Data Processing Agreement
Last updated: 2026-09-22
This English version is a convenience translation — the Swedish version governs.
Version history
- — Counsel-reviewed final edition of the whole legal pack; effective on this date.
- — Original DPA version with the sub-processor list (draft).
Version: 2026-09-22
The boxed summaries are reading aids, not the binding text.
1. Introduction
1.1Annex to the Terms of Service: This data processing agreement (the "DPA") constitutes an annex to the terms of service (the "Terms of Service") in force between Lubb IT AB (reg. no: 556938-6484) and the Course Organizer regarding the Course Organizer's use of Kursregistrering.se (the "Platform"). The Course Organizer and Lubb IT AB are below jointly referred to as the "Parties".
1.2Roles and scope: This DPA is entered into in accordance with Article 28 of the EU General Data Protection Regulation (EU) 2016/679 (the "GDPR") and governs the Parties' rights and obligations when Lubb IT AB processes personal data on the Course Organizer's behalf within the framework of providing the Platform. For such processing, the Course Organizer is the controller and Lubb IT AB the processor.
1.3Applicable data protection legislation: The Parties shall each ensure compliance with applicable legislation on the processing of personal data, including the GDPR and supplementary national data protection legislation ("Applicable Data Protection Legislation").
1.4Precedence over the Terms of Service: In the event of a conflict between this DPA and the Terms of Service, the DPA shall take precedence in matters concerning Lubb IT AB's processing of personal data on the Course Organizer's behalf.
1.5Annexes to the DPA: The following annexes form an integral part of the DPA:
- Annex: Instructions.
- Annex: Approved Sub-processors.
- Annex: Security Measures.
1.6Definitions under the GDPR: This DPA uses definitions from the GDPR, such as "personal data", "processing", "data subject", "controller" and "processor". These terms have the same meaning as in Article 4 of the GDPR.
2. The Course Organizer's undertakings and representations
2.1The Course Organizer's responsibilities: The Course Organizer hereby represents that it:
- ensures that there is a valid legal basis for the processing and that the data subjects have received the information required under Applicable Data Protection Legislation;
- ensures that the instructions given to Lubb IT AB are lawful, accurate and sufficient for the processing;
- shall without undue delay inform Lubb IT AB if the instructions change or need to be supplemented; and
- shall without undue delay inform Lubb IT AB of such requests from data subjects, supervisory authorities or other third parties that Lubb IT AB needs to know of in order to fulfil its obligations under the DPA.
2.2Assessment of security measures: The Course Organizer confirms that the technical and organizational security measures that Lubb IT AB undertakes to implement, as set out in Annex: Security Measures, are appropriate in view of the processing covered by the DPA, and that Lubb IT AB thereby provides sufficient guarantees in accordance with Article 28(1) of the GDPR.
3. Lubb IT AB's undertakings
3.1Lubb IT AB's obligations: Lubb IT AB:
- may only process personal data on documented instructions from the Course Organizer, including with regard to transfers of Personal Data to a third country or an international organization, unless such processing is required under Union law or the national law of a Member State to which Lubb IT AB is subject; in that case, Lubb IT AB shall inform the Course Organizer of that legal requirement before the data is processed, unless such information is prohibited on important grounds of public interest under that law. This DPA and Annex: Instructions constitute the Course Organizer's documented instructions to Lubb IT AB;
- shall immediately inform the Course Organizer if Lubb IT AB considers that an instruction infringes the GDPR or other Union or Member State data protection provisions. While the Course Organizer investigates the objection, Lubb IT AB is entitled to suspend the processing in question;
- ensures that persons authorized to process the personal data have committed themselves to confidentiality by written agreement or are under an appropriate statutory obligation of confidentiality. The duty of confidentiality continues to apply after this DPA has terminated;
- shall, taking into account the nature of the processing, assist the Course Organizer by appropriate technical and organizational measures, insofar as this is possible, so that the Course Organizer can fulfil its obligation to respond to requests for exercising the data subject's rights in accordance with Chapter III of the GDPR;
- shall assist the Course Organizer in ensuring that the obligations are fulfilled concerning security of processing (Article 32 of the GDPR), notification of a personal data breach to the supervisory/data protection authority (Article 33 of the GDPR), communication of a personal data breach to the data subject (Article 34 of the GDPR), data protection impact assessments (Article 35 of the GDPR) and prior consultation with the supervisory authority (Article 36 of the GDPR), taking into account the nature of the processing and the information available to Lubb IT AB;
- shall, at the choice of the Course Organizer, delete or return all personal data to the Course Organizer after the end of the provision of processing services, and delete existing copies unless storage of the personal data is required under Union law or the national law of a Member State. Return and deletion shall take place in accordance with Annex: Instructions; and
- shall, to the extent practically possible and lawful, without undue delay notify the Course Organizer of requests for disclosure of personal data, or of information concerning the processing, received from a data subject, an authority or another third party, and shall in such cases refer the matter to the Course Organizer. Lubb IT AB is not entitled to represent the Course Organizer or act on its behalf towards a supervisory authority or another third party, unless the Course Organizer approves this in writing.
- shall keep a written record, which can be kept in electronic form, of all categories of processing carried out on behalf of the Course Organizer, in accordance with Article 30(2) GDPR. The record shall contain:
- the name and contact details of us and of the Course Organizer and, where applicable, of the Course Organizer’s or our representative and data protection officer,
- the categories of processing carried out on behalf of the Course Organizer,
- where applicable, transfers of personal data to a third country, including the identification of that third country and, in the case of transfers referred to in the second subparagraph of Article 49(1), the documentation of suitable safeguards, and
- a general description of the technical and organizational security measures referred to in Article 32(1).
We keep the record up to date and make it available on request to the supervisory authority and, insofar as it concerns processing on behalf of the Course Organizer, to the Course Organizer.
4. Sub-processors
4.1General prior authorization: The Course Organizer hereby gives Lubb IT AB a general written prior authorization to engage other processors ("Sub-processors") to carry out specific processing on the Course Organizer's behalf. The Sub-processors approved in advance by the Course Organizer are listed in the version of Annex: Approved Sub-processors in force at any given time.
4.2Requirements on Sub-processors: Where Lubb IT AB engages a Sub-processor to carry out specific processing on the Course Organizer's behalf, the same data protection obligations as set out in the DPA shall be imposed on the Sub-processor by way of a contract or another legal act under Union or Member State law. The Sub-processor shall in particular provide sufficient guarantees to implement appropriate technical and organizational measures in such a manner that the processing meets the requirements of the GDPR.
4.3Liability for Sub-processors: Where the Sub-processor fails to fulfil its data protection obligations, Lubb IT AB shall remain fully liable to the Course Organizer for the performance of the Sub-processor's obligations.
4.4Changes of Sub-processors: The Course Organizer shall be informed in advance of any intended engagement of a new Sub-processor or replacement of an existing Sub-processor, and be given the opportunity to object in writing to the change. Information about the change can be provided through the Platform a reasonable time before the new or replacement Sub-processor begins processing personal data on the Course Organizer's behalf.
4.5Objection to Sub-processors: If the Course Organizer has justified data-protection-related grounds to object to a new or replacement Sub-processor, the Parties shall seek to find a reasonable solution. If no such solution can be reached, the Course Organizer is entitled to terminate the part of the service affected by the change or, where this is not possible, the agreement under the Terms of Service.
5. third-country transfers
5.1Transfers outside the EU/EEA: If Lubb IT AB, or a Sub-processor engaged by Lubb IT AB, transfers personal data to, or makes personal data accessible from, a country outside the EU/EEA, such transfer shall take place in accordance with Chapter V of the GDPR and only where a valid transfer mechanism exists, such as an adequacy decision, the EU standard contractual clauses or binding corporate rules.
5.2Information about the transfer mechanism: Lubb IT AB shall on request provide the Course Organizer with information about the transfer mechanism applied to the third-country transfers taking place under the DPA.
6. Security
6.1Technical and organizational security measures: Lubb IT AB undertakes to implement the measures required under Article 32 of the GDPR, taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of the processing, as well as the risks to the rights and freedoms of natural persons. This includes, among other things, that Lubb IT AB shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk. In assessing the appropriate level of security, particular account shall be taken of the risks presented by the processing, in particular the risk of accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or unauthorized access to, the personal data. The technical and organizational security measures that Lubb IT AB undertakes to implement are set out in more detail in Annex: Security Measures.
6.2Changes to the security measures: Lubb IT AB decides how the measures are to be implemented within its operations in order to achieve the required level of protection. Lubb IT AB is entitled to change the implemented measures, provided that the ensured level of security is not lower than the level ensured by the measures in place when the DPA was entered into.
6.3Compliance with security requirements: Lubb IT AB represents that its operations are conducted in a manner that ensures that the provisions and requirements of the GDPR on adequate protection of processing are complied with and achieved.
6.4Evaluation and updating of the security measures: Lubb IT AB shall regularly evaluate the effectiveness of the technical and organizational security measures and update them as needed to ensure a continued appropriate level of protection in accordance with Article 32 of the GDPR.
7. Audits
7.1Information to demonstrate compliance: Lubb IT AB shall give the Course Organizer access to all information, and provide the details and documents, necessary to demonstrate that the obligations of Lubb IT AB under this DPA and Article 28 of the GDPR have been fulfilled.
7.2Audits and inspections: Lubb IT AB shall allow for and contribute to audits and inspections of the processing of personal data covered by this DPA, conducted by the Course Organizer or by an auditor mandated by the Course Organizer, to the extent required under the GDPR.
7.3Audits by the supervisory authority: Lubb IT AB shall allow the competent supervisory authority to carry out the audits required under Applicable Data Protection Legislation concerning the processing of personal data.
7.4Audit conditions: The following practical conditions apply to audits:
- The audit shall be notified to Lubb IT AB at least thirty (30) calendar days in advance;
- The Course Organizer is entitled to conduct no more than one audit per calendar year, unless there are justified reasons, such as a personal data breach or reasonable grounds to suspect a serious deviation from this DPA or applicable data protection legislation;
- The audit shall be carried out at the Course Organizer’s expense, and Lubb IT AB is entitled to charge the Course Organizer for the costs arising from the audit.
- The audit shall only concern the processing of personal data that Lubb IT AB carries out on the Course Organizer's behalf under this DPA;
- The audit must not entail the disclosure of trade secrets or other protected information in breach of applicable law.
8. Personal data breach
8.1Notification of a personal data breach: Lubb IT AB shall inform the Course Organizer in writing without undue delay after becoming aware of a personal data breach concerning personal data covered by this DPA. The written notification shall be sent in writing by e-mail and shall, where possible:
- describe the nature of the personal data breach including, where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned,
- communicate the name and contact details of the data protection officer or another contact point where more information can be obtained,
- describe the likely consequences of the personal data breach, and
- describe the measures Lubb IT AB has taken or proposed to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects.
8.2Supplementary information: If it is not possible to provide all the information under clause 8.1 at the same time, the information may be provided in phases without further undue delay.
8.3Assistance in the event of a personal data breach: Lubb IT AB shall also assist the Course Organizer with the information necessary for the Course Organizer's potential notification to the supervisory authority and communication to the data subjects concerned.
8.4Documentation of personal data breaches: Lubb IT AB shall document all personal data breaches covered by the DPA, including the circumstances of the personal data breach, its effects and the corrective measures taken.
9. Liability
9.1Liability for damages: For damages arising from incorrect or unlawful processing of personal data which, under a final judgment or a settlement, are to be paid to the data subject due to an infringement of the provisions of this DPA and/or applicable data protection legislation, Article 82 of the GDPR shall apply, including its provisions on the allocation of liability and recourse between the Parties.
9.2Administrative fines: Administrative fines imposed under Article 83 of the GDPR or Chapter 6 of lagen (SFS 2018:218) med kompletterande bestämmelser till EU:s dataskyddsförordning (the Swedish act with supplementary provisions to the EU General Data Protection Regulation) shall be borne by the Party on which the fine is imposed. However, if a fine is imposed on a Party as a result of the other Party's infringement of the provisions of this DPA and/or Applicable Data Protection Legislation, the infringing Party shall indemnify and hold the non-infringing Party harmless for the damage the non-infringing Party has incurred as a result of the administrative fine and the infringing Party's conduct.
9.3Exclusive remedy: The obligation of the Party concerned to hold the other Party harmless under clauses 9.1 and 9.2 shall constitute the other Party's sole and exclusive right to compensation in connection with the infringement of applicable data protection legislation.
10. Term
10.1Term of the DPA: This DPA applies for as long as Lubb IT AB processes personal data on the Course Organizer's behalf and terminates only when such processing has ended in accordance with the DPA and Annex: Instructions.
11. Governing law and dispute resolution
11.1Governing law: The DPA shall be interpreted in accordance with Swedish law.
11.2Dispute resolution: Disputes arising in connection with this DPA shall be finally settled through the dispute resolution procedure set out in the Terms of Service.
Annex: Instructions
In addition to what is set out in the DPA, Lubb IT AB shall follow the instructions below when processing personal data on the Course Organizer's behalf.
1. Subject matter of the processing
The processing concerns personal data that Lubb IT AB processes on the Course Organizer's behalf within the framework of the provision and use of the Platform.
2. Purposes of the processing
The personal data may be processed to administer the Course Organizer's courses through the Platform, including to:
- manage course registrations and participant details,
- administer payment and invoicing records,
- communicate with Course Participants in connection with registration and course administration,
- record and administer attendance,
- create, administer and make available course certificates and other records of completed courses,
- conduct and administer course evaluations, and
- otherwise carry out such processing as is necessary for the Platform features the Course Organizer uses for its course administration.
3. Categories of personal data
The processing may include the following categories of personal data:
| Type of data | Details |
|---|---|
| Identification and contact details | First name, surname, personal identity number (personnummer), e-mail address and telephone number. |
| Employment and organization details | Employer, organization and other details about the Course Participant's professional affiliation. |
| Invoicing details | Invoicing details and other data needed for the administration of payment and invoicing of course fees. |
| Course and participant records | Details of course sign-up, registration, attendance, completed courses and course certificates. |
| Profession-related data | For example, details of professional license, license number, specialty and continuing education, to the extent such data is processed for the course in question. |
| Evaluation data | Answers and other information submitted in connection with course evaluations. |
| Other data | Other personal data that the Course Organizer collects or otherwise processes through the Platform within the scope of the features used. |
4. Categories of data subjects
The processing may concern the following categories of data subjects:
- Course Participants and persons registering for the Course Organizer's courses,
- users and other contact persons at the Course Organizer, and
- contact and invoicing persons at companies or other organizations that register Course Participants for the Course Organizer's courses or are responsible for paying course fees to the Course Organizer.
5. Processing activities
Lubb IT AB may carry out the following processing on the Course Organizer's behalf:
- collect and record personal data submitted through the Platform,
- structure, organize and store personal data,
- display and make personal data available to authorized users,
- use and process personal data to perform the Platform features the Course Organizer uses,
- generate and make available documents and records, such as course certificates and invoicing records,
- send automated messages and other course-related communication in accordance with the Course Organizer's instructions,
- import and export personal data,
- change, rectify, restrict and delete personal data, and
- otherwise process personal data to the extent necessary for the purposes set out in section 1.
6. Place of processing
Personal data may be processed within the EU/EEA and, where relevant, in a third country in accordance with section 5 of the DPA. The Sub-processors engaged for the processing and their respective processing locations are set out in the version of Annex: Approved Sub-processors in force at any given time.
7. Retention period and deletion
The following retention and deletion rules apply to personal data processed on the Course Organizer's behalf:
| Situation | Retention and deletion |
|---|---|
| Course records | Personal data linked to courses and Course Participants is retained for two (2) years after the end of the course in question. The data is then purged from the active Platform, with the exception of the data that needs to be kept for the validation of course certificates already issued. |
| Validation of course certificates | The personal data necessary to validate a course certificate already issued may be processed for the certificate's period of validity. If the Course Organizer requests deletion of the data, the certificate can then no longer be validated via the Platform. |
| Ended subscription period | The end of a subscription period does not in itself mean that the personal data is deleted. Instead, the customer account transfers to the Platform's free tier, and the personal data is processed and purged in accordance with this annex and the Terms of Service. |
| Ended processing or closed customer account | When Lubb IT AB's processing of personal data on the Course Organizer's behalf ends, the personal data shall be deleted or returned in accordance with clause 3.1 f) of the DPA. |
| Backups | When personal data is erased from our active systems, it can remain in backups for up to thirty (30) calendar days before it is erased or overwritten. |
Annex: Approved Sub-processors
The Course Organizer hereby gives its express approval for Lubb IT AB to engage the processors listed below ("Sub-processors") for the processing of personal data on the Course Organizer's behalf in accordance with section 4 of the DPA.
| Sub-processor | Purpose | Data categories | Region | Transfer basis | Vendor terms |
|---|---|---|---|---|---|
| Required for the service | |||||
| Supabase (Opens in a new tab)Supabase Pte. Ltd | Database, authentication, and file storage | All data categories in section 3 | EU | standard contractual clauses (SCCs) | Processing terms — Supabase (Opens in a new tab) |
| Resend (Opens in a new tab)Plus Five Five, Inc. | Transactional email delivery | Name, email address, email content | US | adequacy decision: EU-US Data Privacy Framework | Processing terms — Resend (Opens in a new tab) |
| Vercel (Opens in a new tab)Vercel, Inc. | Application hosting and content delivery | All data passing through the application | EU/Global | adequacy decision: EU-US Data Privacy Framework | Processing terms — Vercel (Opens in a new tab) |
| Sentry (Opens in a new tab)Functional Software, Inc. d/b/a Sentry | Error monitoring (consent-gated in the browser) | Technical error data; IP address | EU | adequacy decision: EU-US Data Privacy Framework | Processing terms — Sentry (Opens in a new tab) |
| Upstash (Opens in a new tab)Upstash, Inc. | Distributed rate limiting (Redis) | IP addresses and transient counters | EU | adequacy decision: EU-US Data Privacy Framework | Processing terms — Upstash (Opens in a new tab) |
| Engaged only when the feature is used | |||||
| Stripe (Opens in a new tab)Stripe, Inc. | Subscription and per-course billing (Kursregistrering.se's own billing of the organization) | The organization's billing details | EU/US | adequacy decision: EU-US Data Privacy Framework | Processing terms — Stripe (Opens in a new tab) |
Annex: Security Measures
The security measures Lubb IT AB applies to the processing covered by the DPA are described below.
1. Access control and authentication
Lubb IT AB applies the following measures for access control and authentication:
- Organization users sign in to the Platform with individual user accounts.
- Server operations that change data are subject to authorization checks that verify the user's session, membership and role in the organization.
- Access to personal data is restricted based on the user's permissions and organization membership.
- Course Participants access participant pages through personal links intended for a specific purpose.
- Public endpoints are subject to rate limiting.
2. Isolation between organizations
The Platform is a multi-tenant service. Lubb IT AB applies the following measures to keep different organizations' data separate:
- Database tables containing organization data are protected by Row Level Security (RLS).
- Database queries are restricted by organization membership to prevent unauthorized access to other organizations' data.
- The isolation between organizations is covered by automated tests that run when the Platform is changed.
3. Encryption
Lubb IT AB applies the following encryption measures:
- Traffic to and from the Platform is encrypted in transit with TLS.
- Personal data is encrypted at rest through the security features provided by Lubb IT AB's infrastructure providers, including for database storage and backups.
- API keys are stored in encrypted configuration in the production environment and not in the Platform's codebase.
4. Backups and continuity
Lubb IT AB applies the following measures for backups and continuity:
- The production database is backed up automatically.
- Backups are encrypted at rest.
- The Platform's application layer is stateless and runs on managed, redundant infrastructure.
- The application layer can be redeployed or restored to an earlier version independently of the production database.
5. Incident management
Lubb IT AB maintains routines for handling security incidents and personal data breaches, which include:
- an internal incident response plan,
- a designated person responsible for assessing and handling incidents,
- measures to investigate, contain and handle identified incidents,
- documentation of incidents in an internal incident log, and
- assessment of incidents against applicable notification and information obligations.
6. Technical security measures and monitoring
Lubb IT AB applies technical measures to prevent, detect and handle security-related events in the Platform, which include:
- error monitoring and technical troubleshooting,
- rate limiting for public endpoints,
- authorization checks for server operations that change data, and
- automated tests of the isolation between different organizations' data.
7. Vulnerability management
Lubb IT AB provides a dedicated channel for reporting suspected security vulnerabilities in the Platform.
Reported vulnerabilities are investigated and handled based on their impact on the confidentiality, integrity and availability of the Platform and the personal data.
8. Review of the security measures
Lubb IT AB regularly evaluates the effectiveness of the security measures and updates them as needed in view of changes to the Platform, the processing and identified security risks.