Data Privacy Agreement
ProjectTimeTracker
Last updated: 8 August 2026
This is a translation for convenience. The legally binding version is the German privacy policy.
- Scope and controller
This privacy policy applies to the ProjectTimeTracker mobile application and to the website projecttimetracker.de. It explains which personal data is processed, for which purposes and on which legal basis.
Controller within the meaning of Art. 4 (7) GDPR:
Lukas Hummel
Kurmainzer Straße 105
65936 Frankfurt am Main
Germany
projecttimetracker@hummeldevelopments.de
There is no statutory obligation to appoint a data protection officer. - User identifier via the Apple account (iCloud)
Using the app requires no registration and no disclosure of a name, email address or telephone number. Instead, the iCloud user identifier (CloudKit user record ID) assigned by Apple for this app is read in order to associate the data. This identifier is the same across all devices using the same Apple ID and thereby enables synchronisation across devices without a separate user account.
This identifier is stored on the server as the user ID and linked to the recorded project data. It contains neither the name nor the email address of the user. However, as the identifier is permanently associated with an individual, it constitutes pseudonymous and therefore personal data within the meaning of Art. 4 (1) GDPR.
Legal basis: Art. 6 (1)(b) GDPR (performance of the usage contract – provision of backup and synchronisation). - Which data is processed in the app?
The following is stored on the server:
• the iCloud user identifier described in section 2
• the project data, time entries and tags created by users, including the associated timestamps
• usage statistics such as the number of projects and time entries created and the duration of app usage
Users determine the content of their project data themselves. I recommend not recording special categories of personal data under Art. 9 GDPR, or third-party data that is not required, in project names, tags and notes.
Purposes: backing up data, synchronisation across devices, restoring data on new devices, and improvement of the app. Legal basis: Art. 6 (1)(b) GDPR for backup and synchronisation, Art. 6 (1)(f) GDPR for usage statistics (legitimate interest in improving the stability and quality of the application). - Hosting and processing on our behalf
The server infrastructure used to store the data is provided by:
Contabo GmbH
Aschauer Straße 32a
81549 Munich
Germany
The data is stored exclusively on a Contabo GmbH server located in Düsseldorf and therefore within the Federal Republic of Germany. In this respect, Contabo acts as a processor; a data processing agreement pursuant to Art. 28 GDPR has been concluded to this effect. The privacy information of Contabo GmbH is available at https://contabo.com/de/legal/privacy. - Google Analytics and transfers to third countries
Google Analytics is used in the app and on this website to analyse usage statistically. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. This involves processing usage data such as the pages or screens accessed, the time and duration of use, technical information about the device and a truncated IP address. This data may also be transferred to servers of Google LLC in the United States.
For transfers to the USA, Google relies on the EU-US Data Privacy Framework and, in addition, on the European Commission's Standard Contractual Clauses pursuant to Art. 46 (2)(c) GDPR. Despite these safeguards, access to the data by US authorities cannot be entirely ruled out.
The legal basis is consent pursuant to Art. 6 (1)(a) GDPR in conjunction with § 25 (1) TDDDG. On this website, Google Analytics is only loaded after consent has been given via the consent banner; without consent, no data is transmitted to Google and no analytics cookies are set. Consent may be withdrawn at any time with effect for the future using the "Withdraw consent to analytics cookies" button at the bottom of the page; the cookies that have been set are deleted in the process. In the app, consent is governed by the settings available there. Further information is available at https://policies.google.com/privacy. - Error reports
To improve stability, crash and error reports are collected via Apple's system services, provided the user has agreed to share analytics data in the iOS settings. These reports contain technical information about the device and the state of the app at the time of the error. Collection takes place in aggregated form via Apple; the details are governed by Apple's privacy policy. - Purchase of the Premium subscription
The Premium subscription is processed exclusively via the Apple account. Payment data is neither collected nor stored nor accessed by me. Payment and purchase data is processed solely by Apple as an independent controller. - Retention period
Project data, time entries and tags are stored until erasure is requested. This ensures that data can be restored on a new device at any time. Upon a request for erasure, all data stored under the relevant user identifier is removed. - Disclosure to third parties
Personal data is disclosed only to the service providers named in this policy (Contabo as processor, and Google and Apple to the extent described) and where there is a legal obligation to do so. Data is not sold. - Rights of data subjects
Data subjects have the right of access (Art. 15 GDPR), rectification (Art. 16 GDPR), erasure (Art. 17 GDPR), restriction of processing (Art. 18 GDPR), data portability (Art. 20 GDPR) and the right to object to processing based on Art. 6 (1)(f) GDPR (Art. 21 GDPR). Consent that has been given may be withdrawn at any time with effect for the future.
To exercise these rights, an informal message to projecttimetracker@hummeldevelopments.de is sufficient. As no contact details are stored, please state the user identifier shown in the app so that the request can be assigned. This identifier allows the stored data to be located, exported or erased.
There is also a right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The competent authority is the Hessian Commissioner for Data Protection and Freedom of Information, Postfach 3163, 65021 Wiesbaden, Germany. - Data security
Transmission between the app and the server is encrypted using TLS. Access to the database is limited to the controller. Appropriate technical and organisational measures pursuant to Art. 32 GDPR are in place; however, absolute protection against unauthorised access cannot be guaranteed. - Amendments to this privacy policy
This privacy policy will be adapted where changes to the application or to the legal situation require it. The version published on this page applies.