Last updated: 2026-07-08. Version 1.6. Next review: 2027-07-06.
This is a public summary of Skolkoll's Records of Processing Activities (ROPA) under GDPR article 30. The full internal ROPA is in version control and can be requested as an extract by Municipal Licence customers. The summary is structured so a municipal lawyer or procurement officer can get a complete picture without needing infrastructure-level detail.
1. Roles — municipality vs Skolkoll
- For Municipal Licence data (user accounts within the organisation, billing data, watchers, and support cases concerning the customer's users or organisation): the municipality is the data controller; Skolkoll is the data processor.
- For our own data (visitors to skolkoll.se without an account, anonymous analytics, public support/sales enquiries and journalist data orders not concerning Municipal Licence data): Skolkoll is the data controller.
- No joint controllers: we do not share data with third parties under joint control.
2. Data category overview
| Category | Contents | Legal basis | Retention |
|---|---|---|---|
| User accounts | Email, name, organisation membership, role, login timestamps | Contract (art. 6.1.b) | Until account deletion; 36 mo of inactivity → automatic deletion |
| Organisation data | Organisation name, organisation number, billing address, customer number (SK-NNNNN) | Contract (art. 6.1.b) | Active for the lifetime of the subscription |
| Billing history | Invoices, payment metadata (card details never pass through Skolkoll's servers) | Legal obligation (art. 6.1.c) — Swedish bookkeeping act | 7 years |
| Watchers | Selected school/municipality/school operator, email address, email hash, frequency, confirmation/unsubscribe tokens and watcher events for the digest | Consent (art. 6.1.a) for anonymous double opt-in; contract (art. 6.1.b) for signed-in account features | Active watchers until the user removes them. Pending confirmations have a 48-hour token window and are cleaned by the cleanup flow. Watcher events are cleaned continuously, normally within 35 days. |
| Mail contacts (newsletter) | Email, name, list memberships, opt-in token | Consent (art. 6.1.a) for newsletters; contract (6.1.b) for transactional | Until unsubscribed; anonymised hash for 24 mo |
| Analytics events (raw) | Random sessionId, page path, event name — no personal data, no IP, no UA | Legitimate interest (art. 6.1.f) — product development | 90 days; aggregated summaries retained indefinitely (no PII) |
| Zoho PageSense (consent-based web analytics) | Page views, clicks/scrolling, heatmaps, session recording, experiment variant, device and browser info on public pages. PageSense does not run on noindex/account/admin pages. | Consent (art. 6.1.a) | According to the selected PageSense plan, max 12 months for Skolkoll's use |
| Zoho Desk (customer support) | Support cases from paying customers: name, email address, organisation membership, ticket content, ticket history, and voluntarily attached technical material. | Contract (art. 6.1.b) and legitimate interest (art. 6.1.f) — support, troubleshooting, and contract follow-up | Maximum 36 months after case closure, or shorter on customer request when no legal obligation requires retention |
| Commercial lead forms (Zoho CRM) | Form record in leadSubmissions with name, email, organisation, phone, message, track/surface, consent metadata, UTM fields and the stored Zoho CRM record. The collection is only accessible via the Admin SDK; clients cannot read or write it directly. | Pre-contractual steps where applicable (art. 6.1.b), consent for the marketing opt-in (art. 6.1.a) and legitimate interest (art. 6.1.f) for abuse prevention and operational recovery | Each record is written with purgeAfter for target deletion 90 days from submission and is purged via Firestore TTL once the policy is active. Automatic replay to Zoho happens only for new records marked safe to replay; unclear CRM outcomes are blocked for manual reconciliation. The Zoho CRM record is reviewed at least annually and is not used for newsletters/campaigns without separate consent. |
| Journalist data orders | Form record in journalist_orders with newsroom/outlet, beat, name, email, order message, consent version/timestamp and Zoho Desk/CRM status. When the Zoho intake is approved, a Desk ticket of type Databeställning and a minimal Zoho CRM contact are created. | Consent (art. 6.1.a) for storage/contact through the form; request handling/pre-contractual steps where applicable (art. 6.1.b); legitimate interest (art. 6.1.f) for abuse prevention, operational recovery and editorial relationship handoff | FAS-0 decision: each Firestore record is written with purgeAfter for target deletion 180 days from submission. Firestore TTL must be deployed and verified before full go-live; until TTL is active, a named monthly manual purge owner is required. Unresolved orders need documented extension and have a 12-month hard cap. Desk ticket max 12 months after closure; CRM contact reviewed at least annually and not used for campaigns/newsletters without separate consent. |
| Audit log | Admin actions with timestamp, target and before/after | Legitimate interest (art. 6.1.f) — security/traceability | 2 years via expiresAt and Firestore TTL once the policy is active |
| Account deletion audit | uid, email hash (SHA-256), deletion status and timestamps — no raw email address | Legitimate interest (art. 6.1.f) — accountability (art. 5.2) that an erasure request was carried out | 12 months via expiresAt and Firestore TTL once the policy is active |
| API quota | Number of calls per organisation per month | Legal obligation (art. 6.1.c) — billing reconciliation | 13 months |
| AI chat conversation | Browser sessionStorage only — never on our server | Consent (art. 6.1.a) | Deleted when the browser tab is closed |
| Lane-D document extraction (internal AI support) | Raw text from public records (allmän handling) is sent to OpenAI (gpt-4o-mini) for structured extraction, primarily statistics on degrading treatment. The raw text may contain pupil data before masking; requests are made with storage disabled (no-store). Only masked, human-reviewed values can be published — auto-publication is disabled. | Legitimate interest (art. 6.1.f) — compiling figures from public records for school transparency | Extracted candidates sit in a human-reviewed queue until approved or rejected; rejected ones are purged. Approved values become part of school data and are updated when the source updates. |
| Journalist email drafts (internal AI support) | Incoming journalist email content (name, email, newsroom, message text) is sent to Anthropic (Claude) to classify the query and propose a draft reply. A human reviews and sends; nothing is sent automatically. Anthropic does not train on API content by default. | Legitimate interest (art. 6.1.f) — efficient and accurate press response | Drafts are created in Gmail for review; the email itself is retained per the mail account's retention. The data is not used for mailings or CRM without separate consent and provenance. |
The full internal ROPA contains per Firestore collection: exact field list, exact subprocessor link, exact retention mechanism. Municipal Licence customers can request the extract as an annex via support@skolkoll.se; delivered within 5 working days.
3. Subprocessors
Current list published at Data protection and subprocessors section 2 — includes Google Cloud, Stripe, Resend, Sentry, Zoho PageSense, Zoho Desk, Zoho CRM and Anthropic and OpenAI. AI chat and school image require consent; Lane-D document extraction (OpenAI) and journalist-email drafts (Anthropic) run on legitimate interest — see the Internal AI support section on the data-protection page. 30-day prior notice for subprocessor changes to Municipal Licence administrators.
4. International transfers
Primarily within the EU/EEA, including Firestore in Google Cloud europe-west1 (Belgium). For transfers to a third country (USA): Standard Contractual Clauses (SCCs) per EU Commission decision 2021/914 and, where applicable, the EU-US Data Privacy Framework. Transfer Impact Assessment (TIA) performed per provider — summary available on request to Municipal Licence customers.
5. Data subject rights — operational owner
| Right | Contact | Timeline |
|---|---|---|
| Access (art. 15) | info@skolkoll.se | 14 days (GDPR limit 30) |
| Rectification (art. 16) | info@skolkoll.se | 14 days |
| Erasure (art. 17) | Self-service in the portal, or support@skolkoll.se | Self-service: immediate. Mediated: 14 days. |
| Portability (art. 20) | info@skolkoll.se | 14 days |
| Object (art. 21) | info@skolkoll.se | 14 days |
| Restriction (art. 18) | info@skolkoll.se | 14 days |
6. DPIA assessment
A simplified DPIA (DPIA-light) is published at Data protection and subprocessors section 5. Its conclusion — that a full DPIA is not required, because the processing does not meet high-risk criteria (no large-scale monitoring, no special categories of personal data stored systematically, no automated decision-making with legal effect on individuals) — applies to the processing within the Municipal Licence, where Skolkoll acts as data processor. For the public review activity, where Skolkoll is the data controller, a separate, full DPIA is in progress (2026). DPIA-light section 5 addresses the temporary exposure of raw text during Lane-D document extraction.
7. Incident response
The Incident Response runbook (internal process) is followed for any personal data breach:
- 72-hour notification to the Swedish Data Protection Authority (IMY) per GDPR art. 33.
- Customer notification direct via email — for Municipal Licence customers also to organisation administrators.
- Roles: Incident Commander, Communications Lead, Legal/Compliance Lead (all coordinated by Skolkoll).
- Post-mortem published within 14 days of the incident.
The full IR runbook is delivered as an annex to the Municipal Licence agreement and can be requested before signing via info@skolkoll.se.
8. Review and update
This ROPA summary is reviewed and updated:
- Quarterly — review of the subprocessor list against actual system calls.
- Pre-release — every feature that adds a new collection or subprocessor updates the ROPA in the same PR.
- After every incident — updated with lessons learned.
- Annually — full re-read with date stamp.
Related documents
- Data protection and subprocessors — operational GDPR detail.
- DPA template — data processing agreement.
- SLA — uptime, support, escalation.
- Privacy policy — for end users and anonymous visitors.