Effective Date: 06/07/2026
Applicable Services: Creating Together (https://create.bykidstokids.com) and AnimaPIC (https://animapic.bykidstokids.com)
By Kids To Kids Oy Ltd ("BKTK", "we", "us", or "our") provides educational software platforms—specifically Creating Together and AnimaPIC (the "Platforms")—to schools, cities, municipalities, and educational institutions (the "Institution").
This Institutional Platform Privacy Policy explains how data is processed within these authenticated educational environments.
IMPORTANT DISTINCTION: This policy applies only to the authenticated educational Platforms. It supersedes any general privacy policy found on our public marketing websites.
The public marketing website is governed by a separate policy and operates on separate infrastructure.
Under applicable data protection laws, including the EU General Data Protection Regulation (GDPR) and the Brazilian General Data Protection Law (LGPD), the Institution is the Data Controller.
BKTK acts strictly as a Data Processor. We do not own the institutional data, nor do we determine the purposes for which it is processed. We process data solely on behalf of, and strictly in accordance with the documented instructions of, the Institution, as formalized in a Data Processing Agreement (DPA) and Subscription Agreement.
Our Platforms are designed with privacy by default and rely on strict data minimization principles.
To provide access to the Platforms, we collect the minimum necessary data from authorized educators:
We do not collect, process, or store the personal data (such as names, email addresses, or contact details) of students.
Within our authenticated educational Platforms (Creating Together and AnimaPIC), we enforce a strict prohibition on commercial tracking.
Technical logging is strictly limited to security, system performance, and necessary functional operations to ensure the stability of the educational tools.
Centralized EU Hosting (Personal Data): To ensure the highest level of data security and regulatory compliance, all Personal Data (including teacher administrative credentials, institutional metadata, and account infrastructure) is stored and processed exclusively on secure servers located within the European Economic Area (EEA).
Global Production Pipeline (Non-Personal Data): As part of the core Creating Together service, the uploaded creative assets (e.g., digitized drawings, scripts, and audio files) are utilized to produce final animated films. Prior to entering the animation production pipeline, these files are strictly and permanently decoupled from any institutional or user identifiers.
These fully anonymized, non-personally identifiable payloads may be transferred securely to our global network of professional editors and animators (including external sub-contractors and our Studio BKTK network) located outside the EU/EEA. Because this operational transfer involves strictly non-personal data, it falls outside the restricted international transfer mechanisms defined by Chapter V of the GDPR.
Ad Hoc Technical Support (Cross-Border Data Flows): For operational IT support, authorized technical engineering personnel from our parent company in Brazil may require strictly limited, remote access to the EU-based servers. This access is governed by the European Commission’s Standard Contractual Clauses (SCCs) to ensure equivalent data protection safeguards.
BKTK implements comprehensive technical and organizational measures to protect institutional data against unauthorized access, loss, or alteration. These measures include:
Infrastructure Sub-processors: We engage strictly vetted, industry-leading cloud infrastructure providers located within the EU/EEA to host our platforms. A full list of our current infrastructure sub-processors is detailed in the respective institution's Data Processing Agreement (DPA).
Operational Animation Vendors: We engage external sub-contractors and animation professionals to assist in the creation of the animated films and content. Because these vendors receive only completely anonymized, non-personally identifiable assets (e.g., decoupled drawings and audio files), they do not process Personal Data on behalf of the Data Controller. Therefore, they do not qualify as "Sub-processors" under Article 28 of the GDPR.
We retain institutional data only for the duration of the active subscription or as directed by the Data Controller.
Upon termination of the agreement, or upon written request from the Institution, BKTK will securely delete or return all institutional data (including teacher accounts and pedagogical outputs) within the timeframe specified in the applicable DPA, unless longer retention is strictly required by applicable law.
BKTK does not use any personal data or identifiable pedagogical outputs to train artificial intelligence or machine learning models. Any system improvements or analytics are conducted using strictly aggregated and anonymized metadata that cannot be linked back to any individual teacher, student, or school.
If you are an administrator or DPO of an Institution and have questions regarding our data processing practices, please contact our Data Protection Officer at:
By Kids To Kids Oy Ltd
Address: Azorienkuja 1 C 56, 00220 Helsinki, Finland
Email: [email protected]