Skillhabit Data
Processing Agreement

Last updated 22 June 2026

Annexes

ANNEX A

Instructions for carrying out the Processing

Subject matter

Provision of the Skillhabit cloud-based learning platform to the Controller, including user account management, content delivery, learning activity tracking and reporting.

Nature of the Processing

Hosting, storing, accessing, displaying, organizing, transmitting and (on Controller instruction) deleting Personal Data uploaded to or generated through the Skillhabit platform.

Purpose of the Processing

To provide the Services under the Main Agreement, namely to enable the Controller to distribute digital learning and follow up on learning activity.

Duration of the Processing

From acceptance of this DPA until termination of the Main Agreement, with deletion or return as set out in Section 11.2.

Categories of Data Subjects

Internal users (the Controller's employees and contractors who use the platform), external users (third parties to whom the Controller grants access for learning purposes) and administrators designated by the Controller.

Categories of Personal Data

(a) Account and identification data: name, work email address, employer, role and optionally national identification number (where the Controller chooses to use it as a user identifier).

(b) Profile data: contact information, language preference, learning team or group assignment.

(c) Learning activity data: course enrolments, learning progress, completion status, quiz and assessment scores, learning-path activity, engagement metrics, certificates earned.

(d) Technical data: device and browser information, IP address (for access logging and security), session identifiers.

(e) Communication data: messages sent through in-platform messaging features (if used).

(f) Any other Personal Data uploaded by the Controller or its users into the Skillhabit platform, including any optional fields configured by the Controller.

Special categories of Personal Data

The Skillhabit platform is not designed to process special categories of Personal Data under Article 9 GDPR. The Controller shall not upload such data unless it has separately confirmed with the Processor the technical and contractual conditions for doing so.

Retention

Personal Data is retained for the duration of the Main Agreement and deleted in accordance with Section 11.2. Specific retention rules for in-platform features (for example, training records retained for compliance purposes) are configurable by the Controller within the platform.

Contact information to the Processor's representative

Email: gdpr@tictac.se
Phone number: +46 40 631 88 30

ANNEX B

Approved Sub-Processors

The Sub-Processor List in force at the date of execution of this DPA is set out below and contains, for each Sub-Processor: legal entity name, address, the processing activity performed, whether the Sub-Processor transfers Personal Data outside the EU/EEA and, for any Sub-Processor that does, the transfer mechanism relied on. The Processor will keep this list up to date and will notify the Controller of any addition or replacement of a Sub-Processor in accordance with Section 6.2.

Sub-Processors (legal entities)

Skillhabit AB
Address: Dockplatsen 1, 211 19 Malmö, Sweden
Processing activity: Development, maintenance and technical support of the learning platform.
Transfer outside the EU/EEA: No

GleSYS AB
Address: Box 134, 311 22 Falkenberg, Sweden
Processing activity: Data storage, server hosting and DNS services.
Transfer outside the EU/EEA: No

BACTO NET (Stackhero)
Address: 1 rue de Stockholm, 75008 Paris, France
Processing activity: Logging and event queue system. Logs may contain limited data (IP/email) for up to 30 days.
Transfer outside the EU/EEA: No

AppSignal B.V.
Address: P.O. Box 10212, 1001 EE Amsterdam, Netherlands
Processing activity: Front-end error detection and temporary URL-based debugging.
Transfer outside the EU/EEA: No

Simple Analytics B.V.
Address: Jacob van Lennepstraat 78 H, 1053 HM Amsterdam, Netherlands
Processing activity: Privacy-first analytics. Tracks views and sessions without PII.
Transfer outside the EU/EEA: No

Rapidmail GmbH
Address: Wentzingerstraße 21, 79106 Freiburg, Germany
Processing activity: Legacy email provider. Stores sent emails for one year for traceability.
Transfer outside the EU/EEA: No

BunnyWay d.o.o.
Address: Cesta Komandanta Staneta 4A, 1215 Medvode, Slovenia
Processing activity: CDN, website assets and video storage.
Transfer outside the EU/EEA: No

OpenAI Ireland Ltd
Address: 1st Floor, The Liffey Trust Centre, 117-126 Sheriff Street Upper, Dublin 1, Ireland
Processing activity: AI services for processing user-submitted content and course context.
Transfer outside the EU/EEA: Yes
Transfer mechanism: EU Standard Contractual Clauses (SCCs), Commission Decision (EU) 2021/914 of 4 June 2021.

Lettermint B.V.
Address: Willemsvaart 16B, Unit 1.08, 8019 AB Zwolle, Netherlands
Processing activity: Email service provider. Stores sent emails for one year for traceability.
Transfer outside the EU/EEA: No

Bouncer Sp. z o.o.
Address: ul. Cypriana Kamila Norwida 24/1, 50-374 Wrocław, Poland
Processing activity: Email verification and bounce rate protection.
Transfer outside the EU/EEA: No

ANNEX C

Technical and organizational security measures

This Annex describes at a functional level the technical and organizational measures the Processor implements to protect Personal Data processed under this DPA. The Processor maintains ISO/IEC 27001 certification covering the Skillhabit Services and may rely on that certification as evidence of compliance with this Annex. The Processor may update this Annex from time to time, provided the overall level of protection is not materially reduced.

1. Encryption

Personal Data is encrypted in transit using industry-standard protocols (TLS 1.2 or higher) and at rest using strong cryptographic algorithms appropriate to the data category. Video files served through the Processor's content delivery network Sub-Processor (identified in Annex B) are stored without at-rest encryption, consistent with industry practice for video content delivery; that Sub-Processor maintains ISO/IEC 27001 certification.

2. Access control and authentication

Access to Personal Data is restricted on a need-to-know basis. The Processor enforces role-based access control, strong authentication for administrative accounts (including multi-factor authentication where appropriate) and individual user accountability.

3. Network security

The Processor implements perimeter defences (firewalls, intrusion detection), network segmentation between environments and protection against denial-of-service attacks.

4. System hardening and vulnerability management

Servers and applications are configured according to documented hardening standards. The Processor performs regular vulnerability scanning, applies security patches in a risk-prioritized manner and conducts periodic penetration testing of the Skillhabit Services.

5. Backup and disaster recovery

The Processor performs regular backups of Personal Data, stores backups in geographically separated locations, encrypts backups at rest and tests recovery procedures.

6. Logging and monitoring

Security-relevant events are logged, retained for a defined period and monitored for indicators of compromise. The Processor maintains incident detection capabilities sufficient to identify Personal Data Breaches within the timelines specified in Section 4.5.

7. Incident management

The Processor maintains a documented incident response procedure covering identification, containment, eradication, recovery, notification and post-incident review.

8. Personnel screening and training

Personnel with access to Personal Data are bound by confidentiality obligations and receive periodic data protection and information security training.

9. Secure software development

The Processor follows a documented secure software development lifecycle, including code review, dependency management and pre-release security testing.

10. Data segregation

Personal Data of each Controller is logically segregated from that of other Controllers within the Skillhabit Services.