🇩🇪 🇭🇷 🇬🇧 🇮🇹 🇪🇸 🇷🇸 🇦🇱 🇹🇷 🇵🇱 🇷🇴

Privacy policy

Before publication: complete every placeholder and have the final version reviewed by legal counsel specialising in German IT and data-protection law. Translations are provided for information; the reviewed German version is authoritative.

1. Controller and contact

Controller under the GDPR: [COMPANY NAME AND LEGAL FORM], [FULL ADDRESS], email: [PRIVACY EMAIL]. Data protection officer, if appointed: [NAME/CONTACT].

2. Data and purposes

We process account, login, device, assignment and permission data to provide the service securely. Depending on use, calendar, task, chat, contact, support, working-time, GPS, health, weight and notification data are processed. Server logs support security, troubleshooting and abuse prevention.

3. Legal bases

Contract performance and pre-contractual steps: Article 6(1)(b) GDPR; legal obligations: (c); security and abuse prevention: (f); voluntary features, notifications and GPS: (a), or (b) where required for the selected service. Health data are processed only with explicit consent under Article 9(2)(a). Consent can be withdrawn prospectively at any time.

4. Recipients and international transfers

Access is limited to authorised members of the selected assignment and necessary service providers. Intended processors: [HOSTING PROVIDER, COUNTRY], [EMAIL PROVIDER, COUNTRY], [BACKUP/MONITORING PROVIDER, COUNTRY]. Processing agreements must be concluded before use. Transfers outside the EU/EEA require a valid legal basis and documented safeguards.

5. Chat, location and sensitive data

Chat text and images are end-to-end encrypted before transmission; the server stores ciphertext and technical metadata only. Location is processed only when permission is enabled. Live GPS points are retained for no more than 48 hours and working-time GPS data for no more than two months. Health and weight data are private by default and visible only according to the selected sharing settings.

6. Cookies and device storage

The web application uses necessary session, security and language settings for login, CSRF protection and requested functions. Non-essential tracking or advertising is not planned. Android apps store the URL, device identifier, settings and access tokens encrypted in protected app storage. The cookie-dialog choice is stored locally.

7. Retention and deletion

Data are retained only for the contract, requested function, security or statutory obligations. Chat messages follow the selected auto-deletion period; manually deleted messages are removed from the active store. Account and module data are deleted or restricted after a valid request unless retention duties apply. Backups are overwritten under the documented backup cycle.

8. Your rights

Data subjects may exercise access, rectification, erasure, restriction, portability, objection and consent-withdrawal rights under the GDPR. Contact: [PRIVACY EMAIL]. A complaint may also be lodged with a data protection authority, particularly at the place of residence or the controller's establishment.

9. Security and changes

We use role-based access, multi-factor authentication for privileged accounts, transport encryption, encrypted storage, audit records, deletion jobs and backups. No solely automated decision with legal or similarly significant effects is made. Before production, the impact assessment, processor contracts, retention policy, authorisation tests and security review must be documented. Last updated: 20 July 2026.