Municipal templates
321school can use this DPA draft directly or complete the municipality's own DPA template, including templates based on KS/SkoleSec or Digdir structure.
- • This page provides the information needed to complete common DPA appendices.
- • The municipality may request that the same information is transferred into its own template.
- • Project-specific details such as contacts, regions and sub-processors should be confirmed before signing.
Parties and roles
The school or school owner is normally the controller for school use. 321school acts as processor when processing personal data on behalf of the school.
- • Controller: school or school owner.
- • Processor: 321school.
- • Users: teachers, students, parents/guardians and school administrators where relevant.
Purpose
Personal data is processed to provide digital learning activities, Spaces, assignments, feedback, administration and related support.
- • Provide access to rooms, assignments, quizzes and learning activities.
- • Allow teachers to follow up student work.
- • Support account, billing and school administration where enabled.
Feide and authentication
When Feide login is used, Feide and the connected identity provider authenticate the user. 321school receives the identity information needed to create and maintain access to the service.
- • Feide approval by a school owner allows users from that school owner to sign in; it does not by itself create a paid school agreement.
- • 321school processes login identity data only to provide account access, security, support and documented school administration.
- • 321school does not request national identity numbers for ordinary use.
Categories of data
The categories depend on how the school uses 321school.
- • Anonymous Spaces: technical user ID, display name, room membership and submitted work.
- • Accounts: name, email where available, role, profile data, login provider, saved work, feedback and activity needed for the service.
- • Teacher/school: rooms, assignments, generated content, administration and support information.
Storage location
The main Firestore database for the active 321school Firebase project is located in europe-west1, Belgium. Other provider-specific processing locations should be confirmed before signing.
- • Core Firestore data is stored at rest in europe-west1 (Belgium).
- • Firebase Authentication processes authentication data in the United States according to Firebase documentation; transfers should rely on Google's Firebase data processing terms and SCCs where applicable.
- • The active school Storage bucket 321skole-storage is located in the EU multi-region.
- • AI, hosting, email and payment providers may have separate processing locations described in the sub-processor overview.
No commercial resale or advertising
321school does not process school data for sale of personal data, third-party advertising or targeted advertising.
- • Student work and profile data are not sold.
- • School data is not used to build advertising profiles.
- • Personal data is processed for the documented service purposes and according to the agreement with the school/school owner.
AI and student use
Students in Spaces normally do not use AI directly. Signed-in students may use AI features in self-study where account use and such functions have been approved.
- • Teachers may use AI to create or adapt content before sharing.
- • AI use should be assessed by the school before systematic student use.
- • For children under 13, account use and AI features should be clarified by school or guardians.
Sub-processors
321school may use sub-processors to provide hosting, authentication, storage, AI, payment and email services.
- • A current sub-processor overview is available and should be confirmed before signing.
- • 321school should notify schools of material changes where required by agreement.
- • Sub-processors should only be used for documented service purposes.
Deletion and return
When school use ends, personal data should be deleted or returned according to the school’s instructions, unless law or necessary service records require continued storage.
- • Teachers can remove or archive students from Spaces.
- • Schools can request deletion of school-related data.
- • Backups and technical logs may follow separate retention cycles that should be specified before signing.
Security and confidentiality
321school should use appropriate technical and organizational measures to protect personal data.
- • Access control for user roles.
- • Secure authentication through the identity provider in use.
- • Logging and monitoring appropriate for service operation.
- • Feide login where enabled by the school owner.