Privacy Policy
Last updated: December 29, 2024
Effective date: December 29, 2024
This Privacy Policy explains how ZeitSol ("we", "us", "our") collects, uses, stores, and protects your personal data when you use the Zeitarc mobile application ("App") and related services. This policy is designed to comply with the General Data Protection Regulation (EU) 2016/679 ("GDPR") and other applicable data protection laws.
Zeitarc helps families create digital timelines to preserve memories of their children and pets. We understand the sensitive nature of this data and are committed to protecting your privacy and your family's personal information.
Important: By using Zeitarc, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our practices, please do not use the App.
Table of Contents
1. Data Controller
The data controller responsible for your personal data is:
As the data controller, we determine the purposes and means of processing your personal data and are responsible for ensuring compliance with applicable data protection laws.
2. Personal Data We Collect
We collect and process the following categories of personal data:
2.1 Account Data
When you create an account, we collect:
- Email address - Required for account creation and communication
- Username - Chosen by you for identification within the App
- Profile photograph - Optional, uploaded by you
- Password - Stored in hashed (encrypted) form; we cannot read your password
- Authentication tokens - Technical tokens for secure session management
2.2 Timeline Content Data
Content you voluntarily add to your timelines:
- Photographs and media files - Images and videos you upload
- Timeline entries - Text descriptions, dates, titles, and notes
- Milestone data - Birth information, growth measurements, vaccination records
- Names and biographical information - Names of children, pets, and family members
2.3 Technical Data
Automatically collected when you use the App:
- Device information - Device type, operating system, and version
- App version - Version of Zeitarc installed
- IP address - Collected for security and fraud prevention
- Crash reports - Technical data when the App encounters errors
- Usage data - Features used, timestamps, and interaction patterns
2.4 Data from Third Parties
If you choose to sign in with Google:
- Google account email - Your primary Google email address
- Google profile name - Your display name from Google
- Google profile picture - If available and permissions granted
We only receive data you authorize Google to share. We do not access your Google contacts, calendars, or other Google services.
3. Purposes and Legal Basis for Processing
Under GDPR Article 6, we process your personal data based on the following legal grounds:
| Purpose | Data Used | Legal Basis (GDPR Art. 6) |
|---|---|---|
| Account creation and authentication | Email, username, password, authentication tokens | Contract performance (Art. 6(1)(b)) - necessary to provide our service |
| Providing the timeline service | All timeline content, photos, milestone data | Contract performance (Art. 6(1)(b)) - core functionality you requested |
| Service notifications | Email address | Contract performance (Art. 6(1)(b)) - essential service communications |
| Customer support | Email, account data, relevant timeline data | Contract performance (Art. 6(1)(b)) - responding to your requests |
| Security and fraud prevention | IP address, device info, usage patterns | Legitimate interests (Art. 6(1)(f)) - protecting our service and users |
| App improvement and bug fixes | Crash reports, usage data (anonymized) | Legitimate interests (Art. 6(1)(f)) - improving service quality |
| Legal compliance | Account data, transaction records | Legal obligation (Art. 6(1)(c)) - complying with applicable laws |
3.1 Legitimate Interests Assessment
Where we rely on legitimate interests, we have conducted a balancing test to ensure our interests do not override your fundamental rights:
- Security: Our interest in preventing fraud and unauthorized access is balanced against minimal privacy impact of technical data collection
- Improvement: Our interest in fixing bugs and improving the App uses anonymized/aggregated data where possible
You have the right to object to processing based on legitimate interests. See Section 7 for how to exercise this right.
4. Special Categories of Data
Zeitarc may process data that could be considered special category data under GDPR Article 9:
4.1 Health-Related Data
If you choose to record vaccination records, growth measurements, or health milestones, this may constitute health data. We process this data based on:
- Explicit consent (Art. 9(2)(a)) - You actively choose to enter this data
- Data manifestly made public by you (Art. 9(2)(e)) - If you choose to share it
You are never required to enter health data. All health-related fields are optional.
4.2 Children's Biographical Data
While Zeitarc stores information about children (names, birth dates, photos), this data is provided and controlled by parents/guardians - the actual users of the App. Parents retain full control over what information is recorded.
4.3 Biometric Data
We do not process biometric data. Photographs are stored as regular image files and are not used for facial recognition or biometric identification.
5. Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected:
| Data Category | Retention Period | Reason |
|---|---|---|
| Active account data | Duration of account + 30 days | Service provision; grace period for account recovery |
| Timeline content | Duration of account + 30 days | Core service; deleted with account |
| Uploaded media files | Duration of account + 30 days | Core service; deleted with account |
| Technical/server logs | 90 days | Security monitoring and debugging |
| Crash reports | 12 months | Bug fixing and stability improvements |
| Backup copies | 30 days after deletion | Disaster recovery; permanently deleted after |
| Legal hold data | As required by law | Legal proceedings or regulatory requirements |
5.1 Account Deletion
When you delete your account:
- Your personal data is marked for deletion immediately
- Data is permanently deleted from active systems within 30 days
- Backup copies are purged within 30 additional days
- Some anonymized, aggregated data may be retained for analytics
To delete your account, use the "Delete Account" option in App settings or email privacy@zeitarc.com.
6. Data Recipients and International Transfers
6.1 Categories of Recipients
We may share your data with the following categories of recipients:
| Recipient | Purpose | Data Shared | Safeguards |
|---|---|---|---|
| Cloud hosting provider (Hetzner) | Data storage and infrastructure | All data stored in the App | EU-based servers; GDPR compliant |
| Google (Sign-In only) | Authentication | OAuth tokens only | Standard Contractual Clauses |
| Error tracking service | Crash reporting | Technical data, no personal content | Data Processing Agreement |
6.2 International Transfers
Your data is primarily stored on servers located within the European Union (Germany). Where data is transferred outside the EU/EEA, we ensure appropriate safeguards are in place:
- Adequacy decisions: Transfers to countries with EU adequacy decisions
- Standard Contractual Clauses (SCCs): EU-approved contract terms with recipients
- Supplementary measures: Additional technical and organizational safeguards where required
You may request a copy of the safeguards in place by contacting us.
6.3 We Do Not Sell Your Data
We do not sell, rent, or trade your personal data to third parties for marketing purposes. Your family memories are not a product.
6.4 Legal Disclosures
We may disclose your data if required by law:
- To comply with legal process or government requests
- To protect our rights, privacy, safety, or property
- To enforce our Terms of Service
- In connection with a merger, acquisition, or sale of assets (with notice to you)
7. Your Rights Under GDPR
As a data subject under GDPR, you have the following rights. We will respond to valid requests within one month (extendable by two months for complex requests):
7.1 Right of Access (Article 15)
You have the right to obtain confirmation of whether we process your personal data and to receive a copy of that data. This includes information about:
- The purposes of processing
- The categories of data processed
- Recipients of your data
- Retention periods
- The source of data (if not collected from you)
7.2 Right to Rectification (Article 16)
You can correct inaccurate personal data or complete incomplete data. You can update most data directly in the App, or contact us for assistance.
7.3 Right to Erasure / Right to be Forgotten (Article 17)
You can request deletion of your personal data when:
- The data is no longer necessary for its original purpose
- You withdraw consent (where consent was the legal basis)
- You object to processing and there are no overriding legitimate grounds
- The data was unlawfully processed
- Deletion is required by law
Note: We may retain data where we have a legal obligation or legitimate need (e.g., legal claims, security records).
7.4 Right to Restriction of Processing (Article 18)
You can request that we limit how we use your data when:
- You contest the accuracy of the data (while we verify)
- Processing is unlawful but you prefer restriction over deletion
- We no longer need the data but you need it for legal claims
- You have objected to processing (pending verification)
7.5 Right to Data Portability (Article 20)
You have the right to receive your personal data in a structured, commonly used, machine-readable format (e.g., JSON, CSV). This applies to data you provided to us and processed based on consent or contract.
You can export your timeline data directly from the App or request a full data export by contacting us.
7.6 Right to Object (Article 21)
You can object to processing based on legitimate interests or for direct marketing purposes. For legitimate interests, we will stop processing unless we demonstrate compelling legitimate grounds that override your interests.
Note: We do not use your data for direct marketing or profiling.
7.7 Rights Related to Automated Decision-Making (Article 22)
We do not make any decisions based solely on automated processing that produce legal or similarly significant effects on you. No profiling or automated decision-making is used in Zeitarc.
7.8 Right to Withdraw Consent
Where processing is based on consent, you can withdraw consent at any time. Withdrawal does not affect the lawfulness of processing before withdrawal.
7.9 How to Exercise Your Rights
To exercise any of these rights:
- Email: privacy@zeitarc.com
- Include your account email address for verification
- Specify which right(s) you wish to exercise
- We may request additional information to verify your identity
There is no fee for exercising your rights, unless requests are manifestly unfounded or excessive.
8. Data Security
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction:
8.1 Technical Measures
- Encryption in transit: All data transmitted between your device and our servers is encrypted using TLS 1.2 or higher
- Encryption at rest: Sensitive data is encrypted on our servers
- Password security: Passwords are hashed using industry-standard algorithms (bcrypt); we cannot read your password
- Access controls: Strict role-based access to production systems
- Secure authentication: JWT tokens with appropriate expiration
- Regular updates: Security patches applied promptly
8.2 Organizational Measures
- Limited employee access to personal data (need-to-know basis)
- Security awareness and data protection training
- Incident response procedures
- Regular security assessments
8.3 Data Breach Notification
In the event of a personal data breach that poses a risk to your rights and freedoms, we will:
- Notify the relevant supervisory authority within 72 hours (where required)
- Notify affected users without undue delay if there is high risk
- Document the breach and remedial actions taken
9. Children's Privacy
9.1 Age Requirement
Zeitarc is intended for use by adults (parents, guardians, and caregivers) aged 16 years or older. We do not knowingly collect personal data directly from children under 16.
9.2 Data About Children
While the App is designed to help document children's lives, we recognize that this data requires special protection:
- Only parents/guardians control what information is entered
- Children's data is not shared with third parties for marketing
- Parents can delete all data about their children at any time
- We do not use children's data for profiling or analytics
9.3 Parental Control
As a parent using Zeitarc, you are the data controller for information you choose to enter about your children. We act as a data processor for this content, storing it securely on your behalf.
9.4 Inadvertent Collection
If we become aware that we have collected personal data from a child under 16 without parental consent, we will delete that data promptly. If you believe a child has provided us data directly, please contact us.
11. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.
11.1 Notification of Changes
We will notify you of material changes by:
- Posting the updated policy with a new "Last updated" date
- Sending an email notification for significant changes
- Displaying a notice in the App for significant changes
11.2 Your Continued Use
Your continued use of Zeitarc after changes take effect constitutes acceptance of the updated policy. If you do not agree with changes, you should stop using the App and delete your account.
12. Contact Information and Complaints
12.1 Contact Us
For any questions or requests regarding this Privacy Policy or your data:
We aim to respond to all legitimate requests within one month.
12.2 Right to Lodge a Complaint
If you believe we have not handled your personal data properly, you have the right to lodge a complaint with a supervisory authority. We encourage you to contact us first so we can address your concerns.
You may contact your local Data Protection Authority (DPA). A list of EU DPAs is available at: https://edpb.europa.eu/about-edpb/about-edpb/members_en
12.3 Response Times
- Standard requests: Within 1 month
- Complex requests: Up to 3 months (with notification)
- Urgent security matters: Within 72 hours
Zeitarc is a product of ZeitSol
This Privacy Policy was last reviewed on December 29, 2024