Backbone

Privacy Policy

Last updated: 29 June 2026

This Privacy Policy explains how Product Space AB (“we”, “us”, “our”) collects, uses, shares, and protects personal data when you use Backbone, our resource-planning and time-tracking application available at backbone.productspace.se (the “Service”). It is written to comply with the EU General Data Protection Regulation (GDPR).

1. Who we are (Data Controller)

Product Space AB is the data controller responsible for your personal data.

2. How the Service is used

Backbone is a business-to-business tool used by organisations to manage projects, allocations, time reporting, expenses, leave, and related operations. In most cases your employer or the organisation that invited you decides which of your data is entered into the Service and acts as the controller of that data, while we process it on their behalf. This policy describes the data we handle in our role and the choices available to you.

3. Personal data we collect

We collect the following categories of personal data:

  • Account & identity data: your name and email address, used to create and authenticate your account.
  • Profile data (optional): date of birth, personal email, personal phone number, and postal address (street, city, postal code, country).
  • Emergency contact data: the name, relationship, and phone number of a person you choose to provide. Please ensure that person is aware before sharing their details with us.
  • Payroll & financial data: bank account details (IBAN, BIC) and tax identification number, where your organisation uses Backbone for payroll-related administration.
  • Preference data: shirt size, dietary requirements, and information about dependents that you choose to provide.
  • Contacts you create: the first name, last name, email, and phone number of external business contacts you add.
  • Technical data: a session cookie required to keep you signed in, and limited server-side telemetry (such as request traces) used to operate and secure the Service.

Sensitive data. Some optional fields — for example dietary requirements — may reveal special categories of data under Article 9 GDPR (such as religious beliefs or health). We process these only where you have voluntarily provided them and on the basis of your explicit consent or your organisation’s legal obligations. You are never required to provide them.

4. Sign in with Google

You can sign in using your Google account. When you do, Google shares your verified email address and basic profile information (such as your name) with us so we can authenticate you and, where applicable, connect you to your organisation. We do not receive your Google password. Your use of Google sign-in is also subject to Google’s own privacy policy.

5. How we use your data and our legal bases

We process personal data for the following purposes:

  • To provide the Service — create your account, authenticate you, and deliver core features. Legal basis: performance of a contract (Art. 6(1)(b)) and our legitimate interest in operating the Service (Art. 6(1)(f)).
  • To send transactional emails — such as invitations, account notifications, and security messages. Legal basis: performance of a contract (Art. 6(1)(b)) and legitimate interest (Art. 6(1)(f)).
  • To administer payroll and financial information where your organisation requires it. Legal basis: legal obligation (Art. 6(1)(c)) and the controller’s legitimate interest.
  • To secure and maintain the Service — monitoring, troubleshooting, and preventing abuse. Legal basis: legitimate interest (Art. 6(1)(f)).
  • To handle optional and sensitive fields you choose to provide. Legal basis: consent (Art. 6(1)(a) and, where relevant, Art. 9(2)(a)).

We do not use your data for advertising, and we do not sell your personal data or use it for remarketing.

6. Who we share data with

We do not sell personal data. We share it only with service providers (processors) who help us run the Service under appropriate data protection agreements:

  • Hosting: our infrastructure is hosted with Hetzner in Finland (EU). Your data is stored within the European Union.
  • Authentication: Google, where you choose to sign in with Google.

We may also disclose data where required by law or to protect our legal rights. Because our hosting is located within the EU, your data is not subject to international transfers outside the EU/EEA in the normal course of operating the Service.

7. How long we keep your data

We keep personal data only as long as necessary for the purposes described above:

  • Account and profile data — for as long as your account is active. After your account or your organisation’s account is closed, we delete or anonymise it within 90 days, unless a longer period is required.
  • Payroll, financial, and tax records — retained for the statutory period required by applicable accounting and tax law (in Sweden, generally up to 7 years).
  • Technical logs and telemetry — retained for a short period (typically up to 90 days) for security and troubleshooting.

8. Your rights under the GDPR

You have the right to:

  • access the personal data we hold about you;
  • request correction of inaccurate or incomplete data;
  • request erasure of your data (“right to be forgotten”);
  • restrict or object to certain processing;
  • data portability — receive your data in a structured, machine-readable format;
  • withdraw consent at any time, where processing is based on consent (without affecting prior processing).

To exercise any of these rights, contact us at backbone-privacy@productspace.se. If your data was entered by your employer or organisation, we may direct your request to them as the relevant controller. You also have the right to lodge a complaint with your local supervisory authority. In Sweden, this is the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY, imy.se).

9. Cookies

We use a strictly necessary session cookie to keep you signed in. We do not use advertising, analytics, or third-party tracking cookies.

10. Data security

We use appropriate technical and organisational measures to protect personal data, including encryption in transit, access controls, and tenant isolation between organisations. No method of transmission or storage is completely secure, but we work to protect your data and to notify you and the relevant authority of any breach as required by law.

11. Children

Backbone is a workplace tool intended for use by businesses and their staff. It is not directed to children, and we do not knowingly collect personal data from anyone under the age of 16. (Fields relating to dependents are about your family members for administrative purposes and are not accounts for those individuals.)

12. Changes to this policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last updated” date above and, where appropriate, notify you through the Service.

13. Contact us

For any questions about this Privacy Policy or your personal data, contact us by email at backbone-privacy@productspace.se, or by post at Product Space AB, Tegnérgatan 37, 111 61 Stockholm, Sweden.