Privacy policy

Last updated: 7 August 2026

English

Happihem is built with privacy as a founding principle. That is a precondition for digital technology in health and social care. From day one we have therefore made deliberate decisions about where data is stored, what we collect and how we protect the people who use the platform.

This policy describes how Careots AB (company reg. no. 559485-3938) processes personal data in the Happihem service. It covers the web service at happihem.com, the Happihem Medarbetare app for staff and the Happigram app for family members. Section 11 describes specifically how the Happigram app handles your data.

1. Who is responsible for your data

The roles differ between the two parts of the service. That determines who you turn to with a request.

The web service and the staff app. Here we process personal data on behalf of the workplace or care provider using the service. The workplace is the data controller and Careots AB is the data processor. The processing is governed by the data processing agreement signed with the organisation. If you are an employee and want to exercise your rights, turn to your employer in the first instance.

The Happigram app. Here Careots AB is the data controller for your account, your content, your subscription and the delivery of the booklet. You turn directly to us.

2. Privacy as a design principle

Happihem is built according to the principle of privacy by design. Privacy protection is not an add-on but part of the architecture. That means we:

  • Only collect the data required for the service to work.
  • Never sell personal data and never share it with third parties beyond what is described in this policy.
  • Never use marketing or advertising cookies inside the logged-in service. Logged-in users are never profiled for advertising.
  • Use a privacy-friendly analytics tool (PostHog) to understand how the service is used and improve it. It is activated only after your consent to statistics, links events to a pseudonymous user ID (never your email or your name) and is never used for advertising. See sections 4 and 6.
  • On the public marketing pages we also use Meta’s tools to measure and optimise advertising, but only after your active consent. See section 5.
  • Keep uploaded photos with a single provider in Sweden, plus the print shop when a booklet is to be printed. See section 9.
  • Assess every new feature for its effect on user privacy before it launches.

3. What data we process

We process only the personal data required to provide the service:

  • Account details: the name and email address you give when registering, plus a profile picture if you add one.
  • Workplace affiliation: which workplace and, where applicable, organisation you belong to. Applies to the web service.
  • Family affiliation: which family you belong to and your relationship to the family member in care. Applies to the app.
  • User-generated content: activities, comments, photos, captions and material you create or upload.
  • Delivery and subscription details: delivery address, chosen plan, payment status and payment history. Applies to the app, see section 11.
  • Visitor data on public marketing pages: IP address, browser information and events such as page views and conversions. This happens only after your consent and is described in sections 5 and 6.
  • Usage and event data: how the service is used, for example which features you use and actions you perform, linked to a pseudonymous user ID. This is collected with our analytics tool only after your consent to statistics and is described in sections 4 and 6.
  • Error and crash diagnostics: technical information when something goes wrong, see section 11.

We do not collect personal identity numbers, health data about care home residents or other sensitive personal data.

4. Cookies and consent

This section covers the happihem.com website. The apps use no cookies and no advertising identifier.

We divide cookies into three categories: strictly necessary (required for the service to work), statistics (which measure how the service is used so we can improve it) and marketing (used on public pages for advertising and conversion measurement). Statistics and marketing cookies are set only if you actively consent via the cookie banner.

CookieCategoryPurposeDuration
better-auth.session_tokenNecessaryKeeps you logged in and protects against unauthorised access.The session
_iub_cs-*NecessarySaves your cookie settings (Iubenda).1 year
ph_*_posthogStatisticsRecognises your browser in order to measure how the service is used (PostHog). Contains a pseudonymous ID, never an email address or name. Set only with your consent to statistics.1 year
_fbpMarketingIdentifies browsers for Meta advertising and conversion measurement. Set only with your consent.3 months
_fbcMarketingRecords that you clicked a Meta ad, in order to measure conversions. Set only with your consent.3 months

Strictly necessary cookies require no consent under the EU ePrivacy Directive. Marketing cookies are set only after you have clicked Accept in the cookie banner. You can change your settings at any time:

5. Marketing and the Meta pixel

On Happihem’s public marketing pages (the home page, the pricing page, the page for family members and similar) we use Meta’s tools to measure the results of our ads on Facebook and Instagram. We do not use them inside the logged-in service and not in the apps.

  • The Meta pixel (in the browser): records events such as page views and expressions of interest so we can measure the effect of ads.
  • Conversions API (server to server): sends the same events directly from our server to Meta. We share your email address in hashed form (SHA-256) together with technical information such as IP address so that Meta can match the event to the right ad impression.

The legal basis is consent under Article 6(1)(a) GDPR. You can withdraw your consent at any time via the button above, after which Meta cookies are no longer set and no new events are sent.

The Meta pixel means a transfer of personal data to Meta Platforms Ireland Limited and on to the United States. The transfer takes place under the EU-US Data Privacy Framework (DPF), which the European Commission has found to provide an adequate level of protection. Meta is certified under the DPF. We and Meta are joint controllers for the collection via the pixel, following the case law of the Court of Justice of the EU (Fashion ID).

We never load the Meta pixel for logged-in users, and we share no data about care home residents, family members or patients with Meta.

6. Where data is stored and who processes it

The service’s core data, everything you create and everything about your residents, is stored on servers in Sweden, with Swedish providers.

  • Database and application server: run on Swedish infrastructure via Glesys AB, with data centres in Sweden.
  • File storage: uploaded files and images are stored on Glesys object storage in Sweden.
  • Backups: daily encrypted backups are stored in Sweden.
  • Print shop: when a Happigram is to be printed we send the finished booklet as a PDF to our print shop, together with the recipient’s name and delivery address. The PDF contains the family’s photos and greetings. The print shop processes the data as our data processor, solely in order to print and post the booklet, and may not use it for anything else. The processing takes place in Sweden. See section 9 for how the transfer works.
  • Product and web analytics: PostHog, which we use to understand how the service is used and improve it. Data is stored within the EU (PostHog Cloud EU, Frankfurt). Collection is cookieless and anonymous until you consent to statistics. After consent, events are linked to a pseudonymous user ID. We never send email addresses, names or data about residents to PostHog, and IP addresses are not stored. PostHog, Inc. is a US company, see the note on third-country transfers below.
  • Error and crash diagnostics: Sentry, which we use to detect and fix technical faults in the web app, the API and the apps. Error reports are stored in Sentry’s EU region. Sentry’s provider is a US company that may in some cases be given support access to the data, which is protected by standard contractual clauses.
  • Email delivery: Brevo (Sendinblue SAS) for newsletters and engagement mailings, Scaleway SAS for transactional email such as verification, password resets and invitations. Both process the data within the EU/EEA as data processors.
  • Payment: Stripe, see section 11.
  • Push notifications: Apple and Google via Expo, see section 11.
  • Bot protection: Cloudflare Turnstile at registration and password reset.

Transfers outside the EU/EEA occur in the following limited cases: marketing via Meta (section 5, requires your consent), payment handling via Stripe, delivery of push notifications via Apple and Google, bot protection via Cloudflare, and any support access to analytics data at PostHog and to error reports at Sentry. These are protected by the European Commission’s standard contractual clauses or the EU-US Data Privacy Framework. No photos and no health data about residents leave the EU/EEA.

7. Newsletters and email

We send newsletters, onboarding email and reminders via Brevo. For these mailings your name and email address are shared with Brevo, which processes the data as our data processor and solely within the EU/EEA.

You can unsubscribe from the mailings at any time via the link in the footer of each email. Onboarding and system messages needed for you to get started with the service may still be sent after that.

8. AI and third-party services

The web service uses AI services to generate activity suggestions, support material and images. When these features are used, parts of the text you write may be sent to AI providers for processing.

  • No personal data about residents or patients may be entered into the AI features. They are designed to handle activity descriptions, not sensitive information.
  • The AI providers do not store data from Happihem for their own training or other purposes.
  • The Happigram app does not use the AI features. Your family photos are never sent to an AI service.

9. How printing works

This section describes the one occasion when your photos leave our own infrastructure.

When the month’s Happigram has locked, we assemble a finished booklet as a PDF. It contains the photos and greetings the family has added, the recipient’s name and the delivery address, which is printed in the booklet’s address window.

The PDF is placed in a separate, access-protected area of our Swedish object storage. The print shop receives an email with time-limited download links that stop working after seven days. We hand over no login details, and the print shop has no access to the platform otherwise.

The print shop receives: the recipient’s name, the delivery address and the contents of the booklet. The print shop does not receive: your email address, your password, your payment details, the family’s comments in the app, or anything about families other than those whose booklets are part of the month’s delivery.

10. Legal basis

ProcessingLegal basis
Account, family, content and delivery of the HappigramPerformance of a contract, Article 6(1)(b)
Payment and accountingPerformance of a contract, Article 6(1)(b), and legal obligation, Article 6(1)(c)
Security, troubleshooting and crash diagnosticsLegitimate interest, Article 6(1)(f)
Newsletters and engagement mailingsLegitimate interest, Article 6(1)(f), with the option to unsubscribe
Product analytics and statisticsConsent, Article 6(1)(a)
Marketing and conversion measurement on public pagesConsent, Article 6(1)(a)
Processing on behalf of a workplace in the web serviceThe workplace’s legal basis; we act as processor

11. The Happigram app

The Happigram app lets you follow and contribute to a Happigram, a monthly booklet in digital and printed form for your family member in care. In the app we process the following data:

  • Account details: the name and email address you give when registering, plus a profile picture if you choose to add one.
  • Photos and captions: images you add via the camera or your photo library, with any captions and messages. The images are stored on Swedish object storage (section 6) and sent to the print shop when the booklet is to be printed (section 9).
  • Data about your family member: only their first name and which unit they belong to, following the principle of data minimisation. We do not collect surnames, personal identity numbers or health data about residents.
  • Delivery address: the postal address the booklet is to be sent to. The address is used solely to print and deliver, and is printed in the booklet’s address window.
  • Subscription details: your plan, payment status and payment history, mirrored from Stripe.
  • Notifications: if you allow push notifications we store a device-specific notification token so we can send them. Notifications are delivered via Apple’s and Google’s push services and Expo.
  • Usage analytics: if you actively allow analytics at the end of onboarding or under Account and Privacy, PostHog collects app launches, the names of screens visited and events for features used. The events are linked to your pseudonymous user ID. We never send names, email addresses, comments, captions, images, searches or data about residents to PostHog.
  • Error and crash diagnostics: Sentry automatically receives error reports if the app crashes or an unexpected technical fault occurs. A report may contain a stack trace, app version, operating system, device type, technical app state and pseudonymous installation or session identifiers. Sentry is configured not to send names, email addresses, user IDs, user-created content, full URLs or request bodies, screenshots or view hierarchies. Error reports are stored in Sentry’s EU region and kept for at most 90 days.

Permissions. The app asks for access to the camera and the photo library only when you actively add a photo. We never read your photo library in the background. You can withdraw the permissions at any time in your device settings.

Payment. The subscription is handled by Stripe. Your card and payment details are entered directly into Stripe’s payment form and never reach Happihem’s servers. We store only a customer number at Stripe and your subscription status. Stripe acts as an independent data controller for the payment handling.

Analytics only after consent. Usage analytics is off from the start and is activated only when you turn it on yourself at the end of onboarding or under Account and Privacy. The choice is saved on your device and can be changed at any time under Account and Privacy. The app collects no advertising identifier, such as IDFA or the Google Advertising ID, and we do not track you across apps or websites. Analytics data is stored within the EU as described in section 6.

Mandatory crash reporting. Error and crash diagnostics is always active while the app is in use and cannot be switched off in the app. It is used only to detect, investigate and fix technical faults and to follow the app’s stability, never for advertising or product analytics. The processing is based on our legitimate interest in providing a secure and reliable service.

Photos of other people, including children. Photos in a Happigram often show people other than the person uploading them, for example grandchildren and the resident themselves. The person uploading is responsible for ensuring that those pictured, or their guardians or representatives, have agreed to the photo being shared within the family and printed. We show the photos only to the family’s members and send them only to the print shop. If you believe a photo of you or your child should not be in the service, contact privacy@happihem.com and we will remove it.

Age limit. You must be at least 13 years old to create an account and join a family. That age follows the Swedish Data Protection Act, which uses the option in the GDPR to lower the default of 16. To take out a subscription and be the payer you must be 18, because a subscription is a binding contract. See § 4 of the terms of use for Happigram.

12. How long we keep data

DataRetention
Account, family and uploaded contentFor as long as the account exists. Deleted when you delete the account.
Printed Happigrams as PDFs6 months after printing, after which the file is deleted. The record that the booklet was sent remains.
Notifications in the app inbox90 days
Error reports at SentryAt most 90 days
Backups35 days, after which they are deleted automatically
Invitations to a family7 days, after which they expire
Records of completed payments7 years, under the Swedish Accounting Act (bokföringslagen)
Delivery addressFor as long as the subscription is active, then until the account is deleted

13. Your rights

Under the GDPR you have the right to:

  • Access the personal data we hold about you.
  • Request rectification of inaccurate data.
  • Request erasure of your data (the "right to be forgotten").
  • Request data portability: receive your data in a machine-readable format.
  • Object to processing based on legitimate interest.
  • Request restriction of the processing.
  • Withdraw a consent you have given, without affecting processing that has already taken place.

To exercise your rights, contact us at privacy@happihem.com. We answer your request within 30 days.

If your request concerns data in the web service, where your employer is the data controller, we forward it to the employer.

You can request that certain data be deleted without closing your account. The page Delete certain data in Happihem (in Swedish) has instructions, examples of data that can be deleted and information about what we need to keep.

Deleting your account and your data

You can delete your account and your personal data at any time. In the mobile app you do it directly under Account and then Delete account. The deletion happens immediately and requires no contact with us.

Full instructions and information about which data is deleted or kept are on the page Delete your Happihem account (in Swedish).

On deletion, your name, your email address, your profile picture and the content you uploaded are removed. Families where you are the sole administrator are removed for all members, and active subscriptions are ended. A Happigram that has already gone to print cannot be recalled. Certain data is kept for a limited time to meet legal requirements, see section 12.

You can also request deletion by email to privacy@happihem.com, from your registered email address. We confirm the deletion within 30 days.

14. Data protection in practice

We take technical and organisational measures to protect your data:

  • All traffic is encrypted with TLS (HTTPS).
  • Passwords are stored with secure hashing.
  • Access control ensures that you only reach data belonging to your workplace or your family.
  • Daily encrypted backups protect against data loss. The backups are write-protected and cannot be altered after the fact.
  • Soft delete is used. Removed data is marked as deleted and permanently purged after a reasonable period.
  • Photos are downscaled on your phone before upload and never pass through a content delivery network or any external image service.

15. Changes to this policy

This policy may be updated. For material changes, registered users are notified by email. The latest version is always available on this page.

16. Contact

Careots AB, company reg. no. 559485-3938.

Drottninggatan 29, c/o D29
411 14 Göteborg, Sweden

Careots AB is the data controller for the Happigram app and the data processor for the web service, see section 1.

If you are not satisfied with how we handle your data, you have the right to lodge a complaint with the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY), www.imy.se.