Data Processing Addendum
Last updated: 24 September 2026.
This DPA forms part of the accepted StreamingVideoProvider or ScreenRec service agreement (Agreement) between TeddySoft OOD (Processor) and its customer (Customer). It applies when TeddySoft OOD processes personal data on Customer's behalf under applicable data-protection law. It does not replace a more specific existing DPA without the agreed change process.
D1. Scope, roles and instructions
Customer is controller or a processor authorized by its controller to engage TeddySoft OOD. TeddySoft OOD is processor or subprocessor accordingly. Customer Personal Data is personal data in Content and other data processed for Customer's instructed service purposes, as specified in Annex 1. It excludes data for a purpose TeddySoft OOD independently determines, which must be separately identified and lawfully processed as controller.
TeddySoft OOD will process Customer Personal Data only on documented instructions, including the Agreement, accepted settings, authorized user/organization instructions and additional lawful written instructions consistent with the Services. The instructions include only transfers permitted by D5. If Union or Member State law requires other processing, TeddySoft OOD will inform Customer before it occurs unless the law prohibits notice on important public-interest grounds. TeddySoft OOD will promptly inform Customer if, in its opinion, an instruction infringes applicable data-protection law and may suspend that instruction pending resolution.
Customer is responsible for its lawful grounds, accurate notices, required permissions and authority to give instructions, including workplace administration and viewer processing. That responsibility does not remove TeddySoft OOD's own duties. Organization impersonation described in B3 of the Agreement is an administrative instruction channel, not an exception to data-protection law or third-party integration restrictions.
D2. Confidentiality and security
TeddySoft OOD will ensure that persons authorized to process Customer Personal Data are bound by confidentiality and have access limited to their authorized duties. It will implement and maintain appropriate technical and organizational measures under Article 32 GDPR, taking account of risks, the nature of processing, state of the art and implementation costs. Measures may evolve without materially reducing the agreed level of protection.
D3. Subprocessors
Customer gives general written authorization for the subprocessors identified in Annex 2. TeddySoft OOD will give Customer at least 15 days' contractual notice of intended additions or replacements before new processing begins, allowing a meaningful opportunity to object on reasonable data-protection grounds. An urgent necessary replacement will be handled in accordance with applicable law and with as much advance notice and opportunity to object as reasonably possible; this is not blanket authorization to bypass Article 28.
TeddySoft OOD will impose obligations providing the same level of data protection required by this DPA and remain responsible to Customer for its subprocessors' performance as required by Article 28(4). If an objection cannot be resolved through a reasonable alternative, Customer may terminate the affected processing service before the new subprocessor processes the data; prepaid fees for the unused affected service will be returned. A fee or objection mechanism may not make statutory objection rights ineffective. Independent controllers must be identified separately and are not deemed subprocessors for convenience.
D4. Assistance, incidents and audit
Taking account of the nature of processing, TeddySoft OOD will assist Customer through appropriate measures to respond to data-subject rights requests. It will promptly route requests concerning Customer Personal Data to Customer unless instructed or legally required to respond directly, and not obstruct requests relating to its own controller processing.
TeddySoft OOD will assist Customer with obligations concerning security, breach notification, impact assessments and prior consultations, taking account of the processing and information available to it. It will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, describe available information about its nature, affected data and persons, likely consequences, response and contact, and supply further information in stages as it becomes available. Notification is not deferred until final confirmation of every detail. The SLA does not substitute for this obligation. Customer's own regulatory notification deadline is separate.
To the extent required by Article 28(3)(h) GDPR, TeddySoft OOD will make available information necessary to demonstrate compliance with Article 28 and allow and contribute to audits, including inspections, by Customer or an auditor mandated by Customer.
Reviews will begin with available documentation and remote clarification where sufficient. Routine audits must have a scope relevant to Customer Personal Data and use reasonable advance notice, business hours and arrangements that minimize disruption. Auditors must be subject to appropriate confidentiality obligations. Access will be managed to protect security, confidential information and other customers' data. These arrangements do not restrict legally required access or prevent additional review or inspection where necessary.
Bespoke questionnaires, custom reports, certifications and assistance beyond applicable legal requirements are not included in standard subscription fees and may be separately agreed and charged. Any charges for legally required audit assistance must be reasonable, agreed in advance where lawful, and must not discourage or obstruct statutory rights. Payment is not a condition for performing a non-excludable duty.
Routine notice and scheduling arrangements do not delay urgent incident investigations or supervisory-authority access.
D5. International transfers and government access
TeddySoft OOD will not make a restricted transfer without the applicable legal safeguard and documented instructions. Where required, the appropriate EU transfer SCC module and completed annexes, and any applicable UK addendum or Swiss adaptations, must be executed for the actual exporter/importer relationship before transfer. This DPA is an Article 28 processing contract; it does not by itself constitute completed international transfer SCCs or certify any recipient under the Data Privacy Framework.
TeddySoft OOD will assess legally binding disclosure demands, challenge or narrow unlawful or disproportionate requests where legally appropriate, disclose only what law requires and notify Customer unless prohibited. It will apply required safeguards to non-personal data as well where the Data Act applies.
D6. Return, deletion and duration
At Customer's choice after the service ends, TeddySoft OOD will return or delete Customer Personal Data and delete copies unless Union or Member State law requires storage. The Agreement's export and retrieval procedures implement that choice and may not reduce mandatory rights. During any lawful residual retention, data remains subject to this DPA, access is restricted and no unrelated use is permitted. Residual backup, cache and log copies remain protected and unavailable for ordinary use while awaiting deletion; a backup process cannot override a stricter mandatory erasure deadline. Excess-storage deletion of Content follows the 14-day remediation process in the Terms. Independent billing and invoice records are not Customer Personal Data under this DPA. On reasonable request TeddySoft OOD will confirm completion of the agreed deletion.
This DPA remains in force while TeddySoft OOD retains Customer Personal Data. It does not permit indefinite retention for general business purposes.
D7. Liability and priority
The Agreement's lawfully applicable exclusions and cap govern interparty contractual liability under this DPA, subject to its B14.1 carve-outs. They do not limit data-subject rights, regulator powers, legally non-excludable liabilities or obligations and liability under binding transfer clauses. SLA credits are not the exclusive remedy for a processing or security breach. This DPA controls a conflict about Customer Personal Data; mandatory law and applicable binding transfer clauses prevail.
Annex 1. Processing description
| Required item | Description |
| Parties and contacts | TeddySoft OOD, Bulgarian company 203070568, VAT BG203070568, 91 Bul. Hristo Botev Street, Plovdiv 4000, Bulgaria. Headquarters and contracting seat are in Bulgaria. Processor privacy contact: privacy@streamingvideoprovider.com. General/legal and content-report contact: info@streamingvideoprovider.com. Support and withdrawal requests: support@streamingvideoprovider.com. Customer identity and authorized privacy contact from its Order. Switching, assisted export and illegal-content reports may also use the Contact Us page or live chat. |
| Subject and purpose | Providing the activated hosting, storage, streaming, sharing, organization administration, viewer, transcription and other features on Customer's instructions. Independently controlled billing and marketing processing is excluded from this DPA. |
| Nature | Collection, receipt, storage, organization, retrieval, encoding, transmission, display, instructed analysis, support and deletion necessary for the activated features. |
| Duration | Contracted processing period plus authorized retrieval under the Terms and legally permitted residual retention under D6. Excess-storage Content may be deleted after the 14-day remediation process in the Terms. |
| Individuals | Customer personnel, collaborators, viewers, customers and other people whose information Customer submits or instructs us to collect. |
| Data | Submitted media and recordings, voices and images, contact and viewer-form fields, viewing events, and generated metadata where the relevant feature is enabled. Enabled Speechmatics processing covers dictation audio sent via our servers and on-demand video transcription. Enabled OpenAI processing covers transcripts used to generate titles, short and long descriptions, and chapters. Independently controlled billing and marketing data are excluded. |
| Sensitive data | May be present in customer-submitted Content. Ordinary plan terms are not a healthcare authorization, parental-consent mechanism or other special regulatory authorization. No special-category certification is claimed. |
| Frequency and Customer instructions | Ongoing during enabled Services, with submission, access, sharing and deletion events initiated through accepted features, authorized instructions, and the Contact Us page or live chat where used for switching or assisted export. |
Annex 2. Subprocessors
Customer gives general written authorization under D3 for the following providers to process Customer Personal Data on Customer's instructions for the functions listed, when those functions are used. Marketing, payment and website-analytics providers used for TeddySoft OOD's own controller purposes are not listed as subprocessors.
| Provider | Service performed | Legal entity and address |
| Speechmatics | Dictation audio via our servers and on-demand video transcription, when those features are enabled | Cantab Research Limited (trading as Speechmatics), One Cambridge Square, Milton Avenue, Cambridge CB4 0AE, United Kingdom |
| OpenAI | Transcripts processed to generate titles, short and long descriptions, and chapters, when those features are enabled | OpenAI Ireland Ltd, 1st Floor, The Liffey Trust Centre, 117-126 Sheriff Street Upper, Dublin 1, D01 YC43, Ireland |
| Storage of Content and analytics data used for the Services | Google Cloud EMEA Limited, 70 Sir John Rogerson's Quay, Dublin 2, Ireland | |
| CDN77 | Content delivery for static content | DataCamp Limited, 9 Coldbath Square, London EC1R 5HL, United Kingdom |
| EvoSwitch | Data center services | EvoSwitch Netherlands B.V., Hessenbergweg 95, 1101 CX Amsterdam, Netherlands |
| iomart | Data center services | iomart group plc, 6 Atlantic Quay, 55 Robertson Street, Glasgow G2 8JD, United Kingdom |
| SoftLayer Dutch Holdings BV | Data center services | SoftLayer Dutch Holdings B.V., Paul van Vlissingenstraat 16, 1096 BK Amsterdam, Netherlands |
| DigitalOcean | Infrastructure for temporary caching and delivery of customer videos, images and other static content | DigitalOcean, LLC, 105 Edgeview Drive, Suite 425, Broomfield, CO 80021, United States |
| Vultr | Infrastructure for temporary caching and delivery of customer videos, images and other static content | The Constant Company, LLC (trading as Vultr), 319 Clematis Street, Suite 900, West Palm Beach, FL 33401, United States |
| Hivelocity | Infrastructure for temporary caching and delivery of customer videos, images and other static content | Hivelocity, LLC, 8010 Woodland Center Blvd, Suite 700, Tampa, FL 33614, United States |
| OneProvider | Infrastructure for temporary caching and delivery of customer videos, images and other static content | BrainStorm Network Inc. (trading as OneProvider), 3275 Avenue Francis-Hughes, Laval, Quebec H7L 5A5, Canada |
| UpCloud | Infrastructure for temporary caching and delivery of customer videos, images and other static content | UpCloud Oy, Aleksanterinkatu 15 B, 7th floor, 00100 Helsinki, Finland |
| Alibaba Cloud | Infrastructure for temporary caching and delivery of customer videos, images and other static content | Alibaba (Netherlands) B.V., Herengracht 448, 1017 CA Amsterdam, Netherlands |
| LightNode | Infrastructure for temporary caching and delivery of customer videos, images and other static content | LightNode, LLC, 6/F Manulife Place, 348 Kwun Tong Road, Kowloon, Hong Kong |
| Curt Creation (curtcreation.net) | Infrastructure for temporary caching and delivery of customer videos, images and other static content | Curt Creation (curtcreation.net) |
| Bunny.net | Infrastructure for temporary caching and delivery of customer videos, images and other static content | BunnyWay d.o.o., Dunajska cesta 165, 1000 Ljubljana, Slovenia |
D3 notice and objection and D5 lawful-transfer obligations continue to apply. The Privacy page lists additional providers used for TeddySoft OOD's own controller purposes.