Effective October 1, 2026 · Version 1.0 · Forms part of the daybell Terms of Service and applies to every center automatically
This Addendum forms part of the daybell Terms of Service between ThinkUncommon LLC ("daybell", "we", "us") and the center that has a daybell account ("Center", "you"). It applies automatically to every Center. No signature is needed for it to apply. If your organization requires a countersigned copy, see Section 15.
Where this Addendum and the Terms of Service disagree about how we handle information about children and families, this Addendum wins.
Center Data means information about children, families, staff and the Center that you or your staff put into daybell, or that daybell generates in the course of recording attendance, messages and access.
You control it. We process it for you. You decide what Center Data goes into daybell, who may see it, how long it is kept within our published schedule, and when it is deleted. Where privacy law uses the words "controller" and "processor", or "business" and "service provider", you are the controller or business and we are the processor or service provider.
We are not the owner of Center Data, and we make no claim to it.
We process Center Data solely to provide the Service, on your documented instructions, and for no other purpose.
Your instructions are: these Terms, this Addendum, the configuration choices you make in the Service, and any further written instruction you give us. If we think an instruction breaks the law, we will tell you rather than follow it.
These are absolute. They are not qualified by consent, by contract, or by any other exception, and we do not read the words "to provide the Service" as permitting any of them.
We will not:
a. Sell, rent, license or share Center Data, or disclose it for money or anything else of value.
b. Use Center Data for targeted or behavioral advertising, or disclose it to anyone else for that purpose.
c. Build a profile of any child, family or individual for any purpose unrelated to providing the Service to you.
d. Use Center Data to train, fine-tune, evaluate or develop any artificial intelligence or machine learning model, or allow any third party to. This prohibition applies to model training of any kind, including training we might otherwise characterize as improving the Service. "Improvement of the Service" does not permit training on Center Data, and nothing in this Addendum or the Terms may be read to permit it.
e. Combine Center Data with data from any other source, except where you instruct us to for your own purposes.
f. Retain, use or disclose Center Data outside the direct business relationship between us, or for any commercial purpose other than providing the Service.
g. Use Center Data for our own marketing, or to market to your families.
We certify that we understand these restrictions and will comply with them.
We will not collect, process or maintain Center Data that is not reasonably necessary to provide the Service to you.
We will make optional fields genuinely optional, so that a Center can run daybell without entering a date of birth, a photo, or a medical or free-text note if it chooses not to.
We maintain a written information security program, based on CIS Controls Implementation Group 1, appropriate to the sensitivity of Center Data and to our size. It includes:
We will give you a summary of this program on request. Everyone with access to Center Data is bound by a duty of confidentiality that survives the end of their engagement.
We may engage subprocessors to help provide the Service.
Before any subprocessor handles Center Data, we will take reasonable steps to satisfy ourselves that it can protect the confidentiality, security and integrity of the information, and we will obtain written assurances that it will use reasonable measures to do so. We will impose obligations at least as protective as this Addendum by written contract, and we remain responsible to you for what our subprocessors do.
We keep a current list of our subprocessors at daybell.app/subprocessors. You can subscribe to be notified of changes.
Before adding a new subprocessor, we will give you thirty days' notice. If you reasonably object on data protection grounds within that period, we will work with you to find a solution, and if we cannot, you may terminate the affected part of the Service without penalty and receive a refund of prepaid fees for the unused period.
At your direction, we will:
We will action a request from you within ten business days, or tell you why we need longer.
If an individual comes to us directly, we will not respond substantively on your behalf. We will acknowledge them, tell them their center controls the information, and pass the request to you within two business days, unless the law requires us to act ourselves. We will then help you respond.
You are responsible for handling requests from parents and guardians about their own records. We will make sure you can.
We retain Center Data only as long as it is reasonably necessary, and never indefinitely.
We maintain a written retention schedule setting out, for each category of Center Data, why it is collected, the business need for retaining it, and a timeframe for deletion. That schedule is published in our Privacy Policy at daybell.app/privacy. We follow it.
Retention periods for children's records are configurable by you, so you can meet the record keeping rules your licensing authority imposes. You are responsible for choosing a period that meets those rules. We do not advise on them.
On your instruction, and on termination, we will delete or return Center Data:
The only exception is where the law requires us to keep something, or where it is needed for a legal claim or investigation already under way. If that applies, we will tell you what we kept and why, keep only what is needed, isolate it, and delete it when it is no longer needed.
a. Notice. If we confirm a Data Breach affecting Center Data, we will notify you without unreasonable delay and in any event within seventy-two (72) hours of confirming it. Our internal target is twenty-four hours, and we usually expect to meet it, but seventy-two is what we commit to.
"Data Breach" means unauthorized access to, or acquisition of, Center Data.
b. What the notice will contain, so far as we know it at the time:
If we do not yet know the scope, we will say so plainly rather than estimate, and we will update you as we learn more. We will not characterize the scope of an incident as smaller than we know it to be, and we will not delay a first notice in order to complete our investigation.
c. Cooperation. We will cooperate with your own assessment and your notification obligations, including under state breach notification law, state student privacy law and your licensing rules. We will give you the information you need, on the timeline you need it.
d. Who notifies whom. You are responsible for notifying parents, guardians, regulators and your licensing authority where the law requires. We will not notify your families directly unless you ask us to or the law requires us to. Where we must notify a regulator ourselves, we will tell you first where we lawfully can.
e. Cost. Where a Data Breach is caused by our breach of this Addendum, we will reimburse your reasonable and documented costs of notification, subject to Section 14(c) of the Terms.
We may create de-identified data from Center Data and use it to operate, secure, support and improve the Service.
Where we do:
For the avoidance of doubt, this section does not permit anything prohibited by Section 3, including model training.
We will obtain an independent security assessment at least once a year, and after any Data Breach, and make the report available to you under a confidentiality agreement.
On reasonable written request, no more than once a year, we will give you the information reasonably necessary to demonstrate our compliance with this Addendum. Where the annual assessment answers your question, that is how we will answer it. If it does not, we will work with you on a proportionate alternative, which may include a questionnaire or a call with the person who runs our security program.
You confirm that:
We do not collect or process biometric identifiers. daybell does not use fingerprints, facial geometry, voiceprints or any other biometric identifier, and we will not introduce one without amending this Addendum and asking you to accept the change.
For transparency, since Centers sometimes ask: we will not ask you to accept responsibility for our compliance with any law that applies to us, and we will not state anywhere that you are responsible for our legal compliance.
Where a state law that applies to you requires terms not set out here, those terms are added by the applicable supplement at daybell.app/dpa#state-supplements and form part of this Addendum. In case of conflict, the supplement wins for that state.
If your state requires a term we cannot meet, we will tell you before you sign up rather than after.
This Addendum applies to every Center without signature. If your organization's procurement or insurance process requires a countersigned copy, email hello@daybell.app and we will send one. It will contain the same terms as this version, and signing it does not change your rights or ours.
We may update this Addendum. A change that reduces your rights or our obligations is a material change, and we will give you thirty days' notice and ask you to accept it, in the same way as a change to the Terms.
This Addendum applies for as long as we hold Center Data, including after your account ends and until deletion or return is complete.
Subject matter. Provision of the daybell attendance, kiosk and family messaging service.
Duration. For as long as the Center has an account, plus the retention and deletion periods in Section 8.
Nature and purpose. Recording arrivals and departures; holding a roster of children and families; holding authorized pickup lists and custody restrictions; sending messages the Center asks us to send; providing records for the Center's own record keeping and inspection obligations.
Categories of individual. Children enrolled at the Center; their parents, guardians and authorized adults; the Center's staff and owners.
Categories of Center Data. Names; dates of birth; arrival and departure times; family relationships; contact details including phone numbers and email addresses; authorized pickup lists and custody restrictions; allergy, medical, dietary and incident notes where the Center records them; photographs where the Center uses them; message content and delivery records; consent records; account credentials and access logs.
Sensitive categories. Data relating to children under 13. Allergy and medical information where a Center records it. We treat both as sensitive regardless of whether a particular state law classifies them that way.
Subprocessors. The current list is at daybell.app/subprocessors.
No state-specific supplements are currently published. If a state law that applies to your Center requires terms not set out in this Addendum, the supplement will be published here and we will tell you before you sign up rather than after.