Technical and Organisational Measures
| Supplier | Yuzu Educational Thinking AB, company reg. no. 559558-8137 |
| Service | Pomelo – SaaS for systematic student wellbeing work, socio-emotional learning and student participation |
| Version / date | v1.3, 2026-09-07 |
| Responsible | Magnus Lindberg, Head of Technology |
| Review | Annually and upon material change |
This is the published version of the technical and organisational measures that form an annex to the data processing agreement. In the event of any discrepancy, the signed Swedish annex governs.
1. Scope and personal data
The measures below protect the processing carried out in Pomelo. The scope of the processing is deliberately limited by the design of the service:
- Staff (users): name, email address and role/permissions.
- Students: no personal data is processed. Responses are submitted anonymously without logging in. Only aggregates at group/class level are stored. Aggregates are presented only at a level that does not permit identification of individual students (a view with only one respondent is not shown).
For schools connected via Skolon, class lists are retrieved automatically. The students are counted to give the class its size and year group, and no data about individual students is stored. Student accounts created by earlier versions of the service are deleted automatically at every synchronisation. Only staff accounts are created via Skolon, and students do not log in to the service.
No special categories of personal data (Art. 9) are processed.
2. Access control and authentication
- Authentication: staff sign in via email with a one-time code (OTP), with a username and password if the school has chosen that, via SSO with the school's Google or Microsoft account, or via Skolon. Students never sign in.
- Authorisation: role-based access following the principle of least privilege; a user can reach only what their role requires.
- Lifecycle: the school's administrator deactivates user accounts when a person should no longer have access.
- Internal access: access to the production environment is limited to Yuzu's founders.
3. Encryption
- In transit: all communication is protected with TLS. Traffic passes through Cloudflare, which terminates TLS at its edge network and establishes a new TLS session to the operating environment at Elastx. No part of the transport is unencrypted. On the current plan there is no contractual geographic restriction on where termination takes place.
- At rest: primary data on Elastx block and object storage is encrypted at rest with AES-256 at the infrastructure level. Yuzu applies no additional encryption layer at application or volume level on top of this. Backups are encrypted in accordance with section 5.
4. Operations, storage and data location
Hosting: the service is operated by the Swedish cloud provider Elastx AB, certified to ISO/IEC 27001:2022 (certificate 0095098, valid until 2027-12-09).
All storage takes place in Sweden. The database and the application runtime are hosted at Elastx in Sweden. Backups are stored in accordance with section 5. No personal data is stored outside the EU/EEA.
Traffic passes a US provider in transit. Cloudflare, Inc. provides DNS, proxy and TLS termination. Data therefore passes a provider subject to US legislation, but only in transit and without being stored with them. The transfer is made on the basis of standard contractual clauses under Cloudflare's data processing agreement.
- Architecture: multi-tenant solution with logical separation of data per school organisation.
- Technical platform: .NET backend, React/Vite frontend, MariaDB, nginx, containerised operation (Docker).
5. Backup and continuity
- Backup: automatic daily backups of the database.
- Location and retention: one copy is kept in the operating environment at Elastx in Sweden and is deleted after 7 days. One copy is transferred every night to Yuzu's own off-site storage at the company's address in Sweden and is deleted after 30 days. No backup is kept longer than 30 days.
- Backup encryption: the copy at Elastx is covered by the encryption at rest described in section 3. The off-site copy is held on an encrypted disk (full-disk encryption with LUKS) on the company's own premises, and the transfer takes place over ssh.
6. Logging and monitoring
- Infrastructure logs: nginx logs incoming requests (including IP address, timestamp, URL) and these are used for operations and troubleshooting.
- Log retention: 90 days. The logs contain IP addresses and should not be kept longer than necessary.
7. Handling personal data breaches
Yuzu has the following procedure for detecting, handling and reporting personal data breaches. The procedure ensures that the undertaking in the data processing agreement (§10) can be met.
7.1 Detection
Breaches are detected through supervision of the operating environment and infrastructure logs in connection with operations and changes, and through reports from users or the school.
7.2 Responsibility
Responsible for breach handling: Head of Technology.
7.3 Steps
- Confirm the breach and limit its scope (e.g. block access).
- Assess what has happened: which data and which data subjects are affected, and the likely consequences.
- Document the breach and the measures taken.
- Notify the controller (the school) without undue delay after becoming aware, in accordance with the data processing agreement §10.
- Remedy the root cause and follow up to prevent recurrence.
Notification to the supervisory authority (IMY for Swedish schools) and any information to data subjects rests with the controller (the school). Yuzu assists with the necessary documentation.
8. Sub-processors
| Sub-processor | Processing | Location | Third country? |
|---|---|---|---|
| Elastx AB | Hosting/IaaS – operation and storage | Sweden | No |
| Cloudflare, Inc. | DNS, proxy and TLS termination. Stores only Yuzu's own media content, no personal data | Edge network global, company in the USA | Yes, in transit |
| Brevo (Sendinblue SAS) | Transactional email to staff, including sign-in codes | France/EU | No |
No product analytics are used in Pomelo.
Skolon is not a sub-processor to Yuzu – the relationship is the reverse. For schools that have purchased Pomelo through Skolon's reseller model, the school is the controller, Skolon is its processor and Yuzu is a sub-processor to Skolon. For schools that have purchased directly from Yuzu, Yuzu is the processor for the school. In both cases the school may request a direct data processing agreement with Yuzu, which then takes precedence over the chain via Skolon.
9. Personnel and confidentiality
- Access to personal data in the service is limited to Yuzu's founders, following the principle of least privilege.
- As owners and representatives of the company, the founders are bound by confidentiality regarding the personal data processed in the service.
- Any future employees or consultants given access to personal data must sign a confidentiality undertaking before access is granted.
10. Retention and erasure
- Staff account data: erased when the account or the agreement ends.
- Backups: data may remain in backups until these are rotated in accordance with section 5.
- On termination of the agreement: erasure or return takes place in accordance with the data processing agreement §12.
11. Review of this document
This document is reviewed annually and upon material changes to the service, the operating environment or the processing.
See also Anonymity and data handling in surveys for how the anonymity is constructed in practice, and How we work with GDPR.