This Data Processing Agreement (the "DPA") governs the Processor's processing of personal data on behalf of the Controller. The DPA forms part of, and applies together with, the main agreement on the use of the Schackappen service (the "Main Agreement"). In the event of a conflict regarding the processing of personal data, the DPA prevails over the Main Agreement.
Controller (the school/principal organiser):
Name / organiser Organisation number Address Contact person and emailProcessor:
Schackappen, operated by Ulf Austin Cato, Sweden.
Organisation number: to be stated upon signing.
Contact: ulf@schackappen.se
The parties are referred to below individually as a "Party" and jointly as the "Parties".
The Processor provides the web-based chess education service Schackappen, including a student app and a teacher portal. For the service to work, the Processor processes certain personal data about students, teachers and principals on behalf of the Controller. The purpose of the DPA is to meet the requirements of Article 28 of the EU General Data Protection Regulation (GDPR) and to protect the rights of the data subjects.
Terms such as "personal data", "processing", "controller", "processor", "sub-processor", "data subject" and "personal data breach" have the same meaning as in the GDPR (Regulation (EU) 2016/679).
About the student (child):
About the teacher or principal (adult):
About the school: the school's name, contact email, subscription and trial status, and email addresses of invited teachers.
The Processor notifies the Controller without undue delay after becoming aware of a personal data breach and assists with information reasonably needed for the Controller's possible notification to the supervisory authority and the data subjects.
The Controller gives the Processor a general written authorisation to engage sub-processors in order to deliver the service. The Processor ensures that each sub-processor is bound by data protection obligations equivalent to those in this DPA. The Controller is informed in advance of any planned changes to sub-processors so that objections can be made. At the time of signing, the following sub-processors are engaged:
| Sub-processor | Function | Location / transfer |
|---|---|---|
| Supabase | Database and authentication (storage of student, teacher and principal data) | Storage within the EU. DPA with Standard Contractual Clauses. |
| Netlify, Inc. | Hosting and serverless functions that deliver the website, app and portal | US-based company. EU-US Data Privacy Framework and the European Commission's Standard Contractual Clauses (SCCs). |
| Resend | Sending transactional emails (account and invitation emails to teachers and principals) | US-based company. EU-US Data Privacy Framework and Standard Contractual Clauses (SCCs). |
Personal data is stored primarily within the EU/EEA (Supabase). Some sub-processors (Netlify and Resend) are US-based. Such transfers are made on the basis of valid transfer mechanisms under GDPR Chapter V, primarily the EU-US Data Privacy Framework and the European Commission's Standard Contractual Clauses (SCCs). No other transfers to third countries take place without such a mechanism in place.
The Controller is responsible for ensuring that there is a legal basis for the processing, that the data subjects (or their guardians) have been informed to the extent required, and that the instructions given to the Processor are lawful.
The Parties' liability for damages is governed by Article 82 of the GDPR and by the liability provisions of the Main Agreement. Limitations of liability in the Main Agreement also apply to this DPA to the extent compatible with mandatory law.
The DPA applies for as long as the Processor processes personal data on behalf of the Controller. Upon termination, the personal data is deleted or returned in accordance with section 7.7. When a student, class or school is removed in the service, the associated personal data is deleted.
Amendments to this DPA must be in writing. The version in force from time to time is published on this page with an updated date. Material changes to sub-processors are notified in accordance with section 9.
This DPA is governed by Swedish law. Disputes shall be settled by the Swedish general courts, with Stockholm District Court as the court of first instance, unless otherwise required by mandatory law.
This DPA is signed in two copies, one for each Party.
For the Controller
Place and date Signature Name in printFor the Processor
Place and date Signature Name in print: Ulf Austin Cato, Schackappen