This Privacy Policy explains how helloswap, CVR no. DK29075794, Halmtorvet 28, 4th, 1700 København V, Denmark ("helloswap," "we," "us") collects, uses, discloses, and protects personal data in connection with the helloswap workforce-scheduling platform (the "Service"). It applies to visitors of our website, account holders, and the people whose work schedules are managed through a customer's account. It should be read together with our Terms of Service, which also covers some of the same ground from a contractual rather than a data-protection angle — where the two differ on a factual point, this Policy is the more current and more detailed statement of our actual practices.
helloswap is a workforce-scheduling platform for shift-based teams — a schedule builder, shift swaps, time-off requests, an open-shift board, and related features, sold to companies ("Customers") who use it to organize their own employees' work. We are a Danish company, and Danish and EU data protection law (including the GDPR) apply to how we handle personal data.
This Policy covers personal data we handle in three overlapping roles:
We do not sell personal data, and we do not use Customer Data (employees' schedules, contact details, or other workforce records) to train AI models or share it with third parties for their own marketing purposes.
Where GDPR applies, we rely on the following legal bases:
For Customer Data about a Customer's own employees, the Customer is responsible for having its own lawful basis (typically contract or legitimate interest in the employment relationship) — see Section 6.
For the personal data of a Customer's own employees (names, contact details, schedules, and similar), the Customer is the data controller and helloswap is the data processor, acting only on the Customer's instructions as expressed through use of the Service's features. The Customer is responsible for having a lawful basis to collect and share its employees' personal data with us, and for telling its employees that their schedule data is processed through helloswap.
If you're an employee whose schedule is managed through helloswap and you have a question about how your data is used, please contact your employer first — they control that data and are best placed to answer. We'll support them in responding to you.
For account-holder and billing information a Customer provides directly about itself, helloswap is the data controller. A separate Data Processing Agreement is available on request for Customers that require one under GDPR or similar frameworks — contact hello@helloswap.dk.
We use the following categories of sub-processors to provide the Service. We may update this list as our infrastructure evolves.
Some of these providers are located outside the European Economic Area — see Section 10 for the safeguards that applies to those transfers.
Instead of a password, you can sign in with a Google account. When you do, Google shares your name, email address, and confirmation that Google has verified you own that email address — nothing else. We use it only to match you to an existing helloswap account, or, if signing up, to create one. We never receive or store your Google password, and we don't use this to access anything else in your Google account.
Separately, on our Enterprise plan, a Customer can configure single sign-on so its own employees sign in through the Customer's own identity provider (for example, Okta, Microsoft Entra ID, or Google Workspace) instead of a helloswap password. In that setup, the identity provider is chosen and configured by the Customer, not by us — the Customer is the controller of that relationship, and we simply verify the identity assertion it sends us to complete sign-in, the same way we'd verify a password.
We don't use third-party advertising cookies to track you across other websites. Where your consent is legally required for a category above, we'll ask for it before setting that cookie.
Some of our sub-processors (Section 7) are located outside the European Economic Area, including in the United States. Where that's the case, we rely on appropriate safeguards recognized under GDPR — such as Standard Contractual Clauses, or the provider's own certification under an approved transfer framework — before personal data leaves the EEA.
We use industry-standard measures to protect personal data, including encryption in transit, database row-level access controls scoped per company (so one Customer's data is never visible to another), hashed passwords, and an append-only audit log of account activity. No method of transmission or storage is completely secure, and we can't guarantee absolute security.
If a personal data breach affecting your personal data occurs, we will notify the competent supervisory authority without undue delay, and — where the breach is likely to result in a high risk to your rights and freedoms — the affected individuals or the relevant Customer, consistent with GDPR Articles 33 and 34.
We retain personal data for as long as the relevant account is active. When a Customer closes its account, we schedule the underlying company and workforce records for permanent erasure 30 days later — a short window that exists only to recover from an accidental deletion, not to keep data longer than needed. After that window, the records are irreversibly erased, except for a minimal billing history we keep on file where we're legally required to (for example, for tax and accounting purposes), and an append-only audit trail of account-level actions that, by design, can never be altered or deleted once written.
Under GDPR and similar laws, you may have the right to:
If your employer manages your schedule through helloswap, they're the controller for that data (see Section 6) — please contact them first for requests about your own workforce records. For anything else, or if your employer is unresponsive, contact us at hello@helloswap.dk and we'll help.
The Service is intended for business and employment use and isn't directed at children. We don't knowingly collect personal data from children. If you believe a child's data has been provided to us, contact us and we'll delete it.
We may update this Policy from time to time. For material changes, we'll give reasonable notice (for example, by email or an in-app notice) before they take effect. The "Last updated" date at the top of this page always reflects the current version.
Questions about this Policy, or a request under Section 13?
helloswap, CVR no. DK29075794
Halmtorvet 28, 4th, 1700 København V, Denmark
hello@helloswap.dk