FOR U.S. SCHOOLS AND CHILDCARE PROVIDERS

Customer data agreement

This agreement forms part of the ChildQix terms between Smartqix LLC and the organization whose authorized owner accepts it. It applies to the child, family, staff and operational records the organization entrusts to ChildQix.

1. Ownership, authority and instructions

The organization retains ownership and control of its records and determines the purposes for processing them. Smartqix LLC acts as its service provider or processor for those records. We process records only to provide, secure and support ChildQix, follow documented authorized instructions, or comply with law. The organization confirms it is located in the United States or a U.S. territory and has authority to provide the records and grant access to them.

Instructions include the organization’s selected features, membership and child-access assignments, authenticated actions, and verified support requests. The organization is responsible for accurate records, required notices and permissions, custody and pickup decisions, staff authorization, and applicable record-retention requirements. Adult terms acceptance does not constitute parental consent for a child’s records.

2. Records and permitted use

Records may include identities and contact details; child enrollment, attendance and classroom records; photographs and documents; health, allergy and incident information; messages and daily reports; and invoices, payments and account-access records. The organization selects the information needed for its work and must avoid unnecessary sensitive information, Social Security numbers and payment-card security codes.

We do not sell or rent these records, use them for targeted advertising, build commercial profiles unrelated to the service, or use them to train general-purpose AI models. We do not combine them with unrelated customer records for those purposes. Access to records does not grant a right to republish photographs or other private content.

3. Confidentiality, security and providers

We restrict personnel access to authorized service and support needs, require confidentiality, and maintain safeguards appropriate to the information, including authenticated role-based access, separate organization databases, protected transport, password hashing and audit records. The organization must maintain its own device, account and emergency procedures.

We may engage providers for hosting, private files, backups, email, notifications, crash diagnostics and payments. We require applicable confidentiality, security and purpose restrictions and remain responsible for our obligations. The privacy policy describes integrations. The service order must identify the deployment’s providers, processing regions, backup expiry and any agreed restrictions. Smartqix personnel operate in the United States and Ghana; this agreement does not promise U.S.-only processing.

We will notify the organization before a material provider or processing-location change, allow reasonable objections based on data protection, and work to resolve them. If an agreed restriction cannot be met, the parties will arrange an export and orderly end to the affected service.

4. Privacy requests, education records and incidents

We assist the organization with verified access, correction, export and deletion requests. Families may request review or correction through their school or childcare provider, or contact us to route the request. We do not disclose one family’s records to another requester. We also provide information reasonably needed to review our handling and meet applicable privacy obligations.

Where FERPA applies to the organization and this service, the organization retains direct control over use and maintenance of education records, and we use and redisclose them only for authorized purposes under applicable requirements. FERPA does not apply to every childcare provider or private school. Any required state or school-district contract terms must be agreed before the affected records are uploaded. ChildQix does not offer a blanket FERPA, COPPA or HIPAA certification.

We notify the organization without unreasonable delay after confirming unauthorized access to its records and meet any shorter applicable legal deadline. We provide known facts, affected information and mitigation steps as available, cooperate on response, and issue updates. The organization handles notices to families or authorities unless law or a written agreement requires us to do so. Report suspected incidents to support@childqix.com without forwarding unnecessary child records.

5. Retention and ending service

The organization determines lawful retention periods for its records. Archiving a child, canceling a subscription or deleting an adult account does not erase school records. Before service ends, the owner should arrange an authorized export and provide written instructions for the return or deletion of records, including any lawful retention requirement.

We verify and carry out those instructions under the agreed termination schedule and applicable law. Where information must be retained, we identify the reason and restrict use to that purpose. Isolated backups expire under the schedule recorded in the service order; restored backups must have approved deletions reapplied. Financial, security and agreement records may be retained where necessary for legal obligations or documented disputes. We do not promise an automatic school-record purge when an individual deletes an account.

6. Changes and contact

A specifically negotiated school agreement takes priority for its subject where it conflicts with this agreement. We provide notice of material changes and obtain renewed agreement where required. Additional school or state requirements must be resolved before the organization uses a feature that depends on them.

Smartqix LLC · ChildQix
175 South 3rd Street, Suite 200
Columbus, OH 43215, United States
support@childqix.com

Terms of service · Privacy policy