Privacy Policy
This Privacy Policy explains how Headcount Technologies AB (reg. no. 559465-8527) (“Headcount Technologies”, “we”, “our”, “us”) manages and processes personal data collected when you use our services or products via our website, platform, or consultancy services.
We prioritise transparency in how we handle personal data. We may update this Privacy Policy to reflect new features or improvements. When updates occur, we will take reasonable steps to inform you unless changes are minor. If you have questions about our use of personal data, please contact us using the details at the end of this policy.
This Privacy Policy applies to personal data processed by Headcount Technologies within the scope of our services. It does not cover other parties involved in delivering these services; please review their respective privacy policies.
“Processing” includes any operation performed on personal data, such as collection, handling, storage, sharing, access, use, transfer, and deletion.
“Applicable Data Protection Laws” refers to all current legislation and regulations, including those issued by supervisory authorities, that protect individuals’ rights and freedoms in relation to privacy and personal data processing. This includes Regulation (EU) 2016/679 (GDPR) and national laws supplementing the GDPR.
“Personal data” means any information relating to an identified or identifiable natural person.
The data controller
Headcount Technologies AB, reg. no. 559465-8527, Hornsbruksgatan 23b, 117 28 Stockholm, Sweden, is the data controller responsible for processing your personal data as described in this Privacy Policy.
For personal data processed on behalf of our customers within the platform, Headcount Technologies acts as a data processor and the customer is the data controller.
Personal data we collect
We collect personal data from:
- You directly, e.g., when you sign up for newsletters, download free templates, visit our site, or use our services (including technical data such as device type and browser version).
- Other sources, such as publicly available information and third parties.
You may choose to withhold certain information, but some data is necessary to provide the services you expect. Without it, we may not be able to deliver certain features.
Logging in with Google
We use the OAuth 2.0 standard for secure authentication. If you log in with Google, we do not store access tokens or other credentials that would allow us to access your Google account or its data.
Purposes for processing your personal data
We process personal data to create and manage accounts, provide support, send service updates/notifications, deliver software updates, and fulfil contractual obligations. Below we describe typical purposes, examples, legal bases, and storage periods.
Data retention
We retain personal data only as long as necessary for the purposes collected or longer if required by law. Retention per purpose is specified below.
1) Using our services on the platform
We process personal data to provide a fast, secure, and reliable service experience and to deliver requested functionality. Necessary cookies may be used; see our Cookie Policy for details.
Purpose: Register and manage user accounts; verify login to enhance security and prevent misuse; communicate to assist with services.
Categories: Name, email, IP address, phone number, title, personal identification number.
Source: You; Company Registry and Ratsit.
Legal basis: Contract performance and our legitimate interest in verifying identity, enhancing security, preventing misuse, and delivering platform services.
Retention: For as long as the user holds an account or longer if agreed after termination.
2) Visitors to our website
We use a third-party service to collect standard internet log information and visitor behaviour to understand site usage. This information is processed in a way that does not identify individuals. Necessary cookies may be used; see our Cookie Policy.
3) Downloading templates
Purpose: Facilitate template downloads from our site.
Categories: Name, email, IP address.
Source: You.
Legal basis: Consent.
Retention: Until consent is withdrawn.
4) Customer support via chat and email
Purpose: Enable efficient customer support communication.
Categories: Name, email, IP address, phone number.
Source: You.
Legal basis: Legitimate interest in verifying identity, providing support, and fulfilling contractual commitments.
Retention: For as long as the user holds an account or longer if agreed after termination.
5) Purchasing our platform via checkout
We process data to manage purchases, contact you about orders, process payments, provide information, and request feedback. Payments are handled by Stripe. We do not store card details.
Purpose: Process webshop purchases.
Categories: Name, address, email, IP address, phone number.
Source: You.
Legal basis: Legitimate interest in verifying identity, preventing misuse, delivering products, processing payments, and meeting bookkeeping obligations.
Retention: As needed to deliver the purchase and as required by applicable law (e.g., the Swedish Accounting Act).
6) Newsletters
We collect data during newsletter sign-up to send updates about documents, tools, and services, and to ensure records remain accurate. You consent to receive these communications and can withdraw consent at any time via the unsubscribe link or by emailing hello@headcounthr.se.
We use third-party providers (e.g., Brevo) to deliver newsletters and measure opens/clicks to improve content. See their privacy policies for details.
Purpose: Send newsletters to subscribers.
Categories: Name, email.
Source: You.
Legal basis: Consent.
Retention: Until you opt out.
7) Statistics and analytics
Purpose: Collect statistics and perform analytics to improve services and user experience.
Categories: Email, IP address, browser information.
Source: You.
Legal basis: Legitimate interest in service improvement.
Retention: 14 months.
8) Legal compliance
Purpose: Fulfil legal obligations (e.g., bookkeeping, anti-money laundering) or protect legal rights, including responding to court or authority requests.
Categories: Name (and other data as legally required).
Source: You.
Legal basis: Legal obligation.
Retention: For the period required by applicable laws.
9) Security and misuse prevention
We process data to prevent misuse, unauthorised access, and crime, and to protect our IT environment (e.g., encryption, access controls, monitoring). Necessary cookies may be used.
Purposes include:
- Prevent spam, phishing, harassment, unauthorised login attempts, or other prohibited actions.
- Prevent and investigate potential fraud or legal violations.
- Implement security measures (including cookies) to protect and improve our IT environment.
Categories:
- User-generated data (e.g., clicks, visitor statistics).
- Device information (e.g., device type, language and web settings, time zone).
- Name.
- Online identifiers (e.g., IP address, cookie ID, user ID).
Source: You.
Legal basis: Legitimate interest in providing secure services and preventing misuse or crime.
Retention: 36 months after the end of the year of collection; longer if needed to defend legal claims.
Who we share personal data with
-
Data processors
We engage third parties (typically IT service providers) that process personal data on our behalf under data processing agreements (DPAs) and our instructions.Sub-processors
We maintain an up-to-date list of sub-processors that meet our security and compliance standards (GDPR Art. 28):Provider Purpose Location Privacy Policy UpCloud Cloud hosting & infrastructure (storage of customer data) Sweden upcloud.com/privacy-policy Scaleway Cloud infrastructure / backup & redundancy France (EU) scaleway.com/en/privacy-policy Atlas Cloud Database migrations / managed database tasks EU / UK atlascloud.co.uk/privacy-policy GlitchTip (Elestio) Application monitoring, error reporting, log metadata EU / Global glitchtip.com/legal/privacy Chatwoot Customer support chat / user interaction EU / Global chatwoot.com/privacy-policy Google Workspace / Google Cloud Email, documents, collaboration tools EU (Ireland) workspace.google.com/terms Stripe Payment processing USA / Global stripe.com/privacy -
Independent data controllers
We may share personal data with entities acting as independent controllers. We may also disclose data to authorities (e.g., law enforcement) where required or lawful. -
Transfers outside the EU/EEA
We strive to process data within the EU/EEA. If transfers outside the EU/EEA are necessary, we ensure appropriate safeguards are in place.
Your rights
Subject to applicable law, you may have the right to:
- Access – request confirmation and access to your personal data and related information, including a copy.
- Object – object to processing based on legitimate interests where your situation justifies it; we will stop unless we demonstrate compelling legitimate grounds or processing is needed for legal claims.
- Rectification – request correction of inaccurate or incomplete data.
- Erasure – request deletion where data is no longer necessary or other grounds apply.
- Restriction – request limited processing (storage only) under certain circumstances.
- Withdraw consent – withdraw consent at any time where processing relies on consent.
- Data portability – receive personal data you provided in a structured, commonly used, machine-readable format and, where feasible, have it transmitted to another controller.
Complaints
If you have concerns about our handling of personal data, you may lodge a complaint with the relevant supervisory authority. In Sweden, this is Integritetsskyddsmyndigheten (IMY) – see imy.se. You can also email us at hello@headcounthr.se.
Contact
Data Controller: Headcount Technologies AB
Reg. No: 559465-8527
Address: Hornsbruksgatan 23b, 117 28 Stockholm, Sweden
Email: hello@headcounthr.se