Idun Blue
ProductWhy Idun?PricingArticlesToolsHelp
EN / SV Log in Waitlist
ProductWhy Idun?PricingArticlesToolsHelp Log in
EN / SV Waitlist

Data Processing Agreement

Last updated: October 2, 2026

1. Introduction

This Data Processing Agreement ("DPA") forms part of the Terms of Service between you ("Data Controller", "Controller", or "Operator") and Idunblue AB, company registration no. 559595-9791, VAT no. SE559595979101, Överälve, 827 93 Ljusdal, Sweden ("Data Processor", "Processor", or "Company") for the Idun Blue platform.

This DPA governs the processing of personal data by the Processor on behalf of the Controller in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR") and applicable Swedish data protection legislation.

2. Definitions

In this DPA, the following terms shall have the meanings set out below. Terms not defined here shall have the meaning assigned in the GDPR:

  • "Personal Data" means any information relating to an identified or identifiable natural person processed by the Processor on behalf of the Controller through the Platform.
  • "Processing" means any operation performed on Personal Data, including collection, storage, use, transmission, and deletion.
  • "Sub-processor" means any third party engaged by the Processor to process Personal Data on behalf of the Controller.
  • "Data Subjects" means the Members and other individuals whose Personal Data is processed through the Platform.

3. Scope and Purpose of Processing

The Processor shall process Personal Data solely for the purpose of providing the Idun Blue platform services to the Controller, as described in the Terms of Service. This includes:

  • Storing and serving course content, community content, and member profiles
  • Managing member authentication and access control
  • Processing communications between the Controller and their Members (emails, messages)
  • Processing payment transactions through Stripe
  • Generating analytics and reports for the Controller
  • AI assistance for content and administration according to documented instructions. Relevant personal data may be included; universal de-identification is not promised. Idun AI runs through Requesty Ltd. against a language model hosted on Microsoft Azure in Sweden; the creator may instead use their own Claude or Codex account or their own API key. Other AI features include content generation, summaries and translation of community posts. Own AI connections are also covered by the Controller’s agreement with the connected service. See the AI section of the privacy policy.

4. Categories of Personal Data

The following categories of Personal Data may be processed:

  • Identity data: Name, email address, profile picture, username
  • Authentication data: Hashed passwords, session tokens
  • Activity data: Course progress, lesson completions, quiz responses, community interactions
  • Communication data: Messages, email interactions, community posts
  • Payment data: Billing information processed through Stripe (the Processor does not store full card details)
  • Technical data: IP addresses, browser information, device identifiers

5. Categories of Data Subjects

Data Subjects include:

  • Members who access courses, community, and other content
  • Prospective members who interact with the Controller's public pages or forms
  • The Controller's team members with access to the operator dashboard

6. Obligations of the Processor

The Processor shall:

  • Process Personal Data only on documented instructions from the Controller, unless required by EU or Swedish law
  • Ensure that persons authorized to process Personal Data are subject to confidentiality obligations
  • Implement appropriate technical and organizational security measures as described in Section 8
  • Engage Sub-processors only under the general prior authorization set out in Section 9
  • Assist the Controller in responding to Data Subject requests
  • Assist the Controller in ensuring compliance with obligations regarding data breach notification and data protection impact assessments
  • Delete or return all Personal Data upon termination of the agreement, at the Controller's choice
  • Make available all information necessary to demonstrate compliance with this DPA

7. Obligations of the Controller

The Controller shall:

  • Ensure that there is a lawful basis for the processing of Personal Data
  • Provide appropriate privacy notices to Data Subjects
  • Ensure that instructions given to the Processor comply with applicable data protection laws
  • Promptly notify the Processor of any Data Subject requests received directly

8. Security Measures

The Processor implements and maintains the following technical and organizational measures:

  • Encryption: TLS for all data in transit. Passwords are stored as cryptographic hashes; access tokens for connected services are stored encrypted.
  • Access control: Role-based access control, data isolation between workspaces, JWT-based authentication.
  • Infrastructure: Application server and live database with Contabo GmbH in the EU; Cloudflare for proxy, DDoS protection and object storage. Sentry uses an EU region in Germany.
  • Backups: The database is backed up automatically every night — 14 days on the server, 30 days on Google Drive. Scheduled database backups are encrypted before off-server storage; restoration requires Idun’s separately held key.
  • Monitoring: Automated error monitoring with alerting.
  • Personnel: Principle of least privilege; access to production data is limited to those who need it to operate and support the Service.

We hold no SOC 2 or ISO 27001 certification, and we do not claim to.

9. Sub-processors

The Controller gives general prior authorization for the Processor to engage the services below as Sub-processors where they process personal data on the Processor’s behalf. The list also includes optional connections; their contractual role depends on the actual processing and who engages the service. An own AI connection is not automatically Idun’s Sub-processor. Rows marked optional are used only when the feature is enabled.

Sub-processor Purpose Location
Contabo GmbH Server hosting — our database, queue and media files run on our own server with them EU
Cloudflare, Inc. Proxy, CDN and DDoS protection for all traffic; storage of podcast audio on ingest Global network and object storage
Stripe, Inc. Payments, subscriptions and payouts EU/US; see the transfers section
Resend Email delivery — both transactional mail and broadcasts US; processing may take place outside the EEA
Google LLC (Drive) Off-server storage of the daily database backup US; processing may take place outside the EEA
Google LLC (Gmail SMTP) Fallback path for email delivery when Resend is unavailable US; processing may take place outside the EEA
Requesty Ltd. Idun AI: routes AI assistance, content generation and member translation to the model, with zero retention of content; see the AI processing section EU region; the company is registered in the United Kingdom
Microsoft Ireland Operations Ltd. (Azure) Idun AI: runs the language model that Requesty routes to Sweden (Azure Sweden Central); the provider belongs to a US group
Anthropic PBC (Claude) (optional) Only when the creator connects their own Claude or their own Anthropic key US; processing may take place outside the EEA
Sentry (Functional Software, Inc.) Error monitoring — receives error reports and technical context when something breaks EU data region: Germany; US provider
Meta Platforms, Inc. (optional) Publishing to Instagram, and measurement via the pixel and Conversions API US; processing may take place outside the EEA
TikTok Technology Limited (optional) Receives videos the creator explicitly transfers as TikTok drafts or, after separate approval, publishes directly EU/US; see the transfers section
Google LLC (YouTube) (optional) Receives videos the creator explicitly uploads to their connected YouTube channel EU/US; see the transfers section
Google LLC (Analytics) (optional) Visitor measurement on the pages where you have switched it on US; processing may take place outside the EEA
OpenAI (optional) Only when the creator connects their own ChatGPT, Codex or their own OpenAI key US; processing may take place outside the EEA
Apple, Google, Mozilla (optional) Push notifications to phones and browsers US; processing may take place outside the EEA
EU-kommissionen (VIES) (optional) Validation of VAT registration numbers on business purchases EU

The Processor shall notify the Controller at least 30 days before adding or replacing a Sub-processor. The Controller may object to the change within 14 days. Each Sub-processor is bound by data processing terms that provide at least the same level of data protection as this DPA.

10. Data Breach Notification

The Processor shall notify the Controller without undue delay, and in any event within 48 hours, after becoming aware of a Personal Data breach. The notification shall include:

  • A description of the nature of the breach, including categories and approximate number of affected Data Subjects and records
  • The name and contact details of the Processor's point of contact
  • A description of the likely consequences of the breach
  • A description of measures taken or proposed to address the breach

11. Data Subject Rights

The Processor shall assist the Controller in fulfilling Data Subject requests under GDPR Articles 15-22 (access, rectification, erasure, restriction, portability, objection). The Processor provides self-service data export tools and will respond to Controller-directed deletion requests within 30 days.

12. International Transfers

The application server and live database are hosted with Contabo in the EU. External providers and connected services may process data outside the EEA. See Section 9 and the privacy policy for storage and AI connections.

Processing outside the EEA requires an applicable transfer mechanism, such as an adequacy decision covering the recipient or Standard Contractual Clauses with any necessary supplementary safeguards. Contact us for information about the mechanism applicable to a particular service. An EU-hosted primary system does not mean all processing takes place within the EEA.

13. Audits

The Processor shall make available to the Controller all information necessary to demonstrate compliance with this DPA. The Controller may conduct audits or appoint an independent auditor, provided reasonable notice is given and the audit does not unreasonably disrupt the Processor's operations. The Processor currently holds no SOC 2 or ISO 27001 certification to offer in lieu of an audit.

14. Duration and Termination

This DPA applies for as long as the Processor processes Personal Data on behalf of the Controller. Upon termination of the Terms of Service, the Processor shall, at the Controller's election, delete or return all Personal Data within 30 days, and certify such deletion in writing.

15. Liability

Each party's liability under this DPA is subject to the limitations set forth in the Terms of Service. Nothing in this DPA shall limit either party's liability for breaches of GDPR where such limitation is not permitted by law.

16. Governing Law

This DPA is governed by the laws of Sweden and shall be subject to the jurisdiction of Swedish courts.

17. Contact

For questions about this DPA:

Idunblue AB
Company registration no.: 559595-9791
VAT no.: SE559595979101
Överälve, 827 93 Ljusdal, Sweden
Email: [email protected]
Website: idun.blue

Idun Blue

A home for your work. A business to make a living from.

Internal beta. The first creators will be invited soon.

Product

Product demoFeaturesPricingCoursesSignup & follow-upPaymentsSwitch to IdunWaitlist

Resources

Courses on IdunHelp centreGuidesFree toolsAbout

Compare

vs Kajabivs Teachablevs Circlevs Skoolvs Simplerovs Mailchimp

Company

ContactTermsPrivacyDPA
Online course platformCoachesTherapistsYoga teachersBreathworkCourse creatorsMembership sites
AIWebsitesEmail & automationsPodcastCommunityAds & Analytics
© 2026 Idunblue AB
Language EN / SV Instagram LinkedIn

May we use optional cookies?

They help us understand what works and improve the site — for analytics and marketing. The site still works if you choose no.

What does this choice mean?

Necessary cookies:Always used for essential functions such as security and sign-in.

Analytics and marketing:Only enabled if you allow them. You can change your choice through Cookie settings in the footer.