Data processing agreement

How Playsa processes personal data on behalf of your organisation: what we do, who helps us, how we protect the data and what happens when the agreement ends.

Version 1.0, in effect from 16 September 2026

On this page

This is a translation for your information. The Swedish version applies.

Agreement under Article 28 of the General Data Protection Regulation (GDPR) between an organiser, which is the data controller, and Hodla AB, which is changing its name to Playsa AB, which is the data processor.

Parties

  1. Data controller: the organisation that has accepted the agreement in Playsa's portal for organisers. Called "the controller".
  2. Data processor: Hodla AB, which is changing its name to Playsa AB, company registration number 559427-7252, Vimpelgatan 1, 211 14 Malmö. Called "Playsa".

1. Background and how the agreement is entered into

1.1 The parties have an agreement on Playsa's service under the Terms for organisers ("the main agreement").

1.2 When Playsa delivers the service, Playsa processes personal data on behalf of the controller. This agreement governs that processing.

1.3 The agreement is entered into electronically when an administrator at the controller accepts it in the claim or in the portal. It applies from when Playsa has approved the claim, or from the acceptance if the claim is already approved. Playsa stores who accepted, when and which version applied.

1.4 The agreement is based on the European Commission's standard contractual clauses between controllers and processors (Implementing Decision (EU) 2021/915), shortened and adapted.

2. Definitions

The terms personal data, processing, controller, processor, data subject, personal data breach and supervisory authority have the same meaning as in the GDPR. In addition:

  • The service: Playsa's search page and portal for organisers, and the parts added under the main agreement.
  • Sub-processor: a party engaged by Playsa that processes personal data covered by the agreement.
  • Instruction: the controller's documented instruction under section 5.1.
  • Data protection rules: the GDPR, the Swedish Act (2018:218) with supplementary provisions to the EU General Data Protection Regulation and other applicable data protection legislation.

3. Roles and the boundary with Playsa's own responsibility

3.1 For the personal data the controller enters or receives in the service, the controller is the data controller and Playsa the processor. Today this covers bookings of trial sessions and queue registrations that have been sent to the controller, the queue's entries, offers and deviations, and the controller's photos. The processing is described in annexes 1 and 2.

3.2 Playsa is itself the data controller for the search page, the parents' family accounts and the bookings and queue registrations that parents make, until the booking or queue registration has been sent to the controller. From that moment the controller is responsible for its handling of it, for example who gets a place, and Playsa processes it as a processor under this agreement.

3.3 Playsa is also itself responsible for:

  • a) the controller's users and contact persons, their sign-ins and the invoicing of the subscription,
  • b) security logs and operation of the platform, to the extent required to protect the service as a whole,
  • c) reports about photos submitted with the button at the photo.

3.4 Playsa does not use the controller's data for its own purposes, for example marketing or profiling.

4. The controller's obligations

The controller shall:

  • have a legal basis for every processing and inform the data subjects, also that Playsa is used,
  • only enter the personal data that is needed,
  • not enter personal identity numbers, health data or other sensitive data, not even in free text,
  • give people access with the least possible privileges and ask Playsa to remove anyone who should no longer have access,
  • protect its sign-ins and notify Playsa immediately on suspicion of unauthorised access,
  • for photos, follow section 10 a of the main agreement,
  • carry out its own data protection impact assessment when required,
  • ensure that the instructions to Playsa comply with the data protection rules.

5. Playsa's obligations

5.1 Instructions

  • Playsa processes the personal data only according to the controller's documented instructions.
  • The instructions are this agreement with its annexes, the main agreement and the features and settings the controller chooses in the service.
  • Playsa may process the data without an instruction only when Union or Swedish law requires it. Playsa then informs the controller first, unless the law prohibits it.
  • If Playsa considers that an instruction infringes the data protection rules, Playsa informs the controller immediately.

5.2 Confidentiality

Playsa ensures that everyone who processes the data has committed to confidentiality or is under a statutory obligation of confidentiality, and that they only have access to what they need for their task.

5.3 Security

Playsa takes the technical and organisational measures required by Article 32. The measures are set out in annex 4. Playsa may change the measures provided the level of protection is not lowered.

5.4 Sub-processors

  • The controller gives Playsa a general authorisation to engage sub-processors. Those engaged today are listed in annex 3.
  • Playsa informs the controller's administrators by email at least 30 days before Playsa adds or replaces a sub-processor.
  • The controller may object within 30 days on reasonable grounds. If the parties find no solution, the controller may terminate the main agreement free of charge before the change takes effect.
  • Playsa enters into written agreements with the sub-processors with the same obligations as in this agreement.
  • Playsa is liable to the controller for the sub-processors' work.

5.5 Transfers to third countries

  • Playsa transfers personal data to a country outside the EU and the EEA only on the basis of Chapter V of the GDPR.
  • The transfers and their grounds are set out in annex 3. The grounds are the European Commission's Decision (EU) 2023/1795 on the EU-U.S. Data Privacy Framework for certified US recipients, and standard contractual clauses under Implementing Decision (EU) 2021/914.
  • Playsa has assessed the consequences of the transfers for Supabase, Vercel and Sentry and shows the assessments to the controller on request.
  • If the Data Privacy Framework is invalidated, or the conditions change in some other way, Playsa informs the controller and takes measures.

5.6 Assistance with the data subjects' rights

  • Playsa helps the controller to show, correct, disclose and delete data about a data subject, on request and free of charge.
  • If Playsa receives a request from a data subject concerning the controller's data, Playsa forwards it within five working days. Playsa does not reply itself unless the controller has instructed it to.
  • Playsa helps the controller to reply within the time the GDPR requires.

5.7 Other assistance

Playsa assists the controller with security, personal data breaches, data protection impact assessments and prior consultation under Articles 32 to 36, taking into account the nature of the processing and the information available to Playsa. Playsa's data protection impact assessment may be used as a basis and is provided on request.

5.8 Personal data breaches

Playsa notifies the controller without undue delay and no later than 24 hours after Playsa has become aware of a personal data breach concerning data Playsa processes on behalf of the controller. Times and contents are set out in annex 6. The controller assesses whether the breach is to be reported to IMY and whether the data subjects are to be informed. Playsa assists.

5.9 Deletion and return

When the main agreement ends, Playsa returns and deletes the data under annex 8.

5.10 Audits

Playsa provides the controller with the information needed to demonstrate compliance with Article 28, and allows audits under annex 7.

5.11 Records and contact with IMY

  • Playsa keeps records of processing under Article 30.2.
  • Playsa cooperates with IMY on request.
  • If IMY contacts Playsa about the controller's processing, Playsa informs the controller, where permitted.

5.12 Requests from public authorities

If a public authority, also in a country outside the EU, requests data, Playsa refers it to the controller where possible. Playsa examines the request, discloses only what the law requires and informs the controller unless prohibited.

5.13 Public organisers

If the controller is a municipality or another public authority, the following also applies:

  • Playsa assists when the controller has to disclose public records, preserve data under archival rules or assess secrecy.
  • Playsa processes the data only for technical processing and storage under the agreement.

6. Remuneration

Playsa's work under the agreement is included in the price under the main agreement. On-site audits under annex 7 are remunerated by agreement.

7. Liability

  • The parties' liability towards the data subjects follows Article 82 of the GDPR.
  • Between the parties, each is liable for damage caused by its own breaches of the agreement or of the data protection rules.
  • An administrative fine is borne by the party it is imposed on.
  • The limitation of liability in section 15 of the main agreement also applies to this agreement.

8. Term

The agreement applies for as long as the main agreement applies and thereafter for as long as Playsa processes data on behalf of the controller.

9. Changes

  • Playsa announces changes by email to the controller's administrators at least 30 days before they take effect. A change is accepted in the portal.
  • Annex 3 is changed under section 5.4.
  • If changed law or a decision by a public authority requires a change, the parties shall negotiate in good faith.

10. Precedence

In the event of conflict, this agreement takes precedence over the main agreement in matters of personal data. Standard contractual clauses the parties enter into take precedence over both.

11. Law and disputes

Swedish law applies. Disputes are tried by the ordinary courts with Malmö District Court as the court of first instance.

Annexes:

  1. The processing
  2. Categories of data subjects and personal data
  3. Sub-processors and transfers
  4. Security measures
  5. Storage and deletion
  6. Breach handling with deadlines
  7. Audits and reviews
  8. Termination and a copy of the data
  9. Contact persons

Annex 1. The processing

Part Description
Subject matter Personal data the controller enters or receives in the service
Duration For as long as the main agreement applies, plus the time in annex 8
Nature Collection, storage, organisation, retrieval, use, display to the controller's users, mailings on behalf of the controller and deletion
Purpose To deliver the service to the controller under the main agreement

The parts of the service and what Playsa does in them:

  • Trial sessions: receives bookings for the controller's sessions, counts the places and shows the bookings to the controller's administrators and office.
  • Queue: keeps the queue's entries in order by time and the group's priority rules, sends offers and reminders, records deviations with reasons and shows the queue to the controller's administrators and office.
  • Alerts and reminders: emails the controller's administrators and office when a queue and a free place exist at the same time, when a yes is waiting for word and when the places status is old. The alerts contain counts, never names.
  • Photos, when the feature opens: stores, re-encodes and shows the controller's photos on the search page and in Playsa's apps, hides photos after a report and removes them, under section 10 a of the main agreement.
  • Support and troubleshooting: at the controller's request under annex 4, O6.

New parts are added under section 9.

Annex 2. Categories of data subjects and personal data

Data subjects:

  • children who have been booked for a trial session or are in a queue at the controller,
  • guardians who have booked a trial session or put the child in a queue,
  • people who appear in the controller's photos.

Personal data:

Category Examples Protection
The child First name and year of birth Other parents never see the child's name
Guardian Email, when the controller needs it for a booking or an offer
Trial sessions Session and the booking's status
Queue Place, time, status, offers and replies, deviations with reasons The parent sees deviations concerning their own child
Photos Images in which people can be recognised, alt text without names, who confirmed and when Metadata is removed. The original is not stored.

The service processes no personal identity numbers, health data or other sensitive data on behalf of the controller.

Annex 3. Sub-processors and transfers

Sub-processors in use:

Sub-processor Does for Playsa Where the data is processed Contracting party Transfer ground Notifies Playsa of a breach
Supabase Database, sign-in, queues and scheduling for mailings, backups Region eu-north-1, Stockholm. Under the agreement the data is stored in that region and processed mainly there. Supabase's staff and support may access the data from the USA, Singapore and other countries. Supabase Pte. Ltd, Singapore. Supabase Inc., USA, provides support as a sub-processor. Standard contractual clauses, modules 2 and 3 Without undue delay and where possible within 48 hours
Vercel The website and the portal, server functions, firewall and the running of scheduled mailings The server functions in Stockholm. Parts of the delivery, for example the CDN and the connection, take place in Vercel's network worldwide. Vercel Inc., USA Vercel states that the company is certified under the EU-U.S. Data Privacy Framework. Standard contractual clauses, modules 1, 2 and 3, are in Vercel's agreement as a fallback. Without undue delay after a confirmed breach
Brevo Email: codes for claims, alerts and reminders to organisers, confirmations and offers to parents EU: OVH in France and Germany, fallback at Google Cloud in Belgium Sendinblue SAS, France, trading as Brevo No transfer from Playsa. Brevo's own sub-processors for support functions outside the EU, Cloudflare and Zendesk in the USA and Sinch in the United Kingdom, are covered by standard contractual clauses, the Data Privacy Framework and in part binding corporate rules. Without undue delay
Sentry Error reports, stripped of IP addresses, cookies and query strings. The reports go via Playsa's own address on Vercel in Stockholm. The EU region in Frankfurt. Accounts and some metadata are in the USA. Functional Software, Inc., USA EU-U.S. Data Privacy Framework, with standard contractual clauses module 2 as a fallback Without undue delay

Planned sub-processors, not in use today and added under section 5.4:

  • GatewayAPI, ONLINECITY.IO ApS, Denmark: SMS. The data in Germany with a fallback in Finland. No transfer outside the EU and the EEA.
  • Expo, 650 Industries, Inc., USA: notifications in Playsa's apps, delivered via Apple and Google.
  • Stripe, Stripe Payments Europe, Limited, Ireland: payments.
  • Idura, Idura ApS, Denmark: BankID.

Annex 4. Security measures

Technical measures:

  • T1 Isolation. Authorisation is checked in the service layer at every call. Row Level Security in Postgres on every table with the controller's data is the second line of defence. A table without a policy is closed.
  • T2 Isolation tests. A test suite tries to read other organisations' and other families' data. Changes are not merged with red tests.
  • T3 Encryption at rest and in transit. Supabase encrypts the database and the backups with AES-256. The connections use TLS, and the database refuses connections without TLS.
  • T4 Two-factor authentication. Everyone who uses the portal signs in with two-factor authentication. So does Playsa's staff in the systems where the data is held.
  • T5 Audit log. Administrative actions are written to a log that cannot be changed through the service: who, what and when. The controller gets its own log on request.
  • T6 Logging without personal data. Playsa's logs mask email addresses, phone numbers and personal identity numbers. Error reports are stripped of IP addresses, cookies and query strings.
  • T7 Application protection. Validation at every boundary, CSP, HSTS, secure cookies, CSRF protection and rate limits.
  • T8 Region. The database and the server functions are in Stockholm.
  • T9 Backups. Daily backups.
  • T10 Minimal content in mailings. Email contains at most the child's first name. Alerts to the controller contain counts only.
  • T11 Photos, when the feature opens. The photos are re-encoded, all metadata is removed and the original is not stored. The photos are delivered only from playsa.se, and search engines are asked not to show them in image search.
  • T12 Sensitive data, before it is stored. Personal identity numbers and health data are encrypted per field with AES-256-GCM and a key per organisation, and the master key is kept separate from the database.

Organisational measures:

  • O1 Confidentiality. Anyone who works for Playsa and has access to personal data has committed to confidentiality.
  • O2 Least privilege. Only those at Playsa who need access to production have it. Secrets exist only in environment variables, never in the code.
  • O3 Tested changes. Changes are tested with automated tests, including the isolation tests, before they are merged.
  • O4 Penetration test. An external penetration test is carried out before the service stores personal identity numbers or health data.
  • O5 Incident routine. Playsa has a written incident plan that is rehearsed. The deadlines towards the controller are set out in annex 6.
  • O6 Support access. Playsa reads the controller's data only when needed for support the controller has asked for, to fix an error, to handle an incident or when the law requires it.
  • O7 Training. Anyone given access to personal data goes through the routines for data protection and security.

Annex 5. Storage and deletion

The service's periods apply to every organiser. If the controller wants something deleted earlier, the controller gets in touch and Playsa deletes it. Deletion runs every night.

Data Deleted
Bookings of trial sessions 12 months after the session
The queue's entries, offers and deviations 12 months after the child left the queue, was removed or got a place
Closed alerts 12 months after the alert was closed
Mailing log 90 days
Audit log 24 months
Photos Under section 10 a of the main agreement
Backups Deleted data remains in the backups for at most 30 days

Annex 6. Breach handling with deadlines

When What Playsa does
Immediately on suspicion Limits the damage, secures logs and starts the incident routine.
No later than 24 hours after becoming aware First notification to the controller's administrators by email, and by phone if the controller has provided a number: what happened, when, which data and how many people are likely affected.
No later than 48 hours after becoming aware Supplementary information under Article 33.3: likely consequences, measures taken and planned and a contact person at Playsa. This gives the controller the basis to report to IMY within 72 hours.
Ongoing New information is sent as soon as it exists. What cannot be provided at once is provided in phases.
On request Playsa helps to inform the data subjects, for example by email.
No later than 30 days after becoming aware Final report with cause and measures.
  • The controller assesses whether the breach is to be reported to IMY and whether the data subjects are to be informed.
  • If the breach affects several organisers, each gets its own notification.
  • The sub-processors notify Playsa under annex 3. Playsa's deadline runs from when Playsa became aware, also when the breach started at a sub-processor.

Annex 7. Audits and reviews

  • Playsa answers a questionnaire on security and data protection once a year free of charge.
  • Playsa provides the sub-processors' audit reports, for example SOC 2, where the sub-processor permits it.
  • Playsa provides on request a summary of the penetration test in annex 4, O4, once it has been carried out.
  • The controller, or an independent auditor with a confidentiality undertaking, may audit Playsa on site or remotely once a year, with 30 days' notice. More often after a breach or when IMY requires it.
  • The controller bears its own costs for the audit. If the audit requires more than one working day of Playsa, Playsa is remunerated by agreement.
  • IMY's right to audit is not affected.

Annex 8. Termination and a copy of the data

  • The controller can get a copy of its data at any time. Playsa provides it in CSV or JSON within 30 days, free of charge.
  • After the main agreement has ended, the controller can get a copy for 60 days.
  • After that Playsa deletes the controller's data within 30 days. Deleted data remains in the backups for at most 30 more days.
  • Playsa confirms the deletion in writing on request.
  • Data that Playsa itself is responsible for, for example the parents' family accounts and their bookings and queue places, is handled under Playsa's privacy policy.
  • If the law requires Playsa to keep something, Playsa tells the controller what and why.

Annex 9. Contact persons

Role The controller Playsa
Agreement and data protection The administrators in the portal hej@playsa.se. The address dataskydd@playsa.se goes to the same inbox.
Breaches The administrators in the portal, and a phone number if the controller has provided one hej@playsa.se, with "Incident" in the subject line
Data protection officer The controller notifies Playsa if it has one Playsa has no data protection officer
Postal address Vimpelgatan 1, 211 14 Malmö