Legal

Data Processing Agreement

Last updated: 30.09.2026

This agreement sets out the terms on which Zehinly (the processor) processes the personal data that a course center (the controller of the personal data) enters into the Platform, and forms an integral part of the Terms of Use.

01Subject matter of processing

  • Data subjects: students, parents, teachers, staff, people who contact the Center and other people whose data the Center enters into the system.
  • Types of data: identity and contact details, education data (group, schedule, attendance, assessment), financial data (tuition fees, payments, debts, salaries) and files uploaded by the Center.
  • Purpose: providing the Platform’s features to the Center.
  • Duration: the subscription period and the retention periods set out in this agreement.

02Zehinly’s obligations

  • to process data only on the Center’s instructions — on the basis of the operations it performs on the Platform and this agreement;
  • to restrict access to data to staff who need it to provide the service, and to ensure they are bound by confidentiality;
  • to apply the technical and organizational security measures described in the Privacy Policy;
  • not to sell data, not to use it for advertising purposes and not to combine it with other Centers’ data;
  • to assist the Center in responding to data subjects’ requests;
  • to notify the Center of a data breach without delay, and where possible within 72 hours of detecting it.

03Obligations of the Center

  • to ensure that data is collected on a lawful basis and that data subjects are informed about it;
  • to obtain the consent of a parent or legal representative for minors;
  • to enter only the data needed for the teaching process and billing;
  • to assign staff roles and permissions correctly and to close the accounts of departing staff.

04Sub-processors

We use the following providers to deliver the service:

  • hosting provider — servers, database, files and backups;
  • Cloudflare — traffic delivery and attack protection;
  • email delivery service — system emails such as password resets;
  • browser push services — notifications the user has allowed.

If we start using a new sub-processor, we will update this list.

05After the relationship ends

  • Data is not deleted when the subscription ends: the Center switches to read-only mode and can export its data.
  • At the Center’s written request, we delete its data within 30 days; copies in backups are overwritten by newer ones within a further 14 days.
  • Data that must be retained by law may be kept for the period specified by law.

06Audit

The Center may request information to verify compliance with this agreement; we provide a written response within a reasonable time.