Hapio Privacy Policy

This Privacy Policy explains how Viström Digital Development AB (“Hapio,” “we,” “us,” or “our“) collects, uses, shares, and protects personal data when you interact with:

  • hapio.io — our marketing website, including pricing, product, and industry pages;
  • hapio.app — the Hapio web application, including registration, login, and account dashboard;
  • docs.hapio.io — our developer documentation portal; and
  • eu-central-1.hapio.net — our live API endpoint, which receives and processes the actual booking/scheduling requests sent by our customers’ systems and, depending on how a customer has built their integration, sometimes by their end-users’ browsers or apps directly,

(together, the “Sites“), collectively delivering the Hapio scheduling and booking service (the “Service“).

This policy is written to be read together across all three properties, since they form one connected product. Where a section applies to only one property, that is noted.

1. Who we are

Hapio is operated by:

Viström Digital Development AB Hertig Johans Gata 16 541 31 Skövde, Sweden Email: hi@hapio.io

For most of the personal data described in this policy, Viström Digital Development AB is the data controller under the EU General Data Protection Regulation (GDPR). Section 10 explains an important exception: data our business customers store through the Hapio API about their own end-users, where we act as a data processor instead.

2. Scope of this policy

PropertyWhat it’s forWho typically uses it
hapio.ioMarketing, pricing, industry pages, contact formsProspective customers, visitors
hapio.appThe developer portal — registration, login, dashboard, billing, API tokensRegistered customers and their team members
docs.hapio.ioAPI reference and developer guidesDevelopers integrating with Hapio
eu-central-1.hapio.netThe live API endpoint — where booking/scheduling requests are actually sent and processedOur customers’ backend systems, and, in some integrations, their end-users’ browsers/apps directly

This policy covers all personal data we process in connection with these Sites and the Service, except data that our customers submit to the Hapio API about their own end-users (e.g., the people booking appointments through a product built on Hapio) — that data is covered by our Data Processing Agreement, referenced in Section 10.

3. Personal data we collect

3.1 Visitors to hapio.io and docs.hapio.io

  • Usage data, collected automatically via analytics: pages viewed, referring URL, approximate location (derived from IP address), device and browser type, and time spent on pages. This is collected via Matomo Analytics (hosted on our Matomo Cloud instance).
  • Contact form and inquiry data: if you contact us (e.g., via the “Contact us” page), we collect your name, email address, phone number, company name and the content of your message.
  • Cookies and similar technologies: see Section 5.

3.2 Registered customers and account holders (hapio.app)

When you register for or use a Hapio account, we collect:

  • Account data: name, email address, password (stored hashed, never in plain text), company name, and any other profile details you provide.
  • Billing data: billing address, VAT/tax ID (if applicable), and subscription plan details. Payment card and payment method details are collected and processed directly by our payment provider, Paddle — we do not store your full card details ourselves. Paddle acts as the merchant of record for paid subscriptions, which means Paddle also handles invoicing and applicable sales tax/VAT.
  • API tokens and credentials: tokens you generate to authenticate with the Hapio API, and the permissions you assign to them.
  • API and platform usage data: requests made to our API endpoint (eu-central-1.hapio.net), including timestamps, the IP address and user-agent of the calling system, rate-limit consumption, webhook configurations, and logs available through the Developer Portal.
  • Support and communications data: messages you send us through our live chat widget (LiveChat) or by email, including any attachments or information you choose to share while troubleshooting an issue.
  • Marketing preferences: if you opt in to product updates or newsletters, your email address and engagement with those emails, processed via Mailchimp.

3.3 Data processed on behalf of our customers (via the API)

If you are an end-user of a product built on Hapio (for example, someone booking an appointment through one of our customers’ apps), the business you interacted with — not Hapio — is responsible for telling you how your data is used. Hapio processes this data (which may include names, email addresses, phone numbers, appointment/booking details, and time zone information) only as instructed by our customer, under a Data Processing Agreement. See Section 10.

Depending on how a customer has built their integration, your device may send booking requests to our API endpoint (eu-central-1.hapio.net) directly, or your data may reach us only via the customer’s own backend systems. Either way, our API endpoint logs standard technical request metadata (such as IP address, timestamp, and user-agent) as part of operating, securing, and troubleshooting the Service, in addition to the booking data itself.

4. How we use personal data, and our legal basis

PurposeExamplesLegal basis (GDPR Art. 6)
Providing the ServiceCreating and maintaining your account, authenticating API requests, delivering the booking/scheduling functionalityPerformance of a contract
BillingProcessing subscription payments and usage-based charges via PaddlePerformance of a contract
Customer supportResponding to questions via LiveChat or emailPerformance of a contract / legitimate interest
Product improvementUnderstanding how the Sites and API are used, fixing bugs, planning featuresLegitimate interest
Marketing communicationsSending product updates or newsletters via MailchimpConsent (you can withdraw at any time)
Website analyticsUnderstanding site traffic via MatomoLegitimate interest / consent, where required
SecurityDetecting abuse, enforcing rate limits, preventing fraudLegitimate interest / legal obligation
Legal complianceResponding to lawful requests, maintaining tax and accounting recordsLegal obligation

We do not sell personal data, and we do not use personal data submitted through the API (Section 3.3) for our own marketing or profiling purposes.

5. Cookies and similar technologies

We use cookies and comparable technologies across the Sites for the following purposes:

  • Strictly necessary — e.g., keeping you logged in to hapio.app, remembering security tokens. These cannot be switched off, as the Sites won’t work properly without them.
  • Analytics — Matomo on hapio.io, and tags deployed through Google Tag Manager on hapio.app, used to understand usage patterns and improve the product.
  • Support — cookies set by our LiveChat widget to maintain your chat session.

Our API endpoint (eu-central-1.hapio.net) does not set cookies. Requests to it — whether from a customer’s server or an end-user’s device directly — are authenticated using API tokens rather than browser sessions.

We use Cookiebot as our cookie consent management platform on hapio.io, hapio.app, and docs.hapio.io. Cookiebot detects the cookies set on each site and blocks non-essential cookies (such as the analytics and support cookies described above) until you’ve given consent. You can view or change your consent choices at any time via the cookie settings link on each site. Cookiebot may itself process your IP address, to determine which consent rules apply based on your location, and to keep a record of your consent choice.

Our API endpoint (eu-central-1.hapio.net) has no browser interface, so Cookiebot doesn’t run there — as noted above, that domain doesn’t set cookies at all.

6. Who we share personal data with

For the current, named list of our subprocessors within each category — including where each is located — see our Subprocessors page.

We require these providers to protect personal data consistently with this policy and applicable law, and we only share what each provider needs to perform its function. We’ll update the Subprocessors page — and notify affected customers as required under our DPA — before adding or replacing a subprocessor.

7. International data transfers

We are based in Sweden (EU). hapio.app (including the Developer Portal) and our API endpoint (eu-central-1.hapio.net) run on Amazon Web Services in the eu-central-1 region (Frankfurt, Germany), meaning account data, API data, and booking/scheduling data submitted through the API — including data covered by Section 10 — is stored within the EU at that layer. That said, this AWS environment is deployed and managed with the help of a third-party infrastructure management provider based in the United States; this means personnel or systems based outside the EU may have operational access to that environment — for example, to manage deployments and infrastructure — even though the underlying data remains stored in Frankfurt.

hapio.io and docs.hapio.io are hosted separately, with Vultr (operated by The Constant Company, LLC), in Vultr’s Amsterdam, Netherlands data center — so that data is also stored within the EU. As with Laravel Vapor above, Vultr itself is a US-headquartered company, so the same storage-vs-access distinction applies: the data stays in an EU data center, but Vultr’s systems and personnel are operated by a US company.

If we add infrastructure in other regions in the future, we will update this policy.

Some of our service providers — including Paddle, Mailchimp, LiveChat, Google, our infrastructure management provider, and Vultr — are located outside the European Economic Area, including in the United States. Where we transfer personal data outside the EEA, or where a non-EEA provider may access it, we rely on appropriate safeguards, such as the European Commission’s Standard Contractual Clauses, or transfers to countries recognized as providing adequate protection. You can contact us for more information about the safeguards used for a specific transf

8. Data retention

We keep personal data only as long as needed for the purposes described in this policy:

  • Account data: for as long as your account is active, and for 14 days (backups) after closure, to allow for account recovery and to meet legal/accounting obligations.
  • Billing records: for the period required by Swedish tax and accounting law (typically at least 7 years).
  • API request logs: request and response bodies (which may contain personal data submitted via a booking, such as names or contact details) are automatically purged after 14 days. Log metadata — such as timestamps, IP addresses, endpoints called, and status codes — is retained indefinitely, for debugging, security, and abuse-prevention purposes.
  • Support conversations: emails and LiveChat conversations are retained indefinitely by default — we do not routinely delete them, and LiveChat’s own security architecture is designed around permanent retention of this data. You can request deletion of your support history at any time (see Section 9); we will honor that request unless we have a specific, legitimate reason to retain particular records (for example, an active legal dispute or a statutory obligation).
  • Marketing data: until you unsubscribe or ask us to delete it.
  • Website analytics data: in line with Matomo’s configured data retention (indefinitely by default) settings.

When we no longer need personal data, we delete or anonymize it.

9. Your rights

If you are located in the EEA, UK, or another jurisdiction with similar protections, you have the right to:

  • Access the personal data we hold about you;
  • Correct inaccurate or incomplete data;
  • Delete your data, subject to legal retention requirements;
  • Restrict or object to certain processing, including processing based on legitimate interest;
  • Port your data to another provider, where technically feasible;
  • Withdraw consent at any time, where processing is based on consent (e.g., marketing emails); and
  • Lodge a complaint with your local data protection authority. In Sweden, this is the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY) imy.se.

To exercise any of these rights, contact us at hi@hapio.io. We may need to verify your identity before responding.

If your data was submitted to Hapio by one of our business customers (see Section 10), please contact that business directly — we will support them in responding to your request.

10. Hapio as a data processor for our customers

Hapio is a headless, API-first scheduling and booking platform. Our customers (businesses and developers) use the Hapio API to build their own scheduling products, and in doing so, they submit personal data about their end-users — for example, names, contact details, and appointment information.

For this category of data, our customer is the data controller, and Hapio acts only as a data processor, processing the data solely on the customer’s documented instructions, as governed by our Data Processing Agreement (DPA). We do not use this data for our own purposes (such as marketing), and we apply appropriate technical and organizational security measures to protect it.

If you are a Hapio customer and don’t yet have a signed DPA in place, please contact us at hi@hapio.io. Our DPA is available at Data Processing Addendum and is incorporated into our Terms of Service.

11. Security

We use technical and organizational measures designed to protect personal data against unauthorized access, loss, misuse, or alteration, including encryption in transit, access controls on production systems, and hashed password storage. We are also currently working toward ISO/IEC 27001 certification, a widely recognized international standard for information security management, and will update this policy once certification is achieved. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

12. Children’s privacy

The Sites and Service are intended for businesses and developers, and are not directed to children. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us so we can delete it.

13. Users outside the EEA

While Hapio is based in Sweden and this policy is primarily written with GDPR in mind, we work with customers and prospective customers around the world. If you are located in a jurisdiction with its own privacy law — such as the California Consumer Privacy Act, or other US state, Brazilian, Canadian, Australian, or other laws — you may have additional or different rights under that law. We will do our best to honor those rights even where this policy doesn’t spell them out individually. Contact us at hi@hapio.io with any request, and we’ll respond appropriately based on your location.

14. Changes to this policy

We may update this Privacy Policy from time to time, for example to reflect changes in our practices or for legal reasons. We will post the updated version on this page with a new “Last updated” date, and where changes are material, we will provide additional notice (such as an email to account holders).

15. Contact us

If you have questions about this Privacy Policy or how we handle personal data, contact us at:

Viström Digital Development AB Hertig Johans Gata 16 541 31 Skövde, Sweden Email: hi@hapio.io

Last updated: 2026-08-12