DPIA Support Material
Version 2026-08-11 - Karri AB, org. no. 559250-7700
This page forms Annex 1 and Annex 2 to the data processing agreement. It gives customer organisations the processor-side facts needed for their own assessment. The customer remains responsible for deciding whether a DPIA is required and for carrying it out.
Processing details
Purpose. Voluntary workplace wellness: logging activities, planning training, following own progress, and showing aggregated participation statistics to the organisation.
Data subjects. Employees and other invited members, workspace administrators, coaches.
Data categories. Email, self-chosen alias, role and membership status; activity type, numeric value, date and optional note; optional photos; training routines; coaching relationships; technical logs.
Special categories. Activity data may indirectly reveal information about physical health and is therefore treated as Article 9 data, processed only on the member's explicit consent.
Not collected. No medical records, diagnoses, medication, blood pressure, heart rate, weight, sleep, mood or diet data. No location tracking. No automated decision-making with legal effect. No profiling for advertising.
Retention. See the retention schedule.
Subprocessors and transfers. See the subprocessor list. Production data is stored in the EU.
Security measures (Annex 2)
- TLS in transit and encryption at rest.
- Logical isolation per workspace enforced by database row level security.
- Role-based access: members see their own data, administrators see aggregated statistics and administrative information only.
- No anonymous read access to member profiles, workspace records or activity data; public surfaces use opaque identifiers.
- Two-factor authentication available for administrators.
- Server-side authorisation for all privileged operations, with input validation.
- Audit logging of administrative and privacy-relevant actions.
- Least-privilege internal access, limited to documented support, security and maintenance work.
- Automated dependency and configuration security scanning.
- Backups with a rolling 30-day window.
Employer visibility
Administrators never see individual activity entries, notes, photos or training history. They see workspace-level aggregates, and aggregates are suppressed entirely when fewer than five individuals contributed to the figure, so a small team cannot be reverse-engineered into individual behaviour.
Administrators do see administrative information needed to run the workspace: member alias, email, role, membership status and invitation state.
Identified risks and mitigations
Perceived pressure to participate. Mitigation: participation is voluntary, consent is a separate unticked checkbox, withdrawal is self-service and erases activity data, and the customer confirms in the controller declaration that non-participants are not disadvantaged.
Re-identification from small-group statistics. Mitigation: suppression below five contributors and no per-member drill-down for administrators.
Unintended public exposure. Mitigation: new profiles are private by default, public display is opt-in, and existing members are asked to review their visibility once.
Secondary use by the employer. Mitigation: contractual prohibition on using the data for performance, disciplinary, recruitment, salary or insurance decisions.
Processor access. Mitigation: confidentiality obligations, least privilege, audit logging.
Data-subject rights support
Members can export or delete their account, withdraw consent, adjust visibility and submit access, correction, restriction, objection and portability requests from their own profile page. Requests are logged with a 30-day due date. Karri AB assists the customer with any request it cannot handle itself in the product.
Contact
Karri AB, Sandgatan 2, 263 62 Viken, Sweden. Privacy contact: info@upzdownz.com.
