Privacy Policy for the service and the app

Gobrilla Development AB, company reg. no. 559082-1640

Effective from: 2026-08-15 · Version 4.0 · Covers the Favvos service and the Favvos app for iOS and Android.

This policy applies when you use the logged-in service or the Favvos app. If you only visit our website favvos.com, the Privacy Policy for favvos.com applies instead.

1. About this policy

Favvos is a cloud-based service that supports the management of officials at events and other activities. The service is provided by Gobrilla Development AB (“Gobrilla”, “we”, “us”) and is used by sports clubs, federations and other organisers (“the Club”) as well as by the individuals who sign up for and carry out official assignments (“Users”, “you”).

2. Who is responsible for what?

It is important to distinguish two situations, as it determines whom you should turn to.

The Club is the data controller for information about members, officials and assignments. Gobrilla is then the data processor and processes the information solely on the Club’s instructions, governed by a data processing agreement. Contact your Club with questions about why a piece of information is collected, how long it is needed, or about access to and erasure of assignment data.

Gobrilla is the data controller for:

  • your user account, login and account security
  • technical operation, logging, troubleshooting and protection against misuse and intrusion
  • support you contact us about directly
  • aggregated and anonymised statistics about use of the service

3. Contact details

Gobrilla Development AB, Stockholm, Sweden.
Data protection matters: dpo@favvos.com

Support: support@favvos.com

4. What personal data is processed?

Information we receive from the Club

From the Club’s membership register we may receive name, personal identity number, address, contact details, contact details for a guardian or next of kin, and training group.

Information you provide yourself

  • Account and profile: name, email address, telephone number, date of birth, profile picture, role and password in hashed form
  • Assignment-related: clothing sizes, food preferences, merits and qualifications, club affiliation
  • Sign-ups for official assignments
  • Chat messages, attachments, images and documents you send in the service’s chat, and reactions
  • Support requests you send us

Information created when you use the service

  • Attendance and check-in data with timestamps, recorded among other things via QR scanning
  • Technical data: device type, operating system version, app version, IP address and push notification token
  • Security and operational logs, including login events

5. Purposes and legal basis

Purpose

Data

Legal basis

Create and administer your account

Account and profile data

Contract, Art. 6.1 b

Handle sign-ups and official assignments

Assignment and member data

The Club’s legal basis, Art. 6.1 b or f

Record attendance and completed shifts

Attendance and check-in data

The Club’s legal basis, Art. 6.1 b or f

Plan staffing based on sizes and dietary needs

Clothing sizes, food preferences

The Club’s legal basis, Art. 6.1 f, and Art. 9.2 a for data about health or religion

Send notifications and reminders about assignments

Email, telephone number, push token

Contract, Art. 6.1 b

Communication between participants at an event

Chat messages and attachments

The Club’s legal basis, Art. 6.1 f

Operation, security and protection against misuse

Technical data, logs

Legitimate interest, Art. 6.1 f

Support

Case data

Legitimate interest, Art. 6.1 f

Accounting and other legal obligations

Contract and invoicing data

Legal obligation, Art. 6.1 c

6. Sensitive data, food preferences and personal identity numbers

Food preferences may reveal sensitive data. Information about an allergy, gluten intolerance or special diet may reveal a health condition, and information about halal, kosher or vegetarian diet may reveal religious belief. Such information constitutes special categories of personal data under Article 9 GDPR.

The same applies to information the Club chooses to collect in custom fields, such as allergies or medical information, and to content shared in the chat.

Such processing requires a valid exemption under Article 9.2 GDPR, in practice normally your explicit consent. It is the Club, not Gobrilla, that is responsible for ensuring that such an exemption exists. We recommend that the Club obtain explicit consent and offer a free-text option instead of fixed categories where possible.

Personal identity numbers are processed only where clearly justified in relation to the purpose, in accordance with Chapter 3, Section 10 of the Swedish Data Protection Act (2018:218). Personal identity numbers are not used as login identity and are not displayed unnecessarily in the interface.

7. Children and young people

Official assignments are often carried out by young people, and the Club’s membership register may contain data about children. We therefore process data about individuals under the age of 18.

The processing is not based on the child’s consent but on the Club’s legal basis for member and official management. Registered data about a guardian or next of kin is used for contact on matters relating to the assignment.

If you are a guardian and have questions about data relating to your child, contact the Club in the first instance. We assist the Club in responding to such requests.

8. Permissions in the app

Permission

Purpose

What happens to the data

Camera

Scanning a QR code at check-in

No image is stored or sent anywhere. Only the content of the QR code is read

Photo library

Upload profile picture and attachments in the chat

The image is sent to the Favvos backend and, for chat attachments, to the chat platform

Files

Attach documents in the chat

The file is sent to the Favvos backend and the chat platform

Push notifications

Reminders and updates about your assignment

The device token is registered in the Favvos backend and used for sending

The app never reads your photo library in the background. Only the files you choose yourself are transferred. Permissions can be withdrawn at any time in your device settings.

9. Information stored locally on your device

Data

Protection

Login token

Encrypted in the iOS Keychain and Android Keystore respectively

Selected club or organisation

The app’s local storage

App settings and preferences

The app’s local storage

The data is deleted when you log out or uninstall the app.

10. No tracking in the app

We want to be clear about what the app does not do:

  • no cookies, no analytics software and no behavioural tracking, neither Firebase Analytics, Mixpanel, Sentry nor equivalent
  • no login via Google, Apple or Facebook
  • no payment services

The AI-based classification via OpenAI described in Section 12 processes public calendar information in order to categorise events. It does not involve behavioural tracking or profiling of you, and the data we store about you is not sent to OpenAI.

11. Recipients

Data is shared only in the following cases:

  • Your Club and its administrators, who have access to data about membership and assignments
  • Other users at the same event, to the extent the assignment requires, such as name and role in the schedule and chat
  • Providers that process data on our behalf, as listed in Section 12
  • Public authorities, where we are required by law or official decision
  • On a transfer of the business, whereby the recipient is bound by equivalent terms

12. Providers and sub-processors

All providers below are bound by data processing agreements.

Provider

Purpose

Data

Processing location

Amazon Web Services EMEA SARL

Operation, storage and backup of the Favvos backend

All data in the service

EU

Amazon SES (AWS), eu-west-1 Ireland

Sending email from the service

Name, email address, message content

EU (Ireland)

Expo Inc.

Relaying push notifications to Apple and Google

Device token and the content of the notification

USA

Apple Inc.

Apple Push Notification service, notifications to iOS

Device token, notification content

USA

Google LLC

Firebase Cloud Messaging, notifications to Android

Device token, notification content

USA

OpenAI

AI-based classification of event information retrieved from a calendar URL

Publicly available calendar information, such as the event’s title, time and place

USA

The chat function runs on Rocket.Chat, open-source software that Gobrilla operates in its own infrastructure at Amazon Web Services within the EU. Rocket.Chat Technologies Corp. has no access to the data and is not a sub-processor. Chat data is therefore processed within the EU by Amazon Web Services in accordance with the row above.

About OpenAI. We use OpenAI to automatically classify and categorise events based on information retrieved from a publicly available calendar URL. What is sent to OpenAI is therefore the public calendar information, not the data we store about you as a user, such as your account, your assignments, your food preferences or chat content. We use OpenAI’s API in such a way that the data is not used to train their models. Should the public calendar information in an individual case contain personal data, for example a name in an event title, that processing is also covered by a data processing agreement with OpenAI and by the safeguards in Section 13.

13. Transfers to third countries

Operation and storage of the service take place within the EU/EEA.

Some services mean that data is processed in the USA. This applies to the relaying of push notifications via Expo, Apple and Google, and the AI-based classification via OpenAI.

For these transfers we apply the European Commission’s Standard Contractual Clauses under Article 46.2 c GDPR, where applicable combined with the recipient being certified under the EU-U.S. Data Privacy Framework, together with supplementary safeguards such as encryption and data minimisation.

Note on push notifications. The content of a notification passes through the infrastructure of Expo, Apple and Google respectively. We therefore design notifications to contain as little personal data as possible, and place details about the assignment in the app rather than in the notification text.

You can request a copy of the applicable safeguards by emailing dpo@favvos.com.

14. Retention periods

Data

Retention period

Account and profile data

As long as the account is active

Member and assignment data from the Club

According to the Club’s instructions, at longest until the Club’s agreement ends

Data after a terminated customer agreement

Deleted one month after the agreement ends, after the Club has had the opportunity to export data

Attendance history

According to the Club’s instructions

Chat messages and attachments

24 months after the end of the event, unless the Club instructs otherwise (justified by events recurring, sometimes more than 12 months apart)

Profile picture

Until you change or delete it, or the account is closed

Login token on the device

Until logout or uninstallation

Security and operational logs

12 months

Support cases

24 months

Backups

Rotated continuously, deleted at the latest after 90 days

Records subject to the Accounting Act

Seven years

The active retention of chat, attendance and assignments is set so that you and the Club retain the information between the editions of a recurring event, even when there is more than a year in between. Backups are disaster-recovery copies only and rotate quickly; they are not used as an archive, and erased information disappears from them within the rotation period.

15. Security

We apply technical and organisational measures under Article 32 GDPR, including:

  • encryption of all traffic with TLS over HTTPS, and of the real-time chat over a secure WebSocket connection
  • encryption of stored data at the hosting provider
  • passwords stored hashed, and the login token stored encrypted on the device via the operating system’s key management
  • access control based on the principle of least privilege
  • logging of access to personal data
  • continuous backup
  • confidentiality undertakings for staff and consultants
  • a routine for handling and reporting personal data breaches

16. Your rights

You have the right to request access to your personal data, rectification of inaccurate data, erasure, restriction of processing, data portability, and to object to processing based on legitimate interest. Where you have given consent, you may withdraw it at any time.

Where do you turn? If your request concerns data for which the Club is responsible, contact the Club. If it concerns your account or our own processing, contact dpo@favvos.com. We normally respond within one month. If you contact us on a matter for which the Club is responsible, we forward the request and inform you.

17. Account deletion

You can request that your user account be deleted directly in the app or by emailing dpo@favvos.com. Data for which the Club is the controller may need to remain with the Club even after your account is deleted.

18. Complaints

Please contact us first. You also have the right to lodge a complaint with the supervisory authority:
The Swedish Authority for Privacy Protection (IMY) imy@imy.se.

19. Changes

We update this policy when legislation changes or as the service develops. For significant changes we inform you by email or in the service at least 30 days in advance. The version published from time to time applies.