Last updated: 2026-09-12
For municipal IT-security managers and procurement officers: see also Security page for technical security information (encryption, secrets management, incident response, compliance status).
For municipal procurement officers: see also Data protection and subprocessors for operational GDPR detail (subprocessor list, retention for each set of stored data in the database, DPIA-light), and the DPA template for a data processing agreement.
Data controller
Data controller: Skolspegeln AB (org. no. 559359-7288). Contact person: Markus Reimer. Contact: info@skolspegeln.se
What data do we collect?
User accounts
If you create an account on Skolkoll, we store the following in our database (Firebase/Firestore — see Data protection and subprocessors for the current database regions):
- Email address and display name — for login and identification in the portal.
- Login method — which social login (Google, Microsoft, GitHub, Facebook or Apple) or email/password you use.
- Organisation membership — if you belong to an organisation, we store which organisation and your role (administrator/user).
- Timestamps — when the account was created.
Role and legal basis: If you personally are party to the agreement, Article 6(1)(b) applies to necessary account delivery. For an organisation account, the organisation is controller for membership, role and customer-directed use and Skolkoll processes that data as processor on instruction. Skolkoll is separately controller for strictly necessary identity, access and security administration under legitimate interest (Article 6(1)(f)); Article 6(1)(b) does not apply merely because your employer is a customer.
Retention: Data is stored for as long as the account or documented customer instruction requires it. Account deletion removes the profile, memberships and account-bound watches. A separate pseudonymous deletion-audit record may be retained for no more than 12 months to document completion or a failed step; it contains no raw email address and is not a continuing user account.
Organisation data
If you create or join an organisation, the following may be stored:
- Organisation name and registration number — public information for identification.
- Billing details — contact person, phone, address, email and reference/PO number for invoicing.
- Customer number (SK-NNNNN) — system-generated for invoice management.
Legal basis: Article 6(1)(b) only where the data subject personally is party to the agreement. For contacts at an organisation customer, documented legitimate interest (Article 6(1)(f)) applies to necessary contract and invoice administration. Accounting records are retained under legal obligation (Article 6(1)(c)).
Payments
Payments are handled by Stripe. We do not store card details — these are handled entirely by Stripe in accordance with PCI DSS. We store transaction IDs and payment status to link payments to the correct organisation.
Retention: Payment history is stored for 7 years in accordance with Swedish bookkeeping legislation (BFL).
API access
API keys are handled only for agreed pilot cases, not as public self-service. If a pilot is activated, we store:
- SHA-256 hash of the API key — the full key is shown only at creation time and is never stored in plaintext on our server.
- Label, organisation ID and the user who created the key — so administrators can identify the key in the organisation's API view.
- Usage counters per organisation and month — the number of requests and the organisation's configured monthly quota.
Role and legal basis: Customer-directed keys and access rules within the Municipal Licence are processed under the organisation's documented instruction. Skolkoll is separately controller for strictly necessary key security, quota control and dispute evidence under legitimate interest (Article 6(1)(f)); Article 6(1)(b) applies only where the data subject personally is party to the agreement. Usage counters are retained for no more than 13 months for quota, invoice and dispute checks.
Webhook subscriptions
Pro organisations can register webhook subscriptions to receive events in real time. We store:
- Webhook URL — the address that events are delivered to. Only HTTPS URLs with a public host are accepted (private IP literals and userinfo are blocked at registration).
- Encrypted signing secret — stored as an AES-256-GCM-encrypted envelope. The plaintext version is returned to the customer once at creation and never stored on our server. The secret is used by the customer to verify webhook signatures.
- Configuration and delivery status — which event types trigger delivery, an optional description (200 characters max), enabled/paused status, and the time and result of the most recent delivery.
Server logs record only the webhook hostname, not the full URL — because subscription URLs often carry tokens in path or query segments.
Role and legal basis: Customer-directed webhook configuration and delivery within the Municipal Licence are processed under the organisation's documented instruction. Skolkoll's own limited security and delivery-integrity data is processed under legitimate interest (Article 6(1)(f)); Article 6(1)(b) applies only where the data subject personally is party to the agreement.
Error monitoring
The website supports error monitoring with Sentry for detecting and fixing technical errors. If error monitoring is switched on in production, Sentry may collect the data below. The website's security settings permit error reports to be sent to Sentry's intake in Germany, but we have not checked in the production environment that error monitoring is switched on, that Sentry actually receives data or in which region it is received; this revision therefore does not claim that the integration is active in production.
- On ordinary public pages: error messages and stack traces. In exceptional cases an error message may contain data held in application state when the error occurred.
- On account pages: only a random event ID, release, coarse account surface, error class and stack file/line/column. The account policy removes user/session identity, email, names, uid/org IDs, tokens, cookies, URL queries, form values, request/response data, breadcrumbs, DOM/input and other arbitrary context before sending. The event ID applies only to that error and is not used for persistent user correlation. Replay and tracing are disabled.
- Browser, operating system and IP address. If the integration is active, the source IP reaches Sentry's network edge. We have not checked Sentry's separate setting for removing IP addresses, so we do not claim that the full IP is always removed or never stored by the provider.
Legal basis: Legitimate interest (GDPR Art. 6(1)(f)) — necessary to maintain the service's functionality.
Journalist data orders
If you submit a data order through the journalist form, we store the details you provide: outlet/newsroom, beat, name, email address, order message, language, consent version and timestamp. We also store minimum technical request and workflow metadata: browser user-agent and source/surface for abuse prevention, status and strictly necessary delivery/error outcomes for operational recovery, and a deletion date stored on the record to enforce retention. The form posts to our own server and is first stored among the journalist orders in our database (Google Cloud Firestore). Our configuration sets europe-west1 (Belgium) as the region, and an archived check of the production environment dated 2026-09-05 establishes the database in that region. The form instructs you not to enter private or sensitive information or personal data about other people. If such unexpected content is nevertheless found, it is not forwarded: it is minimised or deleted, or quarantined for manual legal assessment. Retention then requires a separately documented basis and, for Article 9 or 10 data, an applicable condition.
The current connectors that would pass journalist orders to Zoho Desk and Zoho CRM are switched off in the software code; Zoho CRM receives no new data. The connectors do not tie contact details to the individual order and lack tested matching deletion/minimisation, so they cannot be switched on merely on the strength of general evidence about the account, the contract or retention. No new journalist order is therefore disclosed to Desk or CRM. A future replacement requires an order-bound model without cross-purpose merging and tested deletion/minimisation; it must never send order free text to CRM or put anything into Zoho CRM's free-text description field. A delivery failure instead creates an internal manual-recovery marker; order content is not sent in a fallback email. No automated AI analysis, risk classification or private analysis comment is created. Zoho Mail has no positive release. A new user-initiated inbound email enquiry may be received, manually assessed and answered only to the strictly necessary extent after case-specific minimisation and under the matter's documented basis; content is not sent to AI. Proactive/discretionary contact, campaign/relationship-building, automation and bulk processing are not permitted. We do not use this data for newsletters, Campaigns sends or other marketing without separate consent/provenance.
Legal basis: consent (GDPR Art. 6(1)(a)) to store and handle the form order and contact you with a response; pre-contractual steps under Article 6(1)(b) only where you are personally the prospective contracting party; and legitimate interest (Article 6(1)(f)) only for necessary abuse prevention and operational recovery. Legitimate interest does not cover order handling, the contact response, editorial follow-up or an ongoing relationship. You may withdraw consent at any time by emailing info@skolspegeln.se. We will then stop any further processing based on that consent; withdrawal does not affect the lawfulness of processing before withdrawal.
Retention: the database record is targeted for deletion 180 days from submission through a deletion date stored on the record. A check of the production environment on 2026-07-30 showed the automatic deletion rule (TTL) as active; this proves the configuration state, not that a particular expired sample has completed Firestore's asynchronous deletion cycle. Orders unresolved after 180 days require documented approval and have a hard cap of 12 months. The current Desk and CRM connectors are switched off in the software code and therefore create no record at the provider. A future approved replacement must delete the whole order-bound provider record when the order purpose ends or consent is withdrawn, and always no later than the order hard cap. Longer retention requires a separate future purpose, legal basis and notice.
Campaigns and newsletters
Zoho Campaigns is the designated platform for separately consented campaigns and newsletters, not part of the site's Resend path for service and expressly requested data-event-watch email. On 29 July 2026 the account's complete open tracking and complete link-click tracking were both observed as ON. Account-specific evidence for unintended automations, DPA/SCC incorporation, unsubscribe/RTBF, retention and suppression is still missing. The next send and every send-capable automation are therefore stopped until the owner has documented that no unintended automations are active, verified the account's DPA/SCC, completed dated unsubscribe and RTBF tests, verified retention/suppression and approved the send manually. Tracking must additionally either be off with dated send-specific evidence, or be covered by a separate purpose, LEK Chapter 9 Section 28/ePrivacy assessment, granular informed consent and an equally easy tested withdrawal route. None of those controls is claimed as verified in this revision, and the stop is not a claim that the account is technically shut down at Zoho. The site's older newsletter addresses (sign-up, confirmation and unsubscribe), kept for compatibility reasons, are used for an expressly requested public-data event watch and do not enrol you in campaign email. When you unsubscribe from that data-event watch, the entire record for your data-event watch must be deleted immediately; no inactive record, tombstone or suppression hash may be retained.
Legal basis and retention target: the campaign send itself relies on consent (GDPR Art. 6(1)(a)). Each activation of open pixels, tracked links or IP-derived location requires a separate purpose, an assessment under LEK Chapter 9 Section 28/ePrivacy, granular informed consent and equally easy withdrawal unless a strict statutory exception has been documented. Skolspegeln's governing target is active contact data until consent is withdrawn, the recipient unsubscribes or the purpose ends, and no more than 24 months for minimum consent/withdrawal proof, suppression and identifiable recipient reports. Longer retention for a specific existing or threatened legal claim requires a separate assessment within our processing for establishing, exercising or defending legal claims. The account's actual erasure/RTBF configuration and enforcement of the 24-month target have not been attested in this revision and remain supplier-evidence follow-up; Zoho's possible five-year maximum has not been adopted as our retention period.
Cookies and analytics
If you consent via our consent banner, Zoho PageSense may be used for visitor statistics, A/B testing and site improvement. Skolkoll does not use Google Analytics.
- Which pages are visited and for how long
- Device type, browser, screen size and approximate geographic location
- Page interactions such as clicks, scrolling, heatmaps, session recording and experiment variant when PageSense tests are active on public pages
Zoho PageSense is loaded from Zoho's EU CDN and uses cookies or similar technologies to connect visits, experiment variants and goal conversions. Skolkoll does not sell visitor data. If we later want to use another analytics tool, we will update this policy and the consent banner first.
Retention period: PageSense data is stored according to the selected Zoho PageSense plan, currently 1, 6 or 12 months, and Skolkoll does not use PageSense data for longer than 12 months. See also Zoho's plan-based retention.
If you choose "Only necessary" in the consent banner, PageSense is not loaded.
Third-country transfers
Zoho PageSense is operated by Zoho. We use the EU script (cdn-eu.pagesense.io) and treat PageSense as a processor for Skolspegeln's analytics activity; it is activated only after consent. Zoho publishes DPA/SCC terms for GDPR-regulated processing.
Zoho Desk and Zoho CRM: the current journalist connectors are switched off in the software code, regardless of general evidence about the account, the contract or retention. Desk lacks an enforced order lifecycle and CRM uses a global email-deduplicated contact, so no new journalist order is disclosed to either service. A future replacement must be order-bound, prohibit cross-purpose merging and have tested matching deletion/minimisation before the switch-off in the code is removed, in the same reviewed change. Zoho Mail is subject to the separate restriction below; that restriction is not a positive release.
Zoho Mail and Zoho Campaigns: the services exist within Zoho One for the official mailbox and for campaigns and newsletters respectively. Zoho Mail is subject to a dated interim-risk restriction with no positive release. On 28 July 2026 the mailbox was validated as working, monitored, protected by MFA and covered by documented supplier, storage and deletion rules. Pending transfer closure, new user-initiated inbound enquiries — including rights, privacy, incident, Municipal Licence, quote/demo, verification and journalist/direct matters — may be received, manually assessed and answered only to the strictly necessary extent after case-specific content and necessity minimisation. The basis follows the matter: a legal obligation where applicable; Art. 6(1)(b) only where the data subject is personally the prospective contracting party; otherwise documented Art. 6(1)(f) for the narrow read/minimise/respond purpose. Free text is not assumed to be public; Article 9/10 content requires a separately documented basis or no further processing. Email content is not sent to AI. Proactive/discretionary contact, campaign or relationship-building, automation, bulk processing and new integrations, features or data categories in Mail are not permitted. The Mail restriction does not govern Zoho Campaigns; every send and send-capable automation is independently governed by the separate preconditions for Campaigns described above. The domain's MX and SPF routing points to Zoho's EU services but does not prove the account region. Zoho Legal's 2026-09-08 response identifies SCC Module 3 for Zoho EU → Zoho India in prose. The account-specific DPA was signed on 2026-09-11, but its Schedule 1 is the article 28(3)-(4) standard contractual clauses and states in its own clause 1(f) that they do not by themselves ensure Chapter V compliance, so the transfer mechanism remains supplier-asserted rather than contracted. Clause 5.1(i) makes EEA storage a contractual term, but the agreement's Schedule 2 expressly permits Indian access. Our India assessment must address current law, and the United States leg remains unsupported: Schedule 2 names India alone for EEA customers, while the supplier's own SOC 1, SOC 2 and ISO location annexes place Austin in the United States in scope for support. Our internal deadline of 2026-08-14 for obtaining that evidence passed without the evidence being completed. Those Mail restrictions therefore remain, and the allowed minimised intake continues only while the escalation continues toward a lawful replacement channel. The evidence record contains the full response and its remaining boundaries. The mailbox copy follows the same case lifecycle and hard cap as the underlying matter. Export, minimisation and verified deletion remain permitted. The restriction proves neither Chapter V compliance nor tenant-level technical enforcement.
Resend delivers service, transactional, expressly requested data-event-watch and technical email through the United States. Resend is not used for campaigns, newsletters or trial nurture; those separate sends are handled in Zoho Campaigns. Resend applies EU Standard Contractual Clauses (SCCs).
Stripe (payment provider for Pro services) is a US-based company. Card details are handled entirely by Stripe in accordance with PCI DSS. Stripe applies EU Standard Contractual Clauses (SCC). More information in Stripe's privacy policy.
Sentry (error monitoring) is operated by Functional Software, Inc. (USA). The website's security settings (CSP) permit error reports to be sent to ingest.de.sentry.io in Germany, but we have not yet checked in the production environment whether error monitoring is switched on, in which region events are received and stored, or how Sentry's setting for removing IP addresses is configured; this revision therefore makes neither a positive EU-storage claim nor a claim that full IP is always removed. If the integration is active, Sentry's network edge may receive stack traces, browser information and source IP. EU Standard Contractual Clauses (SCCs) apply for any support or administrative access by Sentry's US team.
Anthropic (AI assistant) is a US-based company. The provider states that API data is stored in the United States and that some processing may additionally occur at selected locations in Europe, Asia and Australia, without publishing a complete country list. A region is not a closed country schedule. No non-EEA country other than the United States is therefore currently approved, and Kollen sends no requests to Anthropic while Anthropic can route processing to an unnamed country. Before a request, dated provider/account evidence must show that processing outside the EEA is limited to the United States and that the DPF for a relevant certified US importer or SCCs with a country- and recipient-specific TIA and supplementary measures apply. Another processing country requires both code and annex review before any request. Processing is governed by Anthropic's Data Processing Agreement (DPA) for the API service and does not require a blanket ZDR agreement. The standard rule is that API inputs and outputs are deleted from Anthropic's backend within 30 days. If automated trust-and-safety systems flag content as a possible Usage Policy violation, the provider's current terms allow input/output to be retained for up to two years and classification scores for up to seven years; legal requirements and explicit feedback may lead to other periods. API data is not used for model training unless the customer expressly opts into such a programme or provides feedback. Messages are not permanently stored by Skolkoll. See Anthropic's processing-location statement, API retention and training policy for commercial services.
OpenAI is a US-based company used for rights-cleared stylisation of school images without identifiable people and for bounded internal extraction from officially published public documents. Image stylisation operates under OpenAI's safety/content policies; those are provider controls, not a separate moderation purpose or additional model call. By default, OpenAI may create abuse-monitoring logs containing customer content or derived safety metadata and retain them for up to 30 days. Longer retention may occur where required by law or reasonably necessary to protect the service or a third party; safety-flagged image files may be retained for manual review. In OpenAI's Chat Completions interface for text generation, OpenAI's optional response storage is switched off, which means that the response object is not retained as application state, but prompt caching may retain encrypted key/value tensors in GPU-local storage for up to 24 hours; the original prompt text is not persisted in that local storage. OpenAI's image-generation and image-edit interfaces have no application-state retention. These interface-specific rules are separate from the provider's 30-day abuse/safety-log period. Skolkoll makes no ZDR claim and does not require a blanket ZDR agreement for these bounded flows. The transfer mechanism is selected per scenario and recipient country: an adequacy decision where its scope covers the recipient and purpose, the DPF for an applicable certified US importer, or otherwise SCCs with the necessary TIA and supplementary measures. See OpenAI's API data controls and prompt-cache retention.
Social login providers — Google, Microsoft, GitHub and Facebook/Meta are contacted only after you select the provider. Skolkoll requests the basic identity needed for sign-in and adds no extra provider scopes. This is treated as part of Skolspegeln's own account security; each provider is independently responsible for its account and authentication stage. Country and transfer mechanism are assessed provider by provider and may, depending on the actual recipient, rely on an adequacy decision, the DPF or SCCs. Apple remains available for recovery of an existing account link but is hidden as a new sign-in option until its production configuration has been verified. Customer-controlled SAML/OIDC is a separate flow for the Municipal Licence's organisation memberships and roles of the customer's users (processing activity P1) and may not be discovered, verified, enforced or used for automatic membership until the organisation-specific assessment is approved and the approval has been recorded for the organisation in our system.
Nominatim: the OpenStreetMap Foundation in the United Kingdom is treated as an independent controller for external requests that reach the service; because no closed country list exists for its vendors/agents, recipient due diligence conservatively covers the world. New external requests must remain stopped for now, in both the browser flow and the scheduled or manually triggered batch flow, because evidence about the provider's raw logs and about the countries in which its vendors process data is still missing. Each flow must be activated separately in the code and both are off by default; we do not claim to have checked in the production environment that this version is deployed, that the switch-off applies there or that a cache is active in production. In the browser flow, the current version of the website shows just-in-time text by the field instructing the user to enter only a town or named public place. Street and home addresses, numbers, contact details and unclear person-like multi-word phrases are blocked before a network request. This is a risk-reduction control, not a claim that every permitted one-word query is thereby proven free of personal data. Under our settings, accepted results may be stored in the browser's session storage (sessionStorage) for no more than 24 hours, with a maximum of 20 entries. The separate batch flow must be activated on its own and is also off by default; cache hits for safe business addresses may be used without an external request, while a cache miss is stopped as long as the batch flow is not activated. If the batch flow is activated, our setting is one thread, at least 15 seconds between request starts and no more than 365 days in Skolkoll's own server cache. An external browser request carries the query and IP/request metadata; an external batch request carries the public business address and the server's IP/User-Agent.
JobEd Connect: only after you open the Career tab in an upper-secondary-school detail does the browser send IP/request metadata and URL parameters containing predefined or public programme text to the Swedish Public Employment Service; user-entered free text is not used. Browser credentials and the referring page are omitted. The legal direct recipient is the Swedish public authority Arbetsförmedlingen (the Swedish Public Employment Service), which is treated as independently responsible for receipt and any later provider processing. The service's configured region designation for Northern Europe is only a label and is not evidence of a physical processing or access country. The flow is reviewed annually, including any raw-log retention. ResRobot and the Skolverket API follow their separate scenarios. Leaflet and D3.js are served locally from our own server. Firebase authentication loads client scripts from Google's CDN (gstatic.com), whose servers may be outside the EU.
Email for school watching
If you choose to watch a school, you provide your email address. The following is stored in our database (Firestore):
- Email address — used to send notifications. Deleted when you unsubscribe.
- SHA-256 hash of your email — used to look up your existing watches without exposing your email in database queries.
- School unit code and name — which school you are watching.
- Timestamps — when the watch was created, confirmed and last notified.
Role and legal basis: An anonymous email watch relies on consent (GDPR Art. 6(1)(a)) through double opt-in. For an organisation-directed Municipal Licence watch, the organisation is controller and Skolkoll is processor on instruction. Article 6(1)(b) applies only where you personally are party to the agreement.
Retention: Your data is stored for as long as the watch is active. On unsubscribe, the record is closed and the email address, confirmation/unsubscribe bearer tokens and other direct watch fields are deleted immediately. A minimised closed tombstone may retain only the email hash, status and close/expiry clocks for documented suppression/accountability, for no more than 24 calendar months and earlier when the need ends. A daily cleanup job goes through older closed records, minimises them and deletes the closure records when their time is up; we have not yet confirmed that the job is deployed, that it has run for the first time or that it works in the production environment. Account deletion instead removes account-bound watches.
What triggers notifications: You receive an email when merit score changes by more than 5 points, gymnasium eligibility changes by more than 5 percentage points, pupil count changes by more than 20%, or the School Inspectorate issues a new decision about the school.
How to unsubscribe: Every notification email contains an unsubscribe link. You can also contact us at info@skolspegeln.se.
School-image submissions
If you upload a façade image of a school, we store the image, school-unit code, school name, selected licence, any photo date and contact details for review, rights traceability and possible AI-based chalkboard stylisation. BY/BY-SA collects the photographer name and an optional HTTPS link; CC0 collects neither a photographer/rights-holder name nor a person/source link.
Legal basis and public attribution: For images submitted through the form, consent (GDPR Art. 6(1)(a)) covers the submitter's own contact data and choices about AI stylisation; the form's licence terms govern permission to use the image. Where CC BY 4.0 or CC BY-SA 4.0 requires attribution, the photographer's name and any HTTPS link are processed and published on the basis of legitimate interest (Art. 6(1)(f)) and the applicable Article 14 route. The link is public only while the current editorial review remains bound to the exact image hash, licence and link. CC0 intake and projection contain no person attribution. The same legitimate interest applies to minimum necessary attribution and verifiable licence provenance for separately imported, rights-cleared images. Where a contact route is available, Article 14 information is provided directly within the Article 14(3) time limits. Article 14(5)(b) may replace direct notice only after dated and signed legal evidence has been expressly registered for the exact source and publication; our server-controlled register for such evidence is empty, and without such a registration the exemption is not used. Contact details are not used for marketing. Contact, attribution, source-link, photo-date and rights metadata is not sent to the image model.
Retention: A submission that remains pending becomes due for deletion 180 days after upload, including after it is returned to review. Rejected submissions and associated contact and rights data become due for deletion 90 days after the rejection decision, or earlier if you request this and we do not need the data to handle a dispute. For approved images, the minimum necessary licence, attribution and provenance data is retained for as long as the image is used or a rights claim reasonably needs to be auditable. Contact details, photo dates, review free text and other intake-only fields become due for minimisation 180 days after approval; legacy CC0 names and links are covered by the same pass. The daily cleanup job performs due deletion or minimisation in the next successful run that reaches the record; queueing or operational failures can delay execution. A photo date is never published for the form image.
Correction form
If you report an error through the correction form, we store what you enter: which school or page it concerns, the type of error, your description and the value you believe is correct, any link, source link and school-unit code, and — if you choose to leave it — your email address (the form has no name field; a name can appear only if the matter was logged manually or via the API). We also store the browser user-agent for abuse prevention and the time the report arrived. No IP address is stored in the record. The record is stored among the correction reports in our database. Only our own server can read the correction reports. If you write to info@skolspegeln.se instead, the matter is logged manually among the same correction reports, with the time the email arrived, and follows the same retention target. Free text and contact details are used solely for internal triage; if a correction is published, it is summarised without your contact details and with sensitive details removed.
Legal basis: legitimate interest (GDPR Art. 6(1)(f)) to receive the report, store it with restricted access, assess it and — where you left a contact — be able to get back to you. Any reply is sent manually from our mailbox; no automated reply is sent. The basis does not cover marketing, any ongoing relationship or AI analysis of the content. If you report that information about yourself is inaccurate, it is handled as a rights request — for example rectification under Article 16. The response period under Article 12(3) runs from when the report arrived, regardless of when we get to assess it; the assessment only determines which right applies. Do not enter sensitive data or data about other people in the free text; such content is minimised or removed without further processing.
Retention: Our target is that email, any name, user-agent and free text are erased or anonymised 90 days after the case is closed, and no later than 12 months after the report arrived even if the case is still open by then. Rights matters (Articles 15–21) instead follow the retention periods for rights handling in our register, not this target. What remains is a de-identified note of which school, which field and which outcome the report concerned. Automatic purging is not yet in operation and no record has been purged so far; until it exists, any deletion is manual, and the state is reported in our record of processing activities.
Local storage (localStorage)
The following data may be stored locally in your browser:
- Consent (
skolkoll_consent) — your choice in the consent banner (accepted/declined) - Home address (
skolnav_home_location) — if you use the commuting feature, coordinates for your home address are stored locally. When you calculate travel times, the coordinates may be sent to ResRobot via our server as the start point for the trip suggestion. You can delete this by clearing the field in settings or clearing your browser's local storage. - Paywall attribution (
skolkoll_paywall_ab_v1) — if you have accepted analytics consent, we store which paywall variant you saw so we can measure conversion between school-page CTAs and trial starts in analytics events. Click attribution (skolkoll_paywall_last_click) is stored only in sessionStorage and cleared when the browser session ends.
The AI chat stores conversation and school context in sessionStorage (automatically deleted when the browser tab is closed): skolkoll_ai_chat and skolkoll_ai_context. Confirmation that the AI information was shown is stored in localStorage under the backwards-compatible key name skolkoll_ai_consent until you clear AI data or the browser's local storage. Paywall click attribution is also stored in sessionStorage under skolkoll_paywall_last_click after accepted analytics consent.
AI assistant (Kollen)
Kollen is not specifically directed at children under 13.
Skolkoll offers an AI-powered chat ("Kollen") that answers questions about school statistics. If you choose to use Kollen, the following applies:
- Information and choice — the first time you open the chat, you are shown information about the AI recipient, data types, retention, risks and the instruction not to enter private or sensitive information. Your confirmation that the information was shown is stored locally in the browser; you may decline by closing the dialog.
- Message processing — only when we hold valid, dated evidence that Anthropic's processing outside the EEA is limited to the United States and covered by a valid transfer safeguard are your chat messages sent to Anthropic via its Claude API to generate responses. A request is allowed only with such valid evidence for the United States; another or unnamed country stops the request under the third-country section above. Messages are not permanently stored by Skolkoll — they are forwarded in real time and only temporarily stored during your session in the browser's session storage (sessionStorage).
- Relevance check — the latest question may first be sent to Anthropic's Claude Haiku model for relevance classification (on-topic/off-topic). Irrelevant questions are normally filtered out. The check is a supporting control and may let the question through if classification fails technically; the answer is not safety-screened in a separate model step.
- Audit log — for each eligible processed Kollen request, the server makes at most one asynchronous write attempt to the Kollen audit log. The response does not await that write, failures are logged, and storage of an entry is therefore not guaranteed. A stored entry contains a domain-separated HMAC-SHA-256 pseudonym of your IP address, truncated to 16 characters (not the full IP), length of the question and response (not content), an exact eight-digit school-unit code or no value, status and timestamp. At write time the entry is given a deletion date 90 days ahead. A check of the production environment on 2026-07-30 showed the automatic deletion rule (TTL) for this exact deletion date as active; this proves policy state, not deletion of a particular expired sample. TTL deletion is asynchronous after expiry and is not guaranteed exactly on day 90. You can request immediate deletion via info@skolspegeln.se.
- Rate limiting — a domain-separated HMAC pseudonym of your IP address is stored for 48 hours for the daily limit (a limited number of questions per day), and for up to 2 hours for short-term burst limiting (max requests per hour).
Legal basis: legitimate interest (GDPR Art. 6(1)(f)) under a documented balancing test for a user-initiated question service. The interface instructs you not to submit private or sensitive data; the dialog confirmation is an information acknowledgement, not consent as the legal basis. The pseudonymised audit log uses the same basis for abuse and security traceability.
If your question mentions someone else: the instruction not to submit private or sensitive data is a safeguard, not an exception from the information duty in GDPR Article 14. This public information is a compensatory measure where direct information is impossible or would involve disproportionate effort under Article 14(5)(b). If Skolkoll gains concrete awareness of the person mentioned and has a usable contact route, we instead provide information directly within the Article 14(3) time limits unless another documented exception applies.
Data processor: Anthropic PBC (San Francisco, USA) — the AI model intended to generate responses. Anthropic is Skolspegeln's intended direct processor in the Kollen flow; suppliers engaged by Anthropic in turn are its subprocessors. Our technical control currently permits only the United States as a country outside the EEA and requires valid evidence of the DPF or of SCCs with a transfer impact assessment (TIA) before a request. As long as the provider's country list is incomplete, a legal stop applies. The code stops the request when the evidence is missing, but we have not yet confirmed that this block is deployed and working in the production environment; another country requires code and annex review and is not approved by a general region-based SCC solution.
Clear and object: close the browser tab to delete the conversation or select "Clear AI data" in the chat to clear the conversation and information acknowledgement. You may object to the processing at any time by emailing info@skolspegeln.se.
Third-party services
The following tables separate browser-loaded services from server-side processors used in specific situations:
Browser-loaded and direct feature services
| Service | When | Data sent |
|---|---|---|
| CARTO | Not used: the map code no longer makes any direct request for map tiles from CARTO. We have not yet confirmed the change in the production environment. | No current transfer from the website's map code. A future external tile service would receive IP/request metadata and map-tile coordinates and requires a reviewed code change and recipient assessment. |
| Zoho PageSense | Page views, experiments, heatmaps and session recording on public pages (requires consent) | Page views, clicks/scrolling, heatmap and session-recording interactions, experiment variant, device and browser info |
| Nominatim (OpenStreetMap) | User-initiated search for a town or named public place and separate batch geocoding of public school/preschool addresses; new external requests are off by default and must be activated separately | If the browser flow is activated: a permitted place query and IP/request metadata. If the batch flow is activated and the address is not in the cache: the public business address and the server's IP/User-Agent |
| JobEd Connect (JobTech) | Only after you open the Career tab in an upper-secondary-school detail | IP/request metadata and URL parameters with predefined or public programme text, not user-entered free text |
| Skolverket API | School view (surveys, documents) | The detail request itself contains only the school-unit code, not a person field. Depending on which of Skolverket's interfaces is called, the source response may contain personal data including the head-teacher name field; that field is discarded at the first processing step as long as our assessment of named person roles is not concluded and such processing is paused. |
| Google CDN (gstatic.com) | Login (Firebase authentication) | IP address when downloading login scripts |
| Stripe | Payment for Pro services | Email, organisation name, card details (handled by Stripe) |
| Sentry (intake in Germany permitted in the website settings; actual region not checked) | If error monitoring is switched on in production and a technical error occurs | Error messages and stack traces, browser information and source IP at the network edge. We have not checked Sentry's separate setting for removing IP addresses. |
External controller services and server-side processors
The following services receive data when you use the relevant feature, contact us or separately consent. Zoho Mail and Campaigns are managed outside the site's server path; the other rows are used through our servers or after approved activation:
| Service | When | Data sent |
|---|---|---|
| ResRobot (Trafiklab) | Commuting tab in school view | Coordinates for start/destination |
| Resend | Service, transactional, requested data-event-watch and technical email; never campaigns/newsletters | Email address, name, subject and message content |
| Zoho Mail | Dated interim-risk restriction with no positive release: new user-initiated inbound enquiries may be received, manually assessed and answered only to the strictly necessary extent after case-specific minimisation and under the matter's documented basis; no AI. Proactive/discretionary contact, campaign/relationship-building, automation, bulk processing and new integrations/features/data categories in Mail are not permitted. The Mail restriction does not govern Campaigns, which has its own independent preconditions. The internal deadline of 2026-08-14 has passed; only the minimised intake continues, while escalation to a lawful replacement channel is under way (Zoho response 2026-09-08: Module 3 identified in prose. DPA signed 2026-09-11, but as an article 28 processor agreement that by its own clause 1(f) does not close Chapter V; India/United States assessments remain open) | Name, email, message, voluntary attachments and technical message headers |
| Zoho Campaigns | Designated separate campaign/newsletter platform; the next send and every send-capable automation are stopped until the account-specific requirements above are fully verified and the send is manually approved | Email, name, organisation/locale, consent provenance, list/segment, delivery status and suppression. Complete open and link-click tracking were observed ON on 2026-07-29; automation, DPA/SCC, unsubscribe/RTBF, retention/suppression and tracking disposition remain unverified |
| Firebase / Google Cloud | User accounts and database | Account and organisation data. Our configuration sets europe-west1 (Belgium); an archived check of the production environment dated 2026-09-05 establishes the actual Firestore and storage-bucket regions |
| Anthropic (Claude API) | User-initiated AI chat (Kollen) — legitimate interest under a documented balancing test, but only when we hold valid, dated evidence of the processing country and transfer safeguard as described in the third-country section | Chat messages, school context |
| OpenAI | Rights-cleared school-image stylisation and bounded internal extraction from officially published public documents | Person-free school image or a locally preflighted and contact-minimised provider copy of a public document. The whole document is blocked when prohibited markers are detected; detector false negatives remain a residual risk. No contact, attribution, source-link, photo-date or rights metadata is sent in the image flow |
| Zoho Desk | Separate support surface; the current journalist connector is switched off in the software code and cannot be switched on by general evidence or settings. No journalist order is sent and no full-content fallback email exists | No current journalist record. A future replacement must use an order-bound object without cross-purpose merging and with tested matching deletion/minimisation; no automated AI analysis or private analysis comment |
| Zoho CRM | The current journalist connector, which creates one global contact per email address, is switched off in the software code and cannot be switched on by general evidence or settings | No current journalist record. A future approved replacement may contain only minimum order-bound metadata, without order free text, Zoho CRM's free-text description field, cross-purpose merging or later relationship/campaign contact |
Both Nominatim external-request paths are off by default, and requests are stopped unless they have been expressly activated. We have not yet confirmed in the production environment that this version is deployed or which cache settings apply there. Our settings limit the browser cache to no more than 20 entries for 24 hours, the batch cache to 365 days, and batch calls to one thread and at least 15 seconds between starts when the batch flow has been expressly activated. JobEd Connect has a separate bounded, flow-specific assessment and is called only after the user opens the Career tab.
Fonts
We use the typefaces Literata and Sora, which are self-hosted on our server. No requests are sent to Google Fonts or other font providers. The Leaflet map library is served locally from our server. Firebase authentication does load client scripts from Google's CDN (gstatic.com), see the table above.
School data and public information
All school data shown on Skolkoll is public information from Skolverket, SCB, Bolagsverket and Skolinspektionen.
Personal data about school staff
Skolkoll does not publish principals' names as part of the automated school directory. Skolverket source responses may contain personal data, including the head-teacher name field. As long as our assessment of named person roles is not concluded and such processing is paused, that field is discarded at the first processing step and must not be stored, indexed, materialised or included in history. Legacy names may be processed only for documented cleanup and rights handling. A public source does not make a name cease to be personal data.
A school's official institutional contact details (email and phone number) are obtained from Skolverket during the daily source sync and, in the active directory processing, stored only in the current, replaceable school record. They may be published in the detail view, API and JSON-LD. When a detail is changed or removed at source, it is replaced or removed on the next successful source sync. Email and phone are not added to temporal history, and new archive generations in the raw-data layer (Bronze) and in the materialised archives are contact-minimised. A one-time migration cleans older materialised rollback archives on the next successful sync. Older internal source snapshots in the raw-data layer produced before this minimisation are not public and remain subject to the existing configured 1,095-day cleanup window; actual deletion requires a completed and evidenced cleanup run and is not claimed here for any particular older snapshot. The legal basis is legitimate interest (GDPR Art. 6(1)(f)) in maintaining an accurate public directory of official school contact channels. An institutional address may nevertheless be personal data if the source uses an individual's address. You may request rectification or object through info@skolspegeln.se. We do not publish the names of pupils, principals, teachers or other school staff through the automated school directory.
Name-free publication boundary
- Scope: the name-free boundary covers visible HTML, open data files, APIs/exports, JSON-LD and other machine-readable artefacts
- What "name-free" means: these surfaces carry no standalone person-name or person-role fields. One exception is stated plainly: the establishment's registered contact address comes from the Swedish National Agency for Education's register and is in 2,133 of 7,445 cases written as firstname.lastname@ — measured against production data on 2026-09-05, corresponding to 1,551 unique local parts — in which case it identifies a natural person. We publish the address exactly as registered. If you object to your own address being published, the objection is assessed individually, and if it is upheld the address is suppressed across all our surfaces; see Your right to object. A second exception: for schools with a CC BY/BY-SA portrait, the page and its structured data carry the photographer's name, because the licence requires attribution.
- Name-free by default: older source data that still contains a principal's name is projected into a name-free public model before publication
- Separate assessment: any future named editorial publication would be a new processing operation requiring its own documented decision and is not part of the directory's baseline display
- Rights: the non-public processing and how to exercise your rights are described under Data protection and subprocessors
Embeddable widgets
Skolkoll offers embeddable widgets for individual schools and municipalities that can be used on external websites. We do not restrict which domains may embed them — they are openly available and designed to support transparency around school data.
Attribution is preserved through the widget footer, which links back to Skolkoll. If you observe misuse (e.g. phishing sites embedding our widgets to gain credibility), contact us at info@skolspegeln.se and we will assess the need for additional measures.
Your rights
Under GDPR, you have the right to:
- Decline consent — choose "Only necessary" in the consent banner
- Withdraw consent — go to Settings and click "Revoke cookie consent", or clear your browser's local storage. Kollen does not rely on consent; for that service you can instead select "Clear AI data", close the browser tab or object through our data-protection contact.
- Delete data — you can delete your account under account settings. The profile, memberships and account-bound watches are deleted. Organisation data and billing history remain if other members remain or law requires retention. A separate pseudonymous entry in our account-deletion log with a hashed document ID, a separate hash of the account ID and an email hash, but without the account ID in plain text or the email address in plain text, may be retained for no more than 12 months to document the deletion outcome or a failed step; it is not a continuing account. Locally stored data (home address, consent and paywall attribution) is deleted by clearing your browser's local storage (localStorage). AI chat data (conversation) and paywall click attribution in the browser's session storage (sessionStorage) are deleted when you close the browser tab. Entries in the Kollen audit log are given a deletion date stored on the entry, for automatic deletion (TTL) after 90 days. A check of the production environment on 2026-07-30 showed the deletion rule for the audit log's deletion date as active; policy status does not prove deletion of a particular expired sample, and Firestore deletion occurs asynchronously after expiry (see Data protection and subprocessors for operational status).
- Object to processing — if you are a named role holder and want to object to non-public processing or an actual editorial publication, email info@skolspegeln.se. See the specific information about the right to object
- Right of access — you have the right to request a copy of your personal data. Contact us at info@skolspegeln.se
- Rectification — you have the right to have inaccurate personal data corrected and incomplete data completed
- Data portability — where the conditions in Article 20 are met, you have the right to receive data you provided in a structured, commonly used and machine-readable format
- Restrict processing — you have the right to request restriction of processing of your personal data under certain circumstances
- Lodge a complaint — you have the right to lodge a complaint with the Swedish Authority for Privacy Protection (IMY), imy.se
Changes
We may update this policy as needed. The latest version is always available on this page.