Data Processing Agreement
Last updated: October 2, 2026
1. Introduction
This Data Processing Agreement ("DPA") forms part of the Terms of Service between you ("Data Controller", "Controller", or "Operator") and Idunblue AB, company registration no. 559595-9791, VAT no. SE559595979101, Överälve, 827 93 Ljusdal, Sweden ("Data Processor", "Processor", or "Company") for the Idun Blue platform.
This DPA governs the processing of personal data by the Processor on behalf of the Controller in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR") and applicable Swedish data protection legislation.
2. Definitions
In this DPA, the following terms shall have the meanings set out below. Terms not defined here shall have the meaning assigned in the GDPR:
- "Personal Data" means any information relating to an identified or identifiable natural person processed by the Processor on behalf of the Controller through the Platform.
- "Processing" means any operation performed on Personal Data, including collection, storage, use, transmission, and deletion.
- "Sub-processor" means any third party engaged by the Processor to process Personal Data on behalf of the Controller.
- "Data Subjects" means the Members and other individuals whose Personal Data is processed through the Platform.
3. Scope and Purpose of Processing
The Processor shall process Personal Data solely for the purpose of providing the Idun Blue platform services to the Controller, as described in the Terms of Service. This includes:
- Storing and serving course content, community content, and member profiles
- Managing member authentication and access control
- Processing communications between the Controller and their Members (emails, messages)
- Processing payment transactions through Stripe
- Generating analytics and reports for the Controller
- AI assistance for content and administration according to documented instructions. Relevant personal data may be included; universal de-identification is not promised. Idun AI runs through Requesty Ltd. against a language model hosted on Microsoft Azure in Sweden; the creator may instead use their own Claude or Codex account or their own API key. Other AI features include content generation, summaries and translation of community posts. Own AI connections are also covered by the Controller’s agreement with the connected service. See the AI section of the privacy policy.
4. Categories of Personal Data
The following categories of Personal Data may be processed:
- Identity data: Name, email address, profile picture, username
- Authentication data: Hashed passwords, session tokens
- Activity data: Course progress, lesson completions, quiz responses, community interactions
- Communication data: Messages, email interactions, community posts
- Payment data: Billing information processed through Stripe (the Processor does not store full card details)
- Technical data: IP addresses, browser information, device identifiers
5. Categories of Data Subjects
Data Subjects include:
- Members who access courses, community, and other content
- Prospective members who interact with the Controller's public pages or forms
- The Controller's team members with access to the operator dashboard
6. Obligations of the Processor
The Processor shall:
- Process Personal Data only on documented instructions from the Controller, unless required by EU or Swedish law
- Ensure that persons authorized to process Personal Data are subject to confidentiality obligations
- Implement appropriate technical and organizational security measures as described in Section 8
- Engage Sub-processors only under the general prior authorization set out in Section 9
- Assist the Controller in responding to Data Subject requests
- Assist the Controller in ensuring compliance with obligations regarding data breach notification and data protection impact assessments
- Delete or return all Personal Data upon termination of the agreement, at the Controller's choice
- Make available all information necessary to demonstrate compliance with this DPA
7. Obligations of the Controller
The Controller shall:
- Ensure that there is a lawful basis for the processing of Personal Data
- Provide appropriate privacy notices to Data Subjects
- Ensure that instructions given to the Processor comply with applicable data protection laws
- Promptly notify the Processor of any Data Subject requests received directly
8. Security Measures
The Processor implements and maintains the following technical and organizational measures:
- Encryption: TLS for all data in transit. Passwords are stored as cryptographic hashes; access tokens for connected services are stored encrypted.
- Access control: Role-based access control, data isolation between workspaces, JWT-based authentication.
- Infrastructure: Application server and live database with Contabo GmbH in the EU; Cloudflare for proxy, DDoS protection and object storage. Sentry uses an EU region in Germany.
- Backups: The database is backed up automatically every night — 14 days on the server, 30 days on Google Drive. Scheduled database backups are encrypted before off-server storage; restoration requires Idun’s separately held key.
- Monitoring: Automated error monitoring with alerting.
- Personnel: Principle of least privilege; access to production data is limited to those who need it to operate and support the Service.
We hold no SOC 2 or ISO 27001 certification, and we do not claim to.
9. Sub-processors
The Controller gives general prior authorization for the Processor to engage the services below as Sub-processors where they process personal data on the Processor’s behalf. The list also includes optional connections; their contractual role depends on the actual processing and who engages the service. An own AI connection is not automatically Idun’s Sub-processor. Rows marked optional are used only when the feature is enabled.
The Processor shall notify the Controller at least 30 days before adding or replacing a Sub-processor. The Controller may object to the change within 14 days. Each Sub-processor is bound by data processing terms that provide at least the same level of data protection as this DPA.
10. Data Breach Notification
The Processor shall notify the Controller without undue delay, and in any event within 48 hours, after becoming aware of a Personal Data breach. The notification shall include:
- A description of the nature of the breach, including categories and approximate number of affected Data Subjects and records
- The name and contact details of the Processor's point of contact
- A description of the likely consequences of the breach
- A description of measures taken or proposed to address the breach
11. Data Subject Rights
The Processor shall assist the Controller in fulfilling Data Subject requests under GDPR Articles 15-22 (access, rectification, erasure, restriction, portability, objection). The Processor provides self-service data export tools and will respond to Controller-directed deletion requests within 30 days.
12. International Transfers
The application server and live database are hosted with Contabo in the EU. External providers and connected services may process data outside the EEA. See Section 9 and the privacy policy for storage and AI connections.
Processing outside the EEA requires an applicable transfer mechanism, such as an adequacy decision covering the recipient or Standard Contractual Clauses with any necessary supplementary safeguards. Contact us for information about the mechanism applicable to a particular service. An EU-hosted primary system does not mean all processing takes place within the EEA.
13. Audits
The Processor shall make available to the Controller all information necessary to demonstrate compliance with this DPA. The Controller may conduct audits or appoint an independent auditor, provided reasonable notice is given and the audit does not unreasonably disrupt the Processor's operations. The Processor currently holds no SOC 2 or ISO 27001 certification to offer in lieu of an audit.
14. Duration and Termination
This DPA applies for as long as the Processor processes Personal Data on behalf of the Controller. Upon termination of the Terms of Service, the Processor shall, at the Controller's election, delete or return all Personal Data within 30 days, and certify such deletion in writing.
15. Liability
Each party's liability under this DPA is subject to the limitations set forth in the Terms of Service. Nothing in this DPA shall limit either party's liability for breaches of GDPR where such limitation is not permitted by law.
16. Governing Law
This DPA is governed by the laws of Sweden and shall be subject to the jurisdiction of Swedish courts.
17. Contact
For questions about this DPA:
Idunblue AB
Company registration no.: 559595-9791
VAT no.: SE559595979101
Överälve, 827 93 Ljusdal, Sweden
Email: [email protected]
Website: idun.blue
