Skip to content
Kursregistrering.se

Data Processing Agreement

DRAFT — pending legal counsel review

This page contains placeholder text and is not yet legally binding. It is awaiting review and approval by legal counsel before it takes effect.

Data Processing Agreement

Last updated: 2026-06-09

This Data Processing Agreement (the "Agreement") is entered into between the course-organizing organization (the controller) and Kursregistrering.se (the processor). It governs how Kursregistrering.se processes personal data on the organization's behalf under Article 28 of the GDPR.

Version: 2026-06-09

The boxed summaries are reading aids, not the binding text.

1. Parties and roles

In short: Your organization is the controller of participants' data. We process it only on your instructions.

The organization arranging courses through Kursregistrering.se is the data controller for its participants' personal data. Lubb IT AB (reg. no. 556938-6484), which provides Kursregistrering.se, is the data processor and processes personal data only on documented instructions from the controller, in accordance with this agreement.

2. Subject matter, duration, nature, and purpose of the processing

In short: The Agreement covers the whole course administration, for as long as you hold an account with us.

The processing comprises the administration of course registrations: receiving registrations, invoicing, attendance tracking, issuing certificates, and course evaluation. The processing continues for as long as the organization holds a Kursregistrering.se account and thereafter for the retention periods set out in section 7.

3. Categories of data subjects and personal data

In short: Ordinary contact details — and for medical staff also license and attendance records.

Data subjects are course participants and the organization's own users. We process name, email address, phone number, employer, and billing details. For licensed medical professionals we also process license number, specialty, and attendance and continuing-education records. These are processed in reliance on Article 9(2)(h) GDPR (occupational-medicine and health-care purposes).

4. Processor obligations (Article 28(3))

In short: Our statutory duties as processor, point by point.

Under Article 28(3) of the GDPR, Kursregistrering.se shall:

  • process personal data only on documented instructions from the controller
  • ensure that everyone processing the data is bound by confidentiality
  • implement appropriate technical and organizational security measures (Article 32)
  • respect the conditions in section 5 when engaging sub-processors
  • assist the controller with data-subject requests and the obligations under Articles 32–36
  • delete or return the data when the processing ends
  • make available the information necessary to demonstrate compliance, and allow for audits

5. Sub-processors

In short: The vendors that operate the service. You review and approve changes in the product.

Kursregistrering.se engages the following sub-processors, and the organization grants general prior authorization for them. When the list changes, a new Agreement version is published. Every customer organization is then prompted in the product to review and accept it — you do not need to monitor this page. The organization has the right to object to a new sub-processor.

Sub-processorPurposeData categoriesRegionTransfer basisVendor terms
Required for the service
Supabase (Opens in a new tab)Database, authentication, and file storageAll data categories in section 3EUstandard contractual clauses (SCCs)Processing terms — Supabase (Opens in a new tab)
Resend (Opens in a new tab)Transactional email deliveryName, email address, email contentEU/UStransfer basis under investigationProcessing terms — Resend (Opens in a new tab)
Vercel (Opens in a new tab)Application hosting and content deliveryAll data passing through the applicationEU/Globaladequacy decision: EU-US Data Privacy FrameworkProcessing terms — Vercel (Opens in a new tab)
Sentry (Opens in a new tab)Error monitoring (consent-gated in the browser)Technical error data; IP addressEUtransfer basis under investigationProcessing terms — Sentry (Opens in a new tab)
Upstash (Opens in a new tab)Distributed rate limiting (Redis)IP addresses and transient countersEUtransfer basis under investigationProcessing terms — Upstash (Opens in a new tab)
Engaged only when the feature is used
Stripe (Opens in a new tab)Subscription and per-course billing (Kursregistrering.se's own billing of the organization)The organization's billing detailsEU/USadequacy decision: EU-US Data Privacy FrameworkProcessing terms — Stripe (Opens in a new tab)

If the organization objects to a new sub-processor and no reasonable solution can be reached, the organization can terminate the service.

6. Instruction on direct handling of data-subject requests

In short: You instruct us to handle participants' GDPR requests directly in the self-service.

The controller instructs Kursregistrering.se to handle participants' requests directly. This covers access, rectification, erasure, portability, and restriction via the self-service interfaces on Kursregistrering.se. No individual request needs the controller's prior approval. The instruction is limited by the statutory exceptions in section 7, for example the Swedish Bookkeeping Act's (bokföringslagen) invoice-retention requirement. An organization that has not accepted the current Agreement version has not given this instruction.

7. Retention and statutory exceptions

In short: Data is purged on fixed schedules; invoices must be kept longer by law.

Personal data is purged on the following schedule: operational registration data 2 years after the course ends by default, and continuing-education evidence (CME/CPD) 7 years after issuance. Invoice records are retained for 7 years under the Swedish Bookkeeping Act (bokföringslagen) and are exempt from erasure. The exemption applies also when a data subject requests erasure.

8. Supervisory authority

In short: The supervisory authority is IMY.

The supervisory authority is the Swedish Authority for Privacy Protection (IMY (Opens in a new tab)). Data subjects have the right to lodge a complaint with IMY.

Legal information

Company
Lubb IT AB
Registration number
556938-6484
Registered seat
Linköping
Address
c/o Marcus Ludvigsson, Kerstinsgatan 13 lgh 1403, 582 13 Linköping, Sverige
VAT number
SE556938648401

← Back to legal overview

Kursregistrering.se© 2026
LegalPrivacy PolicyTerms of ServiceCookie PolicyData Processing AgreementSecurityAccessibility Statement