DRAFT — pending legal counsel review
This page contains placeholder text and is not yet legally binding. It is awaiting review and approval by legal counsel before it takes effect.
Privacy Policy
Last updated: 2026-08-27
Did you attend a course? Then the course organizer is responsible for your registration data, and this policy describes how we process it on the organizer's behalf.
This Privacy Policy explains how personal data is collected and processed when you register for and attend courses administered through Kursregistrering.se. It covers what data we process, why, how long we keep it, who it is shared with, and the rights you have.
The boxed summaries are reading aids, not the binding text.
Who is responsible for your data?
Kursregistrering.se provides the tools; the course organizer decides what data is collected and why. The organizer — the customer organization running the course — is therefore the data controller for participants' data. Kursregistrering.se is the data processor and processes it only on the organizer's documented instructions. For a defined part of the processing we are instead the controller ourselves. That covers organizer user accounts and sign-in, invoicing of the organization via Stripe (Opens in a new tab), support correspondence, and error monitoring of the service. The boundary follows whom the data concerns. Data about you as a course participant is processed on the organizer's responsibility; data about you as an organization administrator is processed on ours.
What data do we process?
Depending on the course, we process your name, email address, telephone number, employer, and billing details. For licensed medical professionals we also process your professional license number, specialty, and course attendance. We process evaluation responses and any other information you enter in the registration form.
When does your data not come from you?
In most cases you provide your data yourself in the registration form. A course organizer can also register participants: through file import (CSV) or through a group booking for their organization. In those cases the data comes from the organizer, who is responsible for informing you under Article 14 of the GDPR. The information reaches you through the service's first message about your registration — normally the confirmation email with a link to this policy and to the participant portal. It must reach you no later than one month after the data was recorded.
What is the legal basis for the processing?
We process your data to perform the registration agreement (Art. 6(1)(b) GDPR). For medical license numbers, specialty, and attendance we rely on Art. 9(2)(h) GDPR — processing necessary for the purposes of occupational medicine and the assessment of professional competence. Optional uses such as marketing rely on your consent (Art. 6(1)(a) GDPR).
How long we keep your data
Operational registration data is purged 2 years after the course ends by default. Documentation evidencing continuing education (CME/CPD) is kept for 7 years from issuance to support accreditation audits. Invoice data is retained for 7 years as required by the Swedish Bookkeeping Act (bokföringslagen) — a statutory period that an erasure request does not override. The concrete purge date for your own registration is shown in the participant portal.
Recipients and sub-processors
We share data with the sub-processors that operate our service: Supabase (Opens in a new tab) (database and authentication), Resend (Opens in a new tab) (email delivery), Stripe (Opens in a new tab) (payments), Vercel (Opens in a new tab) (hosting), Sentry (Opens in a new tab) (error monitoring), and Upstash (Opens in a new tab) (rate limiting). A current sub-processor list is published on our Data Processing Agreement page.
Is data processed outside the EU/EEA?
The following sub-processors are established outside the EU/EEA or process data there: Supabase (Opens in a new tab) (standard contractual clauses (SCCs)), Resend (Opens in a new tab) (transfer basis under investigation), Stripe (Opens in a new tab) (adequacy decision: EU-US Data Privacy Framework), Vercel (Opens in a new tab) (adequacy decision: EU-US Data Privacy Framework), Sentry (Opens in a new tab) (transfer basis under investigation), Upstash (Opens in a new tab) (transfer basis under investigation). The Chapter V GDPR safeguard is stated for each vendor in the list. Where a vendor's basis is under investigation, we complete that investigation before these pages become binding. The same information appears in the sub-processor list in the Data Processing Agreement.
What are your rights?
You have the right to access, rectify, erase, restrict, and port your personal data. You can also object to processing and withdraw consent at any time. The participant portal offers self-service for access, rectification, erasure, and data portability — the link is in your registration emails. Invoice data is subject to the Bookkeeping Act's retention requirement and cannot be erased early. You can also contact the course organizer or us using the details below.
Are any automated decisions made?
The service makes no decisions based solely on automated processing that have legal effects on you or similarly significantly affect you (Article 22 GDPR). No profiling takes place. If a course is fully booked, registrations join a waitlist and are offered seats in order of registration time. Any further decisions to confirm or reject participants are made by the course organizer.
Where can you complain?
If you believe your data is processed unlawfully you can lodge a complaint with the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten (Opens in a new tab), IMY), the supervisory authority for Sweden.
How do you contact us?
The service is operated by Lubb IT AB (see the legal information below). For privacy questions, contact us at info@kursregistrering.se.