Skip to content

Data Processing Addendum

The processor agreement between Viva Longer LLC, doing business as Ashby Care, and the organization that accepts it. It forms part of the Terms of Service. Version dpa-gb-2026-08-29.

Effective: 29 August 2026. Version: dpa-gb-2026-08-29. DRAFT FOR COUNSEL REVIEW — NOT LEGAL ADVICE. Ticket: GUY-175.

This Data Processing Addendum (“DPA”) is between the organization that accepts it (the “Setting”) and Viva Longer LLC, a California limited liability company doing business as Ashby Care (“Ashby”). It forms part of the UK Terms of Service. If you do not agree, do not use the Services.

This DPA is for United Kingdom processing only (England first: GB-ENG). It is not the US DPA. A US organization must accept the US DPA. EEA / Ireland processing is not authorized until a separate pack exists.

1. Roles

The Setting is the controller under UK GDPR. Ashby is a processor. Ashby processes personal data only to provide the Services, on the Setting’s documented instructions.

Ashby does not claim COPPA or FERPA coverage for a child in the United Kingdom.

2. Instructions and limitations

Ashby will: (a) process Customer Data only to provide, maintain, secure, and support the Services; (b) not sell Customer Data; (c) not retain, use, or disclose Customer Data except as this DPA and the Terms allow; (d) ensure persons authorized to process Customer Data are bound to confidentiality; (e) not send children’s profiles, medical records, or photos to any AI provider.

Special-category data (including health-related care notes) is processed only as needed for the Setting to deliver care, on the Setting’s instructions.

3. UK representative (UK GDPR Article 27)

Ashby is not established in the United Kingdom. Ashby’s UK representative (to be completed from the signed DataRep UK mandate — GUY-178):

  • Name: [DATAREP UK — paste legal name from the signed mandate]
  • Address: [DATAREP UK — paste London contact address from the mandate]
  • Contact: contact@datarep.com
  • Buy / mandate: DataRep UK Basic, Sensitive Data Included

The representative does not take Ashby’s liability. Do not allow production UK child records until this block is filled from a signed mandate and this version is re-accepted if the text changes.

4. Subprocessors

The Setting authorizes subprocessors at ashbycare.com/legal/subprocessors. Ashby will give notice of material additions. Flow-down: each subprocessor is bound to data-protection terms no less protective than this DPA for the data it receives.

5. International transfers

Customer Data is hosted in the United States (Google Cloud us-west1) unless counsel later requires europe-west2. Transfers from the UK to Ashby in the US rely on the UK International Data Transfer Addendum to the EU Commission SCCs, or another transfer tool counsel names before production T3. This DPA does not rely on COPPA to authorize that transfer.

6. Assistance, retention, incidents

Parents direct requests to the Setting. Ashby will assist the Setting (export, correction, deletion) so the Setting can respond, including UK GDPR data-subject rights.

Retention follows the Setting’s configured policy and the GB-ENG jurisdiction ruleset, never shorter than an applicable licensing floor, and never indefinite.

Ashby will notify the Setting without undue delay after confirming a personal-data breach, with facts the Setting needs for ICO and parent notice.

7. Security and audits

Ashby maintains encryption in transit and at rest for personal data, tenant isolation, least privilege, and audit of access to child-sensitive records. On written request, Ashby will provide reasonable evidence of that program (not raw child records).

8. Order of precedence

If this DPA conflicts with the UK Terms on data protection, this DPA controls.