Terms of Use of the Paideus platform
Last updated: 31 August 2026
1. Parties and acceptance
1.1. These Terms of Use (“Terms”) govern the provision of the Paideus online educational-institution management platform (the “Platform”) by the general partnership named “AVARI SOLUTIONS G.P.”, seated in Moschato, Attica, at 97 Thermopylon Street, 18345 Moschato, Tax ID (ΑΦΜ) 803381623, GEMI no. 195717907000 (the “Provider”, “we”), to the relevant customer — an educational institution (secondary tutoring centre, foreign-language school or other private educational organisation) (the “Customer”).
1.2. The Platform is offered exclusively to businesses (B2B). By signing a contract, accepting an offer or activating an account, the Customer represents that it is acting in the course of its business and unreservedly accepts these Terms and the attached Data Processing Agreement (DPA), which forms an integral part of them.
1.3. End Users (the Customer’s staff, teachers, parents/guardians and students) obtain access to the Platform solely by invitation and under the Customer’s responsibility, in accordance with clause 5.
2. Subject matter — licence
2.1. For the duration of the cooperation and subject to timely payment of the fees, the Provider grants the Customer a non-exclusive, non-transferable, non-assignable licence to access and use the Platform as a service (Software as a Service), solely for the internal operational needs of the Customer’s educational institution.
2.2. The Platform provides, by way of example, functions for student records, scheduling, finance, communication and educational content (ERP-CMS-LMS). Specific features are described in the then-current commercial offer or documentation and may evolve.
2.3. The following are expressly prohibited: resale, sub-licensing or making the Platform available to third parties; decompiling, reverse-engineering or copying the software; using the Platform to develop a competing product; automated extraction of data (scraping) beyond the export functions provided; and any use contrary to law or these Terms.
3. Trial period
3.1. The Provider may, at its discretion and following communication, provide a free one (1) month trial. During the trial the Platform is provided “as is”, without any warranty of availability or fitness for purpose, and the Provider bears no liability other than for wilful misconduct or gross negligence.
3.2. If at the end of the trial the Customer does not proceed to a commercial relationship, the account is deactivated and the data is deleted in accordance with clause 13.3.
4. Commercial terms
4.1. Fees, billing method and payment terms are set out in the then-current commercial offer or contract between the parties. Prices exclude VAT unless expressly stated otherwise.
4.2. If the Customer is more than thirty (30) days overdue, the Provider may, after written notice, suspend access to the Platform until payment, without that constituting termination and without prejudice to any other rights. Suspension of access does not entail deletion of data.
4.3. The Provider may adjust its price list with at least sixty (60) days’ prior written notice; the adjustment applies from the next billing period.
5. User accounts — Customer responsibility for End Users
5.1. The Customer is solely responsible for creating, managing and deactivating the accounts of its End Users (staff, teachers, parents/guardians, students), for correctly assigning access rights, and for every action carried out through those accounts.
5.2. Minor users. To the extent the Customer grants access to underage students, the Customer is solely responsible: (a) for having obtained the information and, where required, the consent of those exercising parental responsibility, in accordance with the GDPR (Regulation (EU) 2016/679) and Law 4624/2019; and (b) for supervising use of the Platform by minors in the context of the educational relationship. The Provider has no direct contractual relationship with End Users and does not decide who obtains access.
5.3. End Users must keep their credentials secure. The Customer must notify the Provider without delay of any suspected or unauthorised use.
6. Customer Content — custom fields
6.1. “Customer Content” means any data, file, information or material that the Customer or its End Users enter, store or transmit through the Platform, including data entered in dynamic/custom fields created by the Customer itself.
6.2. The Customer represents and warrants that: (a) it has every necessary legal basis, right, licence and, where required, consent for the collection and recording of Customer Content; (b) Customer Content does not infringe third-party rights or applicable law; (c) it will not record special-category data (Article 9 GDPR — for example health data, learning difficulties, religious beliefs) unless it itself has a legal basis for processing and complies with its related obligations as controller.
6.3. The Provider does not review, supervise or determine Customer Content. The Platform is a neutral technical tool; the choice of the type, extent and lawfulness of recorded data belongs exclusively to the Customer as controller.
6.4. Customer Content belongs to the Customer. The Customer grants the Provider a non-exclusive licence to store, copy (backup) and technically process it, solely to the extent required to provide the service.
7. Personal data
7.1. For GDPR purposes, the Customer acts as controller and the Provider as processor in respect of personal data included in Customer Content. The parties’ related obligations are governed by the Data Processing Agreement (DPA), which forms an integral part of these Terms.
7.2. For data the Provider processes for its own purposes (for example contact details of the Customer’s representatives, billing, technical support), the Provider acts as controller in accordance with its Privacy Policy.
8. Availability — maintenance — support
8.1. The Provider makes every reasonable effort for continuous availability of the Platform, without however guaranteeing uninterrupted or error-free operation. The Platform is hosted on Microsoft Azure infrastructure within the European Union.
8.2. The Provider may carry out scheduled maintenance, preferably during low-use hours and with prior notice where feasible, as well as emergency work when required for security reasons.
8.3. The Provider is not liable for unavailability caused by: infrastructure or telecommunications providers; the Customer’s equipment or connection; misuse; force majeure; or third-party cyberattacks despite the taking of appropriate security measures.
9. Intellectual and industrial property
9.1. The Platform, source code, architecture, design environment, trademarks, documentation and any improvement or derivative work belong exclusively to the Provider or its licensors. Nothing in these Terms transfers any intellectual or industrial property right to the Customer beyond the licence in clause 2.
9.2. The Provider may use anonymised and aggregated usage statistics of the Platform (which do not allow identification of natural persons or of the Customer) to improve its services.
10. Confidentiality
10.1. Each party must keep strictly confidential the other party’s confidential information that comes to its knowledge in the course of the cooperation and must not use it for any purpose other than performance of the contract. This obligation lasts throughout the cooperation and for five (5) years after it ends.
10.2. Information is not confidential if it is or becomes publicly known without the recipient’s fault; was lawfully known to the recipient before disclosure; or must be disclosed by law or by order of an authority.
11. Warranties — disclaimer
11.1. The Platform is provided with the greatest possible care, in accordance with industry good practice. To the maximum extent permitted by law, the Provider gives no other warranty, express or implied, including warranties of fitness for a particular purpose.
11.2. The Customer acknowledges that the Platform is a tool supporting its operations and that it remains solely responsible for compliance with the legal and regulatory framework governing educational institutions (tax, labour, education law, and so on).
12. Limitation of liability
12.1. To the maximum extent permitted by law, the Provider’s total liability to the Customer, from any cause whatsoever, is limited to the amount the Customer paid the Provider in the twelve (12) months preceding the harmful event.
12.2. The Provider is not liable for indirect, incidental or consequential loss, lost profits, loss of reputation, or loss of data caused by the Customer’s failure to use the export functions provided.
12.3. The above limitations do not apply in the event of the Provider’s wilful misconduct or gross negligence, nor where limitation is prohibited by mandatory law.
12.4. The Customer must indemnify and hold the Provider harmless from any third-party claim (including End Users, data subjects and supervisory authorities) arising from: (a) the Customer’s breach of these Terms or the DPA; (b) Customer Content; (c) the Customer’s failure to meet its obligations as controller, in particular as regards informing and obtaining the consents of parents/guardians.
13. Term — termination — data after termination
13.1. The cooperation lasts for the period set out in the commercial offer/contract. Either party may terminate the cooperation with thirty (30) days’ written notice, unless otherwise provided in the individual contract.
13.2. The Provider may terminate immediately in the event of: a material breach of the Terms that is not remedied within fifteen (15) days of written notice; use of the Platform in violation of law; or the Customer’s bankruptcy or dissolution.
13.3. After expiry or termination: the Customer retains for thirty (30) days the ability to export Customer Content in a commonly readable format. After ninety (90) days from termination, the Provider permanently deletes Customer Content from active systems. Backups are deleted according to the backup rotation cycle (see DPA), remaining protected and inaccessible for any other use in the meantime. The Provider may retain data to the extent required by tax or other law.
14. Force majeure
Neither party is liable for non-performance caused by events beyond its reasonable control (including natural disasters, war, strikes, large-scale telecommunications or power outages, acts of authorities), provided it notifies the other party without delay.
15. Amendment of Terms
The Provider may amend these Terms, informing the Customer at least thirty (30) days before the changes take effect, via the Platform or email. Continued use after the effective date constitutes acceptance. In the event of a material adverse change, the Customer may terminate without charge before the effective date.
16. Final provisions
16.1. These Terms are governed by Greek law. The courts of Athens have exclusive jurisdiction over any dispute.
16.2. Invalidity of any term does not affect the validity of the remainder. Failure to exercise a right does not constitute a waiver. The Customer may not assign rights or obligations without the Provider’s written consent.
16.3. Contact: info@paideus.com.
Data Processing Agreement (DPA)
Annex to the Terms of Use — pursuant to Article 28 GDPR
1. Roles and subject matter
1.1. The Customer acts as controller (the “Controller”) and the Provider as processor (the “Processor”) in respect of personal data that the Customer and its End Users enter into the Platform (the “Data”).
1.2. The Processor processes the Data solely to provide, maintain and support the Platform, in accordance with the Controller’s documented instructions as set out in the Terms of Use, this DPA and the settings the Controller chooses within the Platform. Details of the processing are in Annex A.
1.3. The Processor shall immediately inform the Controller if, in its opinion, an instruction infringes the GDPR or other data-protection law.
2. Controller’s obligations and representations
2.1. The Controller is solely responsible for: (a) the lawfulness of collection and recording of the Data, including the existence of an appropriate legal basis; (b) informing data subjects (Articles 13–14 GDPR); (c) the accuracy, quality and minimisation of Data it records, in particular in dynamic/custom fields; (d) assigning access rights to its End Users.
2.2. Minors. Given that the Platform is used to manage students, including minors, the Controller warrants that it has obtained all necessary information and, where required, consent of those exercising parental responsibility, in accordance with the GDPR and Article 21 of Law 4624/2019 (age threshold of 15 for information-society services), before recording minors’ data or granting them access.
2.3. Special-category data. The Platform is not specifically designed for special-category data (Article 9 GDPR). If the Controller chooses to record such data (for example health information or learning difficulties) via custom fields or free text, it does so at its sole responsibility and warrants that it meets the conditions of Article 9(2) GDPR.
3. Processor’s obligations
3.1. The Processor: (a) processes the Data only on the Controller’s documented instructions, unless required by EU or Greek law, in which case it informs the Controller before processing unless the law prohibits that; (b) ensures that persons who process the Data are bound by confidentiality; (c) implements the technical and organisational measures of Article 32 GDPR (Annex C); (d) complies with Article 28(2) and (4) GDPR regarding sub-processors; (e) assists the Controller with Articles 32–36 GDPR (security, breach notification, DPIA), taking into account the nature of the processing; (f) deletes or returns the Data after termination (clause 8 below); (g) makes available to the Controller all information necessary to demonstrate compliance and allows audits (clause 9 below).
3.2. The Processor does not use the Data for its own purposes, does not sell it, does not make it available to third parties and does not profile data subjects, except for producing anonymised aggregated statistics that do not allow identification.
4. Sub-processors
4.1. The Controller grants general written authorisation to engage sub-processors. The current list is in Annex B. The Processor shall inform the Controller of any intended addition or replacement at least thirty (30) days in advance, providing an opportunity to object; in the event of a reasonable objection that cannot be accommodated, the Controller may terminate the cooperation without charge as to the future.
4.2. The Processor shall impose on sub-processors, by contract, substantially the same data-protection obligations as this DPA and remains fully liable to the Controller for their performance.
4.3. Optional communication channels. Certain features (for example future sending of messages via Viber) are activated only at the Controller’s choice; activation by the Controller constitutes approval of the corresponding sub-processor.
5. Data-subject rights
5.1. Taking into account the nature of the processing, the Processor shall assist the Controller, with appropriate technical and organisational measures (access, rectification, export and deletion functions within the Platform), in fulfilling data-subject requests (Articles 12–23 GDPR).
5.2. If a data subject contacts the Processor directly, the Processor shall refer them to the Controller and inform the Controller without undue delay, without responding on the merits unless otherwise required by law.
6. Personal-data breach
6.1. The Processor shall inform the Controller without undue delay and in any event within forty-eight (48) hours after becoming aware of a personal-data breach affecting the Data, providing the information in Article 33(3) GDPR to the extent available, so that the Controller can meet the 72-hour deadline towards the Hellenic Data Protection Authority.
6.2. The Processor shall immediately take reasonable containment and remediation measures and cooperate with the Controller. Notification to the supervisory authority and to data subjects is the Controller’s responsibility and decision.
7. Transfers outside the EEA
7.1. The Data is stored and processed in data centres within the European Union (Microsoft Azure, EU region). The Processor does not transfer Data outside the EEA unless the safeguards of Chapter V GDPR (adequacy decision, standard contractual clauses, etc.) are in place and Annex B is updated.
7.2. Certain sub-processors (for example Microsoft), as global providers, may perform limited remote support access outside the EEA, under the safeguards of the standard contractual clauses and the EU-US Data Privacy Framework, where applicable.
8. Deletion and return of data
8.1. After the cooperation ends, the Controller may export the Data within thirty (30) days. The Processor shall permanently delete the Data from active systems no later than ninety (90) days after termination, unless EU or Greek law requires retention.
8.2. Data in backups is deleted automatically at the end of the backup retention cycle as then applicable in the Processor’s infrastructure (indicatively up to 35 days — Annex C); in the meantime it remains encrypted, isolated and is not used for any purpose other than possible disaster recovery.
9. Audits
9.1. The Processor shall make available to the Controller, upon written request, all information necessary to demonstrate compliance with Article 28 GDPR, including descriptions of security measures and any available certifications/reports of infrastructure providers (for example Microsoft Azure certifications).
9.2. On-site audits take place at most once per year, with at least thirty (30) days’ notice, during business hours, in a manner that does not disrupt the Processor’s operations and does not affect the confidentiality of other customers’ data, at the Controller’s expense, unless the audit reveals a material breach.
10. Duration — liability
10.1. This DPA applies for as long as Data is processed in the course of the cooperation.
10.2. The parties’ liability is allocated in accordance with Article 82 GDPR: each party is liable for damage caused by processing that infringes the obligations the GDPR imposes specifically on its role or the Controller’s lawful instructions. Otherwise the limitation of liability in clause 12 of the Terms of Use applies, to the extent permitted by law.
Annex A — Description of processing
Subject matter and nature: Hosting, storage, organisation, transmission (sending notifications/email), backup and generally technical processing of data through the ERP-CMS-LMS Platform.
Purpose: Managing the operation of the Controller’s educational institution (student records, schedule, financial management, communication, educational content).
Duration: For as long as the cooperation lasts, plus the periods in clause 8.
Categories of data subjects: Students (including minors), parents/guardians, teachers and other staff of the Controller.
Categories of data: Identification and contact details (name, phone, email, address), educational data (groups, grades, attendance), tuition financial data, and any data the Controller records in dynamic/custom fields, which are determined exclusively by the Controller.
Special categories: Not provided for by the Platform’s design; any recording is at the Controller’s sole responsibility and decision (DPA clause 2.3).
Annex B — List of sub-processors
| Sub-processor | Service | Location of processing |
|---|---|---|
| Microsoft Ireland Operations Ltd (Microsoft Azure) | Infrastructure hosting, databases, backups | European Union |
| Microsoft — Azure Communication Services | Email delivery | European Union |
| Rakuten Viber — future, upon activation by the Controller | Viber messaging | To be completed before activation |
Annex C — Technical and organisational measures
Encryption of data in transit (TLS) and at rest (encryption at rest on Azure); role-based access control (RBAC) within the Platform; user authentication via an identity provider (Keycloak); logical isolation of data per customer (multi-tenancy isolation); regular automated backups with retention of up to 35 days; activity logging (audit logs); limited Processor staff access on a least-privilege basis with confidentiality undertakings; security updates and infrastructure monitoring via Azure tools.