Privacy Policy for the service and the app
Gobrilla Development AB, company reg. no. 559082-1640
Effective from: 2026-08-15 · Version 4.0 · Covers the Favvos service and the Favvos app for iOS and Android.
This policy applies when you use the logged-in service or the Favvos app. If you only visit our website favvos.com, the Privacy Policy for favvos.com applies instead.
1. About this policy
Favvos is a cloud-based service that supports the management of officials at events and other activities. The service is provided by Gobrilla Development AB (“Gobrilla”, “we”, “us”) and is used by sports clubs, federations and other organisers (“the Club”) as well as by the individuals who sign up for and carry out official assignments (“Users”, “you”).
2. Who is responsible for what?
It is important to distinguish two situations, as it determines whom you should turn to.
The Club is the data controller for information about members, officials and assignments. Gobrilla is then the data processor and processes the information solely on the Club’s instructions, governed by a data processing agreement. Contact your Club with questions about why a piece of information is collected, how long it is needed, or about access to and erasure of assignment data.
Gobrilla is the data controller for:
- your user account, login and account security
- technical operation, logging, troubleshooting and protection against misuse and intrusion
- support you contact us about directly
- aggregated and anonymised statistics about use of the service
3. Contact details
Gobrilla Development AB, Stockholm, Sweden.
Data protection matters: dpo@favvos.com
Support: support@favvos.com
4. What personal data is processed?
Information we receive from the Club
From the Club’s membership register we may receive name, personal identity number, address, contact details, contact details for a guardian or next of kin, and training group.
Information you provide yourself
- Account and profile: name, email address, telephone number, date of birth, profile picture, role and password in hashed form
- Assignment-related: clothing sizes, food preferences, merits and qualifications, club affiliation
- Sign-ups for official assignments
- Chat messages, attachments, images and documents you send in the service’s chat, and reactions
- Support requests you send us
Information created when you use the service
- Attendance and check-in data with timestamps, recorded among other things via QR scanning
- Technical data: device type, operating system version, app version, IP address and push notification token
- Security and operational logs, including login events
5. Purposes and legal basis
Purpose | Data | Legal basis |
|---|---|---|
Create and administer your account | Account and profile data | Contract, Art. 6.1 b |
Handle sign-ups and official assignments | Assignment and member data | The Club’s legal basis, Art. 6.1 b or f |
Record attendance and completed shifts | Attendance and check-in data | The Club’s legal basis, Art. 6.1 b or f |
Plan staffing based on sizes and dietary needs | Clothing sizes, food preferences | The Club’s legal basis, Art. 6.1 f, and Art. 9.2 a for data about health or religion |
Send notifications and reminders about assignments | Email, telephone number, push token | Contract, Art. 6.1 b |
Communication between participants at an event | Chat messages and attachments | The Club’s legal basis, Art. 6.1 f |
Operation, security and protection against misuse | Technical data, logs | Legitimate interest, Art. 6.1 f |
Support | Case data | Legitimate interest, Art. 6.1 f |
Accounting and other legal obligations | Contract and invoicing data | Legal obligation, Art. 6.1 c |
6. Sensitive data, food preferences and personal identity numbers
Food preferences may reveal sensitive data. Information about an allergy, gluten intolerance or special diet may reveal a health condition, and information about halal, kosher or vegetarian diet may reveal religious belief. Such information constitutes special categories of personal data under Article 9 GDPR.
The same applies to information the Club chooses to collect in custom fields, such as allergies or medical information, and to content shared in the chat.
Such processing requires a valid exemption under Article 9.2 GDPR, in practice normally your explicit consent. It is the Club, not Gobrilla, that is responsible for ensuring that such an exemption exists. We recommend that the Club obtain explicit consent and offer a free-text option instead of fixed categories where possible.
Personal identity numbers are processed only where clearly justified in relation to the purpose, in accordance with Chapter 3, Section 10 of the Swedish Data Protection Act (2018:218). Personal identity numbers are not used as login identity and are not displayed unnecessarily in the interface.
7. Children and young people
Official assignments are often carried out by young people, and the Club’s membership register may contain data about children. We therefore process data about individuals under the age of 18.
The processing is not based on the child’s consent but on the Club’s legal basis for member and official management. Registered data about a guardian or next of kin is used for contact on matters relating to the assignment.
If you are a guardian and have questions about data relating to your child, contact the Club in the first instance. We assist the Club in responding to such requests.
8. Permissions in the app
Permission | Purpose | What happens to the data |
|---|---|---|
Camera | Scanning a QR code at check-in | No image is stored or sent anywhere. Only the content of the QR code is read |
Photo library | Upload profile picture and attachments in the chat | The image is sent to the Favvos backend and, for chat attachments, to the chat platform |
Files | Attach documents in the chat | The file is sent to the Favvos backend and the chat platform |
Push notifications | Reminders and updates about your assignment | The device token is registered in the Favvos backend and used for sending |
The app never reads your photo library in the background. Only the files you choose yourself are transferred. Permissions can be withdrawn at any time in your device settings.
9. Information stored locally on your device
Data | Protection |
|---|---|
Login token | Encrypted in the iOS Keychain and Android Keystore respectively |
Selected club or organisation | The app’s local storage |
App settings and preferences | The app’s local storage |
The data is deleted when you log out or uninstall the app.
10. No tracking in the app
We want to be clear about what the app does not do:
- no cookies, no analytics software and no behavioural tracking, neither Firebase Analytics, Mixpanel, Sentry nor equivalent
- no login via Google, Apple or Facebook
- no payment services
The AI-based classification via OpenAI described in Section 12 processes public calendar information in order to categorise events. It does not involve behavioural tracking or profiling of you, and the data we store about you is not sent to OpenAI.
11. Recipients
Data is shared only in the following cases:
- Your Club and its administrators, who have access to data about membership and assignments
- Other users at the same event, to the extent the assignment requires, such as name and role in the schedule and chat
- Providers that process data on our behalf, as listed in Section 12
- Public authorities, where we are required by law or official decision
- On a transfer of the business, whereby the recipient is bound by equivalent terms
12. Providers and sub-processors
All providers below are bound by data processing agreements.
Provider | Purpose | Data | Processing location |
|---|---|---|---|
Amazon Web Services EMEA SARL | Operation, storage and backup of the Favvos backend | All data in the service | EU |
Amazon SES (AWS), eu-west-1 Ireland | Sending email from the service | Name, email address, message content | EU (Ireland) |
Expo Inc. | Relaying push notifications to Apple and Google | Device token and the content of the notification | USA |
Apple Inc. | Apple Push Notification service, notifications to iOS | Device token, notification content | USA |
Google LLC | Firebase Cloud Messaging, notifications to Android | Device token, notification content | USA |
OpenAI | AI-based classification of event information retrieved from a calendar URL | Publicly available calendar information, such as the event’s title, time and place | USA |
The chat function runs on Rocket.Chat, open-source software that Gobrilla operates in its own infrastructure at Amazon Web Services within the EU. Rocket.Chat Technologies Corp. has no access to the data and is not a sub-processor. Chat data is therefore processed within the EU by Amazon Web Services in accordance with the row above.
About OpenAI. We use OpenAI to automatically classify and categorise events based on information retrieved from a publicly available calendar URL. What is sent to OpenAI is therefore the public calendar information, not the data we store about you as a user, such as your account, your assignments, your food preferences or chat content. We use OpenAI’s API in such a way that the data is not used to train their models. Should the public calendar information in an individual case contain personal data, for example a name in an event title, that processing is also covered by a data processing agreement with OpenAI and by the safeguards in Section 13.
13. Transfers to third countries
Operation and storage of the service take place within the EU/EEA.
Some services mean that data is processed in the USA. This applies to the relaying of push notifications via Expo, Apple and Google, and the AI-based classification via OpenAI.
For these transfers we apply the European Commission’s Standard Contractual Clauses under Article 46.2 c GDPR, where applicable combined with the recipient being certified under the EU-U.S. Data Privacy Framework, together with supplementary safeguards such as encryption and data minimisation.
Note on push notifications. The content of a notification passes through the infrastructure of Expo, Apple and Google respectively. We therefore design notifications to contain as little personal data as possible, and place details about the assignment in the app rather than in the notification text.
You can request a copy of the applicable safeguards by emailing dpo@favvos.com.
14. Retention periods
Data | Retention period |
|---|---|
Account and profile data | As long as the account is active |
Member and assignment data from the Club | According to the Club’s instructions, at longest until the Club’s agreement ends |
Data after a terminated customer agreement | Deleted one month after the agreement ends, after the Club has had the opportunity to export data |
Attendance history | According to the Club’s instructions |
Chat messages and attachments | 24 months after the end of the event, unless the Club instructs otherwise (justified by events recurring, sometimes more than 12 months apart) |
Profile picture | Until you change or delete it, or the account is closed |
Login token on the device | Until logout or uninstallation |
Security and operational logs | 12 months |
Support cases | 24 months |
Backups | Rotated continuously, deleted at the latest after 90 days |
Records subject to the Accounting Act | Seven years |
The active retention of chat, attendance and assignments is set so that you and the Club retain the information between the editions of a recurring event, even when there is more than a year in between. Backups are disaster-recovery copies only and rotate quickly; they are not used as an archive, and erased information disappears from them within the rotation period.
15. Security
We apply technical and organisational measures under Article 32 GDPR, including:
- encryption of all traffic with TLS over HTTPS, and of the real-time chat over a secure WebSocket connection
- encryption of stored data at the hosting provider
- passwords stored hashed, and the login token stored encrypted on the device via the operating system’s key management
- access control based on the principle of least privilege
- logging of access to personal data
- continuous backup
- confidentiality undertakings for staff and consultants
- a routine for handling and reporting personal data breaches
16. Your rights
You have the right to request access to your personal data, rectification of inaccurate data, erasure, restriction of processing, data portability, and to object to processing based on legitimate interest. Where you have given consent, you may withdraw it at any time.
Where do you turn? If your request concerns data for which the Club is responsible, contact the Club. If it concerns your account or our own processing, contact dpo@favvos.com. We normally respond within one month. If you contact us on a matter for which the Club is responsible, we forward the request and inform you.
17. Account deletion
You can request that your user account be deleted directly in the app or by emailing dpo@favvos.com. Data for which the Club is the controller may need to remain with the Club even after your account is deleted.
18. Complaints
Please contact us first. You also have the right to lodge a complaint with the supervisory authority:
The Swedish Authority for Privacy Protection (IMY) imy@imy.se.
19. Changes
We update this policy when legislation changes or as the service develops. For significant changes we inform you by email or in the service at least 30 days in advance. The version published from time to time applies.