Skip to content
DOJO Future

GDPR Compliance

Last updated: December 2025

1. Our Commitment

As both a data controller (for our website visitors) and data processor (for our customers' data), we are committed to: • Processing personal data lawfully, fairly, and transparently • Collecting data only for specified, explicit purposes • Ensuring data accuracy and keeping it up to date • Retaining data only as long as necessary • Implementing appropriate security measures • Respecting data subject rights

2. Data Processing Activities

DOJO Future processes the following categories of personal data: • Student Data: Names, personal numbers, contact details, academic records, attendance, CSN status • Staff Data: Employee information, credentials, teaching assignments • LIA Company Data: Contact persons, placement records • Website Visitor Data: Contact form submissions, analytics All processing is based on legitimate legal grounds as defined in Article 6 GDPR.

3. Legal Basis for Processing

We process personal data under the following legal bases: • Contract Performance (Art. 6(1)(b)): To provide our services to educational institutions • Legal Obligation (Art. 6(1)(c)): MYH reporting requirements, tax obligations • Legitimate Interest (Art. 6(1)(f)): Service improvement, security • Consent (Art. 6(1)(a)): Marketing communications, analytics cookies

4. Data Subject Rights

Under GDPR, individuals have the following rights: • Right of Access (Art. 15): Request a copy of your personal data • Right to Rectification (Art. 16): Correct inaccurate data • Right to Erasure (Art. 17): Request deletion of your data • Right to Restrict Processing (Art. 18): Limit how we use your data • Right to Data Portability (Art. 20): Receive your data in a structured format • Right to Object (Art. 21): Object to certain processing activities • Rights Related to Automated Decision-Making (Art. 22) Requests will be processed within 30 days. Contact: nemanja.milosavljevic@infinetcode.se

5. Data Processing Agreements

When we process data on behalf of educational institutions (as data processor), we enter into Data Processing Agreements (DPA) in accordance with Article 28 GDPR. These agreements specify: • The scope and purpose of processing • Security measures implemented • Sub-processor arrangements • Data breach notification procedures • Audit rights

6. International Data Transfers

Our primary data storage is within the EU/EEA. When data transfers outside the EU/EEA are necessary (e.g., certain cloud services), we ensure appropriate safeguards: • EU Standard Contractual Clauses (SCCs) • Assessment of third-country legislation • Additional technical measures where required

7. Security Measures

We implement comprehensive technical and organizational security measures: • Encryption in transit (TLS 1.3) and at rest (AES-256) • Multi-factor authentication • Role-based access control (80+ permissions) • Regular security audits and penetration testing • Audit logging of all data access • Secure Swedish/EU hosting infrastructure • Employee training on data protection

8. Data Breach Procedures

In the event of a personal data breach, we will: • Notify the Swedish Authority for Privacy Protection (IMY) within 72 hours (when required) • Notify affected data subjects without undue delay if there is a high risk • Document all breaches and remedial actions • Notify our customers (data controllers) immediately

9. Data Protection Impact Assessments

We conduct Data Protection Impact Assessments (DPIAs) for processing activities that are likely to result in high risk to individuals, including: • Processing of student data at scale • Implementation of new system features • Changes to data processing activities

10. Sub-Processors

We use carefully selected sub-processors to deliver our services. All sub-processors are bound by data processing agreements and have been assessed for GDPR compliance. A list of sub-processors is available upon request.

11. Data Protection Officer

For data protection inquiries, please contact: InFiNet Code AB Data Protection Contact Email: nemanja.milosavljevic@infinetcode.se Phone: +46 72 513 13 33 Address: Gothenburg, Sweden

12. Supervisory Authority

You have the right to lodge a complaint with the supervisory authority: Swedish Authority for Privacy Protection (IMY) Integritetsskyddsmyndigheten Box 8114 104 20 Stockholm www.imy.se imy@imy.se