Last updated: February 2026
1. Controller
Zeitweise Email:
2. Scope
This privacy policy applies to the website zeitweise.app and the web application my.zeitweise.app (hereinafter “Zeitweise” or “Platform”).
3. Legal basis
Personal data is processed in accordance with the EU General Data Protection Regulation (GDPR) and the Swiss Federal Act on Data Protection (nDSG, in effect since 1 September 2023).
4. Data collected
4.1 Registration
- Name and email address
- Password (stored encrypted with bcrypt)
- Organisation name
4.2 Usage
- Time entries, absences, expenses
- Project and client data
- IP addresses in audit logs (deleted after 12 months)
- Attendance records (clock-in/out)
- Optional GPS coordinates (only when GPS feature is enabled)
4.3 Technical data
- Browser type and version
- Operating system
- Session cookies (required for authentication)
5. Cookies
Zeitweise uses only technically necessary cookies:
- Session cookie: For authentication and session management
- CSRF token: Protection against cross-site request forgery
No tracking cookies, analytics tools, or advertising cookies are used. We do not use Google Analytics, Facebook Pixel, or any comparable services.
6. Third parties
6.1 Hosting
The platform is hosted on servers in Germany (Hetzner Online GmbH). No data is transferred to third countries outside the EEA.
6.2 Email delivery
Transactional emails (password resets, notifications) are sent via Postmark (Wildbit LLC, USA). Postmark is certified under the EU-US Data Privacy Framework.
6.3 Error monitoring
We use Sentry for error monitoring. No personal data (email, name) is sent to Sentry — only anonymised technical error data.
6.4 Payment processing
Payments are processed by Stripe Inc. Credit card data is processed exclusively by Stripe and never stored on our servers. Stripe is certified under the EU-US Data Privacy Framework.
6.5 Fonts
All fonts are served locally (self-hosted). No external font services (e.g. Google Fonts) are used.
7. Data security
- TLS/SSL encryption for all connections
- Encryption of sensitive database fields (AHV numbers, API tokens, OTP secrets)
- Content Security Policy (CSP) for XSS protection
- Two-factor authentication (optional or mandatory)
- Regular security audits with Brakeman and bundler-audit
8. Retention and deletion
- Audit logs: Automatically deleted after 12 months
- Notifications: Read after 30 days, unread after 90 days
- Report archives: Per configured retention period
- Account data: Permanently deleted upon account deletion
9. Your rights
Under GDPR and nDSG, you have the following rights:
- Access (Art. 15 GDPR / Art. 25 nDSG): Information about stored data
- Data portability (Art. 20 GDPR / Art. 28 nDSG): Export your data in JSON format via user settings
- Erasure (Art. 17 GDPR / Art. 32 nDSG): Account deletion via user settings
- Rectification (Art. 16 GDPR / Art. 32 nDSG): Correction of inaccurate data
- Objection (Art. 21 GDPR): Object to processing
- Complaint: Right to lodge a complaint with the FDPIC (Federal Data Protection and Information Commissioner) or an EU supervisory authority
10. Data processing agreement
Zeitweise acts as a data processor within the meaning of Art. 28 GDPR. Organisations using Zeitweise for their employees are the controllers. A data processing agreement (DPA) is available on request.
11. Contact
For data protection enquiries, contact us at: