TENERWISE DATA PROCESSING ADDENDUM

Last updated: August 20, 2026

This Data Processing Addendum ("DPA") is incorporated into and forms part of the Tenerwise Terms of Service ("Terms") between Tenerwise LLC ("Tenerwise," "we," "us," or "our") and the childcare center, daycare, preschool, early-learning program, or other organization accepting the Terms ("Center"). Capitalized terms not defined in this DPA have the meanings given in the Terms.

1. Roles; Scope; Center Responsibilities

1.1 Roles. With respect to Personal Data contained in Center Data that Tenerwise processes on behalf of the Center, the Center acts as controller, business, regulated entity, or analogous role under applicable law, and Tenerwise acts as processor, service provider, contractor, or analogous role, except to the limited extent Tenerwise independently determines the purposes and means of processing for its own lawful business purposes described in the Privacy Policy.

1.2 Scope. This DPA applies to Tenerwise's processing of Personal Data within Center Data, including Sensitive Data. It does not govern Personal Data Tenerwise processes as an independent controller for its own business purposes as described in the Privacy Policy.

1.3 Center Responsibilities. The Center is responsible for ensuring that its instructions to Tenerwise comply with applicable law and that the Center has provided any notices and obtained any permissions, consents, authorizations, or other legal authority required for Tenerwise to process Center Data on the Center's behalf. Nothing in this DPA relieves either party of obligations imposed directly on that party by applicable law.

1.4 Definitions. "Sensitive Data" means Personal Data treated as sensitive, specially protected, or subject to heightened requirements under applicable law, which may include health information, Personal Data relating to children, account credentials, biometric information if ever enabled, precise geolocation if ever collected, and other legally protected categories. "Security Incident" means a confirmed breach of security resulting in accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or unauthorized access to Center Data processed by Tenerwise. Security Incident does not include unsuccessful attempts that do not result in unauthorized access to Center Data, such as unsuccessful login attempts, network scans, pings, or similar events.

2. Processing Details

2.1 Subject Matter. Tenerwise's provision of the Services to the Center as described in the Terms.

2.2 Duration. For the term of the Center's subscription and thereafter only as necessary to complete return, export, deletion, legal-retention, dispute, or backup-lifecycle obligations under this DPA and the Terms.

2.3 Nature and Purpose. Tenerwise processes Center Data to provide, secure, maintain, support, and troubleshoot the Services; carry out the Center's documented instructions; and comply with applicable law.

2.4 Categories of Data Subjects. Children enrolled with or receiving services from the Center; parents; guardians; authorized pickup persons; emergency contacts; Center administrators, staff, contractors, and other Authorized Users; and other individuals whose Personal Data the Center submits to the Services.

2.5 Categories of Personal Data. Child and family records; health and safety information; allergies; immunization records; medication instructions and administration logs; incident and injury records; attendance and room-assignment records; emergency contacts; authorized pickup information; photographs and media; communications; staff and operational records; audit information; invoices; billing records; transaction metadata; and other Center Data described in the Privacy Policy or entered by the Center.

2.6 Sensitive Data. Some Center Data may constitute Sensitive Data. Tenerwise will process Sensitive Data only under the same documented instructions and limitations applicable to Center Data generally and will apply safeguards appropriate to the sensitivity and risk of the processing.

3. Documented Instructions and Processing Restrictions

3.1 Instructions. Tenerwise will process Center Data only: (a) to provide, secure, maintain, support, and troubleshoot the Services in accordance with the Terms; (b) on the Center's documented instructions, including instructions expressed through module enablement, configuration, permissions, data fields, workflows, and other use of the Services; and (c) as required by applicable law. If law requires processing inconsistent with the Center's instructions, Tenerwise will inform the Center before processing unless legally prohibited from doing so.

3.2 Purpose Limitation. Tenerwise will not process Center Data for Tenerwise's independent advertising purposes, sell Center Data, use Center Data for cross-context behavioral advertising or targeted advertising, or use identifiable Center Data for an independent commercial purpose outside the direct business relationship with the Center except as expressly permitted by applicable law and this DPA.

3.3 AI Training Restriction. Tenerwise will not use, and will not permit a third-party AI provider to use, identifiable Center Data to train general-purpose artificial intelligence or machine-learning models. When an AI-assisted feature is enabled, Center Data may be processed for inference solely to provide that feature under the Center's instructions.

3.4 Unlawful Instructions. If Tenerwise reasonably believes a Center instruction violates applicable data-protection law, Tenerwise will inform the Center and may suspend the affected processing until the parties resolve the issue.

3.5 De-identified Data. This DPA does not restrict Tenerwise's use of aggregated or de-identified information as permitted by the Terms, provided Tenerwise maintains the information in de-identified form, does not reasonably identify a Center or individual from it, and does not attempt to re-identify it except as permitted by law to test de-identification effectiveness.

4. Confidentiality and Personnel

Tenerwise will ensure personnel authorized to process Center Data are subject to confidentiality obligations and access Center Data only to the extent reasonably necessary for their role. Tenerwise will apply appropriate access-management practices designed to limit privileged access and remove access when no longer required.

5. Security

5.1 Safeguards. Tenerwise will implement and maintain administrative, technical, and organizational safeguards appropriate to the nature and sensitivity of Center Data and the risks of processing, consistent with the Terms and Privacy Policy and applicable law.

5.2 Security Measures. Safeguards may include, as appropriate to the applicable systems, tenant-aware authorization and logical segregation designed to prevent unauthorized cross-Center access; role-based access controls; authentication controls; encryption; logging and monitoring; secure development practices; vulnerability management; backup and recovery measures; incident-response procedures; and vendor-management controls.

5.3 No Absolute Guarantee. Security safeguards reduce risk but cannot eliminate all risk. Nothing in this DPA is a representation that a Security Incident can never occur.

6. Subprocessors

6.1 General Authorization. The Center provides general authorization for Tenerwise to engage subprocessors to process Center Data as necessary to provide the Services, subject to this Section.

6.2 Subprocessor List. Material active and feature-dependent subprocessors are identified in the Tenerwise Subprocessor List at tenerwise.com/legal/subprocessors. A feature-dependent provider does not process a Center's Center Data unless the applicable feature is enabled or otherwise used for that Center.

6.3 New Subprocessors. Tenerwise will provide reasonable advance notice before a new material subprocessor begins processing Center Data, through an update to the Subprocessor List, direct notice to the Center's account contact, or another reasonable mechanism. If a Center objects on reasonable data-protection grounds within 15 days after notice, Tenerwise will work in good faith to address the objection. If the parties cannot reasonably resolve it, Tenerwise may offer a commercially reasonable alternative or permit termination of the materially affected Service without penalty for the unused portion of the applicable prepaid term. Where a subprocessor must be engaged more quickly to address an urgent security, legal, availability, or service-continuity issue, Tenerwise may provide notice as soon as reasonably practicable.

6.4 Written Flow-Down Terms. Tenerwise will engage each subprocessor under a written agreement imposing data-protection obligations no less protective than those required of Tenerwise under this DPA to the extent applicable to that subprocessor's processing. Tenerwise remains responsible to the Center for the subprocessor's performance of those obligations to the extent required by applicable law and the Terms.

7. Assistance to the Center

7.1 Data Subject and Consumer Requests. Tenerwise will provide reasonable assistance, taking into account the nature of processing and information available to Tenerwise, so the Center can respond to verified requests for access, correction, deletion, portability, withdrawal of consent, or other applicable privacy rights concerning Center Data. Tenerwise may direct individuals who contact Tenerwise about Center-controlled records to the applicable Center.

7.2 Security Incidents. Tenerwise will notify the Center without undue delay after becoming aware of a Security Incident affecting the Center's Center Data. Tenerwise will provide reasonably available information concerning the nature of the incident, categories of affected data, mitigation steps, and other information reasonably necessary for the Center to meet applicable legal obligations. Notice does not constitute an admission of fault or liability.

7.3 AI-Assisted Processing. Where applicable, assistance under this Section includes reasonably available information necessary for the Center to evaluate the security and privacy implications of Personal Data processed through AI-assisted functionality.

7.4 Assessments. Where applicable law requires the Center to conduct a data-protection, privacy, consumer-health, AI, or similar risk assessment covering the Services, Tenerwise will provide reasonably available information necessary to assist the Center.

7.5 Regulatory Inquiries. Tenerwise will provide reasonable assistance to a Center responding to a regulator, attorney general, or other governmental authority concerning Center Data processed under this DPA, subject to confidentiality, security, privilege, and reasonable cost limitations.

8. Return, Export, Retention, and Deletion

8.1 Choice of Return or Deletion. At the Center's direction following termination, Tenerwise will make available then-supported export functionality or a commercially reasonable export of available Center Data, or will proceed with deletion, subject to payment of undisputed amounts, legal restrictions, legal retention obligations, and the backup provisions below.

8.2 Active Systems. Following the applicable export or transition period, Tenerwise will delete Center Data from active systems within a commercially reasonable period consistent with documented operational practices, unless retention is required by law or reasonably necessary for an ongoing dispute, fraud/security investigation, or legal claim.

8.3 Backups. Center Data remaining in backups will be placed beyond ordinary use and deleted or overwritten through Tenerwise's normal backup lifecycle. If a backup containing previously deleted Center Data is restored for disaster recovery, Tenerwise will reapply applicable deletion instructions within a commercially reasonable period.

8.4 Individual Record Deletion. Where the Center instructs Tenerwise to delete a specific record in response to a valid request or Center instruction, Tenerwise will delete the record from active systems within the period required by applicable law or, if no period is specified, within a commercially reasonable period, with backup copies handled under Section 8.3.

9. Audit and Compliance Information

9.1 Documentation First. On reasonable advance written request, ordinarily no more than once per 12-month period except following a Security Incident, a material compliance concern, or a legally required audit, Tenerwise will make available information reasonably necessary to demonstrate compliance with this DPA. Tenerwise may satisfy this obligation through security documentation, relevant certifications if held, independent assessment reports if available, written responses, or other appropriate evidence.

9.2 Additional Audit. If the information under Section 9.1 is insufficient to satisfy a specific legal audit requirement applicable to the Center, the parties will discuss a reasonable alternative. Subject to applicable law, confidentiality, security, protection of other customers, and reasonable scheduling, this may include a remote review, third-party assessment, or on-site audit at the Center's expense unless the audit identifies a material breach by Tenerwise.

9.3 Legal Carve-Out. The limitations in this Section do not restrict an assessment, audit, cooperation, or information obligation that applicable law requires and that cannot lawfully be limited by contract.

10. International and Cross-Border Processing

Tenerwise operates the Services primarily from the United States and may configure primary hosting or database regions in the United States. Tenerwise and its subprocessors may process Personal Data in other jurisdictions where they or their authorized subprocessors maintain operations. Where applicable law requires a cross-border transfer mechanism or other safeguard, Tenerwise will implement an appropriate lawful mechanism before the relevant transfer occurs.

11. U.S. State Privacy Terms

The schedules below apply only to the extent the referenced law applies to the relevant processing. If another U.S. state comprehensive privacy law applies and imposes materially similar processor obligations, the parties intend this DPA to satisfy those obligations to the maximum extent permitted by law. Tenerwise will provide additional terms when reasonably necessary to address a non-waivable requirement not already covered by this DPA.

Schedule A — California Service Provider / Contractor Terms

To the extent the California Consumer Privacy Act, as amended ("CCPA"), applies to Center Data processed under this DPA: Tenerwise acts as a service provider or contractor, as applicable, for Personal Information processed pursuant to the written agreement with the Center. The specific and limited business purposes are to provide, secure, maintain, support, and troubleshoot the Services; carry out the Center's documented instructions; and perform other processing expressly permitted by the CCPA and applicable regulations.

Tenerwise will not sell or share Personal Information collected pursuant to the agreement, and will not retain, use, or disclose such Personal Information for any purpose, including a commercial purpose, other than the specific business purposes stated above or as otherwise expressly permitted by the CCPA and applicable regulations.

Tenerwise will not retain, use, or disclose such Personal Information outside the direct business relationship with the Center, and will not combine it with Personal Information received from another person or collected from Tenerwise's own interaction with an individual, except where expressly permitted by the CCPA and applicable regulations.

Tenerwise will comply with applicable CCPA obligations imposed on service providers or contractors, will provide the same level of privacy protection required by applicable law, and will notify the Center if Tenerwise determines it can no longer meet those obligations. The Center may take reasonable and appropriate steps to stop and remediate unauthorized processing, and may monitor Tenerwise's compliance as permitted by applicable law and Section 9 of this DPA.

Schedule B — Texas Processor Terms

To the extent Chapter 541 of the Texas Business & Commerce Code applies: this DPA governs Tenerwise's processing procedures with respect to processing performed on behalf of the Center and describes the nature, purpose, type, duration, rights, and obligations of the parties.

Tenerwise will assist the Center with applicable consumer-rights requests, security obligations, breach-related duties, and required data-protection assessments, taking into account the nature of processing and information available to Tenerwise. At the Center's direction, Tenerwise will delete or return Personal Data after the provision of Services unless retention is required by law.

Tenerwise will ensure each person processing Personal Data is subject to confidentiality obligations, and will engage subcontractors only under written agreements requiring them to meet applicable processor obligations for the Personal Data they process.

Tenerwise will make compliance information available and will allow and contribute to reasonable assessments, or provide an appropriate independent-assessment alternative as permitted by applicable law. Nothing in this DPA relieves either party from liability imposed directly by applicable Texas law based on that party's role.

Schedule C — Washington Consumer Health Data Terms

To the extent Washington's My Health My Data Act applies to consumer health data processed by Tenerwise on the Center's behalf: the Center's documented instructions in this DPA are binding processing instructions limiting Tenerwise's actions with respect to consumer health data. Tenerwise will process consumer health data only in a manner consistent with those instructions, except where otherwise required by applicable law.

Tenerwise will assist the Center through appropriate technical and organizational measures, insofar as reasonably possible, in fulfilling obligations applicable to the Center under the Act. Tenerwise will not independently collect, share, sell, advertise with, profile from, or otherwise use Center consumer health data for a purpose outside the Center's instructions and this DPA.

If Tenerwise determines it is processing consumer health data outside the scope of the Center's instructions in a manner that would cause Tenerwise to act as a regulated entity for that processing, Tenerwise will stop the processing or address the additional legal obligations before continuing.

12. Liability

Liability arising under this DPA is subject to Section 18 of the Terms except to the extent a limitation is prohibited by applicable law. Indemnification obligations, if any, are governed by Section 17 of the Terms.

13. Relationship to the Terms

This DPA is incorporated into and governed by the Terms. In the event of a conflict between this DPA and the Terms regarding processing of Personal Data, this DPA controls. In all other respects, the Terms control.

14. Contact

Questions about this DPA: support@tenerwise.com

Tenerwise LLC — 5900 Balcones Drive, Suite 100, Austin, TX 78731, United States — https://tenerwise.com