollection, verification, posting, allocation, and reconciliation of financial and funding records, performed exclusively within the AcornCloud Platform.
Purpose of processingGenerating and posting parent invoices; applying funding deductions and allocations; allocating received payments; performing funding reconciliation between the AcornCloud Platform and Hive data made available to CrecheFlow.

5. Categories of Data Subjects

  • Children in the Client's care;
  • Parents and guardians of children in the Client's care;
  • The Client's Authorised Representative(s) and relevant staff.

6. Categories of Personal Data

  • Children's names, and attendance, booking, and session data;
  • NCS, ECCE, and Core Funding eligibility and hours, as reflected in the AcornCloud Platform;
  • Parent/guardian names, contact details, and billing information;
  • Payment records (amounts, dates, and payment method) as provided via bank statements or compliant Written Instructions;
  • Correspondence forming part of Written Instructions, which may reference the above categories.

Client Data does not include special category data within the meaning of Article 9 GDPR (such as health or medical information). If this changes in future, this DPA should be revisited to add appropriate additional safeguards.

7. Processor Obligations

CrecheFlow shall:

  • Process Client Data only on the Client's documented Written Instructions, including with regard to transfers of personal data to a third country, unless required to do otherwise by EU or Irish law (in which case CrecheFlow shall inform the Client of that legal requirement before processing, unless the law prohibits this);
  • Ensure that persons authorised to process Client Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality;
  • Implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as further described in Section 11;
  • Not engage a sub-processor without the Client's general or specific written authorisation, as described in Section 9;
  • Taking into account the nature of the processing, assist the Client by appropriate technical and organisational measures, insofar as possible, in fulfilling the Client's obligation to respond to requests for exercising a data subject's GDPR rights;
  • Assist the Client in ensuring compliance with its obligations relating to security of processing, breach notification, and data protection impact assessments, taking into account the nature of processing and the information available to CrecheFlow;
  • At the Client's choice, delete or return all Client Data to the Client after the end of the provision of Services relating to processing, and delete existing copies, in accordance with Section 11.5 of the Agreement, unless retention is required by applicable law;
  • Make available to the Client all information necessary to demonstrate compliance with this Section 7 and the obligations in Article 28 GDPR, and allow for and contribute to audits, including inspections, conducted by the Client or an auditor mandated by the Client, subject to Section 10 below.

8. Client (Controller) Obligations

As set out in Sections 3 and 4 of the Agreement, the Client remains solely responsible for determining the purposes and means of processing Client Data, ensuring a lawful basis exists for all such processing, providing appropriate privacy notices to parents, guardians, and staff, and responding to data subject rights requests (with CrecheFlow's reasonable assistance as described in Section 7 above). The Client warrants that its Written Instructions to CrecheFlow will comply with applicable data protection law.

9. Sub-processors

The Client provides CrecheFlow with general written authorisation to engage sub-processors in connection with the Services, subject to CrecheFlow imposing data protection terms on each sub-processor that are no less protective than those in this DPA, and to the notification process below.

Sub-processorPurposeLocation
AcornCloud PlatformHosting of the Client's booking, attendance, funding, and financial records, within which CrecheFlow performs the ServicesIreland
Microsoft 365Hosting of CrecheFlow's email ([email protected]), including receipt of Written Instructions that may reference Client DataUnited States (Microsoft Ireland Operations Limited is the EU data controller/representative)

This is the complete and current list of sub-processors involved in processing Client Data.

CrecheFlow shall keep this list current and shall notify Clients of any intended addition or replacement of a sub-processor, giving the Client a reasonable opportunity to object, consistent with GDPR Article 28(2).

10. Audits

CrecheFlow does not maintain an office accessible to the public and does not offer on-site inspections. Instead, CrecheFlow shall make available to the Client such information as is reasonably necessary to demonstrate compliance with this DPA by completing the CrecheFlow Data Protection Questionnaire (a separate document, available on request), on the Client's written request, no more than once every 12 months (or more frequently following a Personal Data Breach affecting Client Data). CrecheFlow shall return the completed Questionnaire within a reasonable time, and in any event within 30 working days of the Client's request.

11. Security Measures

Consistent with Section 4.5 of the Agreement, CrecheFlow implements industry-standard technical and organisational security measures appropriate to the risk, which may include:

  • Restricting access to Client Data to personnel who require it to perform the Services;
  • Requiring confidentiality commitments from personnel with access to Client Data;
  • Relying on the AcornCloud Platform's own security controls for data at rest and in transit within the Platform, as the Platform is operated by AcornCloud, not CrecheFlow;
  • Devices used to access Client Data are password protected, with device (disk) encryption enabled;
  • CrecheFlow is currently operated by a single individual; a formal written password policy will be introduced as the business grows and additional staff are engaged;
  • Any personnel engaged to handle Client Data in future will receive data protection training before being given access.

12. Personal Data Breach Notification

CrecheFlow shall notify the Client without undue delay and in any event within 48 hours after becoming aware of a Personal Data Breach affecting Client Data, and shall provide the Client with such information as CrecheFlow has available to assist the Client in meeting its own breach notification obligations to the Data Protection Commission and affected data subjects under GDPR Articles 33 and 34. Responsibility for making any regulatory notification remains with the Client as Data Controller, consistent with Section 4.1 of the Agreement.

13. International Transfers

The AcornCloud Platform, within which the Services are performed, is hosted in Ireland, and Client Data processed within it does not involve a transfer outside the EEA. Where Written Instructions containing Client Data are sent by email to CrecheFlow's Microsoft 365-hosted mailbox, this may involve a transfer of that data outside the EEA. Any such transfer is subject to the Standard Contractual Clauses incorporated into Microsoft's Online Services Terms, as confirmed in Section 9 above.

14. Hive / Pobal Hive - Special Position

For the avoidance of doubt, and consistent with Sections 2.2, 3.3, and 3.3A of the Agreement, CrecheFlow does not access Pobal Hive as a matter of standard service and this DPA does not authorise such access. Where a specific arrangement requires CrecheFlow personnel to access Hive directly, the additional consent, scope, and indemnity requirements of Section 3.3A of the Agreement apply in full, in addition to this DPA.

15. Deletion or Return of Data on Termination

On termination or expiry of the Agreement, CrecheFlow shall make Client Data available for export via the AcornCloud Platform for 30 days, after which it may be deleted in accordance with CrecheFlow's data retention policies, consistent with Section 11.5 of the Agreement.

16. Liability

Each party's liability arising out of or in connection with this DPA is subject to the limitation and exclusion provisions set out in Section 7 of the Agreement, which apply to this DPA as if set out in full.

17. Order of Precedence and Term

This DPA takes effect on the Effective Date of the Agreement and continues for as long as CrecheFlow processes Client Data on the Client's behalf. Where there is any conflict between this DPA and the Agreement on data processing matters, this DPA prevails, consistent with Section 12.4 of the Agreement. On all other matters, the Agreement continues to apply.

18. Acceptance

By entering into the CrecheFlow Services Agreement, the Client agrees to be bound by this Data Processing Agreement.

Signed for and on behalf of CrecheFlow

Name: ____________________________

Title: ____________________________

Date: ____________________________

Signed for and on behalf of the Client

Name: ____________________________

Title: ____________________________

Date: ____________________________

We prepare. You approve. Together we keep things flowing.

Schedule a call

Site

  • Services
  • How it works
  • Pricing
  • About

Legal

  • Privacy policy
  • Cookie policy
  • Terms of service
  • Data processing agreement

Contact

  • [email protected]
  • Creches across Ireland

© 2026 CrecheFlow. Finance operations for creches in Ireland.