Legal
Privacy policy
How personal data is processed in Regsta, where it is stored, how long it is kept and who to ask.
Last updated 29 September 2026
1. Who is responsible
Regsta is provided by Keyton ApS, CVR 38508571, Aalborg, Denmark.
For employee and working-time data, the employer is the data controller. Keyton ApS processes that data on the employer's instructions and under the data processing agreement.
Keyton ApS is the data controller for its own business contacts, support conversations, messages sent through the website's contact form, and security records.
2. What we process
Depending on how a company sets up Regsta, we may process:
- name and email address, and a phone number if one is given;
- employee number, role and permissions, and which company the person belongs to;
- time entries: start and end times and breaks;
- the reasons given for manual entries and corrections;
- approval and rejection decisions;
- audit trail events and export history;
- IP address and browser details (user agent) in security and audit records;
- a device push token, if someone turns on notifications in the mobile app;
- support correspondence.
Regsta does not collect location (GPS) data.
Do not put health, trade union, criminal or other special-category data in free-text fields unless there is a lawful basis and a written instruction to process it.
3. Why we process it
- to let people sign in, and to control who can see and change what;
- to record, approve and document working time;
- to produce exports and the inspection folder;
- to check working time against the rules a company has set up;
- to give support;
- to keep the service secure;
- to meet agreed and legal obligations.
4. Legal basis
For employee data, the employer decides the legal basis as data controller. Typical purposes are personnel administration and the legal duty to document working time.
Where Keyton ApS is the data controller, the legal basis can be the performance of a contract, our legitimate interest in running and securing the service, or a legal obligation.
5. Where data is stored and who receives it
The production database and sign-in run on Hetzner Online GmbH servers in Falkenstein, Germany. The application runs on Vercel in Frankfurt, Germany. Upstash provides rate limiting (region not yet recorded), and Resend sends email.
Push notifications to the mobile app are delivered by Expo (650 Industries, Inc.) in the USA, which passes them on to Apple or Google. The transfer mechanism for Expo has not yet been recorded. Push messages contain generic text, not names, times or shift details.
Access is limited by role and by company. Regsta does not sell employee data and does not use it for advertising.
See the full list of subprocessors
The public website uses Vercel's cookieless visitor statistics. The signed-in app uses none.
6. How long data is kept
Working-time data and the audit trail are kept for the retention period the company has set. The default is 1,946 days: five calendar years plus the 17-week reference period. The period cannot be set shorter than five years plus the company's reference period.
When the period has passed, a daily job deletes the expired time entries, related events, export history and audit trail events for that company.
The list of signed-in devices stores no sign-in token. It keeps a non-secret session identifier, whether the device used the web or the app, the IP address and browser details, and when the device was first and last seen, for up to 90 days.
When someone deletes their account, their access, push devices and direct personal details are removed. Working-time and audit records the employer must keep are pseudonymised instead of deleted, and stay under the employer's retention period. A company's only Admin must give the Admin role to someone else first.
7. Your rights
Employees should normally contact their employer, because the employer is the data controller for working-time data. If Regsta receives a request directly, we forward it or handle it under the data processing agreement and the employer's instructions.
Employees can see their own time entries in Regsta.
8. Security
- Each company's data is kept apart with Row Level Security in the database.
- Roles are checked on the server before data is changed, not only by hiding buttons.
- The database does not allow the audit trail to be changed or deleted during the retention period.
- Connections are encrypted with TLS, and the site sends security headers (CSP, HSTS and frame blocking).
- Sign-in and other public endpoints are rate limited.