Privacy policy
How Klaffa AB handles personal data — on the website and in the Klaffa app. Short, concrete, no unnecessary legalese.
This policy covers two things: §2–§4 our public marketing site klaffa.app, and §5–§7 the Klaffa app (iOS, Android and web) — schedules, call sheets, agreements, time and payroll. §8–§12 apply to both.
When you use the app as part of a production, Klaffa processes the data both in its own right and on behalf of the production company you are attached to; that relationship is additionally governed by a Data Processing Agreement (DPA) between Klaffa and the company. This policy describes the processing as it affects you as a user.
§1Controller
The controller for processing on klaffa.app and in the Klaffa app is:
- Klaffa AB, corporate ID no. [XXXXXX–XXXX]
- [Registered address, Stockholm]
- Email: privacy@klaffa.app
§2What we collect — the website
Contact form
When you submit the contact form on klaffa.app we store your name, production company, email address, and message. We use it to reply to your enquiry and to follow up on that conversation. Filling in the form is always voluntary.
Server and access logs
Our hosting provider (Vercel) logs standard technical data for every request: IP address, timestamp, URL, HTTP status, referer, user agent. This is standard web-server data needed to operate the site and identify abuse.
Cookies and local storage
Klaffa.app sets no cookies for tracking, analytics, or advertising. We do not display cookie banners because there is nothing to consent to. If we ever introduce analytics, we will announce it clearly and give you a choice.
What we do not collect
- Personnummer or other sensitive personal identifiers via the website.
- Bank account details via the website.
- Data from ad trackers, third-party pixels or social embeds — there are none on the site.
§3Legal basis — the website
| Processing | Legal basis (GDPR art. 6) |
|---|---|
| Contact form: replying to your enquiry | Legitimate interest (art. 6(1)(f)) — responding to a message you sent us |
| Server logs: operations, security, abuse prevention | Legitimate interest (art. 6(1)(f)) |
| Steps toward a contract if the enquiry leads to a quote / dialogue | Pre-contractual measures at your request (art. 6(1)(b)) |
§4Retention — the website
- Contact enquiries — 24 months after the last correspondence, then deleted or anonymised. If it becomes a customer relationship, handling shifts to bookkeeping and customer-agreement processes.
- Server logs — 30 days maximum, then rotated automatically.
§5What the app processes
To deliver call sheets, time reporting and correct pay, the Klaffa app processes the following about you:
Personal data
- Name, email address, phone number and address — identity and contact within the production.
- Personnummer (Swedish personal identity number) — required for salary payment and tax reporting.
- Bank details (clearing and account number, optionally Swish or IBAN) — to pay your salary. Stored encrypted in a separate vault and never shown in plaintext to the production.
Work data
- Assignments, work days, shifts and check-ins/check-outs.
- Signed agreements, including a signature audit log with timestamp, IP address and device — this is the agreement's evidentiary value.
- Payroll records with OB (unsocial hours) breakdown.
Technical data
- Push-notification token, so we can notify you about your call sheet.
- Error and crash reports, to keep the app stable.
The app contains no advertising, no cross-app tracking and no third-party pixels. We never sell your data.
§6Legal basis — the app
| Processing | Legal basis (GDPR art. 6) |
|---|---|
| Delivering the service to you and the production (schedule, time, agreements) | Performance of a contract (art. 6(1)(b)) |
| Personnummer, payroll records and signed agreements | Legal obligation (art. 6(1)(c)) — accounting and tax law |
| Crash reports and operational security | Legitimate interest (art. 6(1)(f)) |
Personnummer is processed for secure identification in payroll and tax reporting, in accordance with Chapter 3 of the Swedish Data Protection Act.
§7Retention — the app
- Payroll records and signed agreements — 7 years under the Swedish Bookkeeping Act (Bokföringslagen, ch. 7). We cannot shorten that period.
- Other personal data — deleted or anonymised when no longer needed.
- On account deletion — name, email, phone, address and personnummer are anonymised, bank details are deleted, pending invitations and unsigned agreements are cancelled, and push tokens are removed. Only the legally required records remain, with your personal data anonymised.
§8Who sees the data
We do not sell personal data. We do not share it for marketing purposes. In the app, the production you are attached to sees the data needed for staffing and payroll — but bank details are never shown in plaintext. The following processors handle data on our behalf:
| Provider | Purpose | Region |
|---|---|---|
| Vercel Inc. | Hosting klaffa.app, HTTP logs | EU / global CDN |
| [Email provider, e.g. Fastmail / Google Workspace] | Receiving form submissions and replying to enquiries | [EU / US] |
| Supabase | Database, authentication and storage for the app | EU (Stockholm) |
| Sentry | Error and crash reporting | [EU / US] |
| Expo | Push-notification delivery | [EU / US] |
For transfers outside the EU/EEA we rely on the European Commission's Standard Contractual Clauses (SCCs) and, where required, supplementary measures.
§9Your rights
Under the GDPR you have the right to:
- request a copy of the data we hold about you (access),
- have inaccurate data corrected,
- request erasure when there is no longer a reason to process it,
- object to processing based on legitimate interest,
- request restriction of processing,
- where applicable, receive your data in a structured format (portability).
In the app you can do this yourself, directly:
- Profile → Privacy → “Request my data” creates a file with everything we hold about you (bank details appear only as “on file”, never in plaintext).
- Profile → Account → “Delete account” closes the account and anonymises your personal data as described in §7.
You can also contact privacy@klaffa.app. We respond within 30 days (GDPR art. 12(3)).
§10Security
Klaffa.app is served exclusively over TLS. Form submissions are encrypted in transit. Access to enquiries is restricted to Klaffa staff who need it to reply.
In the app, additionally: all traffic is encrypted in transit (TLS), bank details are stored encrypted in a separate vault and never logged in plaintext, the database uses row-level security so each production only reaches its own data, and data is stored within the EU (Stockholm). Personnummer is never logged. Supplementary security documentation and the GDPR DPA are available for production companies.
§11Changes
For material changes we update the date and version at the top. For significant changes affecting your rights we will try to notify you directly if we have your email.
§12Contact
Questions about privacy or this policy: privacy@klaffa.app.