Institutional Platform Privacy Policy

Effective Date: 06/07/2026

Applicable Services: Creating Together (https://create.bykidstokids.com) and AnimaPIC (https://animapic.bykidstokids.com)

1. Introduction and Scope

By Kids To Kids Oy Ltd ("BKTK", "we", "us", or "our") provides educational software platforms—specifically Creating Together and AnimaPIC (the "Platforms")—to schools, cities, municipalities, and educational institutions (the "Institution").

This Institutional Platform Privacy Policy explains how data is processed within these authenticated educational environments.

IMPORTANT DISTINCTION: This policy applies only to the authenticated educational Platforms. It supersedes any general privacy policy found on our public marketing websites.

The public marketing website is governed by a separate policy and operates on separate infrastructure.

2. Our Role: Data Processor

Under applicable data protection laws, including the EU General Data Protection Regulation (GDPR) and the Brazilian General Data Protection Law (LGPD), the Institution is the Data Controller.

BKTK acts strictly as a Data Processor. We do not own the institutional data, nor do we determine the purposes for which it is processed. We process data solely on behalf of, and strictly in accordance with the documented instructions of, the Institution, as formalized in a Data Processing Agreement (DPA) and Subscription Agreement.

3. Data Collection and Minimization (The "Zero Student PII" Principle)

Our Platforms are designed with privacy by default and rely on strict data minimization principles.

3.1. Teacher and Administrator Data

To provide access to the Platforms, we collect the minimum necessary data from authorized educators:

  • Identity & Contact Data: Teacher/Administrator name and institutional email address (used solely for account creation, login, and service communications).
  • Authentication Data: Encrypted passwords or Single Sign-On (SSO) tokens.

3.2. Student Data (Zero Personal Information)

We do not collect, process, or store the personal data (such as names, email addresses, or contact details) of students.

  • Anonymous Access: Students access the Platforms (including AnimaPIC) via anonymous, teacher-generated access tokens or generic classroom login codes.
  • Pedagogical Uploads: The platforms serve as a collaborative workspace where students and/or teachers upload digitized versions of student-created content (such as scanned drawings, photos of artwork, and pre-recorded audio narrations).
  • Anonymous Processing: These uploaded files are treated strictly as anonymous pedagogical payloads required to generate the final animated films or books. They are not linked to student names, individual user profiles, biometric identifiers, or behavioral data.
  • No In-App Creation Tracking: The platforms do not feature live, in-app drawing or voice-recording tools that capture real-time telemetry, device sensor data, or behavioral biometrics from the student.

4. Strict Prohibition on Tracking and Profiling

Within our authenticated educational Platforms (Creating Together and AnimaPIC), we enforce a strict prohibition on commercial tracking.

  • No Advertising: We do not display third-party advertisements.
  • No Behavioral Profiling: We do not build behavioral profiles of students or teachers.
  • No Marketing Cookies: We do not deploy marketing cookies, tracking pixels, or commercial analytics trackers within the logged-in student or teacher environments.

Technical logging is strictly limited to security, system performance, and necessary functional operations to ensure the stability of the educational tools.

5. Regional Data Sovereignty and Hosting

Centralized EU Hosting (Personal Data): To ensure the highest level of data security and regulatory compliance, all Personal Data (including teacher administrative credentials, institutional metadata, and account infrastructure) is stored and processed exclusively on secure servers located within the European Economic Area (EEA).

Global Production Pipeline (Non-Personal Data): As part of the core Creating Together service, the uploaded creative assets (e.g., digitized drawings, scripts, and audio files) are utilized to produce final animated films. Prior to entering the animation production pipeline, these files are strictly and permanently decoupled from any institutional or user identifiers.

These fully anonymized, non-personally identifiable payloads may be transferred securely to our global network of professional editors and animators (including external sub-contractors and our Studio BKTK network) located outside the EU/EEA. Because this operational transfer involves strictly non-personal data, it falls outside the restricted international transfer mechanisms defined by Chapter V of the GDPR.

Ad Hoc Technical Support (Cross-Border Data Flows): For operational IT support, authorized technical engineering personnel from our parent company in Brazil may require strictly limited, remote access to the EU-based servers. This access is governed by the European Commission’s Standard Contractual Clauses (SCCs) to ensure equivalent data protection safeguards.

6. Data Security

BKTK implements comprehensive technical and organizational measures to protect institutional data against unauthorized access, loss, or alteration. These measures include:

  • Encryption of data at rest and in transit using industry-standard protocols.
  • Strict Role-Based Access Controls (RBAC) ensuring only authorized personnel have access to the production environment.
  • Logical separation of institutional data to ensure cross-tenant security.

7. Sub-processors and Third-Party Vendors

Infrastructure Sub-processors: We engage strictly vetted, industry-leading cloud infrastructure providers located within the EU/EEA to host our platforms. A full list of our current infrastructure sub-processors is detailed in the respective institution's Data Processing Agreement (DPA).

Operational Animation Vendors: We engage external sub-contractors and animation professionals to assist in the creation of the animated films and content. Because these vendors receive only completely anonymized, non-personally identifiable assets (e.g., decoupled drawings and audio files), they do not process Personal Data on behalf of the Data Controller. Therefore, they do not qualify as "Sub-processors" under Article 28 of the GDPR.

8. Data Retention and Deletion

We retain institutional data only for the duration of the active subscription or as directed by the Data Controller.

Upon termination of the agreement, or upon written request from the Institution, BKTK will securely delete or return all institutional data (including teacher accounts and pedagogical outputs) within the timeframe specified in the applicable DPA, unless longer retention is strictly required by applicable law.

9. Artificial Intelligence and Machine Learning

BKTK does not use any personal data or identifiable pedagogical outputs to train artificial intelligence or machine learning models. Any system improvements or analytics are conducted using strictly aggregated and anonymized metadata that cannot be linked back to any individual teacher, student, or school.

10. Contact Information

If you are an administrator or DPO of an Institution and have questions regarding our data processing practices, please contact our Data Protection Officer at:

By Kids To Kids Oy Ltd

Address: Azorienkuja 1 C 56, 00220 Helsinki, Finland

Email: [email protected]