Klaffa SV
Legal · Personal data

Privacy policy

How Klaffa AB handles personal data — on the website and in the Klaffa app. Short, concrete, no unnecessary legalese.

Effective [YYYY-MM-DD] Version 2.0 Scope klaffa.app + the Klaffa app

This policy covers two things: §2–§4 our public marketing site klaffa.app, and §5–§7 the Klaffa app (iOS, Android and web) — schedules, call sheets, agreements, time and payroll. §8–§12 apply to both.

When you use the app as part of a production, Klaffa processes the data both in its own right and on behalf of the production company you are attached to; that relationship is additionally governed by a Data Processing Agreement (DPA) between Klaffa and the company. This policy describes the processing as it affects you as a user.

§1Controller

The controller for processing on klaffa.app and in the Klaffa app is:

§2What we collect — the website

Contact form

When you submit the contact form on klaffa.app we store your name, production company, email address, and message. We use it to reply to your enquiry and to follow up on that conversation. Filling in the form is always voluntary.

Server and access logs

Our hosting provider (Vercel) logs standard technical data for every request: IP address, timestamp, URL, HTTP status, referer, user agent. This is standard web-server data needed to operate the site and identify abuse.

Cookies and local storage

Klaffa.app sets no cookies for tracking, analytics, or advertising. We do not display cookie banners because there is nothing to consent to. If we ever introduce analytics, we will announce it clearly and give you a choice.

What we do not collect

§3Legal basis — the website

ProcessingLegal basis (GDPR art. 6)
Contact form: replying to your enquiryLegitimate interest (art. 6(1)(f)) — responding to a message you sent us
Server logs: operations, security, abuse preventionLegitimate interest (art. 6(1)(f))
Steps toward a contract if the enquiry leads to a quote / dialoguePre-contractual measures at your request (art. 6(1)(b))

§4Retention — the website

§5What the app processes

To deliver call sheets, time reporting and correct pay, the Klaffa app processes the following about you:

Personal data

Work data

Technical data

The app contains no advertising, no cross-app tracking and no third-party pixels. We never sell your data.

§6Legal basis — the app

ProcessingLegal basis (GDPR art. 6)
Delivering the service to you and the production (schedule, time, agreements)Performance of a contract (art. 6(1)(b))
Personnummer, payroll records and signed agreementsLegal obligation (art. 6(1)(c)) — accounting and tax law
Crash reports and operational securityLegitimate interest (art. 6(1)(f))

Personnummer is processed for secure identification in payroll and tax reporting, in accordance with Chapter 3 of the Swedish Data Protection Act.

§7Retention — the app

§8Who sees the data

We do not sell personal data. We do not share it for marketing purposes. In the app, the production you are attached to sees the data needed for staffing and payroll — but bank details are never shown in plaintext. The following processors handle data on our behalf:

ProviderPurposeRegion
Vercel Inc.Hosting klaffa.app, HTTP logsEU / global CDN
[Email provider, e.g. Fastmail / Google Workspace]Receiving form submissions and replying to enquiries[EU / US]
SupabaseDatabase, authentication and storage for the appEU (Stockholm)
SentryError and crash reporting[EU / US]
ExpoPush-notification delivery[EU / US]

For transfers outside the EU/EEA we rely on the European Commission's Standard Contractual Clauses (SCCs) and, where required, supplementary measures.

§9Your rights

Under the GDPR you have the right to:

In the app you can do this yourself, directly:

You can also contact privacy@klaffa.app. We respond within 30 days (GDPR art. 12(3)).

If you are unhappy with how we handle your data you have the right to complain to the Swedish Authority for Privacy Protection, IMY. We would appreciate hearing from you first so we get a chance to fix it.

§10Security

Klaffa.app is served exclusively over TLS. Form submissions are encrypted in transit. Access to enquiries is restricted to Klaffa staff who need it to reply.

In the app, additionally: all traffic is encrypted in transit (TLS), bank details are stored encrypted in a separate vault and never logged in plaintext, the database uses row-level security so each production only reaches its own data, and data is stored within the EU (Stockholm). Personnummer is never logged. Supplementary security documentation and the GDPR DPA are available for production companies.

§11Changes

For material changes we update the date and version at the top. For significant changes affecting your rights we will try to notify you directly if we have your email.

§12Contact

Questions about privacy or this policy: privacy@klaffa.app.