English · Svenska
Last updated: September 4, 2026
This Privacy Policy describes how Enkel Labs, a Swedish sole proprietorship (enskild firma) based in Stockholm, Sweden ("we," "us," or "our"), processes personal data when you use the Dagning application and related services ("Service"), visit dagning.app, or otherwise interact with us.
Questions? Contact us at privacy@dagning.app.
Dagning is used by Swedish housing cooperatives (bostadsrättsföreningar, "BRF"). We process personal data in two distinct roles, and your rights work differently in each:
Enkel Labs as data controller. For data connected to your account and our own operations — your account email, support correspondence, invoicing — we decide how and why data is processed. This policy is your primary source of information about that processing.
Enkel Labs as data processor. For the content a BRF's board enters into the Service — member information, documents, minutes, messages — the BRF is the data controller and we process the data only on its behalf, under a Data Processing Agreement (personuppgiftsbiträdesavtal). If you are a member of a BRF that uses Dagning and want to exercise rights over that data, your first point of contact is your association's board. We assist the association in responding to such requests.
Account data. Your email address and authentication credentials. If you sign in with Google or Apple, we receive your email address (and name, if provided) from that provider; we do not receive or request anything beyond what is needed to create and secure your account. We do not store your password — authentication is handled by Firebase Authentication.
Association and sync metadata. The name of your association, and technical metadata required for synchronization: device identifiers, timestamps, and version (vector-clock) data. This metadata is not end-to-end encrypted and is retained while the account is active.
Push notification tokens, used to deliver notifications to your device.
Support and billing. Correspondence you send us, and the contact and invoicing details of the BRF's designated contact person (name, role, address) needed to issue invoices.
We collect no data from data brokers or other third-party sources, and we use no advertising or analytics SDKs in the app. Some features, such as search, run entirely on your device and send nothing to our servers.
Content entered into the Service by an association's board and members — tasks, documents, meeting minutes, messages, and any member information the board chooses to manage there — is end-to-end encrypted (AES-256-GCM). We cannot read this content on our servers. The BRF is the controller of this data; the categories of data and the terms of processing are set out in the Data Processing Agreement.
BankID signing. When a board sends a document for digital signing, the document is transmitted to our signing provider, Idura, and signed with BankID. The signed PDF includes the signers' names and personal identity numbers (personnummer) as part of the standard BankID signature evidence. We process personnummer only in this context, where secure identification of signatories is clearly justified by the purpose: producing legally reliable signatures on association documents. Signed documents are then stored end-to-end encrypted like all other content.
We process personal data to:
Processing carried out on behalf of a BRF rests on the legal bases determined by the BRF as controller.
We share personal data only with the service providers needed to run the Service:
| Provider | Role | Location of processing |
|---|---|---|
| Google Cloud / Firebase (Authentication, Firestore, Cloud Functions, Cloud Messaging) | Hosting, authentication, database, push notifications | Core data pinned to the EU (europe-north1, Finland); some global Google services (authentication, push delivery) may involve infrastructure outside the EU under Google's data processing terms |
| Resend | Transactional and account-holder email delivery | Emails dispatched from the EU; account data and email logs are stored in the United States |
| Idura | BankID document signing | Sweden/EU |
We do not sell personal data, and we do not share it with advertisers. We may disclose data if required by law, or in connection with a business transfer (merger, acquisition, or sale of assets), in which case this policy continues to apply to the transferred data.
The current sub-processor list for data processed on behalf of BRFs is maintained in the Data Processing Agreement.
Our core infrastructure runs in the EU (europe-north1, Finland). Two limited exceptions involve transfers to the United States:
These transfers are safeguarded through the providers' data processing agreements, based on the EU–US Data Privacy Framework and/or the European Commission's Standard Contractual Clauses. End-to-end encrypted content is unreadable to these providers in all cases.
Our architecture is built for minimal server-side retention:
Association content is protected with end-to-end encryption (AES-256-GCM); encryption keys are derived from a passphrase known only to the association's members, and only encrypted ("wrapped") key material reaches our servers. Data in transit is protected with TLS. Server-side data is automatically purged after 14 days. We cannot read encrypted content — which also means we cannot recover it if an association loses its passphrase.
No system is perfectly secure, and we cannot guarantee absolute security of information transmitted over the internet.
The Service is intended for adults involved in the governance of housing cooperatives. We do not knowingly collect data from children under 18. If you believe a child has provided us data, contact privacy@dagning.app and we will delete it.
Under the GDPR you have the right to access, rectify, and erase your personal data, to restrict or object to processing, to data portability, and to withdraw consent (where processing rests on consent) without affecting prior processing.
You also have the right to lodge a complaint with a supervisory authority. In Sweden, that is the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY), imy.se. If you are elsewhere in the EEA, you may contact your national data protection authority.
We may update this policy from time to time. The "Last updated" date at the top reflects the current version. If we make material changes, we will notify you through the Service or by email.
This policy is provided in Swedish and English. In case of discrepancies between the language versions, the Swedish version prevails.
Enkel Labs
Selmedalsvägen 14
Hägersten, Stockholm 12936
Sweden
Email: privacy@dagning.app
See also: Terms of Service · Data Processing Agreement