Skip to content

Legal

Privacy Policy

Describes which personal data is processed, which legal basis applies to each purpose, and how data subjects can exercise their rights.

Version 2026-08-18Privacy owner, Compliance ownerEffective August 18, 2026Updated August 18, 2026

Contents

Data Controller

Rojs Software AB (reg. no. 559573-3501), Kongahällagatan 7, 442 36 Kungälv, is the data controller for the processing described in this policy.

Data protection enquiries can be sent to support@vardbemanningsguiden.se.

Personal Data Processed

We process contact details, account identifiers, session and security data, application details, timesheet data, billing records, and moderation data required for the service.

For BankID sign-in, we process strong identity attributes, short-lived BankID attempt state, and the minimum identity binding needed for account access and abuse-prevention security. Raw personnummer is processed transiently to derive keyed identifiers and is not persisted in platform records. BankID identity data is not sent to analytics or marketing.

For manual company authority review, we may process an uploaded registration certificate, signing email, BankID signing state, BankID display name, derived identifiers/fingerprints, encrypted BankID signature and OCSP response, and selected evidence ids.

For interest leads, we also process selected work categories, regions, optional messages, and accepted document versions. For matched interest leads, we additionally process the single assignment, delivery state, and first authorized access.

We do not process sensitive health data for ad targeting or other marketing purposes.

Legal Basis and Purpose

Core product functions such as account access, applications, invitations, timesheets, approvals, and support handling are processed to perform a contract or to take steps before entering into a contract.

BankID is used as necessary strong identity for Swedish member sign-in and is processed to deliver account access, protect against unauthorized use, and bind verified identity to the correct member account.

Manual company authority review is processed to verify that a company can be activated with appropriate authority evidence before or during the customer relationship.

Matched interest leads are processed to provide the matching requested by the consultant and share the request with exactly one eligible firm. If no firm is eligible, the request remains unassigned for manual handling.

Security logging, abuse prevention, moderation, disputes, and auditability are processed under legitimate interests.

Billing, bookkeeping, and other required business records are processed to comply with legal obligations.

Consent is used only for analytics and future marketing categories where consent is required under applicable rules.

Consent is not used as the legal basis for core processing required for matched interest leads.

BankID and Strong Identity

The BankID service is purchased through Danske Bank. When an identification or signing order starts, we send the end-user IP address to BankID. BankID also receives the orderRef when we collect status or request cancellation. For company-authority signing, BankID receives the visible signing text and technical references that bind the text to the correct request.

When BankID completes, we receive data including the name and raw personnummer. Raw personnummer is processed transiently for validation and keyed derivation and is not persisted in platform records. The name may be stored as the account display name or as part of the signing evidence.

The member browser that starts the flow receives orderRef and autoStartToken. The company-authority signing browser receives autoStartToken. Both flows may receive animated QR data containing the QR start token, elapsed time, and an HMAC authentication code. Only the start and QR values listed above are returned to the browser. The raw QR secret, encrypted provider envelopes, raw identity, signature, and OCSP response remain server-side.

For company authority, a link valid for seven days is sent through Resend to the intended email address. The link acts as a bearer key to the limited signing page and may be visible in the recipient mailbox and browser history. It contains no BankID identity data, and a BankID signature never activates the company automatically.

Authorized operators can see the signatory email, signed statement, BankID orderRef, manual signing link, BankID display name, and keyed provider-subject and personnummer fingerprints during manual review. The BankID signature and OCSP response are encrypted and are not shown in the ordinary evidence view.

The 30-day member session and the 10-minute completion proof are signed but not encrypted. They may contain internal user, attempt, site-profile, and purpose references plus expiry, but no BankID provider payload or raw personnummer. HttpOnly prevents ordinary page code from reading them but does not hide them from the browser user or another person sharing the browser profile. Full cookie details are available in Cookies and Similar Technologies.

The minimum identity binding is retained while the member account exists. A pseudonymous BankID identity that is no longer linked to an account, an interest lead, or a pending rights request is automatically deleted after 24 months of inactivity. The link to a terminal interest lead is removed 36 months after closure and the last relevant update. This does not automatically delete the member account; an account-erasure request is reviewed and handled separately.

Current company-authority evidence is retained while it is needed for the company account. When an operator has removed completed evidence, its identifying and BankID-linked contents become eligible for automatic minimization after 24 months. Minimization occurs in the first safe successful daily cleanup after the cutoff, once the signing request is closed and no active or uncertain BankID operation must be preserved. Technical references needed to prevent an old runtime from creating new evidence remain without the signatory name, email, BankID reference, signature, or OCSP contents.

BankID data is not sent to analytics or marketing. A change that stores additional BankID attributes, changes recipients, or reuses the identity for a new purpose requires a new privacy review.

Interest Leads and Recipients

A direct interest lead is sent only to the firm chosen by the consultant and cannot be rerouted to another firm.

A matched interest lead is assigned to exactly one eligible firm. If no firm is eligible, it remains unassigned until Ops handles it manually.

The firm receiving an interest lead is an independent recipient for its follow-up. It may use the data only to handle that specific lead and according to its own legal obligations.

If an interest lead is withdrawn, we stop future access where possible. Data the recipient firm has already accessed may need to be handled by that firm under its own obligations.

Analytics, Marketing, and Public Transparency

When the Analytics category is allowed, we use Vercel Web Analytics for page views and first-party analytics for a limited set of public interactions. First-party analytics uses random pseudonymous session and journey identifiers that are not linked to an account, BankID, an interest lead, or consent evidence.

Private workspaces, sensitive search parameters, contact details, profile values, free text, lead ids, and BankID data are excluded from analytics events. Raw first-party events are retained for 30 days and anonymous daily aggregates for 24 months.

Company authority signing links are excluded from web analytics because the link contains an authority token.

The Marketing category exists in the interface but is not active on this site today. Google tags or other ad measurement must not be enabled before a separate consent model and updated documentation are in place.

If consultant ratings or sponsored firms are shown publicly, they must be described clearly so that ratings, rankings, and sponsorship are not conflated.

The deterministic quality and fair-order matching has been assessed and is not a decision with legal or similarly significant effects under Article 22. Higher ratings do not increase request volume, and Ops can manually handle unassigned and matched requests. A material future change requires a new review.

Cross-border Transfers

Certain subprocessors (Vercel, GitHub, Stripe, and Resend) may process personal data outside the EU/EEA. Resend processes recipient details, message content, and delivery metadata in the United States to deliver transactional email.

Such transfers are protected by the EU Standard Contractual Clauses (SCCs) included in each subprocessor's data processing agreement. Information about the applicable safeguards and how to obtain a copy can be requested from support@vardbemanningsguiden.se.

Rights and Contact

Data subjects may request access, correction, deletion, restriction, or object to processing under applicable data protection law.

Data protection enquiries and requests for human review of an incorrect BankID link, denied access, or disputed identity can be sent to support@vardbemanningsguiden.se. The CEO is accountable for ensuring a human review. The initial human response target is within three business days; this is not a promise of final resolution and does not replace statutory response deadlines for rights requests.

For interest leads, access requests can include the actual recipient firm, assignment history, delivery state, and access timestamp where this can be provided without exposing another person's data.

If you believe your personal data is being processed in violation of data protection law, you have the right to lodge a complaint with the Swedish Authority for Privacy Protection (IMY), imy.se.

Agreement Evidence When a Company Workspace Is Claimed

When the first owner claims a company workspace, we store the company name and organisation number, accepted terms and pricing versions, the privacy-notice and authority-declaration versions shown, the user, time, source invitation, and a minimized reference to the BankID identification.

BankID identification establishes which person claimed the workspace but does not replace the separate review of registration certificates, company signing authority, and BankID signatures before activation.

Commercial Match Status and Retention

To perform customer agreements, establish billing support, handle disputes, and prevent circumvention, we document when an identifiable consultant has been made available to a particular firm through the Service.

The commercial match status has no contractual expiry. To evidence that status, we retain a minimised and access-restricted relationship reference for as long as necessary and lawful for those purposes. Its necessity, access, and minimisation form are reviewed regularly.

The relationship reference is kept separate from the interest lead's full contact details, messages and other free text, and BankID identity data. Those data follow their shorter retention periods and are deleted or minimised when no longer needed; they do not need to be retained for the match status to continue.

The relationship reference is not used for marketing or automated decisions about the consultant. Data subjects can contact support@vardbemanningsguiden.se to request access, correction, deletion, or restriction, or to object to processing under applicable data protection law.

Company contacts

We may temporarily use a name, professional role, and work phone number that a company has published on its website or in a public business source to contact the company about joining the platform. This processing is based on our legitimate interest in offering companies the opportunity to participate. The information is used only by authorized staff and the communications provider needed for the contact. We do not create a contact profile or store the person's name, work number, or individual contact notes in the platform. During the contact, we do not disclose the consultant's name, contact details, message, or identity. If anyone objects, we stop further sales contact and retain only a company-level suppression for as long as needed to honor the objection. You may object at any time during the contact or by emailing support@vardbemanningsguiden.se.

Version history

  • Version: 2026-08-18

    Effective from: August 18, 2026

    Last updated: August 18, 2026

    Current version

  • Version: 2026-07-28

    Effective from: July 28, 2026

    Last updated: July 28, 2026

    View version

  • Version: 2026-07-25

    Effective from: July 25, 2026

    Last updated: July 25, 2026

    View version

  • Version: 2026-07-14

    Effective from: July 14, 2026

    Last updated: July 14, 2026

    View version

  • Version: 2026-07-13-2

    Effective from: July 13, 2026

    Last updated: July 13, 2026

    View version

  • Version: 2026-07-13

    Effective from: July 13, 2026

    Last updated: July 13, 2026

    View version

Allow analytics cookies?