Compliance depends on how you use SWAKIO™, how you configure it, the contract between us and the law that applies to you. This page describes our approach, our controls and our responsibilities, not a certification claim.
For workforce records your organisation is the controller and SWAKIO™ acts as processor under a data processing agreement available to every customer. Processing is purpose limited and minimised by design. Data subject rights are supported in the product itself: access is built in because every employee always sees their own record, and correction, deletion, portability and objection run through your administrators, with our support. Retention follows your configuration, security controls are described on the Security page, every access is audited, and subprocessors and transfer safeguards are documented and available on request.
SWAKIO™ is a workforce platform, not a medical system. A sick day is recorded as a sick day: no diagnosis, no clinical notes, no medical detail. That minimisation is the strongest protection we can offer. For customers who are covered entities or business associates, deployment and contractual requirements, including Business Associate Agreement considerations, need to be evaluated with us before any protected health information is processed. Access controls, audit controls, data security and minimum necessary access are part of the platform's design; what we can sign is a conversation, and you will get a straight answer.
SWAKIO™ does not sell personal information and does not share it for cross context behavioural advertising; the business model contains no advertising at all. As a service provider we process workforce data on your documented instructions. California residents can exercise access, deletion and correction rights through their employer or directly through our contact page, and disclosure of what we process and why is published in the Privacy Policy.