Privacy policy
Version: 15 September 2026Translation — the German version is legally binding.
This policy explains, in accordance with Articles 13 and 14 of the General Data Protection Regulation (GDPR), which personal data LazyHead e.U. processes when you visit the website nymtime.com, purchase and use the NymTime service, for which purposes, on which legal basis and for how long. For the data of our customers' employees, the customers themselves are the controllers; we process that data as a processor (section 8).
1. Controller
The controller within the meaning of Art. 4(7) GDPR is LazyHead e.U., owner Andrii Snikhovskyi, Morizgasse 2/2/14, 1060 Vienna, Austria, e-mail: office@nymtime.com.
The GDPR applies together with the Austrian Data Protection Act (DSG), in particular § 1 DSG (fundamental right to secrecy of personal data, a constitutional provision) and § 24 DSG (complaint to the Data Protection Authority). For processing in the employment context, Art. 88 GDPR and Austrian labour law apply in addition, in particular § 96(1)(3) and § 96a of the Austrian Labour Constitution Act (ArbVG) and § 10 of the Austrian Employment Contract Law Adaptation Act (AVRAG).
No data protection officer has been appointed. The conditions of Art. 37(1) GDPR are not met: we are not a public authority, our core activity does not consist of large-scale regular and systematic monitoring of individuals, and we do not process special categories of personal data within the meaning of Art. 9 GDPR on a large scale. Please send data protection requests to office@nymtime.com.
2. Overview: three groups of data subjects
We distinguish three groups to which different rules apply:
- Visitors of the website nymtime.com (sections 3 to 5): technical access data and contact requests.
- Customers and prospects (sections 6 and 7): conclusion of contract, payment via Stripe, customer account in the Back Office.
- Employees of our customers (section 8): rota, working time and presence — here the employer is the controller and LazyHead e.U. is the processor under Art. 28 GDPR.
3. Visiting the website (server logs)
When a page is requested, the web server processes technically necessary data: IP address, date and time of access, requested address, amount of data transferred, HTTP status code, browser type and operating system, and the referring page (referrer).
Purpose: delivery of the page, defence against attacks, error analysis. Legal basis: Art. 6(1)(f) GDPR — our legitimate interest in the secure and stable operation of the website. Retention: 14 days, after which the logs are deleted automatically. The logs are not combined with other data or evaluated for marketing purposes.
Hosting: the website and the NymTime service run in a data centre in the EU (the provider will be named here before the production system goes live). A data processing agreement under Art. 28 GDPR is in place with the hosting provider; no hosting-related processing takes place outside the EU.
Fonts are served from our own server. No connection is made to Google Fonts or other font providers; no scripts, images or content are loaded from third parties.
4. Cookies and similar technologies (§ 165(3) TKG 2021)
Website nymtime.com: this website sets no cookies and does not use local storage (Local Storage, Session Storage) for recognition. No analytics, statistics or advertising services are embedded. The language follows solely from the address requested (/, /en, /uk) and is not stored.
Back Office (application for customers): after login, the Back Office sets exactly one cookie named nt_session. It contains a random session identifier, is technically necessary for operating the customer account (login, access protection) and expires after 14 days or on logout. Under § 165(3) of the Austrian Telecommunications Act 2021 (TKG 2021), no consent is required for technically necessary cookies; the legal basis for the associated processing is Art. 6(1)(b) GDPR (performance of a contract).
Payment: payment is made via Stripe Checkout on the domain stripe.com. Cookies set there are the responsibility of Stripe and subject to Stripe's cookie policy (https://stripe.com/legal/cookies-policy); no Stripe script is loaded on our website.
A cookie banner is therefore not required. Should we use non-essential cookies or third-party services in the future, we will obtain consent beforehand under § 165(3) TKG 2021 and Art. 6(1)(a) GDPR and update this policy.
5. Contact form and e-mail
If you use the contact form or write to us by e-mail, we process your name, e-mail address, optionally your business and number of locations, the selected topic and the content of your message. Purpose: answering the request, sending requested templates (DPA, works agreement, consent form, DPIA), preparing a contract.
Legal basis: Art. 6(1)(b) GDPR (pre-contractual steps at your request) and, for contact by e-mail, the consent you give in the form under Art. 6(1)(a) GDPR, which you may withdraw at any time with effect for the future.
Retention: until the request has been fully handled, at most 6 months after the last message; if a contract is concluded, the periods of the contractual relationship apply (section 10). Recipient: our e-mail provider with processing in the EU as a processor (the provider will be named here before the production system goes live).
Support requests from customers (support@nymtime.com, Terms § 10(5)): we process name, e-mail address, business, the content of the request and the related correspondence in order to answer the request and resolve faults. Legal basis: Art. 6(1)(b) GDPR (performance of the service contract) and Art. 6(1)(f) GDPR — our legitimate interest in tracing recurring faults and evidencing the quality of support. Retention: 12 months after the request is closed. The customer account is accessed only after explicit enablement by the customer (section 7).
6. Purchase and order processing (Stripe)
When you purchase via nymtime.com/kaufen we collect your company's details (company name, street, postal code and city, country, optionally VAT ID), the number of locations, the number of additionally ordered NFC stickers, first and last name and e-mail address of the contact person, optionally a telephone number for queries about the order and the delivery, optionally a separate delivery address, and the time of your acceptance of the terms of service and the data processing agreement. Purpose: conclusion of the contract, set-up of the customer account, invoicing, shipping of the NFC stickers. Legal basis: Art. 6(1)(b) GDPR (performance of a contract) and Art. 6(1)(c) GDPR in conjunction with § 11 UStG and § 132 BAO (invoicing and record-keeping obligations). For the data of a business customer's contact person the legal basis is Art. 6(1)(f) GDPR — our legitimate interest in performing the contract with the company. When the terms of service and the data processing agreement are accepted, we record the time, version and checksum of the documents, the IP address and the accepting user (accountability under Art. 5(2) GDPR; legal basis Art. 6(1)(f)).
Shipping of the NFC stickers: to deliver the stickers included in the price and any re-ordered stickers, we pass the company name, the name of the contact person and the business or delivery address — and, for courier delivery, the telephone number if provided — to Österreichische Post AG or a courier service. The delivery service is an independent controller for the delivery; no employee data is passed to it. Legal basis: Art. 6(1)(b) GDPR. We keep the shipping data until the guarantee period for the stickers (12 months, terms § 3(3); the statutory warranty under §§ 922 et seq. ABGB remains unaffected) has expired and as part of the invoice under § 132 BAO.
VAT ID check (VIES): if you enter a VAT identification number at purchase or later in the Back Office, we transmit that number together with the country code to the confirmation service of the European Commission (VIES, VAT Information Exchange System) and store the result, the time and the consultation number. We repeat the check quarterly. Purpose: correct invoicing, in particular the decision on the shift of the tax liability (reverse charge). Recipient: European Commission, Rue de la Loi 200, 1049 Brussels, Belgium. Legal basis: Art. 6(1)(c) GDPR in conjunction with § 11(1a) and Art. 21(3) UStG 1994 (invoicing and reporting duties). A VAT identification number identifies a business; it is personal data only where it belongs to a sole trader.
Payment service provider: payment (credit card or SEPA direct debit) is processed via Stripe Checkout. Responsible for payment processing is Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin 2, Ireland. Card numbers, bank details and security features are collected and stored exclusively by Stripe; LazyHead e.U. never receives them. From Stripe we receive a customer and subscription identifier, the payment status, the last four digits of the payment method and the invoicing data.
Transfers to third countries: Stripe Payments Europe, Ltd. may transfer data to Stripe, Inc. (USA) and other group companies. The basis is the European Commission's adequacy decision on the EU-US Data Privacy Framework, to which Stripe, Inc. is subject, and the European Commission's standard contractual clauses under Art. 46(2)(c) GDPR. Details: https://stripe.com/privacy.
We keep invoices and payment records for seven years from the end of the calendar year in which they were issued, in accordance with § 132 BAO.
7. Customer account and Back Office
Address search: when a user types a location address in the Back Office, we send the typed text to the search service Photon of Komoot GmbH, Hauptstraße 35, 12159 Berlin, Germany (servers in the EU) to obtain address suggestions; if that service does not answer, we fall back to Nominatim of the OpenStreetMap Foundation. The request is made by our server, not by the browser — the user's IP address is not transmitted, and we do not log the search text. Purpose: recording the location address. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in accurate address capture). Map data: © OpenStreetMap contributors (ODbL 1.0).
For every user of the Back Office (management, managers, tax adviser) we process name, e-mail address, optionally a telephone number, role and location assignment, login times, session identifier (cookie nt_session, section 4) and a log of security-relevant actions (audit log). Purpose: provision of the service, access protection, traceability of changes. Legal basis: Art. 6(1)(b) GDPR; for the audit log additionally Art. 6(1)(f) GDPR (security, accountability under Art. 5(2) GDPR). For this user data we are the controller ourselves; it is not covered by the data processing agreement, which concerns only the customer's employee data (section 8).
Signing in to the Back Office: the user name is the user's e-mail address, together with a password the user chooses. The password is set through a one-time link we send to that address, valid for 24 hours; a forgotten password is reset through a one-time link valid for one hour. A change of the e-mail address on file is confirmed with a code sent to the new address. Passwords are stored exclusively as a hash with a random salt (scrypt) - we do not know them in clear text and cannot be told them. After 10 consecutive failed attempts the account is locked for 15 minutes; sign-ins, failed attempts, password changes and lockouts are logged. In addition the business can enable two-factor authentication: a time-based one-time code from an authenticator app (TOTP) together with recovery codes; only the encrypted secret of the app and the hashes of the recovery codes are stored. Legal basis: Art. 6(1)(b) GDPR for the sign-in itself, Art. 6(1)(f) GDPR for the lockout, the two-factor authentication and the security log (our and your legitimate interest in preventing unauthorised access). The employee app continues to use activation by a code sent to the e-mail address on file and the binding of exactly one device (section 8).
System e-mails (invitation to the Back Office, notifications, invoices) are sent via an e-mail provider with processing in the EU as a processor (the provider will be named here before the production system goes live).
Access by the platform operator: staff of LazyHead e.U. have no access to the employee data stored in the customer account. Support access is only possible if the customer explicitly enables it in the Back Office under Settings → Subscription → Support access — with scope, duration and revocation at any time; every access is recorded in the customer's audit log.
8. Employee data of our customers (processing on behalf, Art. 28 GDPR)
The controller for employee data is the respective employer using NymTime. LazyHead e.U. processes this data exclusively on behalf of and on the instructions of the employer, on the basis of the data processing agreement (nymtime.com/avv). Informing employees under Art. 13 GDPR is the employer's responsibility; we provide a template for this that is shown in the employee app on first launch.
Categories of data processed: master data (name, contact details, position, location, personnel number, type of employment), rota (planned shifts, roles), working time records (actual start, end, rest breaks and short breaks, corrections with reason), working-time account (target/actual balance within the business's averaging period), absences (holiday, sick leave, time off in lieu, care leave and further types), presence intervals at the location, device data (device identifier, public key, model, status), messages from the employee to the business, availability entries, offers and acceptances in shift swaps, read receipts for company announcements (notice board) and — only if the customer uses these features — personnel documents including evidence uploaded by the employee, payroll documents and internal labour cost figures.
Rest breaks (§ 11 AZG): breaks are recorded according to the rule chosen by the business — deducted automatically, assigned by the manager in the shift, or recorded by the employee at the press of a button. If no break was recorded for a shift longer than six hours, NymTime deducts the statutory minimum rest break so that the record under § 26 AZG does not remain incorrect, and shows the manager the note "break not recorded". That note serves solely to correct the record; it is not a sanction, not a performance assessment and not a basis for a warning. The correction is made by a person in the business with a reason; the employee sees corrections in the app.
Availability: employees may state on which days they are available, would rather not work or are not available. The entry is voluntary, serves only for planning and is neither stand-by nor on-call duty within the meaning of the Austrian Working Time Act; it creates no obligation to start work and no claim to pay. Planning authority and responsibility for the rota remain with the employer. Legal basis: Art. 6(1)(b) GDPR (performance of the employment relationship).
Shift swaps: if an employee offers a shift for swapping, colleagues at the same location with the same role see the name, the role or department and the times of the shift concerned — nothing more. Whoever accepts the swap is shown to the offering employee and to the manager. The swap takes effect when the manager approves it or when the business has enabled automatic approval for like-for-like shifts. Legal basis: Art. 6(1)(b) GDPR; no presence or performance data is disclosed.
Contact details for colleagues (Contacts): an employee's phone number and e-mail address are visible to the other employees of the location only if the employee switches this on themselves in the app settings. The default is off. Legal basis: consent under Art. 6(1)(a) GDPR, which can be withdrawn at any time with effect for the future (Art. 7(3) GDPR) — on withdrawal the contact details are immediately no longer visible. Withdrawal has no disadvantages for the employment relationship; without release, colleagues see only name, role or department and initials. Managers see the business contact details regardless, on the basis of Art. 6(1)(b) and (f) GDPR.
Notice board (company announcements): the business can publish announcements to one location or to all employees. NymTime stores who marked an announcement as read so that the business can demonstrate that important company information was acknowledged. Legal basis: Art. 6(1)(b) and (f) GDPR. The read receipt is not an instrument for monitoring work performance; no further evaluation of behaviour takes place.
Employee documents: the business can file documents and make them visible to the employee concerned in the app (for example a written statement of terms under § 2 AVRAG, pay slips and confirmations); the employee can upload documents themselves (for example a sick note or requested evidence) and the business can request a document. Documents can carry an expiry date (for example a residence permit) for which NymTime sends a timely reminder. A sick note is health data within the meaning of Art. 9 GDPR; it may only be filed to the extent that the employer may request it under § 4 of the Austrian Continued Remuneration Act (EFZG), § 8(8) of the Salaried Employees Act (AngG) or § 17a(7) of the Vocational Training Act (BAG) — the legal basis for this is Art. 9(2)(b) GDPR in conjunction with those provisions. Diagnoses and causes of illness must not be recorded. Access is limited to the persons responsible in the business and to the employee concerned; retention follows the data type "employee documents" in the customer's settings.
Revenue figures: for key figures such as the labour cost ratio, the business may enter or import daily revenue per location. These figures relate to the location and not to persons; on their own they are not personal data. A personal reference only arises when they are compared with labour costs, which are accessible exclusively to the customer's management.
No location coordinates: NymTime stores no GPS coordinates, no routes and no movement profiles. When tapping the NFC sticker, scanning the QR code or using geo-verified clock-in, the employee's device merely checks whether it is inside the location area defined by the employer; only the result "inside", "outside" or "location unavailable" with time and accuracy in metres is stored. No check takes place outside a shift.
Presence check (geofence) only with a legal basis: checking presence at the location is a control measure affecting human dignity. It is only active for an employee once the employer has filed in the Back Office a works agreement under § 96(1)(3) of the Austrian Labour Constitution Act (ArbVG) (in businesses with a works council) or the employee's written consent under § 10 of the Austrian Employment Contract Law Adaptation Act (AVRAG) (in businesses without a works council); Art. 88 GDPR and § 96a ArbVG remain unaffected. Without this basis, no presence intervals are generated.
Legal bases of the employer: Art. 6(1)(c) GDPR in conjunction with § 26 of the Austrian Working Time Act (AZG) (statutory duty to record working time), Art. 6(1)(b) GDPR (employment contract, rota planning), Art. 6(1)(f) GDPR (system security, one device per person) and the labour-law bases named above for the presence check.
Retention: the employer sets the retention periods per data type in the Back Office; NymTime enforces the statutory minimums. Defaults for Austria: working time records 7 years (minimum 1 year under § 26 AZG; 7 years under § 132 BAO where they underlie the payroll account), raw presence events 3 months (after which only the intervals remain), audit log 7 years, documents 7 years, notifications 6 months. A daily job deletes or anonymises expired data and records this.
Employees' rights: employees exercise their rights of access, rectification, erasure, restriction, data portability and objection towards their employer. In the employee app they can view their time records at any time and export them monthly (§ 26(8) AZG). Requests that reach us are forwarded to the employer without delay and we support the employer in answering them.
9. Recipients and transfers to third countries
We pass personal data only to the following recipients: the hosting provider (data centre in the EU, processor), the e-mail provider (processing in the EU, processor), Stripe Payments Europe, Ltd. (independent controller for payment processing), Österreichische Post AG or a courier service (delivery of the NFC stickers, shipping data only), the European Commission (confirmation of the VAT identification number in VIES, country code and VAT ID only — section 6), Komoot GmbH (Photon address search, the typed address text only — section 7), and authorities and courts where a legal obligation exists. The current list of processors is Annex 2 of the data processing agreement (nymtime.com/avv).
Transfers to third countries outside the European Economic Area take place only within payment processing by Stripe (section 6). The data of the NymTime service itself — customer accounts, employee data, documents — is stored and processed exclusively in the EU.
10. Retention periods at a glance
Unless stated otherwise above, the following periods apply:
- Website server logs: 14 days.
- Contact requests: until handled, at most 6 months after the last message.
- One-time links and codes: set password 24 hours, reset password 1 hour, confirmation of a new e-mail address and activation of the employee app 15 minutes each - each stored only as a hash and deleted afterwards.
- Support requests from customers: 12 months after the request is closed.
- Contract and customer account data: duration of the contract; then 30 days for data export by the customer, followed by deletion unless a retention obligation exists.
- Invoices, payment records, acceptance records (terms, DPA): 7 years under § 132 BAO or for the limitation period of claims.
- Employee data of our customers: according to the retention periods set by the customer within the statutory minimums (section 8).
- Backups: overwritten no later than 35 days after the deletion of the primary data.
11. Your rights
You have the right to access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection to processing based on Art. 6(1)(f) GDPR (Art. 21), and the right to withdraw consent at any time with effect for the future (Art. 7(3)). Please contact office@nymtime.com or — as a customer — support@nymtime.com; we respond without undue delay and at the latest within one month (Art. 12(3) GDPR).
You also have the right to lodge a complaint with the supervisory authority (Art. 77 GDPR, § 24 DSG). For us as a controller established in Austria the Austrian Data Protection Authority is competent; under Art. 77(1) GDPR data subjects may also lodge their complaint with the supervisory authority of their habitual residence, their place of work or the place of the alleged infringement — employees of a customer in Germany, for example, with the state data protection authority responsible for their federal state. Austrian Data Protection Authority (Datenschutzbehörde), Barichgasse 40–42, 1030 Vienna, telephone +43 1 52 152-0, e-mail dsb@dsb.gv.at, www.dsb.gv.at.
Employees of our customers address their requests to their employer (section 8); requests that reach us are forwarded.
12. No automated decisions
We make no automated individual decisions, including profiling, within the meaning of Art. 22 GDPR. Fields suggested automatically from documents are marked as such in NymTime and always reviewed by a person; approvals of absences and corrections of working time are always made by a person in the customer's business.
13. Data security (Art. 32 GDPR)
All connections are encrypted with TLS. Back Office passwords are stored exclusively as a hash with a random salt (scrypt), and so are one-time links and codes; after 10 failed attempts the account is locked for 15 minutes, every password change ends all existing sessions, and the business can require two-factor authentication (TOTP app with recovery codes) for all accounts. Access in the Back Office is role- and location-based; each employee device is cryptographically bound (one active device per person); NFC stickers are protected against copying with dynamically signed messages; the audit log is immutable; the database resides on a LUKS-encrypted volume at the hosting provider, documents and backups are stored server-side encrypted in object storage (encryption at rest) and are transmitted exclusively over TLS; daily backups in the EU data centre. The complete technical and organisational measures are Annex 3 of the data processing agreement.
14. Changes to this policy
We adapt this policy when the service, the service providers used or the legal situation change. The version published at nymtime.com/datenschutz applies; the date of the current version is shown at the top of the page. We additionally inform customers of material changes by e-mail.