Acordo de tratamento de dados
Última atualização:
Como o Wind HQ trata os dados pessoais que uma escola registra sobre seus alunos, seguindo as instruções dessa escola. Faz parte do contrato da escola.
O Wind HQ é hoje um piloto brasileiro e egípcio conduzido em inglês. Este documento é publicado somente em inglês, e o texto em inglês é a versão que vale. Pergunte em português sobre qualquer ponto dele e a gente responde em português.
0. What this is, and who it binds
This agreement is between the kite school using Wind HQ (“the Controller”) and Sergei Fedorov Računarsko Programiranje pr cpp Beograd, a sole trader registered in Belgrade, Serbia, trading as Wind HQ (“the Processor”). It forms part of the school agreement and takes effect when that one does. Where the two conflict on the handling of personal data, this one wins.
It is written to satisfy Art. 28(3) of the GDPR, and the equivalent requirements of Brazil’s LGPD and Egypt’s Law No. 151 of 2020. The clause numbers below follow the order of Art. 28(3) so it can be checked against the statute without hunting.
Terms used here — controller, processor, personal data, processing, data subject, personal data breach, supervisory authority — carry their GDPR meanings.
1. Subject matter, duration, nature and purpose
- Subject matter: the personal data the Controller records in Wind HQ in order to run a kite school — scheduling lessons, allocating equipment, and obtaining confirmations from the people involved.
- Duration: for as long as the school agreement lasts, plus the export and deletion windows in clause 8.
- Nature: collection, storage, organisation, retrieval, transmission to the data subject through the channels the Controller has enabled, and erasure.
- Purpose: providing the service described in the school agreement, and nothing else. We do not process the Controller’s personal data for our own purposes, and we do not sell it.
2. Types of personal data and categories of data subject
Data subjects: the Controller’s students (riders), its instructors, and its staff.
Types of personal data:
- identity and contact data — name, email address, phone number, messaging handle;
- language preference;
- relationship data — which school, in what capacity, since when;
- lesson records — scheduled and completed lessons, instructor, spot, and the wind conditions each was planned under;
- body weight and riding level, used solely to match a kite size to the wind, and certification level;
- message records — what was sent about a lesson, whether it was delivered, and whether the recipient answered;
- payment metadata where the Controller takes payments through the platform — amount, currency, date, status. Card details are handled by the payment provider and never reach the Processor.
Special-category data is out of scope. The platform provides no field that accepts free text about a rider, and the school agreement obliges the Controller not to record health information anywhere in it. If the Controller does so regardless, it does so outside the Processor’s documented instructions and clause 3 applies.
3. Processing only on documented instructions (Art. 28(3)(a))
The Processor processes personal data only on the Controller’s documented instructions, including as to transfers to a third country. The Controller’s use of the platform, together with the school agreement and this one, constitutes those instructions; anything further should be sent in writing to hello@windhq.app.
Where the Processor is required by law to process beyond those instructions, it will tell the Controller before doing so unless that law forbids the telling.
The Processor will tell the Controller if an instruction appears to it to infringe data protection law. It is not obliged to police the Controller’s lawful basis, and does not claim to.
4. Confidentiality (Art. 28(3)(b))
Every person authorised by the Processor to process the Controller’s personal data is bound by a written confidentiality undertaking, or by a professional obligation of confidentiality, that survives the end of their engagement. Access is limited to those who need it to run the service, and administrative access is logged.
5. Security (Art. 28(3)(c), Art. 32)
The Processor maintains, at a minimum:
- encryption of personal data in transit and at rest;
- isolation of each school’s data at the database level rather than by application code alone;
- authentication tokens held server-side and never released to a browser;
- role-scoped access, least privilege, and an audit log of administrative actions;
- an append-only history of scheduling decisions, which resists silent alteration;
- the ability to restore availability and access after an incident, and periodic review of these measures.
The privacy policy’s security section describes the same measures in plainer language. Where they differ in detail, this clause governs.
6. Sub-processors (Art. 28(2) and Art. 28(3)(d))
The Controller gives general authorisation for the Processor to engage the sub-processors below. Each is engaged under a written contract imposing data protection obligations no less protective than these.
- Fly.io — application hosting and the public edge.
- Supabase — the databases and file storage.
- Auth0 (Okta) — authentication, including social sign-in where you choose it.
- Mailgun (Sinch) — transactional email — invitations, confirmations, receipts.
- Meta (WhatsApp Business) — lesson messages, where your school has connected WhatsApp.
- Telegram — lesson messages, where you have linked a Telegram account.
- Twilio — automated voice calls at the last step of a confirmation chase.
Changes: the Processor will give the Controller at least 30 days’ written notice before adding or replacing a sub-processor. The Controller may object on reasonable data protection grounds within that period; if the objection cannot be resolved, either party may terminate the school agreement without penalty, and clause 8 applies.
The Processor remains liable to the Controller for its sub-processors’ acts.
7. Assistance (Art. 28(3)(e) and Art. 28(3)(f))
- Data subject requests. The platform gives the Controller the tools to access, correct, export and delete the data it holds. Where a request reaches the Processor directly, it will not answer it on the Controller’s behalf but will forward it without undue delay, and will assist the Controller in responding — including within the 15-day deadline the LGPD sets, which is shorter than the GDPR’s.
- Breach. The Processor will notify the Controller without undue delay and in any event within 48 hours of becoming aware of a personal data breach affecting the Controller’s data, with the information the Controller needs to meet its own 72-hour obligation, and will assist its investigation. Forty-eight rather than seventy-two on purpose: the Controller’s clock is 72 hours and it cannot start after ours ends.
- Impact assessments. The Processor will provide the information reasonably needed for a data protection impact assessment or a prior consultation with a supervisory authority.
8. Deletion or return at the end (Art. 28(3)(g))
On termination, the Controller may export its data for 30 days in a machine-readable format (CSV or JSON). After that window the Processor deletes it within 90 days, including from backups as those rotate, and confirms the deletion in writing on request.
The exception, stated rather than buried: entries the Processor is required by law to keep — financial records for tax — are retained for the statutory period and nothing else is done with them. Records retained for the establishment or defence of legal claims are pseudonymised rather than erased; they are stripped of identifying fields, and the Processor does not claim they could never be re-linked.
9. Audit and information (Art. 28(3)(h))
The Processor will make available the information needed to demonstrate compliance with this agreement, and will allow and contribute to audits — including inspections — conducted by the Controller or an auditor it mandates.
Reasonably, and in a way a two-person company can actually honour: on 30 days’ notice, no more than once a year unless a breach or a supervisory authority requires otherwise, during business hours, subject to confidentiality, and without access to another school’s data. Where a current third-party audit report answers the question, the Processor may offer it instead — it has none today, and says so rather than implying otherwise.
10. International transfers
Wind HQ runs in more than one region, and personal data is placed in a region that satisfies the law applying to the Controller and its students. The region holding a given school’s data is recorded against that school and does not drift.
Region-level disclosure. On request, the Processor will tell the Controller which region holds its data, and will give notice before moving it — the Controller needs that for its own record of processing activities and its own privacy notice. The public privacy policy states the rule rather than a list of locations; this clause is what turns that into an answer for a school that needs one.
The Processor’s personnel are established in Serbia, so operating the service involves access from there. Where a transfer requires standard contractual clauses or another Art. 46 mechanism, the parties adopt it, and the SCCs are incorporated by reference with the Controller as data exporter and the Processor as data importer.
Egypt’s Law No. 151 of 2020 requires a permit for cross-border transfers. Where the Controller is an Egyptian school, the parties will not transfer personal data out of Egypt until that permit is in place.
11. Aggregated and anonymised data
Clause 8 of the school agreement permits the Processor to use aggregated, anonymised data to operate and improve the service. For the avoidance of doubt: that permission extends only to data from which no individual and no school can be identified or re-derived, and anonymisation to that standard takes the data outside this agreement. Pseudonymised data is not anonymised data and stays within it.
12. Liability, and the rest
The school agreement’s liability clause applies to this one. This agreement is governed by the laws of Serbia, with the courts of Belgrade having exclusive jurisdiction, and it ends when the school agreement does.
13. Contact
Data protection matters: hello@windhq.app. The Processor has not appointed a data protection officer; it is a two-person company whose processing does not meet the Art. 37 thresholds, and it will appoint one if that changes.