Data processing terms
These terms apply whenever Zynova Technologies OÜ ("Processor") processes personal data on behalf of a client ("Controller") while providing Vidkiwi services. They form part of our terms of service and any signed agreement, and meet Article 28 of the GDPR. If you need a signed copy, email [email protected].
1. Subject, duration and purpose
The Processor processes personal data only to produce, deliver and host training videos and related materials, and to run the client portal, for the duration of the engagement and the deletion period that follows it. The Processor does not keep training or completion records of the Controller's workers: watch links are anonymous, and SCORM packages report only to the Controller's own learning system.
2. Data and people concerned
| People | People named or shown in the documents, recordings and materials the Controller provides; the Controller's staff who use the client portal. |
| Data | Names, job titles and work contact details appearing in client documents; voices or images in recordings the Controller provides; portal users' names, work emails, sign-in records, comments and approvals. |
| Special categories | None are required. The Controller should not send health or other special-category data; if it does, it must tell the Processor first. |
3. The Processor's obligations
- Process personal data only on the Controller's documented instructions (these terms, the order and the Controller's settings and requests), and tell the Controller if an instruction seems to break data-protection law.
- Make sure everyone authorised to process the data is bound by confidentiality.
- Apply appropriate technical and organisational measures (Article 32): encryption in transit, private storage, unguessable links, one-time sign-in links for the portal, separation of clients' data, access limited to staff who need it, and backups.
- Help the Controller respond to requests from people exercising their rights, and with security, breach notification, impact assessments and prior consultation, taking into account the information available to the Processor.
- Notify the Controller without undue delay, and where possible within 48 hours, after becoming aware of a personal data breach, with the information the Controller needs to meet its own obligations.
- At the end of the engagement, delete or return the personal data at the Controller's choice within 90 days, unless law requires the Processor to keep it.
- Make available the information needed to show compliance with this Article, and allow and contribute to reasonable audits, normally by written questionnaire and on 30 days' notice, at the Controller's cost.
4. Sub-processors
The Controller gives general authorisation for the Processor's current sub-processors (providers of hosting, video delivery, email and AI production tools); the named list is provided on request. The Processor will tell the Controller by email at least 14 days before adding or replacing a sub-processor; the Controller may object on reasonable data-protection grounds, and if no solution is found may end the affected service. The Processor imposes data-protection obligations on each sub-processor equivalent to these terms and remains responsible for their performance.
5. International transfers
Where personal data is transferred outside the EEA, the Processor ensures a valid transfer mechanism under Chapter V of the GDPR: an adequacy decision (including the EU-US Data Privacy Framework for certified providers) or the European Commission's Standard Contractual Clauses, with supplementary measures where needed.
6. The Controller's obligations
The Controller is responsible for having a lawful basis for the processing, for informing the people concerned (for example in its own privacy notice), for any training records it keeps in its own systems, and for the lawfulness of its instructions.
7. Liability and precedence
The liability terms of the main agreement apply. If these terms conflict with the main agreement on data protection, these terms prevail.
Processor: Zynova Technologies OÜ, Sepapaja tn 6, Lasnamäe linnaosa, Tallinn, Harju maakond, Estonia. Contact: [email protected].
Last updated 10 October 2026. Questions: [email protected].