Data Processing Agreement
Last Updated: 18 July 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Two Little Steps ("Processor", "we", "us") and the customer center ("Fiduciary", "you") and applies to our processing of personal data on your behalf under India's Digital Personal Data Protection Act, 2023 (the "DPDP Act").
1. Definitions
"Personal data", "data principal", "data fiduciary", "data processor", "processing" and "personal data breach" have the meanings given in the DPDP Act. Other capitalised terms have the meanings given in the Terms of Service.
2. Roles & Scope of Processing
You are the data fiduciary and we are your data processor. We process personal data only to provide the Service and on your documented instructions, for the duration of your subscription.
- Subject matter: operation of a child development / therapy center management platform.
- Categories of data principals: children, parents/guardians, therapists, and center staff.
- Categories of personal data: identifiers and contact details, dates of birth, appointment and attendance records, clinical/session notes and progress, and billing status.
3. Your Obligations
You warrant that you have provided all notices to, and obtained all consents from, data principals (including verifiable parental consent for children's data) required to enter and process the data in the Service, and that your instructions to us comply with applicable law.
4. Our Obligations
We will: (a) process personal data only on your documented instructions; (b) ensure our personnel are bound by confidentiality; (c) implement the technical and organisational security measures described in Section 7; (d) assist you, taking into account the nature of processing, in responding to data-principal requests and in meeting your security, breach-notification and impact-assessment obligations; and (e) make available information reasonably necessary to demonstrate compliance.
5. Sub-processors
You authorise us to engage the sub-processors listed in our Privacy Policy. We remain responsible for their performance, impose data-protection obligations on them, and will give you reasonable notice of any intended change, allowing you to object on reasonable data-protection grounds.
6. Personal Data Breach
We will notify you without undue delay after becoming aware of a personal data breach affecting your data, and provide information reasonably needed to help you meet your notification obligations to the Data Protection Board of India and to affected data principals.
7. Security Measures
Our measures include: encryption in transit (HTTPS/TLS) and at rest for sensitive fields (AES-256-GCM); argon2id password hashing; role-based access control; database-level row-level tenant isolation; append-only audit logging of access to children's records; and server-side sessions with idle and absolute expiry. Full details are in our Privacy Policy.
8. International Transfers
Where sub-processors are located outside India, transfers are made subject to appropriate contractual safeguards and applicable law, and not to any country or territory restricted by the Government of India.
9. Return & Deletion of Data
On termination or expiry, we will make Center Data available for export for 30 days and then delete it within 90 days, except where retention is required by law.
10. Audit
We will make available information reasonably necessary to demonstrate compliance with this DPA and, on reasonable prior notice and subject to confidentiality, allow audits, no more than once per year or on a for-cause basis where there is a reasonable belief of a material breach, by you or an independent auditor.
11. Liability & Governing Law
Liability under this DPA is subject to the limitations set out in the Terms of Service. This DPA is governed by the laws of India, with exclusive jurisdiction of the courts at Pune, Maharashtra.
12. Contact
Two Little Steps
Hadapsar, Pune — 411028
Email: support@twolittlesteps.com