Privacy Policy BigUp app

BigUp Technical Solution AB
Last updated
2026-02-10

1. Data Controller

Data Controller BigUp Technical Solution AB
Registration Number 559181-4564
Address Gamla Torget 1, 602 23 Norrköping, Sweden
Data Protection Officer (DPO) Joakim Sternander
DPO Contact joakim@bigup.se

BigUp Technical Solution AB ("BigUp", "we", "us") operates the BigUp construction project management platform. This privacy policy describes how we collect, use, store and protect your personal data in accordance with the EU General Data Protection Regulation (GDPR, Regulation 2016/679) and applicable Swedish legislation, including the Swedish Data Protection Act (2018:218).

2. Personal Data We Collect

2.1 Account Information

  • First and last name, email address, phone number, date of birth
  • Company affiliation, language preference, profile picture

2.2 Swedish Identity Data

  • Personal identity number, collected via BankID authentication
  • ID06 card information
  • Organisation registration number

2.3 Construction Site Access

  • Check-in and check-out times
  • GPS coordinates (latitude, longitude, accuracy, altitude) at check-in/check-out
  • These records form part of the electronic personnel register as required by the Swedish Tax Procedures Act

2.4 Emergency Contacts

  • Name, phone number and email address of designated emergency contacts per project

2.5 Activity and Audit Data

  • Activity logs recording who changed what and when
  • Read receipts for documents and files
  • Delivery status and confirmations for messages

2.6 Authentication Data

  • Session cookies and tokens
  • OAuth access and refresh tokens
  • BankID authentication data
  • Device tokens for push notifications

2.7 Communication Data

  • Invitations (email address, name)
  • External sharing recipients
  • Comment mentions

2.8 Addresses

  • Street address, postal code, city, country
  • Geographic coordinates (latitude/longitude) for addresses

2.9 Contacts and Customers

  • Contact and customer names, organisation numbers, email addresses, phone numbers

2.10 Certificates

  • Certificate name, type, issuer, validity dates and associated files

2.11 Session Recordings

  • Screen recordings of user interactions within the platform, including form inputs and navigation patterns
  • Metadata from network requests captured during sessions
  • IP addresses at the time of recording
  • Users are identified in recordings by ID, email, name and phone number

2.12 Photos, Video and Audio

  • Photos taken using the device camera for construction reports and documentation
  • Video recordings (up to 30 seconds, with audio) for site documentation
  • These files are attached to reports, tasks or other project records

2.13 Local Device Storage

  • OAuth tokens and push notification tokens stored on your device
  • Site access keys, project identifiers and language preferences stored locally in your browser or app
  • These are required for the application to function and are not shared with third parties

3. Legal Basis for Processing

We process your personal data based on the following legal grounds under GDPR Article 6.1:

Processing Legal basis
Account creation and platform operation Art. 6.1 b – Necessary for the performance of a contract
BankID identity verification Art. 6.1 c – Legal obligation; Art. 9.2 g – Substantial public interest (Swedish identity verification requirements)
Electronic personnel register and construction site logs Art. 6.1 c – Legal obligation under the Swedish Tax Procedures Act (2011:1244)
GPS location at check-in/check-out Art. 6.1 c – Legal obligation (personnel register requirements); Art. 6.1 f – Legitimate interest (on-site presence verification)
Financial data and accounting integration Art. 6.1 c – Legal obligation under the Swedish Accounting Act (1999:1078), 7-year retention
Activity and audit logs Art. 6.1 f – Legitimate interest (platform security, integrity and accountability)
Error tracking and diagnostics Art. 6.1 f – Legitimate interest (service reliability and improvement)
Session recording and UX analysis (Smartlook) Art. 6.1 f – Legitimate interest (service improvement, UX analysis, debugging)
Address geocoding (Google Maps) Art. 6.1 b – Necessary for the performance of a contract (address search for projects and construction sites)
Camera, video and audio recording Art. 6.1 b – Necessary for the performance of a contract (construction work documentation)
Local data storage (tokens, settings) Art. 6.1 b – Necessary for the performance of a contract (application functionality)
Push notifications Art. 6.1 b – Necessary for the performance of a contract (delivery of platform services)
Emergency contact information Art. 6.1 f – Legitimate interest (occupational safety on construction sites)

Where we rely on legitimate interest (Art. 6.1 f), we have conducted balancing tests to ensure that our interests do not override your fundamental rights and freedoms. You may request information about these assessments by contacting our Data Protection Officer.

4. Retention Periods

We retain personal data only for as long as necessary for the purposes for which it was collected, or as required by law:

Data Category Retention Period Basis
Sensitive personal data (e.g. personal identity numbers) 90 days after last use, or upon account deletion Platform security policy
Activity/audit logs 365 days Platform integrity
User sessions 120 minutes of inactivity Session management
OAuth access tokens 1 day Authentication security
OAuth refresh tokens 30 days Authentication security
Password reset tokens 60 minutes Security
Short-term backups 7 days Disaster recovery
Long-term backups 32 days Disaster recovery
Personnel register (construction site logs) Minimum 2 years Swedish Tax Procedures Act (2011:1244)
Accounting records 7 years Swedish Accounting Act (1999:1078)

After the retention period has expired, data is deleted or anonymised. Some data may be retained in anonymised form for statistical purposes.

5. Third-Party Processors

We use the following third-party service providers (data processors) to operate the platform. All processors are bound by data processing agreements in accordance with GDPR Article 28.

Processor Purpose Country/Region Transfer safeguard
Finansiell ID-Teknik BID AB (BankID) Digital identity authentication Sweden Not applicable (EU/EEA)
46elks AB SMS delivery Sweden Not applicable (EU/EEA)
Fortnox AB Accounting and financial integration Sweden Not applicable (EU/EEA)
BunnyWay d.o.o. (Bunny.net) Video CDN Slovenia (EU) Not applicable (EU/EEA)
Met.no (Norwegian Meteorological Institute) Weather data Norway (EEA) Not applicable (EU/EEA)
Oderland Webbhotell AB Application hosting (managed servers) Sweden Not applicable (EU/EEA)
Hetzner Online GmbH Object storage (S3) and backups Germany (EU) Not applicable (EU/EEA)
Scaleway (Iliad Group) Object storage (S3) and backups France (EU) Not applicable (EU/EEA)
Smartlook.com s.r.o. (Smartlook) Session recording and UX analysis – records user interactions, form inputs, network requests and IP addresses Czech Republic (EU) Not applicable (EU/EEA)
Google LLC (Google Maps Platform) Geocoding, reverse geocoding and address search for construction sites and projects USA/EU EU-US Data Privacy Framework / SCC
Tolgee s.r.o. (Tolgee) Translation and localisation platform Czech Republic (EU) Not applicable (EU/EEA)
Functional Software Inc. (Sentry) Error tracking and diagnostics – collects error reports, user feedback with screenshots, browser performance tracking and release version; users identified by name and email USA EU-US Data Privacy Framework / SCC
Google LLC (Firebase/FCM) Push notifications USA/EU EU-US Data Privacy Framework / SCC
Email provider (Mailgun/Postmark/SES) Transactional email delivery USA/EU EU-US Data Privacy Framework / SCC
HiQ Accelerated Concept Evaluation AB Platform development and data management Sweden Not applicable (EU/EEA)
Typesense Search indexing Sweden Not applicable (EU/EEA)
Google Cloud Translation API USA/EU EU-US Data Privacy Framework / SCC
Autodesk Inc. 3D model processing (BIM) USA EU-US Data Privacy Framework / SCC

When transferring personal data to countries outside the EU/EEA (primarily the USA), we rely on the EU-US Data Privacy Framework and/or Standard Contractual Clauses (SCC) adopted by the European Commission, in accordance with GDPR Articles 44–49.

6. Cookies

BigUp uses only necessary and functional cookies. We do not use any marketing, advertising or third-party tracking cookies.

Cookie Purpose Type Duration
bigup_session Session management Necessary 120 minutes
XSRF-TOKEN CSRF protection Necessary Session
Remember-me token Persistent login (if selected by user) Functional Persistent

As we use only strictly necessary and functional cookies, no cookie banner is required under the ePrivacy Directive Article 5.3.

Local Device Storage

In addition to cookies, BigUp's mobile and web app stores the following data locally on your device:

Storage mechanism Data Type Purpose
localStorage site_access_key, construction_site_id, theme, project_id, locale Necessary Application state and settings
IndexedDB (Ionic Storage) access_token, push_token Necessary Authentication and push notifications

This data remains on your device and is not shared with third parties. It is cleared when you log out or uninstall the application.

7. Device Permissions

BigUp's mobile app may request the following device permissions. Each permission is requested only when needed for a specific feature and can be managed through your device settings.

Permission Purpose
Camera Taking photos for construction reports, task documentation and site records
Microphone Audio recording as part of video recordings for site documentation
Location access (GPS) Determining your position for field reports, construction site check-in/check-out and presence verification
Push notifications (Firebase FCM) Receiving real-time alerts about project updates, tasks and messages

You may revoke these permissions at any time through your device settings. Revoking a permission may limit the functionality of the corresponding feature.

8. Your Rights as a Data Subject

Under GDPR Articles 15–22, you have the following rights regarding your personal data:

8.1 Right of Access (Art. 15)

You have the right to request a copy of the personal data we hold about you, together with information about how it is processed.

8.2 Right to Rectification (Art. 16)

You have the right to request correction of inaccurate or incomplete personal data. You can update most account information directly within the platform.

8.3 Right to Erasure (Art. 17)

You have the right to request deletion of your personal data, subject to statutory retention requirements (e.g. personnel register records must be retained for 2 years, accounting records for 7 years).

8.4 Right to Restriction of Processing (Art. 18)

You have the right to request restriction of processing under certain circumstances, for example when you contest the accuracy of the data.

8.5 Right to Data Portability (Art. 20)

You have the right to receive your personal data in a structured, commonly used and machine-readable format. Data portability requests are currently handled manually by our Data Protection Officer – contact joakim@bigup.se.

8.6 Right to Object (Art. 21)

You have the right to object to processing based on legitimate interest (Art. 6.1 f). We will cease processing unless we can demonstrate compelling legitimate grounds.

8.7 Right Not to Be Subject to Automated Decision-Making (Art. 22)

BigUp does not use automated decision-making or profiling that produces legal effects or similarly significantly affects you.

How to Exercise Your Rights

Contact our Data Protection Officer:

  • Email: joakim@bigup.se
  • Post: BigUp Technical Solution AB, Att: Data Protection Officer, Gamla Torget 1, 602 23 Norrköping, Sweden

We will respond to your request within 30 days. If we need more time (up to 60 additional days for complex requests), we will inform you within the initial 30-day period.

Supervisory Authority

If you are not satisfied with our response, you have the right to lodge a complaint with the Swedish Authority for Privacy Protection (IMY):

9. Account Deletion

You can delete your account directly within the BigUp platform. When you delete your account, the following actions are taken:

  • All authentication tokens and device tokens are revoked and deleted
  • Your personal identity number is permanently deleted
  • Your name is replaced with "Deleted User"
  • Your email address is replaced with a non-functional placeholder address
  • Your phone number, date of birth and push notification tokens are removed
  • Your profile picture is deleted

Please note:

  • Personnel register records subject to statutory retention are kept for the required period but are no longer linked to your identifiable account
  • Accounting records required under the Swedish Accounting Act are retained for 7 years
  • Soft-deleted records may be retained for audit purposes where required by law

10. Security Measures

We implement appropriate technical and organisational measures to protect your personal data in accordance with GDPR Article 32:

  • Password security: Bcrypt hashing algorithm
  • Session security: HTTP-only cookies with SameSite=Lax
  • CSRF protection: Token-based protection against cross-site request forgery
  • Identity data protection: Personal identity numbers are permanently deleted upon account deletion
  • Access control: Role-based access control (RBAC) throughout the platform
  • Backups: Encrypted backups with defined retention periods
  • Privacy in error tracking: Collection of personally identifiable information (PII) is disabled by default in error tracking
  • Transport encryption: All data is transmitted via HTTPS/TLS

11. Changes to This Policy

We may update this privacy policy from time to time. Material changes will be communicated via the platform or by email. The "Last updated" date at the top of this document indicates when the policy was last revised.

12. Contact

For questions about this privacy policy or our personal data processing, please contact:

BigUp Technical Solution AB
Att: Data Protection Officer
Gamla Torget 1, 602 23 Norrköping, Sweden
Email: joakim@bigup.se