Back to terms and conditions
This document is a translation of the Swedish original, provided for convenience. In the event of any discrepancy, the Swedish version — Integritetspolicy (GRADR-LEG-09) — is the legally binding version.

PRIVACY POLICY

Gradr’s processing as controller

Issuer: Gradr AB, corporate identity number 559475-9630, Brännkyrkagatan 103 B, 117 26 Stockholm, Sweden

Document ID: GRADR-LEG-09

Version: 2.0

Date: 3 September 2026

Replaces: the version most recently updated on 15 April 2026

Contents

1. What this policy covers
2. Controller and contact
3. Data protection officer
4. When Gradr is the controller and when Gradr is a processor
5. Processing for which Gradr is responsible
6. Where the data comes from
7. Recipients
8. Where data is processed
9. Cookies and tracking on gradr.se
10. Security
11. Your rights
12. Complaints
13. Changes to this policy
14. Contact
15. Revision history

1. What this policy covers

This policy describes the processing of personal data for which Gradr AB is the controller, in other words where Gradr itself determines the purposes of and means for the processing. The policy covers Gradr’s customer register, Gradr’s own mailings, contract administration, bookkeeping, recruitment, enquiries from persons other than users of Gradr’s platform, and the website gradr.se.

The policy does not cover the processing of pupil and teacher data in Gradr’s platform. In that processing, the school organiser is the controller and Gradr is a processor. That processing is governed by the data processing agreement entered into between the organiser and Gradr, and information to pupils, teachers and guardians is provided by the organiser. Section 4 states what applies and where you should turn.

Gradr provides this information in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council, the General Data Protection Regulation.

2. Controller and contact

Gradr AB, corporate identity number 559475-9630, Brännkyrkagatan 103 B, 117 26 Stockholm, Sweden.

Data protection questions concerning Gradr’s own processing: privacy@gradr.se

Suspected unauthorised access or security issues: security@gradr.se

3. Data protection officer

Gradr has not appointed a data protection officer. This assessment has been made under Article 37(1) of the General Data Protection Regulation and covers both of Gradr’s roles, that is both Gradr’s own processing and the processing carried out as a processor.

Gradr is not a public authority or public body, so Article 37(1)(a) does not apply. Gradr’s assessment is that the processing involves neither regular and systematic monitoring of data subjects at large scale within the meaning of Article 37(1)(b), nor large-scale processing of data covered by Article 9 within the meaning of Article 37(1)(c). The basis for that assessment — which personal data the platform processes and how it logs access — appears from Annex 1 points 2 and 6 of the data processing agreement and from Gradr’s DPIA documentation.

Gradr will re-assess if the scale of the processing changes. The assessment concerns Gradr’s own obligation under Article 37 and does not replace the school organiser’s assessment under Articles 24, 35 and 37, which the organiser makes in its capacity as controller.

4. When Gradr is the controller and when Gradr is a processor

The distinction between these two roles is decisive and determines where you should turn.

SituationWho is the controllerWhere you should turn
You are a pupil or a teacher and your data is processed in Gradr’s platform, for example exam answers, feedback, account and class membershipYour school organiser, that is the municipality or the independent organiser. Gradr is a processor and processes the data on the organiser’s behalf and following the organiser’s instructionsThe organiser’s data protection officer
You use the platform and need help with how it worksYour school organiser. You receive the help from Gradr, but Gradr processes the data in the matter on the organiser’s behalf, and that processing is therefore not covered by this policyThe support function in the platform. If your question concerns data protection, you should turn to the organiser’s data protection officer
You are a contact person at a customer or a prospective customer, or you have contacted Gradr without being a user of the platformGradr ABprivacy@gradr.se
You visit gradr.seGradr ABprivacy@gradr.se
You apply for a job at GradrGradr ABprivacy@gradr.se

If you are unsure which situation applies, contact privacy@gradr.se and Gradr will look into the matter.

5. Processing for which Gradr is responsible

The data covered by this policy is essentially contact data in a professional capacity, that is names, titles, employers and business contact details of people at municipalities, school organisers and schools. Within the scope of this policy, Gradr processes no data about pupils, exam answers or feedback.

PurposeCategories of personal dataLegal basisRetention period
Customer register and sales: recording and keeping up-to-date information about contact persons at municipalities, school organisers and schools, and being able to follow up on dialoguesName, title, employer, business contact details, notes from contactsLegitimate interests under Article 6(1)(f). The interest is being able to conduct sales and customer care towards organisations. The data concerns people in their professional capacityFor the duration of the customer relationship and thereafter for at most twenty-four months from the most recent contact
Gradr’s own mailings of information about the service to contact persons at customers and prospective customersName and business email addressLegitimate interests under Article 6(1)(f) for mailings to existing customers. For mailings to others, Gradr obtains consent under Article 6(1)(a) in accordance with Section 19 of the Marketing Act (2008:486)Until the recipient objects to further mailings
Enquiries and matters from persons other than users of the platform, that is questions about Gradr’s services, contract questions and other approachesName, contact details, substance of the matterLegitimate interests under Article 6(1)(f)While the matter is ongoing and thereafter for at most twenty-four months
Contract administration with customersName and contact details of contract signatories and contact personsLegitimate interests under Article 6(1)(f). The contract is entered into with your organisation and not with you personally. For what must be retained by law, the legal basis is legal obligation under Article 6(1)(c)For the term of the contract and thereafter as required for bookkeeping and for being able to assert legal claims
Bookkeeping and invoicingName, contact details and information in supporting documentsLegal obligation under Article 6(1)(c), the Bookkeeping Act (1999:1078)Seven years after the end of the calendar year in which the financial year was closed
The website gradr.se: providing a functioning website and protecting it against attacksTechnical data, such as IP addresses, in the website’s server logsLegitimate interests under Article 6(1)(f)According to the web server log routine applied by the supplier that delivers the website
RecruitmentName, contact details, application documentsLegitimate interests under Article 6(1)(f). The interest is being able to run the recruitment and thereafter to be able to meet any claim of discriminationDuring the recruitment and thereafter for two years, having regard to the limitation period under the Discrimination Act (2008:567)
Fulfilment of legal obligations and handling of legal claimsThe data that is necessary in the individual caseLegal obligation under Article 6(1)(c) and legitimate interests under Article 6(1)(f) in order to establish, exercise or defend legal claimsDuring the handling and thereafter until the claim is time-barred, in the normal case at most ten years under the Statute of Limitations Act (1981:130)

Mailings to you as a user of the platform. Information about the platform that is sent to teachers and school administrators in their capacity as users is not Gradr’s own processing. It takes place on the school organiser’s instructions under point 1(b), seventh indent of Annex 1 to the data processing agreement and is described in section 7 of Gradr’s user agreement. Gradr does not use data about users in the platform for its own mailings under the table above, which follows from point 9(b) of Annex 1 to the same agreement, and keeps the two sets of recipients separate.

Consent to Gradr’s own mailings. Gradr does not send marketing mailings by electronic mail to a natural person who has not beforehand consented to it, except where the second paragraph of Section 19 of the Marketing Act applies. The consent is obtained when the recipient themselves signs up for Gradr’s mailings and can be withdrawn at any time.

On legitimate interests. Where Gradr relies on legitimate interests, Gradr has weighed its interest against the data subject’s interests and fundamental rights. The processing concerns people in their professional capacity, involves no special categories of personal data and involves no profiling. For recruitment, application documents may contain data that the applicant has provided themselves and that is covered by Article 9. Gradr does not request such data. You have the right to object; see section 11. Gradr provides, on request, an account of an individual balancing.

If you must provide the data. You are not obliged to provide personal data to Gradr. However, for Gradr to be able to administer a contract with your organisation, handle a matter or assess your application, the data stated in the table above is needed. If it is not provided, Gradr cannot carry out the action in question.

What Gradr does not do. Gradr does not sell personal data. Gradr does not use personal data for advertising. Gradr makes no automated decisions with legal effects or similarly significant effect on you under Article 22 of the General Data Protection Regulation within the scope of its own processing. The prohibition on using personal data from the platform to train or fine-tune AI models follows from point 9(a) of Annex 1 to the data processing agreement and also binds sub-processors.

6. Where the data comes from

From you yourself, when you contact Gradr, sign up for a mailing, apply for a job or provide data in a matter.

From your organisation, when it enters into a contract with Gradr or appoints you as contact person.

From public sources, for data about contact persons in their professional capacity at municipalities, school organisers and schools.

7. Recipients

The following suppliers process personal data on Gradr’s behalf within the scope of Gradr’s original processing.

SupplierWhat they are used for
Hetzner Online GmbHServer operations, storage and email server for Gradr’s own systems, with processing in Helsinki, Finland
GoogleDelivery of the website gradr.se, which is a separate installation on infrastructure other than the platform
AttioGradr’s register of business contacts at municipalities, school organisers and schools. Attio processes contact data in a professional capacity
DiscordInternal notification to Gradr’s staff about events in support sessions. The notification contains session identifiers, links into the service and the name of the employee taking over. Personal data about end users is excluded by the system’s design and is not sent to Discord
Positive Group Deutschland GmbH, brand rapidmailTool for Gradr’s own mailings of information about the service to contact persons at customers and prospective customers under section 5, with processing within the EU or EEA

Gradr engages rapidmail in two separate capacities. For Gradr’s own mailings under section 5, the supplier is a processor for Gradr. For mailings of non-transactional information about the platform to teachers and school administrators, the supplier is instead a sub-processor under the data processing agreement entered into by the school organiser, and is listed there in Annex 2. The two processing operations have distinct purposes, distinct sets of recipients and distinct legal bases.

The suppliers engaged for the processing in the platform, that is where Gradr is a processor for a school organiser, are partly different and are listed in Annex 2 to the data processing agreement.

In addition to the suppliers above, Gradr may provide personal data to

  1. public authorities, such as the Swedish Tax Agency, the Swedish Authority for Privacy Protection or the Swedish Police Authority, when required by law or an authority decision,
  2. the customer organisation, that is your school organiser or employer, in matters concerning the contract, and
  3. auditors and legal advisers, within the scope of their engagement.

Everyone at Gradr who processes personal data has undertaken to observe confidentiality. The undertaking also applies after the employment or engagement has ended.

8. Where data is processed

Personal data in Gradr’s platform is processed within the EU and EEA. This follows from point 7 of Annex 1 to the data processing agreement, and the account is given in Annex E to Gradr’s DPIA documentation.

This policy concerns Gradr’s own tools for customer contact and administration. Information about where an individual supplier processes the data, and about which protective measures are applied if the processing takes place outside the EU and EEA, is provided on request to privacy@gradr.se.

9. Cookies and tracking on gradr.se

The website sets no cookies. It loads no third-party scripts, that is no tools for visitor statistics or tracking. Nor does the website have any measurement pixel or any third-party chat function. The only scripts that occur are embedded blocks with structured metadata about the website’s own content.

Because no cookies are set, no consent question arises under Chapter 6, Section 18 of the Electronic Communications Act (2022:482). Should this change, Gradr will provide the website with a consent function before cookies that are not necessary for providing the requested service are set, and will update this policy.

10. Security

Gradr takes technical and organisational measures to protect personal data under Article 32 of the General Data Protection Regulation, adapted to the data this policy covers. The measures include, among other things, encryption in transit with TLS, role-based access control and logging of access. For the suppliers stated in section 7, each supplier is responsible for the measures in its own service.

The security measures that apply to the processing in the platform are stated in point 5 of Annex 1 to the data processing agreement and in Part 6 of Gradr’s DPIA documentation.

11. Your rights

The rights below apply to the processing where Gradr is the controller. If your request concerns data in the platform, you should turn to your school organiser, which is the controller there. Gradr assists the organiser under the data processing agreement.

Access, Article 15. You have the right to know whether Gradr processes your personal data, to obtain a copy of it and to receive information about the processing.

Rectification, Article 16. You have the right to have inaccurate data rectified and incomplete data completed.

Erasure, Article 17. You have, in certain cases, the right to have your data erased, for example when it is no longer needed for the purpose for which it was collected, or when you have objected to processing based on legitimate interests and Gradr has no overriding legitimate grounds that carry greater weight. The right does not apply where Gradr is obliged to retain the data, for example under the Bookkeeping Act.

Restriction, Article 18. You have the right to request that the processing be restricted, for example while an objection or the accuracy of data is being examined.

Data portability, Article 20. You have the right to obtain the data you have yourself provided to Gradr in a structured, commonly used and machine-readable format, and to have it transferred to another controller where it is technically possible. The right applies to processing based on consent or contract and that is carried out by automated means. It therefore does not apply to processing based on legitimate interests or legal obligation.

Objection to direct marketing, Article 21(2). If you object to your data being used for direct marketing, Gradr will stop that processing. You do not need to state any reason. You report it to privacy@gradr.se.

Objection in other cases, Article 21(1). You have the right, on grounds relating to your specific situation, to object at any time to processing based on legitimate interests. Gradr will then stop the processing unless there are overriding legitimate grounds that carry greater weight than your interests, rights and freedoms.

Withdraw consent, Article 7(3). Where processing is based on your consent, you can withdraw it at any time. The withdrawal does not affect the lawfulness of processing that has already taken place.

You exercise your rights by contacting privacy@gradr.se. Gradr answers a request without undue delay and at the latest within one month. If the request is complicated, Gradr may extend the period by two months, and you will then be notified of that within the first month. Gradr may need to request additional information in order to identify you before the request is carried out.

12. Complaints

If you are dissatisfied with how Gradr processes your personal data, you have the right to lodge a complaint with the Swedish Authority for Privacy Protection.

Swedish Authority for Privacy Protection, Box 8114, 104 20 Stockholm, Sweden. Email imy@imy.se, telephone +46 8 657 61 00, website imy.se.

You are welcome to contact Gradr first, but you do not need to do so before complaining.

13. Changes to this policy

Gradr may update this policy. The latest version is published on gradr.se with the date of the latest update. In the event of material changes, Gradr will specifically inform affected data subjects, where possible.

14. Contact

Data protection questions concerning Gradr’s own processing: privacy@gradr.se.

Questions about Gradr’s user agreement: privacy@gradr.se.

Suspected unauthorised access or security issues: security@gradr.se.

Questions about the processing in the platform: your school organiser’s data protection officer.

15. Revision history

VersionDateChange
Without version number2026-04-15The version that version 2.0 replaces
2.02026-09-03The policy delimited to the processing where Gradr is the controller. The processing in the platform, its security measures and the support to users referred to the data processing agreement, so that each relationship is described in one place only. The allocation of roles between controller and processor clarified with a table. Legal bases and retention periods stated per purpose. Sections on recipients, on where data is processed, on cookies and on the data protection officer added. The right to data portability delimited to the bases under which it applies.