ROPA — Records of Processing Activities (summary)

Public summary under GDPR art. 30 for municipal procurement officers and data protection officers.

Last updated: 2026-07-08. Version 1.6. Next review: 2027-07-06.

This is a public summary of Skolkoll's Records of Processing Activities (ROPA) under GDPR article 30. The full internal ROPA is in version control and can be requested as an extract by Municipal Licence customers. The summary is structured so a municipal lawyer or procurement officer can get a complete picture without needing infrastructure-level detail.

1. Roles — municipality vs Skolkoll

2. Data category overview

Per main data category, summarised across related Firestore collections.
CategoryContentsLegal basisRetention
User accountsEmail, name, organisation membership, role, login timestampsContract (art. 6.1.b)Until account deletion; 36 mo of inactivity → automatic deletion
Organisation dataOrganisation name, organisation number, billing address, customer number (SK-NNNNN)Contract (art. 6.1.b)Active for the lifetime of the subscription
Billing historyInvoices, payment metadata (card details never pass through Skolkoll's servers)Legal obligation (art. 6.1.c) — Swedish bookkeeping act7 years
WatchersSelected school/municipality/school operator, email address, email hash, frequency, confirmation/unsubscribe tokens and watcher events for the digestConsent (art. 6.1.a) for anonymous double opt-in; contract (art. 6.1.b) for signed-in account featuresActive watchers until the user removes them. Pending confirmations have a 48-hour token window and are cleaned by the cleanup flow. Watcher events are cleaned continuously, normally within 35 days.
Mail contacts (newsletter)Email, name, list memberships, opt-in tokenConsent (art. 6.1.a) for newsletters; contract (6.1.b) for transactionalUntil unsubscribed; anonymised hash for 24 mo
Analytics events (raw)Random sessionId, page path, event name — no personal data, no IP, no UALegitimate interest (art. 6.1.f) — product development90 days; aggregated summaries retained indefinitely (no PII)
Zoho PageSense (consent-based web analytics)Page views, clicks/scrolling, heatmaps, session recording, experiment variant, device and browser info on public pages. PageSense does not run on noindex/account/admin pages.Consent (art. 6.1.a)According to the selected PageSense plan, max 12 months for Skolkoll's use
Zoho Desk (customer support)Support cases from paying customers: name, email address, organisation membership, ticket content, ticket history, and voluntarily attached technical material.Contract (art. 6.1.b) and legitimate interest (art. 6.1.f) — support, troubleshooting, and contract follow-upMaximum 36 months after case closure, or shorter on customer request when no legal obligation requires retention
Commercial lead forms (Zoho CRM)Form record in leadSubmissions with name, email, organisation, phone, message, track/surface, consent metadata, UTM fields and the stored Zoho CRM record. The collection is only accessible via the Admin SDK; clients cannot read or write it directly.Pre-contractual steps where applicable (art. 6.1.b), consent for the marketing opt-in (art. 6.1.a) and legitimate interest (art. 6.1.f) for abuse prevention and operational recoveryEach record is written with purgeAfter for target deletion 90 days from submission and is purged via Firestore TTL once the policy is active. Automatic replay to Zoho happens only for new records marked safe to replay; unclear CRM outcomes are blocked for manual reconciliation. The Zoho CRM record is reviewed at least annually and is not used for newsletters/campaigns without separate consent.
Journalist data ordersForm record in journalist_orders with newsroom/outlet, beat, name, email, order message, consent version/timestamp and Zoho Desk/CRM status. When the Zoho intake is approved, a Desk ticket of type Databeställning and a minimal Zoho CRM contact are created.Consent (art. 6.1.a) for storage/contact through the form; request handling/pre-contractual steps where applicable (art. 6.1.b); legitimate interest (art. 6.1.f) for abuse prevention, operational recovery and editorial relationship handoffFAS-0 decision: each Firestore record is written with purgeAfter for target deletion 180 days from submission. Firestore TTL must be deployed and verified before full go-live; until TTL is active, a named monthly manual purge owner is required. Unresolved orders need documented extension and have a 12-month hard cap. Desk ticket max 12 months after closure; CRM contact reviewed at least annually and not used for campaigns/newsletters without separate consent.
Audit logAdmin actions with timestamp, target and before/afterLegitimate interest (art. 6.1.f) — security/traceability2 years via expiresAt and Firestore TTL once the policy is active
Account deletion audituid, email hash (SHA-256), deletion status and timestamps — no raw email addressLegitimate interest (art. 6.1.f) — accountability (art. 5.2) that an erasure request was carried out12 months via expiresAt and Firestore TTL once the policy is active
API quotaNumber of calls per organisation per monthLegal obligation (art. 6.1.c) — billing reconciliation13 months
AI chat conversationBrowser sessionStorage only — never on our serverConsent (art. 6.1.a)Deleted when the browser tab is closed
Lane-D document extraction (internal AI support)Raw text from public records (allmän handling) is sent to OpenAI (gpt-4o-mini) for structured extraction, primarily statistics on degrading treatment. The raw text may contain pupil data before masking; requests are made with storage disabled (no-store). Only masked, human-reviewed values can be published — auto-publication is disabled.Legitimate interest (art. 6.1.f) — compiling figures from public records for school transparencyExtracted candidates sit in a human-reviewed queue until approved or rejected; rejected ones are purged. Approved values become part of school data and are updated when the source updates.
Journalist email drafts (internal AI support)Incoming journalist email content (name, email, newsroom, message text) is sent to Anthropic (Claude) to classify the query and propose a draft reply. A human reviews and sends; nothing is sent automatically. Anthropic does not train on API content by default.Legitimate interest (art. 6.1.f) — efficient and accurate press responseDrafts are created in Gmail for review; the email itself is retained per the mail account's retention. The data is not used for mailings or CRM without separate consent and provenance.

The full internal ROPA contains per Firestore collection: exact field list, exact subprocessor link, exact retention mechanism. Municipal Licence customers can request the extract as an annex via support@skolkoll.se; delivered within 5 working days.

3. Subprocessors

Current list published at Data protection and subprocessors section 2 — includes Google Cloud, Stripe, Resend, Sentry, Zoho PageSense, Zoho Desk, Zoho CRM and Anthropic and OpenAI. AI chat and school image require consent; Lane-D document extraction (OpenAI) and journalist-email drafts (Anthropic) run on legitimate interest — see the Internal AI support section on the data-protection page. 30-day prior notice for subprocessor changes to Municipal Licence administrators.

4. International transfers

Primarily within the EU/EEA, including Firestore in Google Cloud europe-west1 (Belgium). For transfers to a third country (USA): Standard Contractual Clauses (SCCs) per EU Commission decision 2021/914 and, where applicable, the EU-US Data Privacy Framework. Transfer Impact Assessment (TIA) performed per provider — summary available on request to Municipal Licence customers.

5. Data subject rights — operational owner

Data subject rights — operational owner and timeline
RightContactTimeline
Access (art. 15)info@skolkoll.se14 days (GDPR limit 30)
Rectification (art. 16)info@skolkoll.se14 days
Erasure (art. 17)Self-service in the portal, or support@skolkoll.seSelf-service: immediate. Mediated: 14 days.
Portability (art. 20)info@skolkoll.se14 days
Object (art. 21)info@skolkoll.se14 days
Restriction (art. 18)info@skolkoll.se14 days

6. DPIA assessment

A simplified DPIA (DPIA-light) is published at Data protection and subprocessors section 5. Its conclusion — that a full DPIA is not required, because the processing does not meet high-risk criteria (no large-scale monitoring, no special categories of personal data stored systematically, no automated decision-making with legal effect on individuals) — applies to the processing within the Municipal Licence, where Skolkoll acts as data processor. For the public review activity, where Skolkoll is the data controller, a separate, full DPIA is in progress (2026). DPIA-light section 5 addresses the temporary exposure of raw text during Lane-D document extraction.

7. Incident response

The Incident Response runbook (internal process) is followed for any personal data breach:

The full IR runbook is delivered as an annex to the Municipal Licence agreement and can be requested before signing via info@skolkoll.se.

8. Review and update

This ROPA summary is reviewed and updated:

Related documents