Skip to content
Clean Clock
Back to Website
Home Legal Privacy Policy
GDPR Art. 13/14

Privacy Policy

Last updated: 2026-04-21 English
This policy is addressed to company administrators and employees who use Clean Clock in an employment context. The Data Controller under GDPR is your employer (the company that has licensed Clean Clock), not Benyamin Jafari as Data Processor.

§1 Data Controller and Data Processor

Data Controller (Art. 4(7) GDPR): The company that licenses and operates Clean Clock for its employees (hereinafter "your company" or "employer"). Your company determines the purpose and means of processing.

Data Processor (Art. 28 GDPR):
Benyamin Jafari
Chemnitzer Str. 69, 01187 Dresden
E-Mail: kontakt@cleanclock.de

Data processing by Benyamin Jafari takes place exclusively on documented instructions from the Controller and on the basis of a Data Processing Agreement (DPA) pursuant to Art. 28 GDPR.

§2 Employment Context and Legal Basis

Clean Clock is a B2B time-tracking solution used exclusively in an employment context. Processing of employee personal data by the employer is based on:

  • Art. 6(1)(b) GDPR – Performance of the employment contract (obligation to record working time)
  • Art. 6(1)(c) GDPR – Compliance with legal obligations (§ 3(2) ArbZG, ECJ C-55/18)
  • Art. 6(1)(f) GDPR – Legitimate interests of the employer in accurate payroll and project controlling
  • § 26 BDSG – Data processing in employment relationships
GPS/Location: Enabling the GPS function requires a versioned manager attestation gate. The employee's browser/device permission is a technical prerequisite, but does not replace the data protection legal basis. The employer is responsible for ensuring the correct legal basis (typically § 26 BDSG in conjunction with a Works Agreement or individual consent).

§3 Categories of Data Processed – Overview

CategoryExamplesData Subjects
Identification dataName, email, user IDAdministrators, employees
Time-tracking dataClock-in/out times, breaks, total hoursEmployees
Location data (optional)GPS coordinates at clock-in/outEmployees (if enabled)
Authentication dataAuth tokens, session metadataAll users
Task dataTask name, assignment, statusAdministrators, employees
Usage analytics dataAnonymised navigation eventsAll users
Technical logsIP address, user agent, timestampsAll users

§4 Time-Tracking and Working Time Data

Purpose: Electronic recording of working time in accordance with statutory obligations and for payroll purposes.

Data processed: Clock-in time, clock-out time, break start and end, calculated working and break duration, assigned cost centres/projects, optional note text.

Storage: In the PostgreSQL database (Supabase) as time entries. Break times are stored as child records of time entries and are cascade-deleted when the parent entry is deleted. There is no independent break timer.

Legal basis: Art. 6(1)(b), (c) GDPR; § 26 BDSG.

§5 Location Data (Geotagging)

Clean Clock offers an optional GPS function that captures the location at the time of clocking in/out.

Activation requirements:

  1. The company administrator enables GPS mode (off / soft / hard) and confirms via a versioned attestation gate that the required legal basis (Works Agreement, consent, etc.) is in place.
  2. The employee's device grants the app browser/device permission for location access.

GPS modes:

  • off – No location capture.
  • soft – Location capture optional; employee can decline without functional restriction.
  • hard – Location capture mandatory; clocking without location not possible.

GPS override: Employees can submit a GPS override request if the captured location was incorrect. These requests are retained for 90 days and then deleted.

Redaction: GPS coordinates in time entries are set to NULL after 30 days by the SQL function redact_old_gps_in_time_entries(). The time entry itself is retained; only the coordinate fields are deleted.

Legal basis: § 26 BDSG in conjunction with a Works Agreement or Art. 6(1)(a) GDPR (consent), depending on the employer's arrangements.

§6 Authentication and Session Data

Purpose: Secure user authentication and session management.

Data processed: Email address, hashed password (via Supabase Auth), JWT token, refresh token, device metadata (user agent, IP address), login timestamp.

Lifecycle: Auth entries are created when a company administrator invites employees. Upon leaving the company or termination, auth entries are removed from the auth system as part of scheduled company clean-up jobs.

Account deletion requests: On request from a data subject, all auth data and linked identification data will be deleted within 12 months, provided no statutory retention obligations apply.

Legal basis: Art. 6(1)(b) GDPR (contract performance), Art. 6(1)(f) GDPR (system security).

§7 Task Management

Task management is not part of the current product. No task data is collected or processed. This section is retained as a placeholder and will be updated if such a feature is introduced.

§8 Usage Analytics Data

Purpose: Improving the application and identifying usability issues.

Data processed: Anonymised navigation events (pages visited, click events), device category (desktop/mobile), browser type, session duration. No direct identification data is stored.

Processor: Product analytics are currently inactive — no analytics service is loaded and no usage data is transmitted. The application contains an integration for Umami (a cookieless, EU-hosted analytics tool) that is not enabled in the current build; if it is ever enabled, this policy will be updated first.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in product improvement through anonymised usage statistics).

§9 Technical Log and Server Data

Purpose: System security, error detection, abuse prevention.

Data processed: IP address, HTTP method, requested URL, HTTP status code, request timestamp, data volume, user agent, referrer.

Processors: Supabase (EU-West, Ireland — database and audit logs) and Hostinger (static hosting; web-server access logs). No Cloudflare or separate CDN/proxy is used.

Retention: Server logs: 30 days rolling. Supabase audit logs: 90 days.

Legal basis: Art. 6(1)(f) GDPR (legitimate interests in IT security and operations).

§10 Retention Periods – Overview

Data CategoryPeriodTrigger
GPS coordinates in time entries30 daysAutomatic daily redaction via pg_cron
GPS override requests90 daysFrom request date
Server logs30 daysRolling
Supabase audit logs90 daysRolling
Auth data (account closure)12 monthsFrom deletion request / company clean-up
Time-tracking dataContract term + statutory retention (typically 6 yrs)Contract end
Accounting records10 years (§ 257 HGB)End of financial year

§11 Recipients and Sub-processors

Data is shared only with the following categories of recipients:

  • Supabase Inc. (USA) – Database, authentication, storage and Edge Functions. Servers in EU-West (Ireland). EU Commission Standard Contractual Clauses (SCCs).
  • Resend Inc. (USA) – Transactional email delivery (manager/owner invitations); processes email address and name only. SCCs.
  • Hostinger International Ltd. – Static hosting of the marketing site and compiled web application; web-server access logs contain IP addresses. No database access.
  • OpenStreetMap Foundation (UK) – Nominatim geocoding only, used once during site setup to convert a work-site postal address into coordinates for the GPS radius. No worker location data is sent; the UK benefits from an EU adequacy decision.

A complete list with purpose, data categories and transfer basis is available at Sub-processors.

§12 Third-Country Transfers

Certain processors (Supabase, Resend) are based in the USA. For all third-country transfers, adequate safeguards exist pursuant to Art. 46 GDPR in the form of:

  • EU Commission Standard Contractual Clauses (SCCs) (Decision 2021/914/EU)
  • Additional technical safeguards (encryption at rest and in transit)

Personal data is stored on EU servers (Supabase: EU-West, Ireland). Resend processes only minimal email metadata (recipient address and name) for the delivery of transactional messages.

§13 Data Subject Rights

As a data subject you have the following rights against the Controller (your employer):

  • Right of access (Art. 15 GDPR) – You may request information about your stored data.
  • Right to rectification (Art. 16 GDPR) – You may request correction of inaccurate data.
  • Right to erasure (Art. 17 GDPR) – You may request deletion of your data, provided no statutory retention obligations apply.
  • Right to restriction (Art. 18 GDPR) – You may request restriction of processing.
  • Right to data portability (Art. 20 GDPR) – You may receive your data in a structured format.
  • Right to object (Art. 21 GDPR) – You may object to processing based on legitimate interests.
  • Right to withdraw consent (Art. 7(3) GDPR) – Consent may be withdrawn at any time (e.g. GPS consent).

For requests regarding data processing by Clean Clock, please contact: kontakt@cleanclock.de

§14 Right to Lodge a Complaint

You have the right to lodge a complaint with a data protection supervisory authority if you believe that processing of your data infringes the GDPR (Art. 77 GDPR).

The competent authority for Saxony:

Sächsischer Datenschutz- und Transparenzbeauftragter
Devrientstraße 5, 01067 Dresden
www.saechsdsb.de

§15 Technical and Organisational Measures (TOMs)

The following measures have been implemented to ensure an appropriate level of protection:

  • Encryption of all data at rest (AES-256) and in transit (TLS 1.3)
  • Row-Level Security (RLS) in the database – each user sees only their own data
  • JWT authentication with short token lifetime and refresh mechanism
  • Automated daily GPS redaction job via pg_cron
  • Audit logging for security-critical actions
  • Data minimisation – no third-party product-analytics service is active, so no analytics data is collected
  • Access to production data only for authorised personnel with MFA
  • Regular automatic backups with encryption

Full TOM documentation is included in the DPA and can be requested at kontakt@cleanclock.de.

§16 Browser and Device Permissions

Clean Clock is a Progressive Web App (PWA) that runs in the browser. Certain features require browser permissions:

  • Location (Geolocation API): Only when GPS mode is enabled. The permission is requested by the employee's browser. This technical permission does not constitute GDPR consent – the legal basis must be separately ensured by the employer.
  • Push notifications: Optional, for reminders. Can be revoked at any time in browser settings.
  • Camera: Not currently used.

All permissions can be revoked at any time in the browser settings of the respective device.

§17 Diagnostics and Observability

A minimalist observability system is used for operating and troubleshooting Clean Clock:

  • In-memory ring buffer: Error events and performance metrics are held temporarily in server memory (not stored persistently). These data are discarded on server restart.
  • Redaction of personal data: Before diagnostic data reaches logs or external systems, personal fields (email, name, IP address) are automatically redacted/pseudonymised.
  • No external error tracker: No service such as Sentry or Datadog is currently used. Diagnostics are performed via Supabase logs (90-day retention).

§18 Changes to this Privacy Policy

This Privacy Policy may be updated in response to technical changes in the application, changes in law, or changes of sub-processors. The date of the last update is shown above.

For material changes affecting data subjects' rights, company administrators will be notified by email.

The current version is always available at cleanclock.de/legal/datenschutz.html (German) and cleanclock.de/en/legal/privacy-policy.html (English).

All Documents Terms of Service
Contents §1 Controller §2 Employment Context §3 Data Categories §4 Time-Tracking §5 Location Data §6 Authentication §7 Tasks §8 Analytics §9 Logs §10 Retention Periods §11 Recipients §12 Third Countries §13 Data Subject Rights §14 Supervisory Authority §15 TOMs §16 Browser Permissions §17 Diagnostics §18 Changes
© 2026 Clean Clock · Benyamin Jafari · Chemnitzer Str. 69, 01187 Dresden
Home· Legal Notice· Privacy Policy· Terms of Service· Legal