Last updated: 15 August 2026
This Privacy Policy describes how VikarStyrken.dk ApS ("VikarStyrken", "we", "us") collects, processes, and protects your personal data when you use our mobile application (the "App").
Data Controller
VikarStyrken.dk ApS, CVR 41886102, Lautruphoj 5, 2750 Ballerup, Denmark, is the data controller responsible for your personal data. Contact: info@vikarstyrken.dk.
Data We Process
- Temp workers: Full name, email, phone number, address, CPR number, experience, student/full-time status, and shift application history.
- Companies: Company name, CVR number, address, contact person name, contact email, contact phone, and created shift data.
- Admin/Owner users: Full name, email, and role.
- Service activity: Shifts, applications, assignments, hours, approval actions, and transactional messages associated with your account.
- Push notifications: Expo push token, device platform, permission status, and notification content needed to deliver requested notifications through Expo and Google Firebase Cloud Messaging.
- Diagnostics: App version, operating system, device model, IP address in infrastructure logs, crash stack traces, and sampled performance data used to secure and improve the App.
We do not collect precise device location, advertising identifiers, contacts, photos, videos, audio, or files from your device.
CPR Number (National Identification Data)
Your CPR number is protected national identification data. It is encrypted at rest using application-level encryption and is only accessible to authorized admin/owner users for identity, employment, and legal-administration purposes. CPR data is never exposed to other workers, companies, advertisers, or the public.
Legal Basis
- Contract performance (Art. 6(1)(b)): Creating and managing your account, shift applications, and assignments.
- Legal obligation (Art. 6(1)(c)): Tax and employment record requirements under Danish law.
- Legitimate interest (Art. 6(1)(f)): Platform security, fraud prevention, and service improvement.
- Consent (Art. 6(1)(a)): Push notifications, which you can disable in your device settings.
- Danish law and GDPR Art. 87: Processing of CPR numbers where necessary and permitted for identification, employment administration, or legal compliance.
Sub-Processors
We use the following third-party providers to operate the platform. Each is bound by data processing agreements:
- Supabase (Supabase Inc.) - Hosting, database, and authentication. Data is stored in the EU region.
- Maileroo - Transactional email delivery (account confirmation, notifications).
- GatewayAPI - SMS delivery for critical shift notifications and reminders.
- Expo - App updates and push notification routing, including Expo push tokens and notification payloads.
- Google Firebase Cloud Messaging - Delivery of push notifications to Android devices.
- Sentry - Crash reporting and sampled performance monitoring. Default personal-data collection is disabled, but technical context such as device model, operating system, app version, stack traces, and network request metadata may be processed.
Data Retention
Account data is retained while your account is active. Shift, assignment, audit, accounting, or employment records may be retained or anonymized for up to five years where Danish law requires it. Push tokens are removed when you sign out or delete your account and may also be removed when invalid. Diagnostic events are retained for a limited operational period, normally no more than 90 days. Encrypted database backups expire within 14 days.
Account Deletion
You can delete your account in the App under More > Delete account. You can also request deletion without installing the App through our account-deletion page. Shared company records and records that must be retained by law may be preserved, restricted, or anonymized instead of erased.
Security Measures
- TLS encryption for all data in transit.
- Row-Level Security (RLS) policies enforce role-based data access.
- CPR numbers are encrypted at rest and restricted to admin access.
- No service role keys or secrets are included in the mobile app.
- Database backups with 14-day retention.
Your Rights Under GDPR
- Right of access: Request a copy of your personal data.
- Right to rectification: Correct inaccurate or incomplete data.
- Right to erasure: Delete your account and all associated data.
- Right to data portability: Receive your data in a machine-readable format.
- Right to object: Object to processing based on legitimate interests.
- Right to withdraw consent: Withdraw consent for push notifications at any time.
To exercise any of these rights, contact info@vikarstyrken.dk.
International Transfers
Primary account and marketplace data is stored in the European Union. Expo, Firebase, Sentry, and other processors may process limited technical or delivery data outside the EU/EEA. Where required, transfers rely on adequacy decisions, Standard Contractual Clauses, or another lawful safeguard.
No Advertising or Sale of Data
We do not sell personal data, use it for third-party advertising, or share it with data brokers.
Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via the App or email. Continued use after changes constitutes acceptance.
Contact
For privacy questions or requests: info@vikarstyrken.dk