Data processing agreement
Version: self-serve-pub-2026-09-1
Decision: self-serve click-wrap, 2026-09-27
1. Parties
The controller is the organisation identified by the organisation number on the Skolkoll account. No separate contact person is stored as the signatory.
The processor is Skolspegeln AB, company registration number 559359-7288, Ejdergatan 6, SE-619 32 Trosa, Sweden, info@skolspegeln.se.
2. How the agreement is made
The agreement is made when an administrator of the organisation, at card checkout, confirms that they are authorised to bind the organisation and accepts this version. The box is not pre-checked. The server sets the time. The version and the time are stored for the organisation. The stored signatory is the role of account holder, never a name, an email address or a personal identity number.
Municipal licences and other negotiated agreements do not use this click-wrap. They use the DPA template, which is completed and registered separately. An agreement that is already active is not replaced by this click-wrap.
3. Subject matter
3.1 Categories of personal data
- The organisation's configuration of the service.
- Contact details of the account's users: email address, display name, organisation membership, role and sign-in timestamps.
- Output the service produces for the customer, such as alerts and standard reports.
- Data the customer supplies for a comparison in Pro.
Import tools and the data cockpit are not included. Skolspegeln's own customer, billing and payment records, including Stripe data, are processed by Skolspegeln as controller and are outside this instruction. The same applies to public source data where Skolspegeln determines the purposes and means.
3.2 Categories of data subjects
- People the controller gives an account in the service.
- People who appear in a watcher, an alert, a report or a comparison that the controller configures.
3.3 Purpose, duration and nature
Processing provides Skolkoll Pro under this agreement and the configuration the customer makes: account, members, watchers, alerts, dashboard, benchmark and standard reports. It lasts while this version is in force, and afterwards only as long as agreed return or deletion requires, unless the law requires a record to be kept.
The processing is collection, storage, organisation, structuring, reading, alteration and erasure. The processor does not carry out profiling or automated decision-making that produces legal effects for data subjects.
4. Processor duties
Processing follows Article 28 of EU 2016/679. The processor shall:
- Process personal data only on documented instructions from the controller, including for a transfer to a third country. If Union or Swedish law requires different processing, the processor informs the controller of that legal requirement before the processing, unless the law prohibits the information.
- Tell the controller at once if the processor considers an instruction to infringe the GDPR or other applicable data-protection law.
- Ensure that people who process the data are under a duty of confidentiality.
- Apply appropriate technical and organisational security measures under Article 32. See Annex A and the data protection page.
- Engage sub-processors only under section 5.
- Assist the controller with data-subject rights under Articles 12–22.
- Assist the controller with the duties under Articles 32–36.
- When the agreement ends, at the controller's choice, delete or return the personal data and delete existing copies, unless the law requires storage.
- Make available the information needed to demonstrate compliance with Article 28, and allow audits under section 8.
The processing is listed in the record of processing.
5. Sub-processors
The controller gives a general written authorisation to engage sub-processors on these conditions:
- The sub-processor is bound by a written contract imposing the same data-protection duties as this agreement.
- The processor remains responsible to the controller for the sub-processor's performance.
- The processor notifies the controller's administrators at least 30 days before a sub-processor is added or replaced.
- The controller may object by ending this agreement before the change takes effect. The processor does not use the new sub-processor for the controller's data before the objection is resolved or the agreement has ended.
- The current list is on the data protection page.
6. International transfers
Firestore, Cloud Functions and Cloud Storage are located in europe-west1 (Belgium). Google Cloud (Firebase) is the sub-processor for that operation. Audit logs may remain in a locked bucket with location global, and Firebase Hosting uses a global CDN. Firebase Authentication is used for account sign-in and is covered by the Google Cloud data processing addendum with standard contractual clauses or the EU–US Data Privacy Framework, without a claim of location in europe-west1. Resend is used for watchers, alerts and standard reports that the controller requests, with a transfer to the United States under standard contractual clauses. Acceptance of this version is the instruction that processing takes place in that architecture. The transfer that architecture entails uses an applicable transfer tool: an adequacy decision within its scope, the European Commission's standard contractual clauses under Decision (EU) 2021/914 where an adequacy decision does not cover the transfer, or the EU–US Data Privacy Framework only where the recipient is certified for the processing in question. Stripe and other providers used only in Skolspegeln's own controllership are not sub-processors under this agreement.
7. Personal-data breach
The processor notifies the controller of a personal-data breach without undue delay, with an internal target of a first notice within 24 hours of becoming aware of it, and then supplements that notice. The notice describes the nature of the breach, the categories concerned, the likely consequences, the measures taken or proposed, and a contact path to the processor's incident handling.
8. Audit
The controller may audit compliance at its own cost and with reasonable notice. The audit may be carried out by the controller or by an independent auditor under a duty of confidentiality. The processor has no approval veto but may require reasonable security and confidentiality rules, and shall limit disruption and protect other customers' data. Certification reports may supplement the evidence. They do not replace the audit right where they are not sufficient for the processing in question.
9. Liability
Article 82 of EU 2016/679 is mandatory. This agreement does not add a separate limitation of liability between the parties.
10. Term
The agreement lasts while the organisation has Skolkoll Pro under this version and the agreement has not been replaced or ended. The duty to delete or return data survives the end of the agreement. Payment status by itself is not an agreement. An ended agreement stops the processing.
11. Assignment
The processor may assign the agreement to another company in the same group if the recipient assumes the duties in writing before processing continues, the security level, sub-processor terms and transfer safeguards are not reduced, and the controller's administrators are notified at least 30 days in advance when that is practicable. The controller may object on a data-protection ground and then end the agreement on 30 days' notice.
12. Changes
A change is a new published version. It binds the organisation only when an administrator accepts that version at checkout. This version continues until it has been replaced or ended.
13. Governing law
The agreement is governed by Swedish law. Disputes are first negotiated and then decided by a competent general court.
Annex A — Security measures
- Encryption in transit (TLS 1.2 or later, HSTS).
- Encryption at rest for Firestore.
- Role-based access control and an audit log for administrator actions.
- Secrets in Google Secret Manager.
- Rate limiting and input validation on public endpoints.
- Monitoring and alerts for failures in scheduled functions.
- The detailed account is on the data protection page.