Roles
The customer is the controller of employee data; SwipeMeIn is the processor and processes data only on the customer's documented instructions — i.e. to provide the service.
Security
Encryption in transit, optional encryption at rest for files, access control with roles, audit logs, daily encrypted backups, staff confidentiality.
Sub-processors
Hosting in the EU, email delivery and payment providers. Customers are informed before new sub-processors are added and may object.
Assistance
We help customers answer data subject requests and with data protection impact assessments where needed.
Breaches
We notify the customer without undue delay after becoming aware of a personal data breach.
End
At the end of the service we return (export) and then delete the data, except where law requires us to keep it.