DRAFT — pending legal counsel review
This page contains placeholder text and is not yet legally binding. It is awaiting review and approval by legal counsel before it takes effect.
Data Processing Agreement
Last updated: 2026-06-09
This Data Processing Agreement (the "Agreement") is entered into between the course-organizing organization (the controller) and Kursregistrering.se (the processor). It governs how Kursregistrering.se processes personal data on the organization's behalf under Article 28 of the GDPR.
Version: 2026-06-09
The boxed summaries are reading aids, not the binding text.
1. Parties and roles
The organization arranging courses through Kursregistrering.se is the data controller for its participants' personal data. Lubb IT AB (reg. no. 556938-6484), which provides Kursregistrering.se, is the data processor and processes personal data only on documented instructions from the controller, in accordance with this agreement.
2. Subject matter, duration, nature, and purpose of the processing
The processing comprises the administration of course registrations: receiving registrations, invoicing, attendance tracking, issuing certificates, and course evaluation. The processing continues for as long as the organization holds a Kursregistrering.se account and thereafter for the retention periods set out in section 7.
3. Categories of data subjects and personal data
Data subjects are course participants and the organization's own users. We process name, email address, phone number, employer, and billing details. For licensed medical professionals we also process license number, specialty, and attendance and continuing-education records. These are processed in reliance on Article 9(2)(h) GDPR (occupational-medicine and health-care purposes).
4. Processor obligations (Article 28(3))
Under Article 28(3) of the GDPR, Kursregistrering.se shall:
- process personal data only on documented instructions from the controller
- ensure that everyone processing the data is bound by confidentiality
- implement appropriate technical and organizational security measures (Article 32)
- respect the conditions in section 5 when engaging sub-processors
- assist the controller with data-subject requests and the obligations under Articles 32–36
- delete or return the data when the processing ends
- make available the information necessary to demonstrate compliance, and allow for audits
5. Sub-processors
Kursregistrering.se engages the following sub-processors, and the organization grants general prior authorization for them. When the list changes, a new Agreement version is published. Every customer organization is then prompted in the product to review and accept it — you do not need to monitor this page. The organization has the right to object to a new sub-processor.
| Sub-processor | Purpose | Data categories | Region | Transfer basis | Vendor terms |
|---|---|---|---|---|---|
| Required for the service | |||||
| Supabase (Opens in a new tab) | Database, authentication, and file storage | All data categories in section 3 | EU | standard contractual clauses (SCCs) | Processing terms — Supabase (Opens in a new tab) |
| Resend (Opens in a new tab) | Transactional email delivery | Name, email address, email content | EU/US | transfer basis under investigation | Processing terms — Resend (Opens in a new tab) |
| Vercel (Opens in a new tab) | Application hosting and content delivery | All data passing through the application | EU/Global | adequacy decision: EU-US Data Privacy Framework | Processing terms — Vercel (Opens in a new tab) |
| Sentry (Opens in a new tab) | Error monitoring (consent-gated in the browser) | Technical error data; IP address | EU | transfer basis under investigation | Processing terms — Sentry (Opens in a new tab) |
| Upstash (Opens in a new tab) | Distributed rate limiting (Redis) | IP addresses and transient counters | EU | transfer basis under investigation | Processing terms — Upstash (Opens in a new tab) |
| Engaged only when the feature is used | |||||
| Stripe (Opens in a new tab) | Subscription and per-course billing (Kursregistrering.se's own billing of the organization) | The organization's billing details | EU/US | adequacy decision: EU-US Data Privacy Framework | Processing terms — Stripe (Opens in a new tab) |
If the organization objects to a new sub-processor and no reasonable solution can be reached, the organization can terminate the service.
6. Instruction on direct handling of data-subject requests
The controller instructs Kursregistrering.se to handle participants' requests directly. This covers access, rectification, erasure, portability, and restriction via the self-service interfaces on Kursregistrering.se. No individual request needs the controller's prior approval. The instruction is limited by the statutory exceptions in section 7, for example the Swedish Bookkeeping Act's (bokföringslagen) invoice-retention requirement. An organization that has not accepted the current Agreement version has not given this instruction.
7. Retention and statutory exceptions
Personal data is purged on the following schedule: operational registration data 2 years after the course ends by default, and continuing-education evidence (CME/CPD) 7 years after issuance. Invoice records are retained for 7 years under the Swedish Bookkeeping Act (bokföringslagen) and are exempt from erasure. The exemption applies also when a data subject requests erasure.
8. Supervisory authority
The supervisory authority is the Swedish Authority for Privacy Protection (IMY (Opens in a new tab)). Data subjects have the right to lodge a complaint with IMY.