Skip to content
Kursregistrering.se

Privacy Policy

DRAFT — pending legal counsel review

This page contains placeholder text and is not yet legally binding. It is awaiting review and approval by legal counsel before it takes effect.

Privacy Policy

Last updated: 2026-08-27

Did you attend a course? Then the course organizer is responsible for your registration data, and this policy describes how we process it on the organizer's behalf.

This Privacy Policy explains how personal data is collected and processed when you register for and attend courses administered through Kursregistrering.se. It covers what data we process, why, how long we keep it, who it is shared with, and the rights you have.

The boxed summaries are reading aids, not the binding text.

Who is responsible for your data?

In short: The organizer is responsible for your course data. We process it on the organizer's behalf.

Kursregistrering.se provides the tools; the course organizer decides what data is collected and why. The organizer — the customer organization running the course — is therefore the data controller for participants' data. Kursregistrering.se is the data processor and processes it only on the organizer's documented instructions. For a defined part of the processing we are instead the controller ourselves. That covers organizer user accounts and sign-in, invoicing of the organization via Stripe (Opens in a new tab), support correspondence, and error monitoring of the service. The boundary follows whom the data concerns. Data about you as a course participant is processed on the organizer's responsibility; data about you as an organization administrator is processed on ours.

What data do we process?

In short: We process what you enter when registering — for example name, email and, for medical professions, license number.

Depending on the course, we process your name, email address, telephone number, employer, and billing details. For licensed medical professionals we also process your professional license number, specialty, and course attendance. We process evaluation responses and any other information you enter in the registration form.

When does your data not come from you?

In short: The organizer can register you via import or group booking. You are then informed in the first email.

In most cases you provide your data yourself in the registration form. A course organizer can also register participants: through file import (CSV) or through a group booking for their organization. In those cases the data comes from the organizer, who is responsible for informing you under Article 14 of the GDPR. The information reaches you through the service's first message about your registration — normally the confirmation email with a link to this policy and to the participant portal. It must reach you no later than one month after the data was recorded.

What is the legal basis for the processing?

In short: The processing is needed to fulfil your registration. Sensitive professional data has specific legal support.

We process your data to perform the registration agreement (Art. 6(1)(b) GDPR). For medical license numbers, specialty, and attendance we rely on Art. 9(2)(h) GDPR — processing necessary for the purposes of occupational medicine and the assessment of professional competence. Optional uses such as marketing rely on your consent (Art. 6(1)(a) GDPR).

How long we keep your data

In short: Data is purged automatically on fixed schedules. Your own purge date is shown in the portal.

Operational registration data is purged 2 years after the course ends by default. Documentation evidencing continuing education (CME/CPD) is kept for 7 years from issuance to support accreditation audits. Invoice data is retained for 7 years as required by the Swedish Bookkeeping Act (bokföringslagen) — a statutory period that an erasure request does not override. The concrete purge date for your own registration is shown in the participant portal.

Recipients and sub-processors

In short: 6 vetted vendors operate the service. The full list is in the Data Processing Agreement.

We share data with the sub-processors that operate our service: Supabase (Opens in a new tab) (database and authentication), Resend (Opens in a new tab) (email delivery), Stripe (Opens in a new tab) (payments), Vercel (Opens in a new tab) (hosting), Sentry (Opens in a new tab) (error monitoring), and Upstash (Opens in a new tab) (rate limiting). A current sub-processor list is published on our Data Processing Agreement page.

Is data processed outside the EU/EEA?

In short: A few vendors are outside the EU/EEA. Every transfer has a GDPR safeguard.

The following sub-processors are established outside the EU/EEA or process data there: Supabase (Opens in a new tab) (standard contractual clauses (SCCs)), Resend (Opens in a new tab) (transfer basis under investigation), Stripe (Opens in a new tab) (adequacy decision: EU-US Data Privacy Framework), Vercel (Opens in a new tab) (adequacy decision: EU-US Data Privacy Framework), Sentry (Opens in a new tab) (transfer basis under investigation), Upstash (Opens in a new tab) (transfer basis under investigation). The Chapter V GDPR safeguard is stated for each vendor in the list. Where a vendor's basis is under investigation, we complete that investigation before these pages become binding. The same information appears in the sub-processor list in the Data Processing Agreement.

What are your rights?

In short: You can view, correct, erase and export your data — mostly right in the participant portal.

You have the right to access, rectify, erase, restrict, and port your personal data. You can also object to processing and withdraw consent at any time. The participant portal offers self-service for access, rectification, erasure, and data portability — the link is in your registration emails. Invoice data is subject to the Bookkeeping Act's retention requirement and cannot be erased early. You can also contact the course organizer or us using the details below.

Are any automated decisions made?

In short: No automated decisions are made about you. The waitlist is strict queue order.

The service makes no decisions based solely on automated processing that have legal effects on you or similarly significantly affect you (Article 22 GDPR). No profiling takes place. If a course is fully booked, registrations join a waitlist and are offered seats in order of registration time. Any further decisions to confirm or reject participants are made by the course organizer.

Where can you complain?

In short: You can complain to IMY.

If you believe your data is processed unlawfully you can lodge a complaint with the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten (Opens in a new tab), IMY), the supervisory authority for Sweden.

How do you contact us?

In short: Email us at info@kursregistrering.se.

The service is operated by Lubb IT AB (see the legal information below). For privacy questions, contact us at info@kursregistrering.se.

Legal information

Company
Lubb IT AB
Registration number
556938-6484
Registered seat
Linköping
Address
c/o Marcus Ludvigsson, Kerstinsgatan 13 lgh 1403, 582 13 Linköping, Sverige
VAT number
SE556938648401

← Back to legal overview

Kursregistrering.se© 2026
LegalPrivacy PolicyTerms of ServiceCookie PolicyData Processing AgreementSecurityAccessibility Statement