Data Processing Agreement
Between the daycare and 4V3D OÜ, for the Minute Mission group service. Version 1.1, 23 September 2026.
This is the English text of the agreement. It is also published in Estonian, and the Estonian text is the one Estonian customers sign. Where the two disagree about an Estonian customer, the Estonian text governs.
How to agree to this
Two ways, with the same effect.
- At checkout. Tick the box that says you accept this agreement, version 1.1. The version and the date are recorded against your account, and the copy we email you is the exact text you accepted. It also stays available in your account.
- On paper, if your organisation needs a signature. Ask us at info@4v3d.ee and we send the same text as a document with a table for your details. Sign it electronically (an eIDAS qualified signature, DocuSign, Adobe Sign or your own national scheme) and send it back. 4V3D OÜ signs the same file and returns it. The agreement takes effect on the later of the two signatures.
If we need to change this agreement. 4V3D OÜ may update it only where the law requires that, or where the change does not reduce the daycare's protection and does not widen the processing. We tell the daycare's contact person by email and give 30 days' notice. A change that only adds information, or that tightens 4V3D OÜ's own obligations, takes effect when that notice runs out. Any other change needs the daycare to accept it actively, and until it does, the version the daycare accepted stays in force. The European Commission's clauses in section 3 are never changed, only their annexes.
Older versions. When a new version is published, the one it replaces stays available at its own address, marked as no longer current, so that a daycare can always read the version it accepted.
Processor: 4V3D OÜ, registration number 17515961, Asula tn 5-26, Kesklinna linnaosa, 11312 Tallinn, Estonia. Representative: Oskar Viil, member of the management board. Contact: info@4v3d.ee.
1. What this agreement covers
The daycare (the controller) uses Minute Mission, a web application operated by 4V3D OÜ (the processor), in which a teacher keeps a board of a group's missions and rewards. To do that, 4V3D OÜ processes the personal data described in Annex II on the daycare's behalf and on its instructions.
This agreement is the whole of what Article 28(3) of the GDPR, and of the UK GDPR, requires to be agreed in writing between a controller and a processor. It applies whether or not the daycare is established in the EEA or the United Kingdom.
2. Which law applies to you
- A daycare in the EEA. The GDPR applies. Section 3 also applies.
- A daycare in the United Kingdom. The UK GDPR and the Data Protection Act 2018 apply. References below to the GDPR are read as references to the UK GDPR, references to a supervisory authority are read as the Information Commissioner, and section 3 does not apply.
- A daycare anywhere else. Your own data protection law applies to you, and these terms apply to 4V3D OÜ as a matter of contract. 4V3D OÜ is established in the European Union, so it is bound by the GDPR for this processing in any case. Nothing here reduces a right your own law gives you.
3. The European Commission's standard contractual clauses
Where the daycare is established in the EEA, the parties apply the standard contractual clauses between controllers and processors in the Annex to Commission Implementing Decision (EU) 2021/915, in their official English wording. Those clauses form part of this agreement and the Annexes below are their annexes. Clause 5 (docking) does not apply. In Clause 7.7, Option 2 applies: general written authorisation of sub-processors, with 30 days' notice of any change. If the clauses and this agreement disagree, the clauses win.
4. What each side undertakes
4V3D OÜ will:
- Process the personal data only to provide the service and only on the daycare's documented instructions, including about transfers to a third country. This agreement and the daycare's use of the service are those instructions. If 4V3D OÜ is required by EU or member state law to process the data otherwise, it will tell the daycare first unless that law forbids it.
- Never use the data for its own purposes, never sell it, never use it to train anything, and never show it to anyone outside the sub-processors named in Annex IV.
- Make sure everyone with access is bound by confidentiality.
- Keep the security measures in Annex III, and not weaken them.
- Use only the sub-processors in Annex IV. 4V3D OÜ may add or replace one, and will give the daycare's contact person 30 days' written notice first. To object, write to info@4v3d.ee within those 30 days. 4V3D OÜ answers within 10 working days, either with a change that meets the objection or with a confirmation that the change stands. If the objection is not met, the daycare may end the service within 30 days of that answer and is refunded for the unused part of the period it has paid for.
- Help the daycare answer a request from a parent or a member of staff. Teachers and the director can already view, correct, export and delete this data in the service themselves. If a request reaches 4V3D OÜ instead, it is passed to the daycare's contact person within five working days and is not answered directly.
- Help the daycare with its obligations under Articles 32 to 36 (security, breach notification, impact assessments, prior consultation), taking into account what 4V3D OÜ actually knows.
- Tell the daycare's contact person about a personal data breach within 24 hours of becoming aware of it, with what is known at the time and the rest as it is established.
- On the end of the service, delete the data within 30 days, or hand it back first if the daycare asks. It disappears from encrypted backups within 90 days. 4V3D OÜ confirms in writing when it is gone.
- Make available the information needed to show these obligations are met, and allow an audit. In practice that means written answers and documentation on request. An on-site or third party audit can be arranged with 30 days' notice, at the daycare's cost, no more than once a year unless there has been a breach.
- Tell the daycare at once if an instruction appears to infringe data protection law.
The daycare will:
- Make sure it has a lawful basis for this processing and that parents have been informed. 4V3D OÜ does not see the parents and cannot do this for you.
- Keep the data in the service to what Annex II describes. In particular, do not type a child's surname, health information, an assessment of a child, or anything about a family's circumstances into a free-text field.
- Keep its own account details correct, and tell 4V3D OÜ when the contact person changes.
- Manage its own staff accounts: remove a teacher's login when that teacher leaves.
5. Two things that are not processing on your behalf
Said plainly here so that nobody has to guess later.
- Staff accounts. A teacher's or director's name, email address and password are needed to run the service at all, and 4V3D OÜ decides how to run it. For that narrow purpose 4V3D OÜ is the controller, not the processor, and its own privacy policy applies. Everything about the children is processing on the daycare's behalf and is covered by this agreement.
- Paying for it. If the daycare pays by card, the payment is handled by Stripe Payments Europe Ltd. Stripe receives the billing name, address, VAT number, email and card details of the daycare, and no data about any child. 4V3D OÜ is the controller of that billing data. Stripe is therefore not a sub-processor under this agreement and is not in Annex IV.
6. Term, law and liability
This agreement runs for as long as 4V3D OÜ processes the daycare's data. After the service ends it stays in force until the data has been deleted and the deletion confirmed in writing.
Estonian law applies, and disputes go to Harju County Court in Tallinn. If the daycare is a public body whose own rules require its national law and courts, we agree that in writing before the agreement starts, and that written agreement replaces this paragraph.
Each of us is liable to the other for loss caused by breaking this agreement, under the ordinary rules of Estonian law.
Unless the law requires otherwise, the most either of us has to pay the other under this agreement and, where they apply, the Minute Mission Terms of Use together is the amount the daycare paid for the service in the twelve months before the event that caused the loss. If the service has run for less than twelve months at that point, the limit is what twelve months would cost at the daycare's price. Fees owed for the service are not covered by the limit.
The limit does not apply to loss caused on purpose or by gross negligence, or to death or injury to a person.
A parent or a member of staff may claim compensation under Article 82 of the GDPR from the daycare or from 4V3D OÜ, and this agreement does not change that. If one of us pays such a claim in full, it may claim back from the other the share that matches the other's responsibility, and the limit above does not reduce that share. A fine from a supervisory authority is paid by whichever of us it is imposed on.
Annex I. The parties
Controller: the daycare, identified by the details it gives at checkout or fills into the signed copy. Role: controller of the children's data kept on the group board. Where the daycare is not a legal person in its own right, the controller is the municipality or other body that runs it, and the person who accepts this agreement does so on that body's behalf.
Processor: 4V3D OÜ, registration number 17515961, Asula tn 5-26, Kesklinna linnaosa, 11312 Tallinn, Estonia. Contact: Oskar Viil, member of the management board, info@4v3d.ee. No data protection officer is appointed, because the GDPR does not require one here.
Either side may change its contact person by writing to the other.
Annex II. Description of the processing
| Whose data | The children in the group, and the teachers and director who use the service. |
| Children's data | First name or nickname, a chosen picture (never a photograph), points, missions completed, rewards received, weekly awards from a fixed list, extra stars with a reason from a fixed list or the teacher's own note of up to 60 characters, and a mark that a child is away today, without a reason. |
| Staff data | Name, email address, password stored only as a hash, and sign-in records: which teacher ticked what, the browser string of a session, and the IP addresses of login attempts, kept only to stop password guessing. |
| Not collected | Surnames, national identity numbers, dates of birth, photographs, health data, addresses, parents' contact details. Photographs cannot be uploaded to a group account at all. |
| Special categories | None. The service is not built to hold any, and the free-text limit above is there to keep it that way. |
| Purpose | A board of missions and rewards for the group, as an aid to teaching and care. |
| Nature of the processing | Storage, display, correction, export and deletion, all started by the daycare's own staff in the service. No profiling, no automated decision-making, no analytics, no advertising. |
| Frequency | Continuous, for as long as the service is used. |
| Duration | For as long as the service is used, or for the trial period agreed. Deletion as in section 4. |
Annex III. Security measures
- The data is in the European Union. The application and its backups run in Hetzner Online GmbH's data centre in Helsinki, Finland (ISO/IEC 27001 certified). Service email is sent from Scaleway SAS in France. There is no transfer to a third country.
- Everything in transit is encrypted (HTTPS, with a Content Security Policy in force). Passwords are never stored, only a hash of them, and session tokens are stored hashed as well, so a copy of the database is not a set of working keys.
- Each group is a separate account. A teacher sees only the children in her own group. The director has one login across her own groups and no access to anyone else's.
- Photographs cannot be uploaded to a group account, push notifications are off, and the children's pictures are fixed to a set of drawings.
- Daily encrypted backups, kept 14 days on the server and 90 days off-site. They are encrypted with a public key the server itself does not hold, so the server cannot read its own backups. Restoring from a backup has been tested.
- Access to the server is limited to 4V3D OÜ's board member. There is no employee, contractor or support agent with access.
- No analytics, no advertising tools and no tracking of any kind. The only routine reporting is a daily count of signups, active accounts and errors, which contains no names.
- Rate limiting on sign-in and signup, and a 30-day limit on how far back a mission can be ticked off, so a mistake or an abuse cannot rewrite months of history.
- A written security review of the whole source has been run twice by an outside model, most recently on 20 September 2026, and its findings closed.
Annex IV. Sub-processors
| Hetzner Online GmbH (Germany) | Server hosting and backups. | Helsinki, Finland (EU) |
| Scaleway SAS (France) | Sending service email to staff, for example a password reset. No child's data is in any email. | France (EU) |
Both are in the European Union. There is no sub-processor outside the EU, and there is no international transfer to assess.