Privacy Policy – DullyApp
Last updated: 5. December 2026
Controller / Data Processor:
Dully ApS
Rådhusstræde 3 st, 1466 København K
support@dully.io
If you have any questions about this Privacy Policy or how we handle your data, please contact us at the email above.
What this Policy Covers
This Privacy Policy describes how DullyApp collects, uses, stores, and protects personal data of users (“you” / “user”) when you use the DullyApp mobile application (the “Application”).
It applies to all operations related to the Application — for example: user registration, shift scheduling, check-in/out, profile data, usage analytics, and any other features made available to you by your employer via DullyApp.
What Data We Collect and Why
We collect only the data strictly necessary to provide the functions of DullyApp, following the principle of data minimisation.
Here are the categories of data we may collect, depending on employer configuration and user activity:
Identity & Account Data
Name, employee ID (or internal identifier), role or position, contact information (email, phone number), profile picture (if enabled)
Purpose: to create your account, identify you, display your profile within the app, and manage access rights.
Work & Employment Data
Scheduled shifts (date, time, location), shift swap / offer data, check-in/out timestamps, vacation/absence requests, employment type (e.g. full/part time), role/permissions, work history, hours worked
•Purpose: deliver scheduling, time tracking, shift management and related functionality to you and your employer.
Usage & Device Data
Device type / OS version, app version, device identifiers, crash/error logs, usage analytics (feature usage, performance metrics)
Purpose: to improve app stability and performance, diagnose bugs, and maintain quality of service.
Optional Data – Location Data (only if employer enables location-based check-in/out and you grant consent)
Approximate location at the moment of check-in/out (not continuous tracking)
Purpose: to verify presence at workplace when required.
If enabled, you will be clearly informed and asked for your consent before location data is collected.
Legal Basis for Processing (for Users in EU / EEA)
We process your personal data under one or more of the following lawful bases:
Contractual necessity — necessary for providing you with the services offered by DullyApp (scheduling, time tracking, account management).
Legitimate interest — for maintaining and improving the App, ensuring security and stability, and administering user accounts.
Consent — only for optional data processing such as location-based check-in (if activated by employer) or any other optional feature.
We commit to processing only data necessary for the stated purposes, and only for as long as required.
4. How We Store and Protect Your Data
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, or loss. These may include (but are not limited to):
Encrypted data transfer (e.g. SSL / TLS)
Secure, access-controlled databases, with role-based access privileges
Separation of data per employer (so one employer cannot see another’s data)
Regular security maintenance and updates
Internal policies to ensure only authorized personnel access user data
We also strive to build data protection by design and by default — meaning we only collect what is necessary.
If a data breach occurs that may risk your privacy, we will notify you (and relevant authorities) in accordance with applicable data protection laws.
5. Data Sharing & Third Parties
We do not sell your personal data.
We may share data with third parties only when strictly necessary, for instance:
Your Employer: Because your employer uses DullyApp to manage work schedules, time tracking, etc., they will receive relevant employment-related data about you (shifts, check-ins, profile details) so they can manage HR within their organisation.
Service Providers / Subprocessors: We may use external partners for hosting, authentication, analytics, crash-reporting, storage, backups, etc. All such providers are bound by Data Processing Agreements and must comply with data protection laws.
Legal Authorities: If required by law or regulation (e.g. labour law, accounting, audit), or to respond to legal requests.
We will always ensure that any third party handling your data provides a level of protection at least as strong as described in this policy.
6. Data Retention
Your personal data will only be kept for as long as needed to fulfil the purposes described in Section 2, or as required by law (e.g. retention for accounting or labour-law obligations). When data is no longer needed, it will be securely deleted or anonymised.
If you leave your employer or your account is deactivated, corresponding data will be deleted or anonymised within a reasonable time frame — unless there is a legitimate legal or business reason to retain certain records (e.g. for audit or compliance).
7. Your Rights as a User (under GDPR / Data Protection Law)
If you are located in the EU/EEA, you have the following rights regarding your personal data:
Right to access the personal data we hold about you
Right to rectify incorrect or incomplete data
Right to delete your personal data (“right to be forgotten”) — when there is no longer a valid reason to keep it
Right to restrict or object to certain types of processing (e.g. optional processing based on consent)
Right to data portability — receive your data in a structured, machine-readable format
Right to withdraw consent at any time (for optional data processing)
To exercise any of these rights, contact us at support@dully.io. We will respond in accordance with applicable data protection law (e.g. within one month).
8. Children / Minors
DullyApp is intended for use by employees; as such, it is not designed for minors under the age of 16. We do not knowingly collect data from children under 16. If we become aware that a user is under 16, we will delete their data.
9. Changes to This Privacy Policy
We may update this Privacy Policy from time to time (for instance, when we add new features, change third-party providers, or adjust data practices).
When we make significant changes, we will notify you within the Application (e.g. via a pop-up or in Settings → Legal) and update the “Last updated” date. Continued use of DullyApp after such changes constitutes acceptance of the updated policy.
10. Contact & Data Controller
If you have any questions, complaints or requests concerning your personal data or this Privacy Policy, contact us at:
Dully ApS
Rådhusstræde 3 st, 1466 København K
support@dully.io
If necessary (for example, if you reside in the EU), you may also contact the relevant national data protection authority to lodge a complaint.