Digital operational resilience (DORA)
1. TicTac Learn and the financial sector
In this notice, 'TicTac' means TicTac Learn Group AB and its operating entities, including TicTac Learn AB (Sweden), TicTac Learn GmbH (Germany) and TicTac Learn Denmark A/S. The contracting entity is the one named on the applicable order or agreement.
TicTac provides learning platforms and content creation services and distributes eLearning authoring and video creation tools from selected technology partners to organizations across the Nordics and parts of Europe. Our customers include companies in the financial sector that are subject to the Digital Operational Resilience Act (Regulation (EU) 2022/2554, "DORA").
We take our financial sector customers' regulatory requirements seriously. This page explains our role, our security posture, and what contractual support we offer to help DORA-regulated customers meet their own obligations.
2. Our role, by product
TicTac Learn Group AB and its group companies, including TicTac Learn AB (Sweden) and TicTac Learn GmbH (Germany), operate in three distinct roles. Which role applies determines what DORA-relevant information and assurances are relevant, and from whom.
- Distributed platforms (Articulate 360, Docebo, Vyond). TicTac is the authorized distributor. We supply the licences, manage the commercial relationship, and provide first-level support, which is itself a DORA-relevant service we can address contractually (see section 4.3). We do not host, operate, maintain or access these platforms. The platform itself is operated by the respective technology partner, who maintains its own certifications and assurance documentation.
- Our own SaaS (Skillhabit, GO+, SkillUp). TicTac develops, hosts and operates these services directly, and controls the data processed within them.
- Professional services (content production, training, learning strategy). Delivered on a project basis.
3. Our security posture
ISO/IEC 27001 certification is held by TicTac Learn AB, the group's parent company, and its scope is defined in the certificate (available on request). The same information security management practices, covering risk management, access control, incident handling, business continuity and supplier management, guide how the group operates. For platform products distributed by TicTac Learn, please also refer to the relevant technology partner's own certifications, referenced in section 5 below.
For details on our technical and organizational security measures, please visit our Trust Centre or contact us directly.
4. DORA and TicTac
4.1 Critical ICT third-party service provider designation
TicTac has not been designated as a critical ICT third-party service provider under DORA Article 31. That designation is made by the European Supervisory Authorities, not by individual providers or their customers.
4.2 Critical or important functions
DORA requires each financial entity to assess whether the ICT services it receives support a critical or important function of that entity (Article 3(22)). This is a separate concept from the ESA designation above. It is the financial entity's own assessment, based on the nature, scale and complexity of its business.
Where a financial entity concludes that a service supports a critical or important function, the stricter DORA requirements for contractual arrangements, governance, subcontracting, exit planning and register documentation apply to that relationship. This assessment is the financial entity's responsibility. TicTac does not make this determination on behalf of its customers and is prepared to provide the information our customers need to complete their own assessment.
4.3 Contractual arrangements
TicTac offers a DORA-aligned contractual addendum for the services it operates directly. This covers two things: our own SaaS products (Skillhabit and related products), where TicTac is the operator; and our own first-level support services, provided in connection with any of the platforms we distribute, including Articulate 360, Docebo and Vyond. Support is an ICT service in its own right, and we are prepared to enter a DORA addendum covering it, scoped to what we actually provide, alongside your existing agreement for the relevant platform.
For the platforms themselves (Articulate 360, Docebo, Vyond), the platform-level DORA-relevant contractual assurances and evidence are provided directly by the respective technology partner, through its own certifications, trust centre and standard terms. TicTac's role for these products is limited to distribution and first-level support; we do not host, operate or control these platforms and cannot give platform-level DORA commitments on our partner's behalf.
5. Data location and subcontracting
Data relating to our own SaaS products and to our first-level support (including support requests) is processed and stored within the EU/EEA. For distributed platforms, data location and subcontracting are determined by the relevant technology partner; please refer to that partner's own security documentation (Articulate’s Trust Center; Docebo’s Trust Center and Vyond’s Trust Center).
6. Exit and transition
For our own SaaS products, we support data export and provide reasonable transition assistance on termination, as set out in the applicable agreement. For distributed platforms, data export and transition support are provided by the relevant technology partner.
7. Supporting your DORA information register
DORA Article 28(3) requires financial entities to maintain a register of information on all contractual arrangements with ICT third-party service providers. TicTac can provide the information our customers need to populate and maintain this register for our own services, including service descriptions, data processing locations, subcontracting arrangements and contact details. For distributed platforms, register information for the platform itself should be obtained from the relevant technology partner.