Legal
Data Processing Agreement
Last updated: 30.09.2026
This agreement sets out the terms on which Zehinly (the processor) processes the personal data that a course center (the controller of the personal data) enters into the Platform, and forms an integral part of the Terms of Use.
01Subject matter of processing
- Data subjects: students, parents, teachers, staff, people who contact the Center and other people whose data the Center enters into the system.
- Types of data: identity and contact details, education data (group, schedule, attendance, assessment), financial data (tuition fees, payments, debts, salaries) and files uploaded by the Center.
- Purpose: providing the Platform’s features to the Center.
- Duration: the subscription period and the retention periods set out in this agreement.
02Zehinly’s obligations
- to process data only on the Center’s instructions — on the basis of the operations it performs on the Platform and this agreement;
- to restrict access to data to staff who need it to provide the service, and to ensure they are bound by confidentiality;
- to apply the technical and organizational security measures described in the Privacy Policy;
- not to sell data, not to use it for advertising purposes and not to combine it with other Centers’ data;
- to assist the Center in responding to data subjects’ requests;
- to notify the Center of a data breach without delay, and where possible within 72 hours of detecting it.
03Obligations of the Center
- to ensure that data is collected on a lawful basis and that data subjects are informed about it;
- to obtain the consent of a parent or legal representative for minors;
- to enter only the data needed for the teaching process and billing;
- to assign staff roles and permissions correctly and to close the accounts of departing staff.
04Sub-processors
We use the following providers to deliver the service:
- hosting provider — servers, database, files and backups;
- Cloudflare — traffic delivery and attack protection;
- email delivery service — system emails such as password resets;
- browser push services — notifications the user has allowed.
If we start using a new sub-processor, we will update this list.
05After the relationship ends
- Data is not deleted when the subscription ends: the Center switches to read-only mode and can export its data.
- At the Center’s written request, we delete its data within 30 days; copies in backups are overwritten by newer ones within a further 14 days.
- Data that must be retained by law may be kept for the period specified by law.
06Audit
The Center may request information to verify compliance with this agreement; we provide a written response within a reasonable time.