Privacy Policy
§1 Data Controller and Data Processor
Data Controller (Art. 4(7) GDPR): The company that licenses and operates Clean Clock for its employees (hereinafter "your company" or "employer"). Your company determines the purpose and means of processing.
Data Processor (Art. 28 GDPR):
Benyamin Jafari
Chemnitzer Str. 69, 01187 Dresden
E-Mail: kontakt@cleanclock.de
Data processing by Benyamin Jafari takes place exclusively on documented instructions from the Controller and on the basis of a Data Processing Agreement (DPA) pursuant to Art. 28 GDPR.
§2 Employment Context and Legal Basis
Clean Clock is a B2B time-tracking solution used exclusively in an employment context. Processing of employee personal data by the employer is based on:
- Art. 6(1)(b) GDPR – Performance of the employment contract (obligation to record working time)
- Art. 6(1)(c) GDPR – Compliance with legal obligations (§ 3(2) ArbZG, ECJ C-55/18)
- Art. 6(1)(f) GDPR – Legitimate interests of the employer in accurate payroll and project controlling
- § 26 BDSG – Data processing in employment relationships
§3 Categories of Data Processed – Overview
| Category | Examples | Data Subjects |
|---|---|---|
| Identification data | Name, email, user ID | Administrators, employees |
| Time-tracking data | Clock-in/out times, breaks, total hours | Employees |
| Location data (optional) | GPS coordinates at clock-in/out | Employees (if enabled) |
| Authentication data | Auth tokens, session metadata | All users |
| Task data | Task name, assignment, status | Administrators, employees |
| Usage analytics data | Anonymised navigation events | All users |
| Technical logs | IP address, user agent, timestamps | All users |
§4 Time-Tracking and Working Time Data
Purpose: Electronic recording of working time in accordance with statutory obligations and for payroll purposes.
Data processed: Clock-in time, clock-out time, break start and end, calculated working and break duration, assigned cost centres/projects, optional note text.
Storage: In the PostgreSQL database (Supabase) as time entries. Break times are stored as child records of time entries and are cascade-deleted when the parent entry is deleted. There is no independent break timer.
Legal basis: Art. 6(1)(b), (c) GDPR; § 26 BDSG.
§5 Location Data (Geotagging)
Clean Clock offers an optional GPS function that captures the location at the time of clocking in/out.
Activation requirements:
- The company administrator enables GPS mode (off / soft / hard) and confirms via a versioned attestation gate that the required legal basis (Works Agreement, consent, etc.) is in place.
- The employee's device grants the app browser/device permission for location access.
GPS modes:
- off – No location capture.
- soft – Location capture optional; employee can decline without functional restriction.
- hard – Location capture mandatory; clocking without location not possible.
GPS override: Employees can submit a GPS override request if the captured location was incorrect. These requests are retained for 90 days and then deleted.
Redaction: GPS coordinates in time entries are set to NULL after 30 days by the SQL function redact_old_gps_in_time_entries(). The time entry itself is retained; only the coordinate fields are deleted.
Legal basis: § 26 BDSG in conjunction with a Works Agreement or Art. 6(1)(a) GDPR (consent), depending on the employer's arrangements.
§6 Authentication and Session Data
Purpose: Secure user authentication and session management.
Data processed: Email address, hashed password (via Supabase Auth), JWT token, refresh token, device metadata (user agent, IP address), login timestamp.
Lifecycle: Auth entries are created when a company administrator invites employees. Upon leaving the company or termination, auth entries are removed from the auth system as part of scheduled company clean-up jobs.
Account deletion requests: On request from a data subject, all auth data and linked identification data will be deleted within 12 months, provided no statutory retention obligations apply.
Legal basis: Art. 6(1)(b) GDPR (contract performance), Art. 6(1)(f) GDPR (system security).
§7 Task Management
Task management is not part of the current product. No task data is collected or processed. This section is retained as a placeholder and will be updated if such a feature is introduced.
§8 Usage Analytics Data
Purpose: Improving the application and identifying usability issues.
Data processed: Anonymised navigation events (pages visited, click events), device category (desktop/mobile), browser type, session duration. No direct identification data is stored.
Processor: Product analytics are currently inactive — no analytics service is loaded and no usage data is transmitted. The application contains an integration for Umami (a cookieless, EU-hosted analytics tool) that is not enabled in the current build; if it is ever enabled, this policy will be updated first.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in product improvement through anonymised usage statistics).
§9 Technical Log and Server Data
Purpose: System security, error detection, abuse prevention.
Data processed: IP address, HTTP method, requested URL, HTTP status code, request timestamp, data volume, user agent, referrer.
Processors: Supabase (EU-West, Ireland — database and audit logs) and Hostinger (static hosting; web-server access logs). No Cloudflare or separate CDN/proxy is used.
Retention: Server logs: 30 days rolling. Supabase audit logs: 90 days.
Legal basis: Art. 6(1)(f) GDPR (legitimate interests in IT security and operations).
§10 Retention Periods – Overview
| Data Category | Period | Trigger |
|---|---|---|
| GPS coordinates in time entries | 30 days | Automatic daily redaction via pg_cron |
| GPS override requests | 90 days | From request date |
| Server logs | 30 days | Rolling |
| Supabase audit logs | 90 days | Rolling |
| Auth data (account closure) | 12 months | From deletion request / company clean-up |
| Time-tracking data | Contract term + statutory retention (typically 6 yrs) | Contract end |
| Accounting records | 10 years (§ 257 HGB) | End of financial year |
§11 Recipients and Sub-processors
Data is shared only with the following categories of recipients:
- Supabase Inc. (USA) – Database, authentication, storage and Edge Functions. Servers in EU-West (Ireland). EU Commission Standard Contractual Clauses (SCCs).
- Resend Inc. (USA) – Transactional email delivery (manager/owner invitations); processes email address and name only. SCCs.
- Hostinger International Ltd. – Static hosting of the marketing site and compiled web application; web-server access logs contain IP addresses. No database access.
- OpenStreetMap Foundation (UK) – Nominatim geocoding only, used once during site setup to convert a work-site postal address into coordinates for the GPS radius. No worker location data is sent; the UK benefits from an EU adequacy decision.
A complete list with purpose, data categories and transfer basis is available at Sub-processors.
§12 Third-Country Transfers
Certain processors (Supabase, Resend) are based in the USA. For all third-country transfers, adequate safeguards exist pursuant to Art. 46 GDPR in the form of:
- EU Commission Standard Contractual Clauses (SCCs) (Decision 2021/914/EU)
- Additional technical safeguards (encryption at rest and in transit)
Personal data is stored on EU servers (Supabase: EU-West, Ireland). Resend processes only minimal email metadata (recipient address and name) for the delivery of transactional messages.
§13 Data Subject Rights
As a data subject you have the following rights against the Controller (your employer):
- Right of access (Art. 15 GDPR) – You may request information about your stored data.
- Right to rectification (Art. 16 GDPR) – You may request correction of inaccurate data.
- Right to erasure (Art. 17 GDPR) – You may request deletion of your data, provided no statutory retention obligations apply.
- Right to restriction (Art. 18 GDPR) – You may request restriction of processing.
- Right to data portability (Art. 20 GDPR) – You may receive your data in a structured format.
- Right to object (Art. 21 GDPR) – You may object to processing based on legitimate interests.
- Right to withdraw consent (Art. 7(3) GDPR) – Consent may be withdrawn at any time (e.g. GPS consent).
For requests regarding data processing by Clean Clock, please contact: kontakt@cleanclock.de
§14 Right to Lodge a Complaint
You have the right to lodge a complaint with a data protection supervisory authority if you believe that processing of your data infringes the GDPR (Art. 77 GDPR).
The competent authority for Saxony:
Sächsischer Datenschutz- und TransparenzbeauftragterDevrientstraße 5, 01067 Dresden
www.saechsdsb.de
§15 Technical and Organisational Measures (TOMs)
The following measures have been implemented to ensure an appropriate level of protection:
- Encryption of all data at rest (AES-256) and in transit (TLS 1.3)
- Row-Level Security (RLS) in the database – each user sees only their own data
- JWT authentication with short token lifetime and refresh mechanism
- Automated daily GPS redaction job via pg_cron
- Audit logging for security-critical actions
- Data minimisation – no third-party product-analytics service is active, so no analytics data is collected
- Access to production data only for authorised personnel with MFA
- Regular automatic backups with encryption
Full TOM documentation is included in the DPA and can be requested at kontakt@cleanclock.de.
§16 Browser and Device Permissions
Clean Clock is a Progressive Web App (PWA) that runs in the browser. Certain features require browser permissions:
- Location (Geolocation API): Only when GPS mode is enabled. The permission is requested by the employee's browser. This technical permission does not constitute GDPR consent – the legal basis must be separately ensured by the employer.
- Push notifications: Optional, for reminders. Can be revoked at any time in browser settings.
- Camera: Not currently used.
All permissions can be revoked at any time in the browser settings of the respective device.
§17 Diagnostics and Observability
A minimalist observability system is used for operating and troubleshooting Clean Clock:
- In-memory ring buffer: Error events and performance metrics are held temporarily in server memory (not stored persistently). These data are discarded on server restart.
- Redaction of personal data: Before diagnostic data reaches logs or external systems, personal fields (email, name, IP address) are automatically redacted/pseudonymised.
- No external error tracker: No service such as Sentry or Datadog is currently used. Diagnostics are performed via Supabase logs (90-day retention).
§18 Changes to this Privacy Policy
This Privacy Policy may be updated in response to technical changes in the application, changes in law, or changes of sub-processors. The date of the last update is shown above.
For material changes affecting data subjects' rights, company administrators will be notified by email.
The current version is always available at cleanclock.de/legal/datenschutz.html (German) and cleanclock.de/en/legal/privacy-policy.html (English).