Privacy policy

Last updated: 2026-09-12

For municipal IT-security managers and procurement officers: see also Security page for technical security information (encryption, secrets management, incident response, compliance status).

For municipal procurement officers: see also Data protection and subprocessors for operational GDPR detail (subprocessor list, retention for each set of stored data in the database, DPIA-light), and the DPA template for a data processing agreement.

Data controller

Data controller: Skolspegeln AB (org. no. 559359-7288). Contact person: Markus Reimer. Contact: info@skolspegeln.se

What data do we collect?

User accounts

If you create an account on Skolkoll, we store the following in our database (Firebase/Firestore — see Data protection and subprocessors for the current database regions):

  • Email address and display name — for login and identification in the portal.
  • Login method — which social login (Google, Microsoft, GitHub, Facebook or Apple) or email/password you use.
  • Organisation membership — if you belong to an organisation, we store which organisation and your role (administrator/user).
  • Timestamps — when the account was created.

Role and legal basis: If you personally are party to the agreement, Article 6(1)(b) applies to necessary account delivery. For an organisation account, the organisation is controller for membership, role and customer-directed use and Skolkoll processes that data as processor on instruction. Skolkoll is separately controller for strictly necessary identity, access and security administration under legitimate interest (Article 6(1)(f)); Article 6(1)(b) does not apply merely because your employer is a customer.

Retention: Data is stored for as long as the account or documented customer instruction requires it. Account deletion removes the profile, memberships and account-bound watches. A separate pseudonymous deletion-audit record may be retained for no more than 12 months to document completion or a failed step; it contains no raw email address and is not a continuing user account.

Organisation data

If you create or join an organisation, the following may be stored:

  • Organisation name and registration number — public information for identification.
  • Billing details — contact person, phone, address, email and reference/PO number for invoicing.
  • Customer number (SK-NNNNN) — system-generated for invoice management.

Legal basis: Article 6(1)(b) only where the data subject personally is party to the agreement. For contacts at an organisation customer, documented legitimate interest (Article 6(1)(f)) applies to necessary contract and invoice administration. Accounting records are retained under legal obligation (Article 6(1)(c)).

Payments

Payments are handled by Stripe. We do not store card details — these are handled entirely by Stripe in accordance with PCI DSS. We store transaction IDs and payment status to link payments to the correct organisation.

Retention: Payment history is stored for 7 years in accordance with Swedish bookkeeping legislation (BFL).

API access

API keys are handled only for agreed pilot cases, not as public self-service. If a pilot is activated, we store:

  • SHA-256 hash of the API key — the full key is shown only at creation time and is never stored in plaintext on our server.
  • Label, organisation ID and the user who created the key — so administrators can identify the key in the organisation's API view.
  • Usage counters per organisation and month — the number of requests and the organisation's configured monthly quota.

Role and legal basis: Customer-directed keys and access rules within the Municipal Licence are processed under the organisation's documented instruction. Skolkoll is separately controller for strictly necessary key security, quota control and dispute evidence under legitimate interest (Article 6(1)(f)); Article 6(1)(b) applies only where the data subject personally is party to the agreement. Usage counters are retained for no more than 13 months for quota, invoice and dispute checks.

Webhook subscriptions

Pro organisations can register webhook subscriptions to receive events in real time. We store:

  • Webhook URL — the address that events are delivered to. Only HTTPS URLs with a public host are accepted (private IP literals and userinfo are blocked at registration).
  • Encrypted signing secret — stored as an AES-256-GCM-encrypted envelope. The plaintext version is returned to the customer once at creation and never stored on our server. The secret is used by the customer to verify webhook signatures.
  • Configuration and delivery status — which event types trigger delivery, an optional description (200 characters max), enabled/paused status, and the time and result of the most recent delivery.

Server logs record only the webhook hostname, not the full URL — because subscription URLs often carry tokens in path or query segments.

Role and legal basis: Customer-directed webhook configuration and delivery within the Municipal Licence are processed under the organisation's documented instruction. Skolkoll's own limited security and delivery-integrity data is processed under legitimate interest (Article 6(1)(f)); Article 6(1)(b) applies only where the data subject personally is party to the agreement.

Error monitoring

The website supports error monitoring with Sentry for detecting and fixing technical errors. If error monitoring is switched on in production, Sentry may collect the data below. The website's security settings permit error reports to be sent to Sentry's intake in Germany, but we have not checked in the production environment that error monitoring is switched on, that Sentry actually receives data or in which region it is received; this revision therefore does not claim that the integration is active in production.

Legal basis: Legitimate interest (GDPR Art. 6(1)(f)) — necessary to maintain the service's functionality.

Journalist data orders

If you submit a data order through the journalist form, we store the details you provide: outlet/newsroom, beat, name, email address, order message, language, consent version and timestamp. We also store minimum technical request and workflow metadata: browser user-agent and source/surface for abuse prevention, status and strictly necessary delivery/error outcomes for operational recovery, and a deletion date stored on the record to enforce retention. The form posts to our own server and is first stored among the journalist orders in our database (Google Cloud Firestore). Our configuration sets europe-west1 (Belgium) as the region, and an archived check of the production environment dated 2026-09-05 establishes the database in that region. The form instructs you not to enter private or sensitive information or personal data about other people. If such unexpected content is nevertheless found, it is not forwarded: it is minimised or deleted, or quarantined for manual legal assessment. Retention then requires a separately documented basis and, for Article 9 or 10 data, an applicable condition.

The current connectors that would pass journalist orders to Zoho Desk and Zoho CRM are switched off in the software code; Zoho CRM receives no new data. The connectors do not tie contact details to the individual order and lack tested matching deletion/minimisation, so they cannot be switched on merely on the strength of general evidence about the account, the contract or retention. No new journalist order is therefore disclosed to Desk or CRM. A future replacement requires an order-bound model without cross-purpose merging and tested deletion/minimisation; it must never send order free text to CRM or put anything into Zoho CRM's free-text description field. A delivery failure instead creates an internal manual-recovery marker; order content is not sent in a fallback email. No automated AI analysis, risk classification or private analysis comment is created. Zoho Mail has no positive release. A new user-initiated inbound email enquiry may be received, manually assessed and answered only to the strictly necessary extent after case-specific minimisation and under the matter's documented basis; content is not sent to AI. Proactive/discretionary contact, campaign/relationship-building, automation and bulk processing are not permitted. We do not use this data for newsletters, Campaigns sends or other marketing without separate consent/provenance.

Legal basis: consent (GDPR Art. 6(1)(a)) to store and handle the form order and contact you with a response; pre-contractual steps under Article 6(1)(b) only where you are personally the prospective contracting party; and legitimate interest (Article 6(1)(f)) only for necessary abuse prevention and operational recovery. Legitimate interest does not cover order handling, the contact response, editorial follow-up or an ongoing relationship. You may withdraw consent at any time by emailing info@skolspegeln.se. We will then stop any further processing based on that consent; withdrawal does not affect the lawfulness of processing before withdrawal.

Retention: the database record is targeted for deletion 180 days from submission through a deletion date stored on the record. A check of the production environment on 2026-07-30 showed the automatic deletion rule (TTL) as active; this proves the configuration state, not that a particular expired sample has completed Firestore's asynchronous deletion cycle. Orders unresolved after 180 days require documented approval and have a hard cap of 12 months. The current Desk and CRM connectors are switched off in the software code and therefore create no record at the provider. A future approved replacement must delete the whole order-bound provider record when the order purpose ends or consent is withdrawn, and always no later than the order hard cap. Longer retention requires a separate future purpose, legal basis and notice.

Campaigns and newsletters

Zoho Campaigns is the designated platform for separately consented campaigns and newsletters, not part of the site's Resend path for service and expressly requested data-event-watch email. On 29 July 2026 the account's complete open tracking and complete link-click tracking were both observed as ON. Account-specific evidence for unintended automations, DPA/SCC incorporation, unsubscribe/RTBF, retention and suppression is still missing. The next send and every send-capable automation are therefore stopped until the owner has documented that no unintended automations are active, verified the account's DPA/SCC, completed dated unsubscribe and RTBF tests, verified retention/suppression and approved the send manually. Tracking must additionally either be off with dated send-specific evidence, or be covered by a separate purpose, LEK Chapter 9 Section 28/ePrivacy assessment, granular informed consent and an equally easy tested withdrawal route. None of those controls is claimed as verified in this revision, and the stop is not a claim that the account is technically shut down at Zoho. The site's older newsletter addresses (sign-up, confirmation and unsubscribe), kept for compatibility reasons, are used for an expressly requested public-data event watch and do not enrol you in campaign email. When you unsubscribe from that data-event watch, the entire record for your data-event watch must be deleted immediately; no inactive record, tombstone or suppression hash may be retained.

Legal basis and retention target: the campaign send itself relies on consent (GDPR Art. 6(1)(a)). Each activation of open pixels, tracked links or IP-derived location requires a separate purpose, an assessment under LEK Chapter 9 Section 28/ePrivacy, granular informed consent and equally easy withdrawal unless a strict statutory exception has been documented. Skolspegeln's governing target is active contact data until consent is withdrawn, the recipient unsubscribes or the purpose ends, and no more than 24 months for minimum consent/withdrawal proof, suppression and identifiable recipient reports. Longer retention for a specific existing or threatened legal claim requires a separate assessment within our processing for establishing, exercising or defending legal claims. The account's actual erasure/RTBF configuration and enforcement of the 24-month target have not been attested in this revision and remain supplier-evidence follow-up; Zoho's possible five-year maximum has not been adopted as our retention period.

Cookies and analytics

If you consent via our consent banner, Zoho PageSense may be used for visitor statistics, A/B testing and site improvement. Skolkoll does not use Google Analytics.

Zoho PageSense is loaded from Zoho's EU CDN and uses cookies or similar technologies to connect visits, experiment variants and goal conversions. Skolkoll does not sell visitor data. If we later want to use another analytics tool, we will update this policy and the consent banner first.

Retention period: PageSense data is stored according to the selected Zoho PageSense plan, currently 1, 6 or 12 months, and Skolkoll does not use PageSense data for longer than 12 months. See also Zoho's plan-based retention.

If you choose "Only necessary" in the consent banner, PageSense is not loaded.

Third-country transfers

Zoho PageSense is operated by Zoho. We use the EU script (cdn-eu.pagesense.io) and treat PageSense as a processor for Skolspegeln's analytics activity; it is activated only after consent. Zoho publishes DPA/SCC terms for GDPR-regulated processing.

Zoho Desk and Zoho CRM: the current journalist connectors are switched off in the software code, regardless of general evidence about the account, the contract or retention. Desk lacks an enforced order lifecycle and CRM uses a global email-deduplicated contact, so no new journalist order is disclosed to either service. A future replacement must be order-bound, prohibit cross-purpose merging and have tested matching deletion/minimisation before the switch-off in the code is removed, in the same reviewed change. Zoho Mail is subject to the separate restriction below; that restriction is not a positive release.

Zoho Mail and Zoho Campaigns: the services exist within Zoho One for the official mailbox and for campaigns and newsletters respectively. Zoho Mail is subject to a dated interim-risk restriction with no positive release. On 28 July 2026 the mailbox was validated as working, monitored, protected by MFA and covered by documented supplier, storage and deletion rules. Pending transfer closure, new user-initiated inbound enquiries — including rights, privacy, incident, Municipal Licence, quote/demo, verification and journalist/direct matters — may be received, manually assessed and answered only to the strictly necessary extent after case-specific content and necessity minimisation. The basis follows the matter: a legal obligation where applicable; Art. 6(1)(b) only where the data subject is personally the prospective contracting party; otherwise documented Art. 6(1)(f) for the narrow read/minimise/respond purpose. Free text is not assumed to be public; Article 9/10 content requires a separately documented basis or no further processing. Email content is not sent to AI. Proactive/discretionary contact, campaign or relationship-building, automation, bulk processing and new integrations, features or data categories in Mail are not permitted. The Mail restriction does not govern Zoho Campaigns; every send and send-capable automation is independently governed by the separate preconditions for Campaigns described above. The domain's MX and SPF routing points to Zoho's EU services but does not prove the account region. Zoho Legal's 2026-09-08 response identifies SCC Module 3 for Zoho EU → Zoho India in prose. The account-specific DPA was signed on 2026-09-11, but its Schedule 1 is the article 28(3)-(4) standard contractual clauses and states in its own clause 1(f) that they do not by themselves ensure Chapter V compliance, so the transfer mechanism remains supplier-asserted rather than contracted. Clause 5.1(i) makes EEA storage a contractual term, but the agreement's Schedule 2 expressly permits Indian access. Our India assessment must address current law, and the United States leg remains unsupported: Schedule 2 names India alone for EEA customers, while the supplier's own SOC 1, SOC 2 and ISO location annexes place Austin in the United States in scope for support. Our internal deadline of 2026-08-14 for obtaining that evidence passed without the evidence being completed. Those Mail restrictions therefore remain, and the allowed minimised intake continues only while the escalation continues toward a lawful replacement channel. The evidence record contains the full response and its remaining boundaries. The mailbox copy follows the same case lifecycle and hard cap as the underlying matter. Export, minimisation and verified deletion remain permitted. The restriction proves neither Chapter V compliance nor tenant-level technical enforcement.

Resend delivers service, transactional, expressly requested data-event-watch and technical email through the United States. Resend is not used for campaigns, newsletters or trial nurture; those separate sends are handled in Zoho Campaigns. Resend applies EU Standard Contractual Clauses (SCCs).

Stripe (payment provider for Pro services) is a US-based company. Card details are handled entirely by Stripe in accordance with PCI DSS. Stripe applies EU Standard Contractual Clauses (SCC). More information in Stripe's privacy policy.

Sentry (error monitoring) is operated by Functional Software, Inc. (USA). The website's security settings (CSP) permit error reports to be sent to ingest.de.sentry.io in Germany, but we have not yet checked in the production environment whether error monitoring is switched on, in which region events are received and stored, or how Sentry's setting for removing IP addresses is configured; this revision therefore makes neither a positive EU-storage claim nor a claim that full IP is always removed. If the integration is active, Sentry's network edge may receive stack traces, browser information and source IP. EU Standard Contractual Clauses (SCCs) apply for any support or administrative access by Sentry's US team.

Anthropic (AI assistant) is a US-based company. The provider states that API data is stored in the United States and that some processing may additionally occur at selected locations in Europe, Asia and Australia, without publishing a complete country list. A region is not a closed country schedule. No non-EEA country other than the United States is therefore currently approved, and Kollen sends no requests to Anthropic while Anthropic can route processing to an unnamed country. Before a request, dated provider/account evidence must show that processing outside the EEA is limited to the United States and that the DPF for a relevant certified US importer or SCCs with a country- and recipient-specific TIA and supplementary measures apply. Another processing country requires both code and annex review before any request. Processing is governed by Anthropic's Data Processing Agreement (DPA) for the API service and does not require a blanket ZDR agreement. The standard rule is that API inputs and outputs are deleted from Anthropic's backend within 30 days. If automated trust-and-safety systems flag content as a possible Usage Policy violation, the provider's current terms allow input/output to be retained for up to two years and classification scores for up to seven years; legal requirements and explicit feedback may lead to other periods. API data is not used for model training unless the customer expressly opts into such a programme or provides feedback. Messages are not permanently stored by Skolkoll. See Anthropic's processing-location statement, API retention and training policy for commercial services.

OpenAI is a US-based company used for rights-cleared stylisation of school images without identifiable people and for bounded internal extraction from officially published public documents. Image stylisation operates under OpenAI's safety/content policies; those are provider controls, not a separate moderation purpose or additional model call. By default, OpenAI may create abuse-monitoring logs containing customer content or derived safety metadata and retain them for up to 30 days. Longer retention may occur where required by law or reasonably necessary to protect the service or a third party; safety-flagged image files may be retained for manual review. In OpenAI's Chat Completions interface for text generation, OpenAI's optional response storage is switched off, which means that the response object is not retained as application state, but prompt caching may retain encrypted key/value tensors in GPU-local storage for up to 24 hours; the original prompt text is not persisted in that local storage. OpenAI's image-generation and image-edit interfaces have no application-state retention. These interface-specific rules are separate from the provider's 30-day abuse/safety-log period. Skolkoll makes no ZDR claim and does not require a blanket ZDR agreement for these bounded flows. The transfer mechanism is selected per scenario and recipient country: an adequacy decision where its scope covers the recipient and purpose, the DPF for an applicable certified US importer, or otherwise SCCs with the necessary TIA and supplementary measures. See OpenAI's API data controls and prompt-cache retention.

Social login providers — Google, Microsoft, GitHub and Facebook/Meta are contacted only after you select the provider. Skolkoll requests the basic identity needed for sign-in and adds no extra provider scopes. This is treated as part of Skolspegeln's own account security; each provider is independently responsible for its account and authentication stage. Country and transfer mechanism are assessed provider by provider and may, depending on the actual recipient, rely on an adequacy decision, the DPF or SCCs. Apple remains available for recovery of an existing account link but is hidden as a new sign-in option until its production configuration has been verified. Customer-controlled SAML/OIDC is a separate flow for the Municipal Licence's organisation memberships and roles of the customer's users (processing activity P1) and may not be discovered, verified, enforced or used for automatic membership until the organisation-specific assessment is approved and the approval has been recorded for the organisation in our system.

Nominatim: the OpenStreetMap Foundation in the United Kingdom is treated as an independent controller for external requests that reach the service; because no closed country list exists for its vendors/agents, recipient due diligence conservatively covers the world. New external requests must remain stopped for now, in both the browser flow and the scheduled or manually triggered batch flow, because evidence about the provider's raw logs and about the countries in which its vendors process data is still missing. Each flow must be activated separately in the code and both are off by default; we do not claim to have checked in the production environment that this version is deployed, that the switch-off applies there or that a cache is active in production. In the browser flow, the current version of the website shows just-in-time text by the field instructing the user to enter only a town or named public place. Street and home addresses, numbers, contact details and unclear person-like multi-word phrases are blocked before a network request. This is a risk-reduction control, not a claim that every permitted one-word query is thereby proven free of personal data. Under our settings, accepted results may be stored in the browser's session storage (sessionStorage) for no more than 24 hours, with a maximum of 20 entries. The separate batch flow must be activated on its own and is also off by default; cache hits for safe business addresses may be used without an external request, while a cache miss is stopped as long as the batch flow is not activated. If the batch flow is activated, our setting is one thread, at least 15 seconds between request starts and no more than 365 days in Skolkoll's own server cache. An external browser request carries the query and IP/request metadata; an external batch request carries the public business address and the server's IP/User-Agent.

JobEd Connect: only after you open the Career tab in an upper-secondary-school detail does the browser send IP/request metadata and URL parameters containing predefined or public programme text to the Swedish Public Employment Service; user-entered free text is not used. Browser credentials and the referring page are omitted. The legal direct recipient is the Swedish public authority Arbetsförmedlingen (the Swedish Public Employment Service), which is treated as independently responsible for receipt and any later provider processing. The service's configured region designation for Northern Europe is only a label and is not evidence of a physical processing or access country. The flow is reviewed annually, including any raw-log retention. ResRobot and the Skolverket API follow their separate scenarios. Leaflet and D3.js are served locally from our own server. Firebase authentication loads client scripts from Google's CDN (gstatic.com), whose servers may be outside the EU.

Email for school watching

If you choose to watch a school, you provide your email address. The following is stored in our database (Firestore):

  • Email address — used to send notifications. Deleted when you unsubscribe.
  • SHA-256 hash of your email — used to look up your existing watches without exposing your email in database queries.
  • School unit code and name — which school you are watching.
  • Timestamps — when the watch was created, confirmed and last notified.

Role and legal basis: An anonymous email watch relies on consent (GDPR Art. 6(1)(a)) through double opt-in. For an organisation-directed Municipal Licence watch, the organisation is controller and Skolkoll is processor on instruction. Article 6(1)(b) applies only where you personally are party to the agreement.

Retention: Your data is stored for as long as the watch is active. On unsubscribe, the record is closed and the email address, confirmation/unsubscribe bearer tokens and other direct watch fields are deleted immediately. A minimised closed tombstone may retain only the email hash, status and close/expiry clocks for documented suppression/accountability, for no more than 24 calendar months and earlier when the need ends. A daily cleanup job goes through older closed records, minimises them and deletes the closure records when their time is up; we have not yet confirmed that the job is deployed, that it has run for the first time or that it works in the production environment. Account deletion instead removes account-bound watches.

What triggers notifications: You receive an email when merit score changes by more than 5 points, gymnasium eligibility changes by more than 5 percentage points, pupil count changes by more than 20%, or the School Inspectorate issues a new decision about the school.

How to unsubscribe: Every notification email contains an unsubscribe link. You can also contact us at info@skolspegeln.se.

School-image submissions

If you upload a façade image of a school, we store the image, school-unit code, school name, selected licence, any photo date and contact details for review, rights traceability and possible AI-based chalkboard stylisation. BY/BY-SA collects the photographer name and an optional HTTPS link; CC0 collects neither a photographer/rights-holder name nor a person/source link.

Legal basis and public attribution: For images submitted through the form, consent (GDPR Art. 6(1)(a)) covers the submitter's own contact data and choices about AI stylisation; the form's licence terms govern permission to use the image. Where CC BY 4.0 or CC BY-SA 4.0 requires attribution, the photographer's name and any HTTPS link are processed and published on the basis of legitimate interest (Art. 6(1)(f)) and the applicable Article 14 route. The link is public only while the current editorial review remains bound to the exact image hash, licence and link. CC0 intake and projection contain no person attribution. The same legitimate interest applies to minimum necessary attribution and verifiable licence provenance for separately imported, rights-cleared images. Where a contact route is available, Article 14 information is provided directly within the Article 14(3) time limits. Article 14(5)(b) may replace direct notice only after dated and signed legal evidence has been expressly registered for the exact source and publication; our server-controlled register for such evidence is empty, and without such a registration the exemption is not used. Contact details are not used for marketing. Contact, attribution, source-link, photo-date and rights metadata is not sent to the image model.

Retention: A submission that remains pending becomes due for deletion 180 days after upload, including after it is returned to review. Rejected submissions and associated contact and rights data become due for deletion 90 days after the rejection decision, or earlier if you request this and we do not need the data to handle a dispute. For approved images, the minimum necessary licence, attribution and provenance data is retained for as long as the image is used or a rights claim reasonably needs to be auditable. Contact details, photo dates, review free text and other intake-only fields become due for minimisation 180 days after approval; legacy CC0 names and links are covered by the same pass. The daily cleanup job performs due deletion or minimisation in the next successful run that reaches the record; queueing or operational failures can delay execution. A photo date is never published for the form image.

Correction form

If you report an error through the correction form, we store what you enter: which school or page it concerns, the type of error, your description and the value you believe is correct, any link, source link and school-unit code, and — if you choose to leave it — your email address (the form has no name field; a name can appear only if the matter was logged manually or via the API). We also store the browser user-agent for abuse prevention and the time the report arrived. No IP address is stored in the record. The record is stored among the correction reports in our database. Only our own server can read the correction reports. If you write to info@skolspegeln.se instead, the matter is logged manually among the same correction reports, with the time the email arrived, and follows the same retention target. Free text and contact details are used solely for internal triage; if a correction is published, it is summarised without your contact details and with sensitive details removed.

Legal basis: legitimate interest (GDPR Art. 6(1)(f)) to receive the report, store it with restricted access, assess it and — where you left a contact — be able to get back to you. Any reply is sent manually from our mailbox; no automated reply is sent. The basis does not cover marketing, any ongoing relationship or AI analysis of the content. If you report that information about yourself is inaccurate, it is handled as a rights request — for example rectification under Article 16. The response period under Article 12(3) runs from when the report arrived, regardless of when we get to assess it; the assessment only determines which right applies. Do not enter sensitive data or data about other people in the free text; such content is minimised or removed without further processing.

Retention: Our target is that email, any name, user-agent and free text are erased or anonymised 90 days after the case is closed, and no later than 12 months after the report arrived even if the case is still open by then. Rights matters (Articles 15–21) instead follow the retention periods for rights handling in our register, not this target. What remains is a de-identified note of which school, which field and which outcome the report concerned. Automatic purging is not yet in operation and no record has been purged so far; until it exists, any deletion is manual, and the state is reported in our record of processing activities.

Local storage (localStorage)

The following data may be stored locally in your browser:

The AI chat stores conversation and school context in sessionStorage (automatically deleted when the browser tab is closed): skolkoll_ai_chat and skolkoll_ai_context. Confirmation that the AI information was shown is stored in localStorage under the backwards-compatible key name skolkoll_ai_consent until you clear AI data or the browser's local storage. Paywall click attribution is also stored in sessionStorage under skolkoll_paywall_last_click after accepted analytics consent.

AI assistant (Kollen)

Kollen is not specifically directed at children under 13.

Skolkoll offers an AI-powered chat ("Kollen") that answers questions about school statistics. If you choose to use Kollen, the following applies:

Legal basis: legitimate interest (GDPR Art. 6(1)(f)) under a documented balancing test for a user-initiated question service. The interface instructs you not to submit private or sensitive data; the dialog confirmation is an information acknowledgement, not consent as the legal basis. The pseudonymised audit log uses the same basis for abuse and security traceability.

If your question mentions someone else: the instruction not to submit private or sensitive data is a safeguard, not an exception from the information duty in GDPR Article 14. This public information is a compensatory measure where direct information is impossible or would involve disproportionate effort under Article 14(5)(b). If Skolkoll gains concrete awareness of the person mentioned and has a usable contact route, we instead provide information directly within the Article 14(3) time limits unless another documented exception applies.

Data processor: Anthropic PBC (San Francisco, USA) — the AI model intended to generate responses. Anthropic is Skolspegeln's intended direct processor in the Kollen flow; suppliers engaged by Anthropic in turn are its subprocessors. Our technical control currently permits only the United States as a country outside the EEA and requires valid evidence of the DPF or of SCCs with a transfer impact assessment (TIA) before a request. As long as the provider's country list is incomplete, a legal stop applies. The code stops the request when the evidence is missing, but we have not yet confirmed that this block is deployed and working in the production environment; another country requires code and annex review and is not approved by a general region-based SCC solution.

Clear and object: close the browser tab to delete the conversation or select "Clear AI data" in the chat to clear the conversation and information acknowledgement. You may object to the processing at any time by emailing info@skolspegeln.se.

Third-party services

The following tables separate browser-loaded services from server-side processors used in specific situations:

Browser-loaded and direct feature services

ServiceWhenData sent
CARTONot used: the map code no longer makes any direct request for map tiles from CARTO. We have not yet confirmed the change in the production environment.No current transfer from the website's map code. A future external tile service would receive IP/request metadata and map-tile coordinates and requires a reviewed code change and recipient assessment.
Zoho PageSensePage views, experiments, heatmaps and session recording on public pages (requires consent)Page views, clicks/scrolling, heatmap and session-recording interactions, experiment variant, device and browser info
Nominatim (OpenStreetMap)User-initiated search for a town or named public place and separate batch geocoding of public school/preschool addresses; new external requests are off by default and must be activated separatelyIf the browser flow is activated: a permitted place query and IP/request metadata. If the batch flow is activated and the address is not in the cache: the public business address and the server's IP/User-Agent
JobEd Connect (JobTech)Only after you open the Career tab in an upper-secondary-school detailIP/request metadata and URL parameters with predefined or public programme text, not user-entered free text
Skolverket APISchool view (surveys, documents)The detail request itself contains only the school-unit code, not a person field. Depending on which of Skolverket's interfaces is called, the source response may contain personal data including the head-teacher name field; that field is discarded at the first processing step as long as our assessment of named person roles is not concluded and such processing is paused.
Google CDN (gstatic.com)Login (Firebase authentication)IP address when downloading login scripts
StripePayment for Pro servicesEmail, organisation name, card details (handled by Stripe)
Sentry (intake in Germany permitted in the website settings; actual region not checked)If error monitoring is switched on in production and a technical error occursError messages and stack traces, browser information and source IP at the network edge. We have not checked Sentry's separate setting for removing IP addresses.

External controller services and server-side processors

The following services receive data when you use the relevant feature, contact us or separately consent. Zoho Mail and Campaigns are managed outside the site's server path; the other rows are used through our servers or after approved activation:

ServiceWhenData sent
ResRobot (Trafiklab)Commuting tab in school viewCoordinates for start/destination
ResendService, transactional, requested data-event-watch and technical email; never campaigns/newslettersEmail address, name, subject and message content
Zoho MailDated interim-risk restriction with no positive release: new user-initiated inbound enquiries may be received, manually assessed and answered only to the strictly necessary extent after case-specific minimisation and under the matter's documented basis; no AI. Proactive/discretionary contact, campaign/relationship-building, automation, bulk processing and new integrations/features/data categories in Mail are not permitted. The Mail restriction does not govern Campaigns, which has its own independent preconditions. The internal deadline of 2026-08-14 has passed; only the minimised intake continues, while escalation to a lawful replacement channel is under way (Zoho response 2026-09-08: Module 3 identified in prose. DPA signed 2026-09-11, but as an article 28 processor agreement that by its own clause 1(f) does not close Chapter V; India/United States assessments remain open)Name, email, message, voluntary attachments and technical message headers
Zoho CampaignsDesignated separate campaign/newsletter platform; the next send and every send-capable automation are stopped until the account-specific requirements above are fully verified and the send is manually approvedEmail, name, organisation/locale, consent provenance, list/segment, delivery status and suppression. Complete open and link-click tracking were observed ON on 2026-07-29; automation, DPA/SCC, unsubscribe/RTBF, retention/suppression and tracking disposition remain unverified
Firebase / Google CloudUser accounts and databaseAccount and organisation data. Our configuration sets europe-west1 (Belgium); an archived check of the production environment dated 2026-09-05 establishes the actual Firestore and storage-bucket regions
Anthropic (Claude API)User-initiated AI chat (Kollen) — legitimate interest under a documented balancing test, but only when we hold valid, dated evidence of the processing country and transfer safeguard as described in the third-country sectionChat messages, school context
OpenAIRights-cleared school-image stylisation and bounded internal extraction from officially published public documentsPerson-free school image or a locally preflighted and contact-minimised provider copy of a public document. The whole document is blocked when prohibited markers are detected; detector false negatives remain a residual risk. No contact, attribution, source-link, photo-date or rights metadata is sent in the image flow
Zoho DeskSeparate support surface; the current journalist connector is switched off in the software code and cannot be switched on by general evidence or settings. No journalist order is sent and no full-content fallback email existsNo current journalist record. A future replacement must use an order-bound object without cross-purpose merging and with tested matching deletion/minimisation; no automated AI analysis or private analysis comment
Zoho CRMThe current journalist connector, which creates one global contact per email address, is switched off in the software code and cannot be switched on by general evidence or settingsNo current journalist record. A future approved replacement may contain only minimum order-bound metadata, without order free text, Zoho CRM's free-text description field, cross-purpose merging or later relationship/campaign contact

Both Nominatim external-request paths are off by default, and requests are stopped unless they have been expressly activated. We have not yet confirmed in the production environment that this version is deployed or which cache settings apply there. Our settings limit the browser cache to no more than 20 entries for 24 hours, the batch cache to 365 days, and batch calls to one thread and at least 15 seconds between starts when the batch flow has been expressly activated. JobEd Connect has a separate bounded, flow-specific assessment and is called only after the user opens the Career tab.

Fonts

We use the typefaces Literata and Sora, which are self-hosted on our server. No requests are sent to Google Fonts or other font providers. The Leaflet map library is served locally from our server. Firebase authentication does load client scripts from Google's CDN (gstatic.com), see the table above.

School data and public information

All school data shown on Skolkoll is public information from Skolverket, SCB, Bolagsverket and Skolinspektionen.

Personal data about school staff

Skolkoll does not publish principals' names as part of the automated school directory. Skolverket source responses may contain personal data, including the head-teacher name field. As long as our assessment of named person roles is not concluded and such processing is paused, that field is discarded at the first processing step and must not be stored, indexed, materialised or included in history. Legacy names may be processed only for documented cleanup and rights handling. A public source does not make a name cease to be personal data.

A school's official institutional contact details (email and phone number) are obtained from Skolverket during the daily source sync and, in the active directory processing, stored only in the current, replaceable school record. They may be published in the detail view, API and JSON-LD. When a detail is changed or removed at source, it is replaced or removed on the next successful source sync. Email and phone are not added to temporal history, and new archive generations in the raw-data layer (Bronze) and in the materialised archives are contact-minimised. A one-time migration cleans older materialised rollback archives on the next successful sync. Older internal source snapshots in the raw-data layer produced before this minimisation are not public and remain subject to the existing configured 1,095-day cleanup window; actual deletion requires a completed and evidenced cleanup run and is not claimed here for any particular older snapshot. The legal basis is legitimate interest (GDPR Art. 6(1)(f)) in maintaining an accurate public directory of official school contact channels. An institutional address may nevertheless be personal data if the source uses an individual's address. You may request rectification or object through info@skolspegeln.se. We do not publish the names of pupils, principals, teachers or other school staff through the automated school directory.

Name-free publication boundary

Embeddable widgets

Skolkoll offers embeddable widgets for individual schools and municipalities that can be used on external websites. We do not restrict which domains may embed them — they are openly available and designed to support transparency around school data.

Attribution is preserved through the widget footer, which links back to Skolkoll. If you observe misuse (e.g. phishing sites embedding our widgets to gain credibility), contact us at info@skolspegeln.se and we will assess the need for additional measures.

Your rights

Under GDPR, you have the right to:

Changes

We may update this policy as needed. The latest version is always available on this page.