We attach great importance to the protection of your privacy and especially to data protection. This privacy statement shows how we handle data and information. When processing your data we comply with Swiss data protection and telecommunications law (revDSG) and, where you or your employer are based in the EU or the EEA, with the General Data Protection Regulation (GDPR). The controller is Gridvision Engineering GmbH, Switzerland; please address questions and requests concerning data protection to info@gleeo.com.
The Gleeo Time Tracker app saves data exclusively on the device where the app is installed. This data only leaves the device if you as the user explicitly trigger this using the export function, switch on the backup to Google Drive, or use the optional Sync&Team Service.
With the Pro Version and Sync&Team the app can access your location data if you have enabled this function. This location data is only used in conjunction with your recorded time data and is accessible to you only. With the Pro Version this location data does not leave your device. With Sync&Team, this location data is stored in strongly encrypted form on our servers and is readable by you only.
When using the Sync&Team Service, the data is stored on our servers. To protect your privacy, the following data is strongly encrypted (AES-256) and is therefore legible neither to us nor to third parties: project names, project extra 1, project extra 2, task names, task extra 1, task extra 2, time entry detail texts, time entry locations.
Not encrypted is the information the service needs in order to assign and calculate: your email address, first and last name (where held), the name of the domain and all times and dates — that is, the start and end of your time entries and the data of the working time module: working hours, holidays, paid absences together with the names of the absence types defined by the customer, workload and approvals. Technically we could read this information; we only do so as far as operation and support require it.
OAuth2 technology is used to access the Sync&Team service. For access itself we therefore only have to store your email address on our servers. The passwords for the Sync&Team Service access and data encryption remain unknown to us at all times.
Retention and deletion
Data in the app stays on your device until you delete it there or uninstall the app.
Data in the Sync&Team Service is kept for as long as you use the service. You can delete your account yourself in the app at any time; all related data on our servers goes with it.
If an account lies dormant, we delete it at the latest 24 months after the last sign of life, provided that no subscription exists at that time. Signs of life are the end of the last subscription, the last sign-in and the last change to your data; the most recent of these is decisive. We announce the deletion at least 14 days in advance by email to the address held in your account, stating the date of deletion. If you take out a new subscription before that date, the deletion does not take place. As long as your data belongs to an active subscription — your employer's, for instance — it is not deleted.
Deleted data is gone from live operation immediately. It then ages out of the encrypted backups within at most 44 days; after that it no longer exists there either.
Log files of our servers (accesses to the website and the web application, plus technical application logs) are kept for 30 days. They serve operations and the investigation of security incidents.
Customer data
When you visit our website, we do not create an account and do not collect any details about you personally. The web server records — as every web server does — the technical access data, including your IP address; these logs are deleted after 30 days.
Cookies
This website sets no cookies. The web application uses a single, technically necessary session cookie (SESSION) that keeps you signed in; it holds nothing but a random identifier and expires 30 days after it was last used. We use no cookies for analytics, statistics or advertising, neither here nor in the web application.
In addition, the web application stores interface settings, your account email address and the encrypted domain passwords in your browser. This information does not leave your browser.
You can delete this data in your browser at any time. Without the session cookie it is not possible to sign in to the web application.
Business relationships with third parties
Our website also contains links to other offers, organizations or companies. We have no influence on the information displayed by third parties. If you have any questions about this website content, please contact these third-party companies directly. We are not responsible for compliance with the data protection regulations of third parties.
Use and disclosure of the data
We process your data in the Sync&Team service exclusively for the provision of the service. We do not sell data and do not pass it on for the purposes of others. For operating the service, however, we use processors that handle data on our behalf and on our instructions:
- Hetzner (Germany) — provision of hardware for servers, database and website; provision of services for our email dispatch. All data stored in the Sync&Team service resides there, partly encrypted.
- Google (Ireland/USA) — Firebase Authentication and Google Sign-In for signing in with a Google account; in the app, signing in with Apple also goes through Firebase Authentication. If you sign in with an email address and password, Google is not involved. In addition Google Play for buying and checking the subscription, Google Drive for the optional backup of the app (only if you switch it on) and Google Maps for showing maps (only when you display a map).
- Apple (Ireland/USA) — “Sign in with Apple” for signing in (only when you sign in this way) and the App Store for buying and checking the subscription.
With Google and Apple, data may reach the USA — in each case only what the service being used requires:
- Signing in with Google or Apple: your email address, the identifier of your Google or Apple account, the sign-in token and your IP address.
- Buying and checking the subscription: the purchase and transaction data of your store account. The purchase itself takes place between you and the respective store anyway.
- Optional backup to Google Drive: the backup files of the app — a CSV export of the data you recorded and your app settings. The files are not encrypted, but they contain no credentials: neither your account password nor the domain passwords your data is encrypted with. They end up in your own Google Drive account, and only if you switch the backup on.
- Showing maps: the map section displayed, including the position you are looking at, and your IP address — only while you have a map open.
Your time entries, working time records and project and task names are not transmitted — with the single exception of the Google Drive backup, which exists for exactly that purpose and which you switch on yourself. The transfer is based on the standard contractual clauses of Google and Apple. We use no analytics, tracking or advertising services, neither in the app nor in the web application.
Changes
We may amend this privacy statement — for instance when we develop the service further, change processors or when legal requirements change. The version published on this page is the one that applies. We also reserve the right to change our website at any time.
