Security and GDPR

Security and personal data belong in the foundation

VagtPilot processes employee and business data with a focus on access control, data minimisation and clear procedures.

What data can be processed?

VagtPilot is not intended as a system for sensitive information or data that is not necessary for employee scheduling, operations and team communication.

  • Employee name
  • Email and contact information
  • Role and department
  • Shift schedules and working hours
  • Clock-in/out and time tracking
  • Absence, changes and shift swaps
  • Team chat and important messages
  • Payroll reports and hours
  • Locations and access control
  • Report and export data

The customer's responsibilities

The customer is responsible for correct use, working-time rules, payroll rules, employment law, internal agreements and its own GDPR obligations.

  • Only create the data that is necessary
  • Give users the right access
  • Remove access when employees leave
  • Avoid sensitive information in the chat
  • Inform employees about the use
  • Comply with regulations for working hours, wages, employment conditions and GDPR

An employee leaves

Access to the schedule, team chat and relevant channels is removed when the employee is no longer employed.

A manager changes role

Access should follow responsibility so that employees, managers and administrators do not see the same data.

Data must be exported

The company may need to find, export or delete relevant employee data following a specific request.

The customer is the data controller. VagtPilot is a data processor.

When a company uses VagtPilot, the company, i.e. the employer, is the data controller for employee data. The customer decides what information is entered, which employees are created, who gets access and how data is used in operations.

VagtPilot does not own the customer's employee data. VagtPilot processes data on behalf of the customer and according to the customer's instructions to provide the platform, support, operations and security.

The data processing agreement and specific subprocessors are described alongside the customer agreement, so responsibilities, purposes and safeguards are clear before data is processed.

VagtPilot does not replace your legal responsibilities

Employee requests for data

If an employee requests access to, correction, deletion or a copy of their information, the request should normally be directed to the employer.

As a rule, VagtPilot cannot disclose employee data directly to employees because VagtPilot is not the data controller for customer data.

VagtPilot can help the customer find, export, correct or delete relevant data according to the customer's instructions.

Access and agreements in practice

Security in day-to-day scheduling

GDPR becomes practical when employees join, leave, change roles or request access to their data.

Frequently asked questions

Is the customer the data controller?

Yes. The customer is generally the data controller for employee data entered into VagtPilot because the customer determines its purpose and use.

Is VagtPilot a data processor?

Yes. VagtPilot acts as a data processor and processes data according to the customer’s documented instructions.

Can an employee obtain their data directly from VagtPilot?

Employees should generally contact their employer, which is the data controller. VagtPilot can assist the employer according to its instructions.

How is employee access controlled?

Access is controlled according to account, role and the business’s setup. The customer is responsible for granting appropriate access and removing it when a role or employment changes.

How are exports and deletion handled?

VagtPilot assists the data controller with relevant requests according to its instructions and the terms of the data processing agreement.

Where is data stored, and which subprocessors are used?

Hosting, data locations and subprocessors are described in the current data processing agreement and associated documentation.

Ready to bring scheduling into one system?