Legal · updated 14 September 2026

Data Processing Addendum

Draft pending legal review. This document describes how TKDS intends to operate and may change before it is finalised. Questions: info@tkdsmedia.com.

This addendum outlines how TKDS processes personal data on behalf of an organisation running a MediaCore2 platform. It forms part of the customer agreement when your order form refers to it. It’s published so you can review it early — the version signed with your order form is the one that applies. To request it, write to sales@tkdsmedia.com.

01Parties and scope

The parties are the customer named in the order form and TKDS Media. This addendum applies to personal data TKDS processes for the customer in providing MediaCore2 under the order form: the customer’s public site, TV and mobile apps, and Studio.

If this addendum and the customer terms conflict on anything to do with personal data, this addendum prevails. The order form may add details specific to the customer.

02Definitions

  • Customer personal data — personal data TKDS processes on the customer’s behalf in providing the services.
  • Services — the MediaCore2 platform and the support described in the order form.
  • Sub-processor — a third party TKDS engages that processes customer personal data.
  • Security incident — a breach of security leading to the accidental or unlawful destruction, loss or alteration of customer personal data, or its unauthorised disclosure or access.
  • Data protection law — the privacy and data protection laws that apply to the processing.

03Roles

  • The customer is the controller. It decides why personal data is processed and which data: the modules and add-ons it switches on, the questions its forms ask, the audiences it emails, the tags it adds to its site.
  • TKDS is the processor. It processes customer personal data only to provide the services, on the customer’s instructions.
  • Where the customer acts for someone else — an agency running a platform for a client, for example — TKDS acts as a sub-processor, and the customer confirms that its instructions are authorised by that controller.

The customer is responsible for having a lawful basis for its processing, for giving its audience the notices the law requires, and for the accuracy of the data it collects.

04Details of the processing

ItemDescription
Subject matterHosting and operating the customer’s MediaCore2 platform
DurationThe term of the order form, followed by the return and deletion steps below
Nature of processingStorage, streaming and delivery; account and access management; subscription, ticket and order records; notification delivery; audience analytics; support
PurposeProviding, securing and supporting the services under the customer’s instructions
Data subjectsViewers and subscribers; buyers, including guest checkout customers; newsletter subscribers; people who submit comments, messages, reels, clips or forms; the customer’s staff, crew and scorers; people featured on team, roster and cast pages
Categories of dataNames and contact details, including a mobile number where phone-number sign-in is used; account, role and device records; subscriptions, tickets, orders and payment status — never full card numbers; saved items, ratings and watch progress; submitted content, uploads and signatures; notification preferences; activity log entries; analytics records keyed to a scrambled visitor value
Special categoriesNone required by the services. If the customer collects any through its own forms, it is responsible for the lawful basis to do so

05Processing on instructions

TKDS processes customer personal data only on the customer’s documented instructions. Those instructions are:

  • The order form, the customer terms and this addendum
  • The customer’s own configuration in the Studio — switching a module off, turning analytics collection off and removing a viewer’s account are all instructions
  • Further written instructions the customer gives, where they are consistent with the agreement

If TKDS believes an instruction breaks data protection law, it tells the customer. If the law requires TKDS to process data some other way, it tells the customer first, unless the law forbids that.

06Confidentiality

Everyone at TKDS who may handle customer personal data is bound by confidentiality obligations, and handles it only as needed to provide the services.

07Security measures

TKDS applies technical and organisational measures appropriate to the risk. The measures built into the platform include:

  • Payments. Card details never reach the platform: buyers pay on the provider’s own hosted page or its own secure field, and only a token is sent on. Every payment is re-verified with the provider before access is granted. Provider credentials are stored encrypted and shown back only as their last four characters.
  • Accounts. Passwords are stored only as one-way hashes. Viewers see every signed-in device on their account and can sign any of them out, and per-plan device limits discourage password sharing.
  • TV sign-in. A QR code valid for 120 seconds. The credential is delivered to the TV itself, never to the phone that scanned the code.
  • Staff access. Roles the customer builds from 43 permission keys in 15 groups. Each person sees only the sections they may open, and guardrails stop anyone promoting themselves or removing the last administrator.
  • Accountability. An append-only activity log across 54 record types records who acted, their role at the time, and the before and after of every changed field.
  • Broadcast controls. Crew, replay-official and scorer logins receive only the feeds or scores they’re cleared for. Stream keys are masked, and a separate password lock guards the settings that could take a broadcast off air.
  • Content access. Access is decided at the moment of play from the purchase record, and a paywalled article’s body is never sent to a reader who isn’t entitled to it.
  • Forms and uploads. Form uploads are stored privately and released only to a reviewer or the applicant’s own link. Sign-in and contact forms are protected against automated abuse, and a contact message is stored before any email about it is sent.
  • Analytics. Visitors are recorded as an irreversible scrambled value, never a readable IP address, and the customer can switch collection off.

TKDS may update these measures over time, provided the overall level of protection doesn’t fall.

08Sub-processors

The customer authorises TKDS to engage sub-processors. Depending on the modules and add-ons in use, they fall into these categories:

CategoryWhat it’s used for
Hosting and storageRunning the platform and keeping its data and media
Streaming and deliveryReceiving live signals and delivering video and audio to viewers
Push notificationsDelivering alerts to phones and TVs
Automated-abuse protectionChecking that sign-in and contact forms are being used by people
Text message deliverySending one-time sign-in codes, where phone-number sign-in is installed
AI-assisted draftingProducing article drafts from what a staff member types, only where an administrator switches it on

For every sub-processor, TKDS:

  • Puts a written contract in place with data protection obligations equivalent to this addendum
  • Remains responsible to the customer for the sub-processor’s performance
  • Provides a current list of named sub-processors to the customer on request
  • Gives notice before adding or replacing one, so the customer can object on reasonable data protection grounds. If an objection can’t be resolved, the remedies in the order form apply

09Helping the customer respond to people

Much of what a data subject might ask can be handled directly in the Studio: looking up a viewer’s account, subscriptions and payments, correcting details, removing content, removing an account from Management → Users, and exporting payment and order records.

If TKDS receives a request from one of the customer’s viewers, it passes the request to the customer and doesn’t answer it unless the customer asks it to. TKDS also gives reasonable help with data protection impact assessments and consultations with authorities, based on the information available to it.

10Security incidents

If TKDS becomes aware of a security incident affecting customer personal data, it notifies the customer without undue delay. As far as the information is available at the time, the notice covers:

  • What happened, and when it was discovered
  • The categories and approximate number of people and records affected
  • The likely consequences
  • What TKDS has done, and proposes to do, to contain the incident and reduce its effects
  • A contact for further information

TKDS adds to the notice as it learns more. The customer decides whether to notify authorities or the people affected, and TKDS helps it do so. Notifying an incident is not an admission of fault. Customers report a suspected incident to security@tkdsmedia.com.

11International transfers

TKDS works from Egypt and the United States, and sub-processors may operate in other countries. Where customer personal data crosses borders in a way data protection law restricts, TKDS puts the safeguard that law requires in place.

12Return and deletion

  1. 1
    During the term

    The customer can export payment and order records and download its reports from the Studio at any time.

  2. 2
    When the agreement ends

    On the customer’s written request, within the period set in the order form, TKDS returns customer personal data in a commonly used format.

  3. 3
    Then deletion

    TKDS deletes customer personal data from its active systems, and any copies kept for recovery are removed on their normal schedule. TKDS confirms deletion in writing on request.

Where the law requires TKDS to keep some data for longer, it keeps that data confidential and uses it only for that purpose.

13Information and audits

TKDS makes available the information reasonably needed to show it meets this addendum, starting with written answers to the customer’s security and privacy questions.

Where that isn’t enough, the customer may audit TKDS’s compliance with this addendum by reasonable request:

  • With reasonable advance notice, during normal business hours
  • At a frequency agreed in the order form, and additionally after a confirmed security incident or where an authority requires it
  • Carried out by the customer or an independent auditor bound by confidentiality
  • Conducted so it doesn’t disrupt the services or expose anyone else’s data
  • At the customer’s cost, unless the audit finds a material breach of this addendum by TKDS

14Term and liability

This addendum lasts as long as TKDS processes customer personal data. Each party’s liability under it is subject to the limits in the customer agreement, to the extent the law allows.

15Contact

  • Privacy questions: info@tkdsmedia.com
  • Security incidents: security@tkdsmedia.com
  • A copy for signature: sales@tkdsmedia.com
  • Cairo, Egypt: Zahraa Maadi · Katameya · Kenda Compound · +1 202 555 0147
  • Ohio, United States: 2792 Indian Ripple Rd · +1 231 360 0088