Privacy Policy BigUp app
1. Data Controller
| Data Controller | BigUp Technical Solution AB |
| Registration Number | 559181-4564 |
| Address | Gamla Torget 1, 602 23 Norrköping, Sweden |
| Data Protection Officer (DPO) | Joakim Sternander |
| DPO Contact | joakim@bigup.se |
BigUp Technical Solution AB ("BigUp", "we", "us") operates the BigUp construction project management platform. This privacy policy describes how we collect, use, store and protect your personal data in accordance with the EU General Data Protection Regulation (GDPR, Regulation 2016/679) and applicable Swedish legislation, including the Swedish Data Protection Act (2018:218).
2. Personal Data We Collect
2.1 Account Information
- First and last name, email address, phone number, date of birth
- Company affiliation, language preference, profile picture
2.2 Swedish Identity Data
- Personal identity number, collected via BankID authentication
- ID06 card information
- Organisation registration number
2.3 Construction Site Access
- Check-in and check-out times
- GPS coordinates (latitude, longitude, accuracy, altitude) at check-in/check-out
- These records form part of the electronic personnel register as required by the Swedish Tax Procedures Act
2.4 Emergency Contacts
- Name, phone number and email address of designated emergency contacts per project
2.5 Activity and Audit Data
- Activity logs recording who changed what and when
- Read receipts for documents and files
- Delivery status and confirmations for messages
2.6 Authentication Data
- Session cookies and tokens
- OAuth access and refresh tokens
- BankID authentication data
- Device tokens for push notifications
2.7 Communication Data
- Invitations (email address, name)
- External sharing recipients
- Comment mentions
2.8 Addresses
- Street address, postal code, city, country
- Geographic coordinates (latitude/longitude) for addresses
2.9 Contacts and Customers
- Contact and customer names, organisation numbers, email addresses, phone numbers
2.10 Certificates
- Certificate name, type, issuer, validity dates and associated files
2.11 Session Recordings
- Screen recordings of user interactions within the platform, including form inputs and navigation patterns
- Metadata from network requests captured during sessions
- IP addresses at the time of recording
- Users are identified in recordings by ID, email, name and phone number
2.12 Photos, Video and Audio
- Photos taken using the device camera for construction reports and documentation
- Video recordings (up to 30 seconds, with audio) for site documentation
- These files are attached to reports, tasks or other project records
2.13 Local Device Storage
- OAuth tokens and push notification tokens stored on your device
- Site access keys, project identifiers and language preferences stored locally in your browser or app
- These are required for the application to function and are not shared with third parties
3. Legal Basis for Processing
We process your personal data based on the following legal grounds under GDPR Article 6.1:
| Processing | Legal basis |
|---|---|
| Account creation and platform operation | Art. 6.1 b – Necessary for the performance of a contract |
| BankID identity verification | Art. 6.1 c – Legal obligation; Art. 9.2 g – Substantial public interest (Swedish identity verification requirements) |
| Electronic personnel register and construction site logs | Art. 6.1 c – Legal obligation under the Swedish Tax Procedures Act (2011:1244) |
| GPS location at check-in/check-out | Art. 6.1 c – Legal obligation (personnel register requirements); Art. 6.1 f – Legitimate interest (on-site presence verification) |
| Financial data and accounting integration | Art. 6.1 c – Legal obligation under the Swedish Accounting Act (1999:1078), 7-year retention |
| Activity and audit logs | Art. 6.1 f – Legitimate interest (platform security, integrity and accountability) |
| Error tracking and diagnostics | Art. 6.1 f – Legitimate interest (service reliability and improvement) |
| Session recording and UX analysis (Smartlook) | Art. 6.1 f – Legitimate interest (service improvement, UX analysis, debugging) |
| Address geocoding (Google Maps) | Art. 6.1 b – Necessary for the performance of a contract (address search for projects and construction sites) |
| Camera, video and audio recording | Art. 6.1 b – Necessary for the performance of a contract (construction work documentation) |
| Local data storage (tokens, settings) | Art. 6.1 b – Necessary for the performance of a contract (application functionality) |
| Push notifications | Art. 6.1 b – Necessary for the performance of a contract (delivery of platform services) |
| Emergency contact information | Art. 6.1 f – Legitimate interest (occupational safety on construction sites) |
Where we rely on legitimate interest (Art. 6.1 f), we have conducted balancing tests to ensure that our interests do not override your fundamental rights and freedoms. You may request information about these assessments by contacting our Data Protection Officer.
4. Retention Periods
We retain personal data only for as long as necessary for the purposes for which it was collected, or as required by law:
| Data Category | Retention Period | Basis |
|---|---|---|
| Sensitive personal data (e.g. personal identity numbers) | 90 days after last use, or upon account deletion | Platform security policy |
| Activity/audit logs | 365 days | Platform integrity |
| User sessions | 120 minutes of inactivity | Session management |
| OAuth access tokens | 1 day | Authentication security |
| OAuth refresh tokens | 30 days | Authentication security |
| Password reset tokens | 60 minutes | Security |
| Short-term backups | 7 days | Disaster recovery |
| Long-term backups | 32 days | Disaster recovery |
| Personnel register (construction site logs) | Minimum 2 years | Swedish Tax Procedures Act (2011:1244) |
| Accounting records | 7 years | Swedish Accounting Act (1999:1078) |
After the retention period has expired, data is deleted or anonymised. Some data may be retained in anonymised form for statistical purposes.
5. Third-Party Processors
We use the following third-party service providers (data processors) to operate the platform. All processors are bound by data processing agreements in accordance with GDPR Article 28.
| Processor | Purpose | Country/Region | Transfer safeguard |
|---|---|---|---|
| Finansiell ID-Teknik BID AB (BankID) | Digital identity authentication | Sweden | Not applicable (EU/EEA) |
| 46elks AB | SMS delivery | Sweden | Not applicable (EU/EEA) |
| Fortnox AB | Accounting and financial integration | Sweden | Not applicable (EU/EEA) |
| BunnyWay d.o.o. (Bunny.net) | Video CDN | Slovenia (EU) | Not applicable (EU/EEA) |
| Met.no (Norwegian Meteorological Institute) | Weather data | Norway (EEA) | Not applicable (EU/EEA) |
| Oderland Webbhotell AB | Application hosting (managed servers) | Sweden | Not applicable (EU/EEA) |
| Hetzner Online GmbH | Object storage (S3) and backups | Germany (EU) | Not applicable (EU/EEA) |
| Scaleway (Iliad Group) | Object storage (S3) and backups | France (EU) | Not applicable (EU/EEA) |
| Smartlook.com s.r.o. (Smartlook) | Session recording and UX analysis – records user interactions, form inputs, network requests and IP addresses | Czech Republic (EU) | Not applicable (EU/EEA) |
| Google LLC (Google Maps Platform) | Geocoding, reverse geocoding and address search for construction sites and projects | USA/EU | EU-US Data Privacy Framework / SCC |
| Tolgee s.r.o. (Tolgee) | Translation and localisation platform | Czech Republic (EU) | Not applicable (EU/EEA) |
| Functional Software Inc. (Sentry) | Error tracking and diagnostics – collects error reports, user feedback with screenshots, browser performance tracking and release version; users identified by name and email | USA | EU-US Data Privacy Framework / SCC |
| Google LLC (Firebase/FCM) | Push notifications | USA/EU | EU-US Data Privacy Framework / SCC |
| Email provider (Mailgun/Postmark/SES) | Transactional email delivery | USA/EU | EU-US Data Privacy Framework / SCC |
| HiQ Accelerated Concept Evaluation AB | Platform development and data management | Sweden | Not applicable (EU/EEA) |
| Typesense | Search indexing | Sweden | Not applicable (EU/EEA) |
| Google Cloud | Translation API | USA/EU | EU-US Data Privacy Framework / SCC |
| Autodesk Inc. | 3D model processing (BIM) | USA | EU-US Data Privacy Framework / SCC |
When transferring personal data to countries outside the EU/EEA (primarily the USA), we rely on the EU-US Data Privacy Framework and/or Standard Contractual Clauses (SCC) adopted by the European Commission, in accordance with GDPR Articles 44–49.
6. Cookies
BigUp uses only necessary and functional cookies. We do not use any marketing, advertising or third-party tracking cookies.
| Cookie | Purpose | Type | Duration |
|---|---|---|---|
| bigup_session | Session management | Necessary | 120 minutes |
| XSRF-TOKEN | CSRF protection | Necessary | Session |
| Remember-me token | Persistent login (if selected by user) | Functional | Persistent |
As we use only strictly necessary and functional cookies, no cookie banner is required under the ePrivacy Directive Article 5.3.
Local Device Storage
In addition to cookies, BigUp's mobile and web app stores the following data locally on your device:
| Storage mechanism | Data | Type | Purpose |
|---|---|---|---|
| localStorage | site_access_key, construction_site_id, theme, project_id, locale | Necessary | Application state and settings |
| IndexedDB (Ionic Storage) | access_token, push_token | Necessary | Authentication and push notifications |
This data remains on your device and is not shared with third parties. It is cleared when you log out or uninstall the application.
7. Device Permissions
BigUp's mobile app may request the following device permissions. Each permission is requested only when needed for a specific feature and can be managed through your device settings.
| Permission | Purpose |
|---|---|
| Camera | Taking photos for construction reports, task documentation and site records |
| Microphone | Audio recording as part of video recordings for site documentation |
| Location access (GPS) | Determining your position for field reports, construction site check-in/check-out and presence verification |
| Push notifications (Firebase FCM) | Receiving real-time alerts about project updates, tasks and messages |
You may revoke these permissions at any time through your device settings. Revoking a permission may limit the functionality of the corresponding feature.
8. Your Rights as a Data Subject
Under GDPR Articles 15–22, you have the following rights regarding your personal data:
8.1 Right of Access (Art. 15)
You have the right to request a copy of the personal data we hold about you, together with information about how it is processed.
8.2 Right to Rectification (Art. 16)
You have the right to request correction of inaccurate or incomplete personal data. You can update most account information directly within the platform.
8.3 Right to Erasure (Art. 17)
You have the right to request deletion of your personal data, subject to statutory retention requirements (e.g. personnel register records must be retained for 2 years, accounting records for 7 years).
8.4 Right to Restriction of Processing (Art. 18)
You have the right to request restriction of processing under certain circumstances, for example when you contest the accuracy of the data.
8.5 Right to Data Portability (Art. 20)
You have the right to receive your personal data in a structured, commonly used and machine-readable format. Data portability requests are currently handled manually by our Data Protection Officer – contact joakim@bigup.se.
8.6 Right to Object (Art. 21)
You have the right to object to processing based on legitimate interest (Art. 6.1 f). We will cease processing unless we can demonstrate compelling legitimate grounds.
8.7 Right Not to Be Subject to Automated Decision-Making (Art. 22)
BigUp does not use automated decision-making or profiling that produces legal effects or similarly significantly affects you.
How to Exercise Your Rights
Contact our Data Protection Officer:
- Email: joakim@bigup.se
- Post: BigUp Technical Solution AB, Att: Data Protection Officer, Gamla Torget 1, 602 23 Norrköping, Sweden
We will respond to your request within 30 days. If we need more time (up to 60 additional days for complex requests), we will inform you within the initial 30-day period.
Supervisory Authority
If you are not satisfied with our response, you have the right to lodge a complaint with the Swedish Authority for Privacy Protection (IMY):
- Website: https://www.imy.se
- Email: imy@imy.se
- Address: Integritetsskyddsmyndigheten, Box 8114, 104 20 Stockholm, Sweden
9. Account Deletion
You can delete your account directly within the BigUp platform. When you delete your account, the following actions are taken:
- All authentication tokens and device tokens are revoked and deleted
- Your personal identity number is permanently deleted
- Your name is replaced with "Deleted User"
- Your email address is replaced with a non-functional placeholder address
- Your phone number, date of birth and push notification tokens are removed
- Your profile picture is deleted
Please note:
- Personnel register records subject to statutory retention are kept for the required period but are no longer linked to your identifiable account
- Accounting records required under the Swedish Accounting Act are retained for 7 years
- Soft-deleted records may be retained for audit purposes where required by law
10. Security Measures
We implement appropriate technical and organisational measures to protect your personal data in accordance with GDPR Article 32:
- Password security: Bcrypt hashing algorithm
- Session security: HTTP-only cookies with SameSite=Lax
- CSRF protection: Token-based protection against cross-site request forgery
- Identity data protection: Personal identity numbers are permanently deleted upon account deletion
- Access control: Role-based access control (RBAC) throughout the platform
- Backups: Encrypted backups with defined retention periods
- Privacy in error tracking: Collection of personally identifiable information (PII) is disabled by default in error tracking
- Transport encryption: All data is transmitted via HTTPS/TLS
11. Changes to This Policy
We may update this privacy policy from time to time. Material changes will be communicated via the platform or by email. The "Last updated" date at the top of this document indicates when the policy was last revised.
12. Contact
For questions about this privacy policy or our personal data processing, please contact:
BigUp Technical Solution AB
Att: Data Protection Officer
Gamla Torget 1, 602 23 Norrköping, Sweden
Email: joakim@bigup.se