Tidvis
Legal

Privacy Policy

The purpose of this privacy policy is to explain how Tidvis collects, uses, stores, and protects personal data. We value your privacy and process personal data according to current data protection legislation, including GDPR.

Last updated: May 27, 2026

Using the Tidvis app? Read the app privacy policy

Data Controller

Tidvis Sverige AB, company reg. no. 556905-5394, with address Kungsgatan 37, 111 56 Stockholm, is the data controller for the processing of your personal data when you visit our website, contact us, or use our services as a customer.

When our customers (assistance companies, LSS housing operations, and municipalities) use Tidvis to manage employees and users, the customer is the data controller and Tidvis is the data processor. This processing is regulated in a data processing agreement.

Collection of Personal Data

We collect personal data that you voluntarily provide when you use our services, contact us, or otherwise interact with us. The types of personal data we may collect include:

  • Name, email address, phone number, and title
  • Company details (organization number, address, billing information)
  • Login and user logs in the service
  • Information you provide via forms (e.g., when booking a demo)
  • Technical information such as IP address, browser, and device

Use of Personal Data

We use your personal data to:

  • Provide, operate, and improve our services
  • Manage the customer relationship and agreements
  • Communicate with you, respond to inquiries, and send important operational information
  • Fulfill legal obligations, such as the Accounting Act and, where applicable, requirements from the Social Insurance Agency, IVO, and the Social Services Act // TODO: korrläs juridisk term
  • Protect our and our customers' rights and prevent misuse

Legal Basis

  • Agreement, to deliver the service to you as a customer or user.
  • Legitimate interest, to develop the service, market Tidvis to existing and potential customers, and ensure operation and security.
  • Legal obligation, to fulfill requirements in law, e.g., accounting.
  • Consent, for e.g., non-essential cookies and newsletters. You can withdraw your consent at any time.

Sharing of Personal Data

We never sell your personal data. We share data with third parties only when it is necessary to deliver the service, fulfill legal obligations, or with your explicit consent. We may share personal data with:

  • Sub-processors who help us operate the service (e.g., cloud provider, email, and support). All sub-processors are bound by data processing agreements.
  • Integration partners (e.g., payroll systems), but only on behalf of the customer and to the extent the customer configures.
  • Authorities when required by law or to protect our rights.

Storage and Transfer

Tidvis is hosted within the EU/EEA. We store your personal data as long as it is necessary for the purposes for which it was collected, or as long as required by law. As a general rule, customer data is deleted no later than 12 months after the termination of the agreement, unless longer storage is required by law (e.g., the Accounting Act's 7 years).

We take appropriate technical and organizational measures to protect your personal data against unauthorized access, loss, or destruction. Read more on the page Information Security.

Cookies

We use cookies and similar technology to make the website functional, remember your settings, and analyze traffic. You can change your choice at any time via the cookie box at the bottom of the page or in your browser settings. If you choose to decline non-essential cookies, some features may be affected.

Your Rights

Under GDPR, you have the right to:

  • Request access to the personal data we process about you
  • Request correction of inaccurate or incomplete data
  • Request deletion under certain circumstances
  • Object to or request restriction of processing
  • Request data portability
  • Withdraw consent you previously provided
  • Submit a complaint to the supervisory authority, the Swedish Authority for Privacy Protection (IMY), imy.se

Contact Us

If you have questions about how we process your personal data or want to exercise any of your rights, you can reach us at:

Privacy Policy for the Tidvis app

Last updated: 21 August 2026

This privacy policy describes how personal data is processed when you use the Tidvis mobile app (the “app”), provided by Tidvis Sverige AB, company registration number 556905-5394, Kungsgatan 37, c/o United Spaces, 111 56 Stockholm, Sweden (“Tidvis”, “we” or “us”).

The app is a work tool for scheduling, time reporting, check-in and check-out, absence, messaging, documentation and expenses, among other things. It is intended for users who have been given an account by their employer or another organisation using Tidvis. You cannot create your own account directly in the app.

The app is a work tool and is not directed at children.

1. Who is responsible for the personal data?

For most data processed in the app – such as data about employees, shifts, service users, absence, documentation and messages – the organisation that gave you access to Tidvis is normally the data controller. Tidvis then processes the data as a data processor, according to the organisation's instructions and its agreement with Tidvis.

Tidvis is itself the data controller for processing where Tidvis determines the purposes and means, for example handling support cases, information security, troubleshooting, abuse prevention and – when enabled – product analytics to improve the app.

Questions about the content of your personnel file, your schedule, a service user's data or other operational data should primarily be directed to the organisation that gave you the account. You can also contact Tidvis as described in section 12.

2. What personal data is processed?

The data actually processed depends on which features your organisation has enabled and how you use the app. The following categories may occur:

  • Account and identity data: name, username, email address, user and employee ID, employer/organisation, permissions, login method and technical session data.
  • Work and schedule data: shifts, working hours, attendance, time reporting, leave, shift swaps, tasks, customer/service-user links and sign-offs.
  • Location data: approximate and precise position when you yourself use a check-in or check-out feature that requires location. The app does not use location for continuous background tracking.
  • Absence and health data: for example sick leave, care of a sick child, carrier of infection leave, the extent of the absence and any note you choose to provide. Such data may be sensitive personal data.
  • Financial data: for example payroll and time reporting bases, mileage allowance, per diem, expenses, receipts and other compensation information.
  • Communication and user-generated content: messages, replies, daily notes, incident reports, comments, records of completed tasks and other content users write or submit.
  • Images, files and documents: for example photos of receipts, attachments, uploaded documents and documents the organisation makes available in the app.
  • Data about service users or other individuals: name, schedule, care-related documentation and other data the user is authorised to view or record. Such content may include health, disability or other particularly sensitive data.
  • App, device and usage data: app platform, device type, push token, technical identifiers, IP address, logs, error data, screens viewed and interactions with features.
  • Product analytics, when enabled: company ID, the user's display name, a user-specific analytics ID, the organisation's name and domain, platform, login method, page views and product interactions. We do not use this data for advertising or for tracking across other companies' apps and websites.

3. How is the data collected?

The data may come:

  • from you when you log in, register or submit information in the app;
  • from the organisation that created your account and administers Tidvis;
  • from other authorised users within the same organisation;
  • automatically from the app and the device, for example technical logs, app interactions and a push token;
  • from the phone's location service, only after you have granted the app permission and use a location-based feature.

4. Why is the data processed?

The data is processed in order to:

  • authenticate the user and give the right person the right permissions;
  • display and administer schedules, working hours, attendance, absence, payroll bases, expenses and related workflows;
  • carry out check-in and check-out, including location verification when the organisation has enabled the feature;
  • enable messaging, documentation, reporting, signing and collaboration within the organisation;
  • send push notifications the user has chosen to allow;
  • provide support, troubleshoot, prevent abuse and protect the security of the service;
  • comply with applicable legal obligations and handle legal claims;
  • analyse how the app's features are used and improve stability and usability, when product analytics is enabled.

Tidvis does not sell personal data and does not use app data for behavioural advertising.

5. Legal basis

Where the organisation that gave you the account is the data controller, that organisation determines the legal basis and is responsible for informing you about it. Tidvis then processes the data according to the organisation's documented instructions.

Where Tidvis is the data controller, processing is based, depending on the situation, on:

  • performance of a contract or steps taken prior to entering into a contract;
  • Tidvis' legitimate interest in providing a secure, stable and usable service, following a balancing of interests;
  • a legal obligation; or
  • establishing, exercising or defending legal claims.

Sensitive personal data is processed only where the feature is used within the organisation's operations and there is a basis under data protection law, typically Article 9(2)(b) (employment and social security) or Article 9(2)(h) (health and social care) of the GDPR. Where Tidvis is a data processor, the controller organisation is responsible for that basis.

6. Location data

If your organisation uses location-based check-in and check-out, the app may request access to approximate and precise position. The position is retrieved only when you start the relevant feature yourself and is used to record or verify the check-in or check-out. The Tidvis app does not use location data for advertising and does not perform continuous background tracking.

You can deny or withdraw the location permission in your phone's settings. Location-based check-in or check-out may then stop working, but other parts of the app are normally unaffected.

7. Push notifications and product analytics

If you enable push notifications, a push token and platform information are registered. Apple Push Notification service (APNs) and Google Firebase Cloud Messaging (FCM) respectively may then process technical delivery data to send the notification to your device. You can turn off push notifications in the app or in your phone's settings. Depending on your system settings, notification content may be shown on the lock screen.

When product analytics is enabled, Tidvis uses Mixpanel to understand page views and feature usage. Analytics data is not used for advertising. You can object to this processing or request removal of your analytics ID by contacting us as described in section 12. The app also respects the device's or browser's do-not-track signal where such a signal is available.

8. AI support for daily notes

Some organisations may enable an optional AI feature that reviews the language of a daily note and suggests a more professional wording. The feature is used only when the user actively requests a review. Direct identifiers recognised by the system are replaced with placeholders before the text is sent to the AI provider Anthropic for processing. The suggestion is then returned to Tidvis, where the placeholders are replaced with the original data. The data is not used to train the AI provider's models.

Anonymisation reduces the risk but does not mean all information is reliably anonymous, particularly since free text may contain care or health data. Users must therefore follow the organisation's documentation instructions. The AI support only provides a text suggestion; it does not make decisions with legal or similarly significant effect. The user is responsible for reviewing and approving the text before it is saved.

9. Who can access the data?

Data may be made available to:

  • authorised users and administrators at the organisation that gave you the account;
  • authorised Tidvis personnel where needed for operations, security, support or troubleshooting;
  • suppliers processing data on our behalf, for example operations and hosting providers as well as providers of push notifications, product analytics and AI support;
  • authorities or other recipients where disclosure is required by law or necessary to handle legal claims.

Relevant suppliers for the app may, depending on enabled features, include Apple, Google, Mixpanel and Anthropic. These suppliers may only process data for the stated purposes and in accordance with applicable agreements and instructions.

Some suppliers may process data outside the EU/EEA. Where such a transfer takes place it must be supported by an applicable transfer mechanism, for example a European Commission adequacy decision or standard contractual clauses, along with supplementary safeguards where needed. Contact us for current information about suppliers and transfers.

10. How long is the data kept?

Operational data in Tidvis is retained according to the controller organisation's instructions, agreements, documented retention rules and the legal requirements applying to, for example, accounting, payroll, employment law, care and documentation. Closing an account therefore does not always mean all data can be erased immediately.

Tidvis retains its own support, security, analytics and log data for as long as needed for each purpose and then erases or anonymises it, unless it must be retained longer due to a legal obligation or a legal claim. Push tokens are retained for as long as push notifications are enabled or until the token is deregistered or becomes invalid.

You can contact us for information about the retention periods or criteria applying in a particular case.

11. Your rights and deletion requests

Depending on the circumstances, you have the right to request access to your personal data, rectification, erasure, restriction, data portability and to object to certain processing. Where processing is based on consent, you have the right to withdraw it. These rights are not absolute; for example, some data may need to be retained by law or to establish, exercise or defend legal claims.

For data your employer or other customer organisation is responsible for, contact that organisation in the first instance. Tidvis assists the organisation in handling requests where we process the data as a data processor.

Requesting deletion of app data

You can request deletion of data collected through the Tidvis app by emailing gdpr@tidvis.se with the subject line “Radering Tidvis-appen”. State your name, the organisation that gave you the account, your username or email address and which data the request concerns. We may need to verify your identity, for example via the organisation, before taking action. We forward the request to the correct data controller where needed and inform you about data that must be retained and why.

Email your deletion request to gdpr@tidvis.se

You have the right to lodge a complaint with the Swedish Authority for Privacy Protection (IMY), www.imy.se.

12. Security and contact

Tidvis applies technical and organisational safeguards adapted to the sensitivity of the data, including access control, logging and encrypted transmission. No method is entirely risk-free. Contact us if you suspect that your account or data has been subject to unauthorised access.

Contact details

Tidvis Sverige AB

Company registration number: 556905-5394

Kungsgatan 37, c/o United Spaces

111 56 Stockholm, Sweden

gdpr@tidvis.se · info@tidvis.se · 033-722 10 10

13. Changes to this policy

We may update this policy when the app's features, suppliers or legal requirements change. The latest version is published on this page and the date at the top is updated. In the event of material changes, we will inform you in an appropriate manner through the app, the service or the organisation that gave you the account.

My tracking data

You can view what we have stored about your anonymous visitor profile at any time, or delete it entirely.

Your anonymous visitor id: