Data processing agreement for Skolkoll Pro

Version self-serve-pub-2026-09-1. The standard agreement for card purchases. It is accepted at checkout and carries the same Article 28 duties as the DPA template.

Data processing agreement

Version: self-serve-pub-2026-09-1
Decision: self-serve click-wrap, 2026-09-27

1. Parties

The controller is the organisation identified by the organisation number on the Skolkoll account. No separate contact person is stored as the signatory.

The processor is Skolspegeln AB, company registration number 559359-7288, Ejdergatan 6, SE-619 32 Trosa, Sweden, info@skolspegeln.se.

2. How the agreement is made

The agreement is made when an administrator of the organisation, at card checkout, confirms that they are authorised to bind the organisation and accepts this version. The box is not pre-checked. The server sets the time. The version and the time are stored for the organisation. The stored signatory is the role of account holder, never a name, an email address or a personal identity number.

Municipal licences and other negotiated agreements do not use this click-wrap. They use the DPA template, which is completed and registered separately. An agreement that is already active is not replaced by this click-wrap.

3. Subject matter

3.1 Categories of personal data

Import tools and the data cockpit are not included. Skolspegeln's own customer, billing and payment records, including Stripe data, are processed by Skolspegeln as controller and are outside this instruction. The same applies to public source data where Skolspegeln determines the purposes and means.

3.2 Categories of data subjects

3.3 Purpose, duration and nature

Processing provides Skolkoll Pro under this agreement and the configuration the customer makes: account, members, watchers, alerts, dashboard, benchmark and standard reports. It lasts while this version is in force, and afterwards only as long as agreed return or deletion requires, unless the law requires a record to be kept.

The processing is collection, storage, organisation, structuring, reading, alteration and erasure. The processor does not carry out profiling or automated decision-making that produces legal effects for data subjects.

4. Processor duties

Processing follows Article 28 of EU 2016/679. The processor shall:

  1. Process personal data only on documented instructions from the controller, including for a transfer to a third country. If Union or Swedish law requires different processing, the processor informs the controller of that legal requirement before the processing, unless the law prohibits the information.
  2. Tell the controller at once if the processor considers an instruction to infringe the GDPR or other applicable data-protection law.
  3. Ensure that people who process the data are under a duty of confidentiality.
  4. Apply appropriate technical and organisational security measures under Article 32. See Annex A and the data protection page.
  5. Engage sub-processors only under section 5.
  6. Assist the controller with data-subject rights under Articles 12–22.
  7. Assist the controller with the duties under Articles 32–36.
  8. When the agreement ends, at the controller's choice, delete or return the personal data and delete existing copies, unless the law requires storage.
  9. Make available the information needed to demonstrate compliance with Article 28, and allow audits under section 8.

The processing is listed in the record of processing.

5. Sub-processors

The controller gives a general written authorisation to engage sub-processors on these conditions:

  1. The sub-processor is bound by a written contract imposing the same data-protection duties as this agreement.
  2. The processor remains responsible to the controller for the sub-processor's performance.
  3. The processor notifies the controller's administrators at least 30 days before a sub-processor is added or replaced.
  4. The controller may object by ending this agreement before the change takes effect. The processor does not use the new sub-processor for the controller's data before the objection is resolved or the agreement has ended.
  5. The current list is on the data protection page.

6. International transfers

Firestore, Cloud Functions and Cloud Storage are located in europe-west1 (Belgium). Google Cloud (Firebase) is the sub-processor for that operation. Audit logs may remain in a locked bucket with location global, and Firebase Hosting uses a global CDN. Firebase Authentication is used for account sign-in and is covered by the Google Cloud data processing addendum with standard contractual clauses or the EU–US Data Privacy Framework, without a claim of location in europe-west1. Resend is used for watchers, alerts and standard reports that the controller requests, with a transfer to the United States under standard contractual clauses. Acceptance of this version is the instruction that processing takes place in that architecture. The transfer that architecture entails uses an applicable transfer tool: an adequacy decision within its scope, the European Commission's standard contractual clauses under Decision (EU) 2021/914 where an adequacy decision does not cover the transfer, or the EU–US Data Privacy Framework only where the recipient is certified for the processing in question. Stripe and other providers used only in Skolspegeln's own controllership are not sub-processors under this agreement.

7. Personal-data breach

The processor notifies the controller of a personal-data breach without undue delay, with an internal target of a first notice within 24 hours of becoming aware of it, and then supplements that notice. The notice describes the nature of the breach, the categories concerned, the likely consequences, the measures taken or proposed, and a contact path to the processor's incident handling.

8. Audit

The controller may audit compliance at its own cost and with reasonable notice. The audit may be carried out by the controller or by an independent auditor under a duty of confidentiality. The processor has no approval veto but may require reasonable security and confidentiality rules, and shall limit disruption and protect other customers' data. Certification reports may supplement the evidence. They do not replace the audit right where they are not sufficient for the processing in question.

9. Liability

Article 82 of EU 2016/679 is mandatory. This agreement does not add a separate limitation of liability between the parties.

10. Term

The agreement lasts while the organisation has Skolkoll Pro under this version and the agreement has not been replaced or ended. The duty to delete or return data survives the end of the agreement. Payment status by itself is not an agreement. An ended agreement stops the processing.

11. Assignment

The processor may assign the agreement to another company in the same group if the recipient assumes the duties in writing before processing continues, the security level, sub-processor terms and transfer safeguards are not reduced, and the controller's administrators are notified at least 30 days in advance when that is practicable. The controller may object on a data-protection ground and then end the agreement on 30 days' notice.

12. Changes

A change is a new published version. It binds the organisation only when an administrator accepts that version at checkout. This version continues until it has been replaced or ended.

13. Governing law

The agreement is governed by Swedish law. Disputes are first negotiated and then decided by a competent general court.

Annex A — Security measures