Data Processing Addendum

Last updated: 24 September 2026.

This DPA forms part of the accepted StreamingVideoProvider or ScreenRec service agreement (Agreement) between TeddySoft OOD (Processor) and its customer (Customer). It applies when TeddySoft OOD processes personal data on Customer's behalf under applicable data-protection law. It does not replace a more specific existing DPA without the agreed change process.

D1. Scope, roles and instructions

Customer is controller or a processor authorized by its controller to engage TeddySoft OOD. TeddySoft OOD is processor or subprocessor accordingly. Customer Personal Data is personal data in Content and other data processed for Customer's instructed service purposes, as specified in Annex 1. It excludes data for a purpose TeddySoft OOD independently determines, which must be separately identified and lawfully processed as controller.

TeddySoft OOD will process Customer Personal Data only on documented instructions, including the Agreement, accepted settings, authorized user/organization instructions and additional lawful written instructions consistent with the Services. The instructions include only transfers permitted by D5. If Union or Member State law requires other processing, TeddySoft OOD will inform Customer before it occurs unless the law prohibits notice on important public-interest grounds. TeddySoft OOD will promptly inform Customer if, in its opinion, an instruction infringes applicable data-protection law and may suspend that instruction pending resolution.

Customer is responsible for its lawful grounds, accurate notices, required permissions and authority to give instructions, including workplace administration and viewer processing. That responsibility does not remove TeddySoft OOD's own duties. Organization impersonation described in B3 of the Agreement is an administrative instruction channel, not an exception to data-protection law or third-party integration restrictions.

D2. Confidentiality and security

TeddySoft OOD will ensure that persons authorized to process Customer Personal Data are bound by confidentiality and have access limited to their authorized duties. It will implement and maintain appropriate technical and organizational measures under Article 32 GDPR, taking account of risks, the nature of processing, state of the art and implementation costs. Measures may evolve without materially reducing the agreed level of protection.

D3. Subprocessors

Customer gives general written authorization for the subprocessors identified in Annex 2. TeddySoft OOD will give Customer at least 15 days' contractual notice of intended additions or replacements before new processing begins, allowing a meaningful opportunity to object on reasonable data-protection grounds. An urgent necessary replacement will be handled in accordance with applicable law and with as much advance notice and opportunity to object as reasonably possible; this is not blanket authorization to bypass Article 28.

TeddySoft OOD will impose obligations providing the same level of data protection required by this DPA and remain responsible to Customer for its subprocessors' performance as required by Article 28(4). If an objection cannot be resolved through a reasonable alternative, Customer may terminate the affected processing service before the new subprocessor processes the data; prepaid fees for the unused affected service will be returned. A fee or objection mechanism may not make statutory objection rights ineffective. Independent controllers must be identified separately and are not deemed subprocessors for convenience.

D4. Assistance, incidents and audit

Taking account of the nature of processing, TeddySoft OOD will assist Customer through appropriate measures to respond to data-subject rights requests. It will promptly route requests concerning Customer Personal Data to Customer unless instructed or legally required to respond directly, and not obstruct requests relating to its own controller processing.

TeddySoft OOD will assist Customer with obligations concerning security, breach notification, impact assessments and prior consultations, taking account of the processing and information available to it. It will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, describe available information about its nature, affected data and persons, likely consequences, response and contact, and supply further information in stages as it becomes available. Notification is not deferred until final confirmation of every detail. The SLA does not substitute for this obligation. Customer's own regulatory notification deadline is separate.

To the extent required by Article 28(3)(h) GDPR, TeddySoft OOD will make available information necessary to demonstrate compliance with Article 28 and allow and contribute to audits, including inspections, by Customer or an auditor mandated by Customer.

Reviews will begin with available documentation and remote clarification where sufficient. Routine audits must have a scope relevant to Customer Personal Data and use reasonable advance notice, business hours and arrangements that minimize disruption. Auditors must be subject to appropriate confidentiality obligations. Access will be managed to protect security, confidential information and other customers' data. These arrangements do not restrict legally required access or prevent additional review or inspection where necessary.

Bespoke questionnaires, custom reports, certifications and assistance beyond applicable legal requirements are not included in standard subscription fees and may be separately agreed and charged. Any charges for legally required audit assistance must be reasonable, agreed in advance where lawful, and must not discourage or obstruct statutory rights. Payment is not a condition for performing a non-excludable duty.

Routine notice and scheduling arrangements do not delay urgent incident investigations or supervisory-authority access.

D5. International transfers and government access

TeddySoft OOD will not make a restricted transfer without the applicable legal safeguard and documented instructions. Where required, the appropriate EU transfer SCC module and completed annexes, and any applicable UK addendum or Swiss adaptations, must be executed for the actual exporter/importer relationship before transfer. This DPA is an Article 28 processing contract; it does not by itself constitute completed international transfer SCCs or certify any recipient under the Data Privacy Framework.

TeddySoft OOD will assess legally binding disclosure demands, challenge or narrow unlawful or disproportionate requests where legally appropriate, disclose only what law requires and notify Customer unless prohibited. It will apply required safeguards to non-personal data as well where the Data Act applies.

D6. Return, deletion and duration

At Customer's choice after the service ends, TeddySoft OOD will return or delete Customer Personal Data and delete copies unless Union or Member State law requires storage. The Agreement's export and retrieval procedures implement that choice and may not reduce mandatory rights. During any lawful residual retention, data remains subject to this DPA, access is restricted and no unrelated use is permitted. Residual backup, cache and log copies remain protected and unavailable for ordinary use while awaiting deletion; a backup process cannot override a stricter mandatory erasure deadline. Excess-storage deletion of Content follows the 14-day remediation process in the Terms. Independent billing and invoice records are not Customer Personal Data under this DPA. On reasonable request TeddySoft OOD will confirm completion of the agreed deletion.

This DPA remains in force while TeddySoft OOD retains Customer Personal Data. It does not permit indefinite retention for general business purposes.

D7. Liability and priority

The Agreement's lawfully applicable exclusions and cap govern interparty contractual liability under this DPA, subject to its B14.1 carve-outs. They do not limit data-subject rights, regulator powers, legally non-excludable liabilities or obligations and liability under binding transfer clauses. SLA credits are not the exclusive remedy for a processing or security breach. This DPA controls a conflict about Customer Personal Data; mandatory law and applicable binding transfer clauses prevail.

Annex 1. Processing description

Required itemDescription
Parties and contactsTeddySoft OOD, Bulgarian company 203070568, VAT BG203070568, 91 Bul. Hristo Botev Street, Plovdiv 4000, Bulgaria. Headquarters and contracting seat are in Bulgaria. Processor privacy contact: privacy@streamingvideoprovider.com. General/legal and content-report contact: info@streamingvideoprovider.com. Support and withdrawal requests: support@streamingvideoprovider.com. Customer identity and authorized privacy contact from its Order. Switching, assisted export and illegal-content reports may also use the Contact Us page or live chat.
Subject and purposeProviding the activated hosting, storage, streaming, sharing, organization administration, viewer, transcription and other features on Customer's instructions. Independently controlled billing and marketing processing is excluded from this DPA.
NatureCollection, receipt, storage, organization, retrieval, encoding, transmission, display, instructed analysis, support and deletion necessary for the activated features.
DurationContracted processing period plus authorized retrieval under the Terms and legally permitted residual retention under D6. Excess-storage Content may be deleted after the 14-day remediation process in the Terms.
IndividualsCustomer personnel, collaborators, viewers, customers and other people whose information Customer submits or instructs us to collect.
DataSubmitted media and recordings, voices and images, contact and viewer-form fields, viewing events, and generated metadata where the relevant feature is enabled. Enabled Speechmatics processing covers dictation audio sent via our servers and on-demand video transcription. Enabled OpenAI processing covers transcripts used to generate titles, short and long descriptions, and chapters. Independently controlled billing and marketing data are excluded.
Sensitive dataMay be present in customer-submitted Content. Ordinary plan terms are not a healthcare authorization, parental-consent mechanism or other special regulatory authorization. No special-category certification is claimed.
Frequency and Customer instructionsOngoing during enabled Services, with submission, access, sharing and deletion events initiated through accepted features, authorized instructions, and the Contact Us page or live chat where used for switching or assisted export.

Annex 2. Subprocessors

Customer gives general written authorization under D3 for the following providers to process Customer Personal Data on Customer's instructions for the functions listed, when those functions are used. Marketing, payment and website-analytics providers used for TeddySoft OOD's own controller purposes are not listed as subprocessors.

ProviderService performedLegal entity and address
SpeechmaticsDictation audio via our servers and on-demand video transcription, when those features are enabledCantab Research Limited (trading as Speechmatics), One Cambridge Square, Milton Avenue, Cambridge CB4 0AE, United Kingdom
OpenAITranscripts processed to generate titles, short and long descriptions, and chapters, when those features are enabledOpenAI Ireland Ltd, 1st Floor, The Liffey Trust Centre, 117-126 Sheriff Street Upper, Dublin 1, D01 YC43, Ireland
GoogleStorage of Content and analytics data used for the ServicesGoogle Cloud EMEA Limited, 70 Sir John Rogerson's Quay, Dublin 2, Ireland
CDN77Content delivery for static contentDataCamp Limited, 9 Coldbath Square, London EC1R 5HL, United Kingdom
EvoSwitchData center servicesEvoSwitch Netherlands B.V., Hessenbergweg 95, 1101 CX Amsterdam, Netherlands
iomartData center servicesiomart group plc, 6 Atlantic Quay, 55 Robertson Street, Glasgow G2 8JD, United Kingdom
SoftLayer Dutch Holdings BVData center servicesSoftLayer Dutch Holdings B.V., Paul van Vlissingenstraat 16, 1096 BK Amsterdam, Netherlands
DigitalOceanInfrastructure for temporary caching and delivery of customer videos, images and other static contentDigitalOcean, LLC, 105 Edgeview Drive, Suite 425, Broomfield, CO 80021, United States
VultrInfrastructure for temporary caching and delivery of customer videos, images and other static contentThe Constant Company, LLC (trading as Vultr), 319 Clematis Street, Suite 900, West Palm Beach, FL 33401, United States
HivelocityInfrastructure for temporary caching and delivery of customer videos, images and other static contentHivelocity, LLC, 8010 Woodland Center Blvd, Suite 700, Tampa, FL 33614, United States
OneProviderInfrastructure for temporary caching and delivery of customer videos, images and other static contentBrainStorm Network Inc. (trading as OneProvider), 3275 Avenue Francis-Hughes, Laval, Quebec H7L 5A5, Canada
UpCloudInfrastructure for temporary caching and delivery of customer videos, images and other static contentUpCloud Oy, Aleksanterinkatu 15 B, 7th floor, 00100 Helsinki, Finland
Alibaba CloudInfrastructure for temporary caching and delivery of customer videos, images and other static contentAlibaba (Netherlands) B.V., Herengracht 448, 1017 CA Amsterdam, Netherlands
LightNodeInfrastructure for temporary caching and delivery of customer videos, images and other static contentLightNode, LLC, 6/F Manulife Place, 348 Kwun Tong Road, Kowloon, Hong Kong
Curt Creation (curtcreation.net)Infrastructure for temporary caching and delivery of customer videos, images and other static contentCurt Creation (curtcreation.net)
Bunny.netInfrastructure for temporary caching and delivery of customer videos, images and other static contentBunnyWay d.o.o., Dunajska cesta 165, 1000 Ljubljana, Slovenia

D3 notice and objection and D5 lawful-transfer obligations continue to apply. The Privacy page lists additional providers used for TeddySoft OOD's own controller purposes.

Related pages: Privacy, Terms.