Business data protection
Data Processing Agreement.
These terms form the controller–processor agreement for a nursery that accepts version 1.0 inside its Little Spaces workspace.
Effective 12 September 2026 · Version 1.0
Parties and status
Controller: the nursery or childcare business whose legal name, trading name and address are shown in its Little Spaces workspace and captured in its electronic acceptance record.
Processor:
North Petherton
Somerset
TA6 6NR
United Kingdom
Email: support@littlespaces.co.uk
Privacy: privacy@littlespaces.co.uk
This agreement forms part of the contract under which Little Spaces provides the booking service. The workspace records the accepting owner, date, agreement version, business details and a cryptographic document fingerprint.
1. Roles and instructions
The nursery determines why and how parent, child and booking information is used and is the controller. Little Spaces processes that information only to provide, secure, maintain and support the service and on the nursery’s documented instructions. Little Spaces will inform the nursery if an instruction appears to infringe data-protection law, unless the law prevents this.
Little Spaces does not sell booking information, use it for advertising, build child profiles or make automated nursery eligibility decisions. People authorised to process the information must be bound by confidentiality.
2. Processing details
- Subject and duration
- Operating the nursery booking service for the term of the service agreement, followed by the limited deletion or return period below.
- Nature and purpose
- Collection, validation, storage, organisation, retrieval, transactional email, payment-status synchronisation, correction, export, deletion, security monitoring and support so parents can request availability and authorised nursery staff can administer bookings.
- People
- Parents and carers, children named in booking requests, and authorised nursery staff.
- Information
- Parent or carer name, email and optional phone number; child’s first name and eligibility confirmation; booking, price and status; accepted terms; payment references; staff identity, role and audit activity; and pseudonymous abuse-prevention records.
- Sensitive information
- Not intentionally collected. The nursery must not enter health, medical, allergy, dietary, safeguarding or other special-category information into Little Spaces.
3. Security and confidentiality
Little Spaces maintains measures appropriate to the risk, including tenant separation, individual staff accounts, role-based server authorisation, encrypted transport and provider-managed encrypted storage, secret management outside source control, Stripe-hosted payment entry, send-only Microsoft email, expiring private booking links, rate limits, audit records and automated retention.
Each nursery must give access only to people who need it, apply the lowest suitable role, promptly remove leavers, keep notification and payment settings accurate and report suspected incidents without delay.
4. Subprocessors and transfers
The nursery gives general written authorisation for the providers on the current Little Spaces subprocessor list. Little Spaces will impose appropriate data-protection duties, remain responsible for their relevant processing, give reasonable advance notice of a material addition or replacement and allow a reasonable opportunity to object on substantiated data-protection grounds.
Little Spaces will not make a restricted international transfer unless an adequacy regulation, the UK International Data Transfer Agreement/Addendum or another lawful safeguard applies.
5. Rights and compliance assistance
Taking account of the nature of the processing, Little Spaces will provide reasonable technical and organisational assistance so the nursery can respond to access, correction, deletion, restriction, objection and portability requests. The nursery remains responsible for identity checks, decisions, exemptions and information held in its other systems.
Little Spaces will provide information reasonably necessary to demonstrate compliance and support a proportionate audit on reasonable notice. Existing independent reports and written evidence should be used first where sufficient.
6. Security incidents
Little Spaces will notify the nursery without undue delay after becoming aware of a personal-data breach affecting nursery-controlled information and will reasonably assist with containment, evidence, risk assessment and required notices. The nursery normally decides whether the ICO or affected people must be notified.
7. Retention and end of service
Unsuccessful or unpaid requests are normally deleted after 90 days. Confirmed, paid and refunded booking records are normally deleted 12 months after the booked date, and private status links expire 30 days after it. Stripe, the nursery or accounting systems may retain financial records longer where law requires.
At the end of the service, Little Spaces will provide an available structured export and delete nursery-controlled information at the nursery’s choice, subject to law and limited records needed to demonstrate compliance or resolve disputes. Protected recovery copies may remain until overwritten through the provider’s normal cycle.
8. Priority, liability and law
This agreement takes priority over the main service terms where they conflict about processing nursery-controlled personal information. Nothing removes either party’s direct legal responsibilities. Liability follows the main service agreement subject to rights or liabilities that cannot lawfully be excluded. The intended governing law and courts are those of England and Wales.
Electronic acceptance
Little Spaces agrees to these processor obligations by publishing this version and making the service available. An authorised workspace owner accepts it for the nursery by completing the recorded acceptance step. Both parties may retain the electronic record as evidence of the agreement.
Questions can be sent to privacy@littlespaces.co.uk.
Back to Little Spaces