Compliance

Built to support responsible workforce data practices.

Compliance depends on how you use SWAKIO™, how you configure it, the contract between us and the law that applies to you. This page describes our approach, our controls and our responsibilities, not a certification claim.

GDPR · European Union

Data protection as architecture, not paperwork.

For workforce records your organisation is the controller and SWAKIO™ acts as processor under a data processing agreement available to every customer. Processing is purpose limited and minimised by design. Data subject rights are supported in the product itself: access is built in because every employee always sees their own record, and correction, deletion, portability and objection run through your administrators, with our support. Retention follows your configuration, security controls are described on the Security page, every access is audited, and subprocessors and transfer safeguards are documented and available on request.

Discuss GDPR requirements
GDPR APPROACH
RolesYou control, we process
DPAAvailable on request
Subject accessBuilt into the product
MinimisationBy architecture
TransfersSafeguards documented
HIPAA · United States

Deliberately built to operate without PHI.

SWAKIO™ is a workforce platform, not a medical system. A sick day is recorded as a sick day: no diagnosis, no clinical notes, no medical detail. That minimisation is the strongest protection we can offer. For customers who are covered entities or business associates, deployment and contractual requirements, including Business Associate Agreement considerations, need to be evaluated with us before any protected health information is processed. Access controls, audit controls, data security and minimum necessary access are part of the platform's design; what we can sign is a conversation, and you will get a straight answer.

Discuss HIPAA requirements
HIPAA APPROACH
PHI required to operateNone
Medical detail behind leaveNever stored
Access and audit controlsPlatform design
BAAEvaluated before PHI, with you
CCPA · California

Nothing is sold. There is nothing to opt out of.

SWAKIO™ does not sell personal information and does not share it for cross context behavioural advertising; the business model contains no advertising at all. As a service provider we process workforce data on your documented instructions. California residents can exercise access, deletion and correction rights through their employer or directly through our contact page, and disclosure of what we process and why is published in the Privacy Policy.

Discuss CCPA requirements
CCPA APPROACH
Sale of personal informationNever, by design
Advertising in the productNone exists
Rights requestsSupported, both routes
RoleService provider on your instructions

Compliance is shared responsibility.

No vendor can make you compliant by itself. Responsible deployment is what our controls, your configuration, your policies and your law produce together.

SWAKIO™ controls+Your configuration+Your policies+Applicable regulation=Responsible deployment

Local law counts too: India's DPDP Act, working time rules under the Indian Labour Codes, EU working time law and their equivalents elsewhere. Working time policies in SWAKIO™ are configurable per region, and records are export ready for audits.

Bring your counsel. We like prepared buyers.