Privacy Policy

As of: 19.09.2026

1. Controller
The controller responsible for processing personal data is:
Mikel Krasniqi, Höllgehau 10, 86381 Krumbach (Schwaben), Deutschland
E-Mail: hello@timetakt.com
2. Purposes and legal bases
We process account and contact information to provide the service and answer contract-related enquiries (Art. 6(1)(b) GDPR). Technical security and abuse prevention serve our legitimate interest in a reliable service (Art. 6(1)(f)). Contract, cancellation, withdrawal and accounting records are also kept to meet legal duties (Art. 6(1)(c)). Optional analytics requires consent (Art. 6(1)(a)).
3. Categories of processed data
Account data includes name, email, optional phone number, password hash, company membership and permissions. Employers enter schedules, working times, leave and substitute information. The employer determines the purposes and legal basis for its employee records; TimeTakt processes those records on its instructions under a data processing agreement. Sickness information can be health data under Art. 9 GDPR. Do not enter diagnoses or medical documents. Contact and contract forms record the details you submit and their receipt time.
4. Recipients and processors
The site uses Hostinger hosting and configured email delivery. Stripe processes payment and billing information when you use paid checkout; TimeTakt does not store full card numbers. Optional Google sign-in exchanges profile and verified email information with Google. Google Analytics runs only on public pages after consent. Some application interface libraries are delivered through jsDelivr; these requests include technical connection data. Access to employee records depends on assigned company permissions. Public sharing links disclose their selected records to people who can unlock them.
5. Transfers to third countries
Google, Stripe and the jsDelivr delivery network can process data outside the EEA. Relevant safeguards depend on the recipient and service, including an applicable adequacy decision or standard contractual clauses. You can request details and copies of applicable safeguards at hello@timetakt.com. Provider privacy information is linked below.
6. Storage period
Account records are kept while the account is maintained. Employee records are retained according to the employer’s instructions and applicable obligations. Enquiries are retained while necessary to handle the matter and any resulting claims. Billing and contract records remain where statutory retention duties or legal claims require them. Deletion can therefore be restricted even after account closure. Contact us for a review of the records and retention grounds applying to your request.
7. Cookies
Session and security cookies are necessary for login and forms (§ 25(2) TDDDG). Language and cookie choices are stored for up to 365 and 180 days respectively. Optional Google Analytics cookies require consent under § 25(1) TDDDG and Art. 6(1)(a) GDPR. You can withdraw that consent in Cookie settings; this affects future processing. No analytics runs on private work pages, authentication pages or contract declaration forms.
8. Data subject rights
Subject to the statutory conditions, you can request access, correction, deletion, restriction and data portability. You can object to processing based on legitimate interests, and withdraw consent at any time without affecting prior lawful processing. You can complain to a supervisory authority, including the Bavarian State Office for Data Protection Supervision (BayLDA), Promenade 18, 91522 Ansbach, Germany. For employee records, contact your employer as controller; we support its handling of requests.
9. Contact
If you have questions about privacy, please contact us using the details under “Controller” or in the imprint.