Privacy policy — Version for Ireland
Version: 30 September 2026Translation. Legally binding language version: German.
This policy explains, in accordance with Articles 13 and 14 of the General Data Protection Regulation (GDPR), which personal data LazyHead e.U. processes when you visit the website nymtime.com, purchase and use the NymTime service, for which purposes, on which legal basis and for how long. For the data of our customers' employees, the customers themselves are the controllers; we process that data as a processor (section 8).
Part A — General provisions
Part A applies equally in all Member States. Part B contains the special provisions for the state for which this version applies — in particular the legal bases of employers in the employment context, the retention periods and the competent supervisory authority of that state; for customers established in that state and for employees at locations in that state they take precedence over Part A. References to Part B mean Part B of the version applicable in each case.
1. Controller
The controller within the meaning of Art. 4(7) GDPR is LazyHead e.U., owner Andrii Snikhovskyi, Morizgasse 2/2/14, 1060 Vienna, Austria, e-mail: office@nymtime.com.
The GDPR applies together with the Austrian Data Protection Act (DSG), in particular § 1 DSG (fundamental right to secrecy of personal data, a constitutional provision) and § 24 DSG (complaint to the Data Protection Authority). For processing in the employment context, Art. 88 GDPR and the rules of the state in which the employees are employed (Part B) apply in addition.
No data protection officer has been appointed. The conditions of Art. 37(1) GDPR are not met: we are not a public authority, our core activity does not consist of large-scale regular and systematic monitoring of individuals, and we do not process special categories of personal data within the meaning of Art. 9 GDPR on a large scale. Please send data protection requests to office@nymtime.com.
2. Overview: three groups of data subjects
We distinguish three groups to which different rules apply:
- Visitors of the website nymtime.com (sections 3 to 5): technical access data and contact requests.
- Customers and prospects (sections 6 and 7): conclusion of contract, payment via Stripe, customer account in the Back Office.
- Employees of our customers (section 8): schedule, working time and presence — here the employer is the controller and LazyHead e.U. is the processor under Art. 28 GDPR.
3. Visiting the website (server logs)
When a page is requested, the web server processes technically necessary data: IP address, date and time of access, requested address, amount of data transferred, HTTP status code, browser type and operating system, and the referring page (referrer).
Purpose: delivery of the page, defence against attacks, error analysis. Legal basis: Art. 6(1)(f) GDPR — our legitimate interest in the secure and stable operation of the website and the service. Retention: the logs of our own servers (the service's interface and web server) contain IP addresses; they are rotated by size (at most five files of 10 MB each per service), usually overwritten within a few days and deleted after 30 days at the latest. The data is not combined with other data or analysed for marketing purposes.
Hosting: the NymTime service (application, database, file storage, backups) runs at Hetzner Online GmbH, Industriestraße 25, 91710 Gunzenhausen, Germany, in the Falkenstein data centre (Germany, region fsn1). The database resides on LUKS-encrypted volumes; database backups are encrypted with pgBackRest (AES-256) and stored in Hetzner Object Storage in the same region. The website nymtime.com is hosted and delivered by Cloudflare (Cloudflare Germany GmbH, Rosental 7, 80331 Munich / Cloudflare, Inc., San Francisco, USA) on Cloudflare Workers. Cloudflare also forwards all traffic to the addresses api.nymtime.com, app.nymtime.com and admin.nymtime.com to our servers (reverse proxy with protection against overload attacks): TLS encryption ends at Cloudflare, and the connection from Cloudflare to our servers is encrypted with TLS again. Cloudflare therefore technically processes all data transmitted between the browser or app and the service — including data of our customers' employees — but stores no content of the service; only static files of the website and the applications (scripts, fonts, images) are cached, and Cloudflare keeps connection logs to fend off attacks. Cloudflare, Inc. is certified under the EU-US Data Privacy Framework (adequacy decision of the European Commission of 10 July 2023, Art. 45 GDPR); in addition, the European Commission's standard contractual clauses from Cloudflare's data processing agreement apply (Art. 46(2)(c) GDPR). A data processing agreement under Art. 28 GDPR is in place with both providers.
Fonts are served as part of the website itself. No connection is made to Google Fonts or other font providers; no scripts, images or content are loaded from third parties.
4. Cookies and similar technologies (§ 165(3) TKG 2021)
Website nymtime.com: this website sets no cookies and does not use local storage (Local Storage, Session Storage) for recognition. No analytics, statistics or advertising services are embedded. The language follows solely from the address requested (/, /en, /uk) and is not stored.
Back Office (application for customers at app.nymtime.com): the Back Office sets the following cookies: nt_session — a random, signed session identifier after login, readable only by the server (HttpOnly), expiring after 14 days or on logout; nt_role — the role of the signed-in person, so that the matching interface is shown; nt_locale — the chosen language; nt_location — the location last selected. nt_role, nt_locale and nt_location contain no names or contact details and expire after 12 months. In addition, the Back Office keeps interface preferences in the browser's local storage: the chosen schedule view per location and whether the set-up hint has been dismissed. In the operator console admin.nymtime.com, which is open only to staff of LazyHead e.U., the session cookie is called nt_platform. These cookies and entries are strictly necessary for the service expressly requested or only store settings the user has chosen; under § 165(3) TKG 2021 no consent is required for them. The legal basis of the associated data processing is Art. 6(1)(b) GDPR (performance of a contract). The Back Office sets no cookies for analytics or advertising.
Payment: payment is made via Stripe Checkout on the domain stripe.com. Cookies set there are the responsibility of Stripe and subject to Stripe's cookie policy (https://stripe.com/legal/cookies-policy); no Stripe script is loaded on our website.
A cookie banner is therefore not required. Should we use non-essential cookies or third-party services in the future, we will obtain consent beforehand under § 165(3) TKG 2021 and Art. 6(1)(a) GDPR and update this policy.
5. Contact form and e-mail
If you use the contact form or write to us by e-mail, we process your name, e-mail address, optionally your business and number of locations, the selected topic and the content of your message. Purpose: answering the request, sending requested templates (DPA, works agreement, consent form, DPIA), preparing a contract.
Legal basis: Art. 6(1)(b) GDPR (pre-contractual steps at your request) and, for contact by e-mail, the consent you give in the form under Art. 6(1)(a) GDPR, which you may withdraw at any time with effect for the future.
Retention: until the request has been fully handled, at most 6 months after the last message; if a contract is concluded, the periods of the contractual relationship apply (section 10). Recipient: our server delivers messages from the contact form to our mailbox via the e-mail delivery service Resend (processor, section 7).
Support requests from customers (support@nymtime.com, Terms § 10(5)): we process name, e-mail address, business, the content of the request and the related correspondence in order to answer the request and resolve faults. Legal basis: Art. 6(1)(b) GDPR (performance of the service contract) and Art. 6(1)(f) GDPR — our legitimate interest in tracing recurring faults and evidencing the quality of support. Retention: 12 months after the request is closed. The customer account is accessed only after explicit enablement by the customer (section 7).
6. Purchase and order processing (Stripe)
When you purchase via nymtime.com/kaufen we collect your company's details (company name, street, postal code and city, country, optionally VAT ID), the number of locations, the number of additionally ordered NFC tags, first and last name and e-mail address of the contact person, optionally a telephone number for queries about the order and the delivery, optionally a separate delivery address, and the time of your acceptance of the terms of service and the data processing agreement, of the separate acceptance of the provisions listed in § 1(5) of the terms of service and of any consent to being named as a reference (§ 16(4) of the terms of service). Purpose: conclusion of the contract, set-up of the customer account, invoicing, shipping of the NFC tags. Legal basis: Art. 6(1)(b) GDPR (performance of a contract) and Art. 6(1)(c) GDPR in conjunction with § 11 UStG and § 132 BAO (invoicing and record-keeping obligations). For the data of a business customer's contact person the legal basis is Art. 6(1)(f) GDPR — our legitimate interest in performing the contract with the company. When the terms of service and the data processing agreement are accepted — at purchase or, if we set up the customer account ourselves on request, at the management's first login to the Back Office — we record the time, version and checksum of the documents (SHA-256 of the accepted text), the IP address and the accepting user (accountability under Art. 5(2) GDPR; legal basis Art. 6(1)(f)).
Shipping of the NFC tags: to deliver the NFC tags included in the price and any re-ordered NFC tags, we pass the company name, the name of the contact person and the business or delivery address — and, for courier delivery, the telephone number if provided — to Österreichische Post AG or a courier service. The delivery service is an independent controller for the delivery; no employee data is passed to it. Legal basis: Art. 6(1)(b) GDPR. We keep the shipping data until the guarantee period for the NFC tags (12 months, terms § 3(3); the statutory warranty under §§ 922 et seq. ABGB remains unaffected) has expired and as part of the invoice under § 132 BAO.
VAT ID check (VIES): if you enter a VAT identification number at purchase or later in the Back Office, we transmit that number together with the country code to the confirmation service of the European Commission (VIES, VAT Information Exchange System) and store the result, the time and the consultation number. We repeat the check quarterly. Purpose: correct invoicing, in particular the decision on the shift of the tax liability (reverse charge). Recipient: European Commission, Rue de la Loi 200, 1049 Brussels, Belgium. Legal basis: Art. 6(1)(c) GDPR in conjunction with § 11(1a) and Art. 21(3) UStG 1994 (invoicing and reporting duties). A VAT identification number identifies a business; it is personal data only where it belongs to a sole trader.
Payment service provider: payment (credit card or SEPA direct debit) is processed via Stripe Checkout. Responsible for payment processing is Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin 2, Ireland. Card numbers, bank details and security features are collected and stored exclusively by Stripe; LazyHead e.U. never receives them. From Stripe we receive a customer and subscription identifier, the payment status, the last four digits of the payment method and the invoicing data.
Transfers to third countries: Stripe Payments Europe, Ltd. may transfer data to Stripe, Inc. (USA) and other group companies. The basis is the European Commission's adequacy decision on the EU-US Data Privacy Framework, to which Stripe, Inc. is subject, and the European Commission's standard contractual clauses under Art. 46(2)(c) GDPR. Details: https://stripe.com/privacy.
We keep invoices and payment records for seven years from the end of the calendar year in which they were issued, in accordance with § 132 BAO.
7. Customer account and Back Office
Address search: when a user types a location address in the Back Office, we send the typed text to the search service Photon of Komoot GmbH, Hauptstraße 35, 12159 Berlin, Germany (servers in the EU) to obtain address suggestions; if that service does not answer, we fall back to Nominatim of the OpenStreetMap Foundation. The request is made by our server, not by the browser — the user's IP address is not transmitted, and we do not log the search text. Purpose: recording the location address. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in accurate address capture). Map data: © OpenStreetMap contributors (ODbL 1.0).
For every user of the Back Office (management, managers, tax adviser) we process name, e-mail address, optionally a telephone number, role and location assignment, login times, session identifier (cookie nt_session, section 4) and a log of security-relevant actions (audit log). Purpose: provision of the service, access protection, traceability of changes. Legal basis: Art. 6(1)(b) GDPR; for the audit log additionally Art. 6(1)(f) GDPR (security, accountability under Art. 5(2) GDPR). For this user data we are the controller ourselves; it is not covered by the data processing agreement, which concerns only the customer's employee data (section 8).
Signing in to the Back Office: the user name is the user's e-mail address, together with a password the user chooses. The password is set through a one-time link we send to that address, valid for 24 hours; a forgotten password is reset through a one-time link valid for one hour. A change of the e-mail address on file is confirmed with a code sent to the new address. Passwords are stored exclusively as a hash with a random salt (scrypt) - we do not know them in clear text and cannot be told them. After 10 consecutive failed attempts the account is locked for 15 minutes; sign-ins, failed attempts, password changes and lockouts are logged. In addition the business can enable two-factor authentication: a time-based one-time code from an authenticator app (TOTP) together with recovery codes; only the encrypted secret of the app and the hashes of the recovery codes are stored. Legal basis: Art. 6(1)(b) GDPR for the sign-in itself, Art. 6(1)(f) GDPR for the lockout, the two-factor authentication and the security log (our and your legitimate interest in preventing unauthorised access). The employee app continues to use activation by a code sent to the e-mail address on file and the binding of exactly one device (section 8).
System e-mails (login and invitation links, activation codes of the employee app, notifications, contract and payment messages, invoices) are sent via Resend, Inc., San Francisco, USA, as a processor. Resend delivers the messages through Amazon Simple Email Service in the region eu-west-1 (Ireland); the recipient address, subject, content of the message and delivery status are processed. Transfers to Resend, Inc. in the USA are based on the EU-US Data Privacy Framework (Art. 45 GDPR) and the European Commission's standard contractual clauses (Art. 46(2)(c) GDPR).
If someone requests a code in the employee app for an e-mail address that no employer has registered, we send one notice to that address (at most once in 24 hours) that no account exists and that the address should be checked with the employer. The app itself shows no difference from a known address. Only the entered address and the time are processed (to limit the notice to one per day, deleted afterwards). Legal basis: Art. 6(1)(f) GDPR — legitimate interest in helping people get access without revealing which addresses exist in the system.
Access by the platform operator: staff of LazyHead e.U. have no access to the employee data stored in the customer account. Support access is only possible if the customer explicitly enables it in the Back Office under Settings → Subscription → Support access — with scope, duration and revocation at any time; every access is recorded in the customer's audit log.
8. Employee data of our customers (processing on behalf, Art. 28 GDPR)
The controller for employee data is the respective employer using NymTime. LazyHead e.U. processes this data exclusively on behalf of and on the instructions of the employer, on the basis of the data processing agreement (nymtime.com/avv). Informing employees under Art. 13 GDPR is the employer's responsibility; we provide a template for this that is shown in the employee app on first launch and can be read in full at any time in the app's settings.
Categories of data processed: master data (name, contact details, position, location, personnel number, type of employment), schedule (planned shifts, roles), working time records (actual start, end, rest breaks and short breaks, corrections with reason), working-time account (target/actual balance within the business's averaging period), absences (holiday, sick leave, time off in lieu, care leave and further types), result of the location check at clocking, device data (device identifier, public key, model, status), messages from the employee to the business, availability entries, offers and acceptances in shift swaps, read receipts for company announcements (notice board) and — only if the customer uses these features — personnel documents including evidence uploaded by the employee, payroll documents and internal labour cost figures.
Rest breaks: breaks are recorded according to the rule chosen by the business — deducted automatically, assigned by the manager in the shift, or recorded by the employee at the press of a button. If no break was recorded for a shift longer than six hours, NymTime deducts the statutory minimum rest break under the law of the state of the location so that the working time record does not remain incorrect, and shows the manager the note "break not recorded". That note serves solely to correct the record; it is not a sanction, not a performance assessment and not a basis for a warning. The correction is made by a person in the business with a reason; the employee sees corrections in the app.
Working time records are generated per location according to the country profile of the state in which the location lies and made available to the employee in the app.
Availability: employees may state on which days they are available, would rather not work or are not available. The entry is voluntary, serves only for planning and is neither stand-by nor on-call duty within the meaning of working time law; it creates no obligation to start work and no claim to pay. Planning authority and responsibility for the schedule remain with the employer. Legal basis: Art. 6(1)(b) GDPR (performance of the employment relationship).
Shift swaps: if an employee offers a shift for swapping, colleagues at the same location with the same role see the name, the role or department and the times of the shift concerned — nothing more. Whoever accepts the swap is shown to the offering employee and to the manager. The swap takes effect when the manager approves it or when the business has enabled automatic approval for like-for-like shifts. Legal basis: Art. 6(1)(b) GDPR; no presence or performance data is disclosed.
Contact details for colleagues (Contacts): an employee's phone number and e-mail address are visible to the other employees of the location only if the employee switches this on themselves in the app settings. The default is off. Legal basis: consent under Art. 6(1)(a) GDPR, which can be withdrawn at any time with effect for the future (Art. 7(3) GDPR) — on withdrawal the contact details are immediately no longer visible. Withdrawal has no disadvantages for the employment relationship; without release, colleagues see only name, role or department and initials. Managers see the business contact details regardless, on the basis of Art. 6(1)(b) and (f) GDPR.
Notice board (company announcements): the business can publish announcements to one location or to all employees. NymTime stores who marked an announcement as read so that the business can demonstrate that important company information was acknowledged. Legal basis: Art. 6(1)(b) and (f) GDPR. The read receipt is not an instrument for monitoring work performance; no further evaluation of behaviour takes place.
Employee documents: the business can file documents and make them visible to the employee concerned in the app (for example the written information on the essential terms of employment, pay slips and confirmations); the employee can upload documents themselves (for example a sick note or requested evidence) and the business can request a document. Documents can carry an expiry date (for example a residence permit) for which NymTime sends a timely reminder. A sick note is health data within the meaning of Art. 9 GDPR; it may only be filed to the extent that the employer may request it under the law of the state in which the employee is employed (Part B names the provisions) — the legal basis for this is Art. 9(2)(b) GDPR in conjunction with those provisions. Where incapacity for work is reported electronically via a social security institution, only the information the employer is entitled to is filed, without diagnosis; where a note contains a diagnosis code, it is made illegible before uploading. Personnel documents may contain national identification numbers (for example the social security number); the employer files them only within the law of its state. Diagnoses and causes of illness must not be recorded. Sick notes and payroll documents can be seen only by management, persons expressly authorised by the customer and the employee concerned; every access is logged. The application encrypts documents with AES-256-GCM before storing them; the keys are held only on the application servers. Retention follows the data types in the customer's settings: payroll documents the data type "payroll documents" (period and start of the period as stated in Part B), the other documents the data type "employee documents".
Camera and photos: the employee app's camera only reads the QR code on the location sign in order to install or open the app; no image is stored. A photo is taken or chosen from the gallery only when the employee uploads a document themselves (for example a sick note). No photos are taken when clocking in or out.
Notifications on the phone (push): the employee app can receive notifications, for example about a new shift or a decided absence. For this we store the device's push token. Notifications are sent via the push service of Expo (650 Industries, Inc., USA) and from there via the Apple Push Notification service (Apple) or Firebase Cloud Messaging (Google). Only the push token, an identifier and the type of notification and a general text without personal content are transmitted; the app shows the details only once it is opened. Legal basis: Art. 6(1)(b) GDPR. Notifications can be switched off at any time in the phone's settings. Technical usage data of the push service (such as the phone's IP address when the push token is fetched) is additionally processed by Expo under its own responsibility for the operation and security of its service (expo.dev/privacy). The transfer to Expo in the USA is based on the EU-US Data Privacy Framework (Art. 45 GDPR), under which Expo is certified; the basis is the Data Processing Addendum of 28 September 2026.
Deleting the account: in the app's settings the employee can request the deletion of their account. The request goes to the employer, who as controller decides on it. Working time records are kept for the statutory period under the law of the state of the location even after deletion (retention below).
Revenue figures: for key figures such as the labour cost ratio, the business may enter or import daily revenue per location. These figures relate to the location and not to persons; on their own they are not personal data. A personal reference only arises when they are compared with labour costs, which are accessible exclusively to the customer's management.
No location coordinates: NymTime stores no GPS coordinates, no routes and no movement profiles. When clocking in by location without NFC, the employee's device sends its current position and accuracy to our server once, at the moment of the clock-in; the server only uses it to check whether the device is inside the location area defined by the employer and discards the coordinates immediately — only the result "inside", "outside" or "location unavailable" is stored, with time and accuracy in metres. When tapping the NFC tag, the position is only sent along and checked the same way if the employer has completed the steps required by the law of the location's country for the location check and recorded them in the Back Office; otherwise not at all. The position is determined only once, at the moment of clocking; there is no location tracking in the background. No check takes place outside a shift.
Location check only after the steps of the respective country: checking the location at clocking is a control measure. It is switched off by default and only becomes active for a location and an employee once the employer has completed the steps required by the law of its country and recorded them in the Back Office; Part B names these steps. In some countries the location check is not offered for fixed workplaces. There is no location tracking in the background; the check happens only at the moment of clocking, and NymTime stores no coordinates, only "inside", "outside" or "location unavailable". Without the completed steps, no location check takes place.
Acknowledgements and consents in the app: where the law of the country requires the employee to be informed about a function or to consent to it, the employee confirms this in the app after viewing the document. The time, the document and its version, and the answer are stored. The employee can withdraw a consent at any time in the app with effect for the future (Art. 7(3) GDPR); the lawfulness of the processing carried out until then remains unaffected. After withdrawal the location check is switched off for that employee; clocking at the NFC tag and other methods provided by the employer remain available.
Legal bases of the employer: Art. 6(1)(c) GDPR in conjunction with the duty to record working time under the law of the state of the location, Art. 6(1)(b) GDPR (employment contract, scheduling), Art. 6(1)(f) GDPR (system security, one device per person) and, for the location check at clocking, the bases required by the law of the respective country; Part B names the rules of the state.
Retention: the employer sets the retention periods per data type in the Back Office; NymTime enforces the statutory minimums. The defaults for working time records, audit log and documents are stated in Part B under the law of the state of the location; raw presence events 3 months, shorter where the law of the state requires it (Part B), notifications 6 months. A daily job deletes or anonymises expired data and records this.
Employees' rights: employees exercise their rights of access, rectification, erasure, restriction, data portability and objection towards their employer. In the employee app they can view their time records at any time and export them monthly. Requests that reach us are forwarded to the employer without delay and we support the employer in answering them.
9. Recipients and transfers to third countries
We pass personal data only to the following recipients: the hosting provider of the service (Hetzner Online GmbH, Falkenstein data centre in the EU, processor), Cloudflare (hosting of the website and forwarding of all traffic to the service, processor — section 3), Resend, Inc. (sending e-mails via Amazon Simple Email Service in Ireland, processor — section 7), Expo (650 Industries, Inc.) with the Apple Push Notification service and Firebase Cloud Messaging (notifications to the employee app without personal content — section 8), Stripe Payments Europe, Ltd. (independent controller for payment processing), Österreichische Post AG or a courier service (delivery of the NFC tags, shipping data only), the European Commission (confirmation of the VAT ID in VIES, only country code and VAT ID — section 6), Komoot GmbH (Photon address search, only the typed address text — section 7) and authorities and courts where there is a legal obligation. The current list of processors is Annex 2 of the data processing agreement (nymtime.com/avv).
The data of the NymTime service — customer accounts, employee data, documents, backups — is stored exclusively in the EU (Hetzner, Falkenstein). Transfers to third countries outside the European Economic Area take place in the following cases: when Cloudflare forwards the traffic (section 3), when e-mails are sent via Resend (section 7), when push notifications are sent via Expo, Apple and Google (section 8) and within payment processing by Stripe (section 6). The basis in each case is the European Commission's adequacy decision on the EU-US Data Privacy Framework (Art. 45 GDPR) for the companies certified under it and, in addition, the European Commission's standard contractual clauses (Art. 46(2)(c) GDPR).
10. Retention periods at a glance
Unless stated otherwise above, the following periods apply:
- Server logs with IP addresses: rotated by size, usually a few days, at most 30 days.
- Contact requests: until handled, at most 6 months after the last message.
- One-time links and codes: set password 24 hours, reset password 1 hour, confirmation of a new e-mail address and activation of the employee app 15 minutes each - each stored only as a hash and deleted afterwards.
- Support requests from customers: 12 months after the request is closed.
- Contract and customer account data: duration of the contract; then 30 days for data export by the customer, followed by deletion unless a retention obligation exists.
- Invoices, payment records, acceptance records (terms, DPA): 7 years under § 132 BAO or for the limitation period of claims.
- Employee data of our customers: according to the retention periods set by the customer within the statutory minimums (section 8).
- Backups: overwritten no later than 35 days after the deletion of the primary data.
11. Your rights
You have the right to access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection to processing based on Art. 6(1)(f) GDPR (Art. 21), and the right to withdraw consent at any time with effect for the future (Art. 7(3)). Please contact office@nymtime.com or — as a customer — support@nymtime.com; we respond without undue delay and at the latest within one month (Art. 12(3) GDPR).
You also have the right to lodge a complaint with the supervisory authority (Art. 77 GDPR, § 24 DSG). For us as a controller established in Austria the Austrian Data Protection Authority is competent; under Art. 77(1) GDPR data subjects may also lodge their complaint with the supervisory authority of their habitual residence, their place of work or the place of the alleged infringement; Part B names the supervisory authority of the state for which this version applies. Austrian Data Protection Authority (Datenschutzbehörde), Barichgasse 40–42, 1030 Vienna, telephone +43 1 52 152-0, e-mail dsb@dsb.gv.at, www.dsb.gv.at. The contact details of all data protection supervisory authorities in the European Union are published by the European Data Protection Board at edpb.europa.eu/about-edpb/about-edpb/members_en.
Employees of our customers address their requests to their employer (section 8); requests that reach us are forwarded.
12. No automated decisions
We make no automated individual decisions, including profiling, within the meaning of Art. 22 GDPR. Fields suggested automatically from documents are marked as such in NymTime and always reviewed by a person; approvals of absences and corrections of working time are always made by a person in the customer's business.
13. Data security (Art. 32 GDPR)
All connections are encrypted with TLS. Back Office passwords are stored exclusively as a hash with a random salt (scrypt), and so are one-time links and codes; after 10 failed attempts the account is locked for 15 minutes, every password change ends all existing sessions, and the business can require two-factor authentication (TOTP app with recovery codes) for all accounts. Access in the Back Office is role- and location-based; each employee device is cryptographically bound (one active device per person); NFC tags are designed with dynamically signed messages against copying; the audit log is immutable; the database resides on a LUKS-encrypted volume at the hosting provider; the application encrypts documents with AES-256-GCM before storing them in object storage (keys only on the application servers), and pgBackRest encrypts database backups with AES-256; all transmission is exclusively over TLS; daily backups in the EU data centre. The complete technical and organisational measures are Annex 3 of the data processing agreement.
14. Changes to this policy
We adapt this policy when the service, the service providers used or the legal situation change. The version published at nymtime.com/datenschutz applies; the date of the current version is shown at the top of the page. We additionally inform customers of material changes by e-mail.
Part B — Special provisions for Ireland
The following provisions apply to customers established in Ireland and to employees at locations in Ireland. They take precedence over the provisions of Part A. The German version is binding; the English version is for information.
B1. Employment context
In addition to Art. 88 GDPR, processing in the employment context is governed by the Irish Data Protection Act 2018 and Irish employment law; there is no works-council co-determination on monitoring systems in Ireland. The employer sets out the time recording in a contract clause or workplace policy and informs employees before their first use.
Location check: in Ireland it is used only at locations for which the employer has recorded a reason (for example no NFC tag possible or a mobile location), on the basis of Art. 6(1)(f) GDPR with a written legitimate-interest assessment and after a data protection impact assessment. You may object under Art. 21 GDPR. Using your private phone is voluntary; the employer offers another way of recording working time. These are the bases required for the location check under section 8 of Part A.
B2. Working time records and documents
The working time records serve the record-keeping duty under section 25 of the Organisation of Working Time Act 1997 and S.I. No. 473/2001; the legal basis is Art. 6(1)(c) GDPR in conjunction with these provisions.
The documents include in Ireland, for example, the written statement of terms of employment under section 3 of the Terms of Employment (Information) Act 1994. The employer may file a medical certificate only to the extent that it may request it under the Sick Leave Act 2022 or the contract of employment, and only with the statement of unfitness for work and its expected duration; the legal basis is Art. 9(2)(b) GDPR in conjunction with that Act.
B3. Storage period
Default values for Ireland: working time records 6 years (at least 3 years under section 25 of the Organisation of Working Time Act 1997), raw attendance events 3 months, audit log 7 years, documents 7 years, payroll documents 6 years (section 886 of the Taxes Consolidation Act 1997), notifications 6 months.
B4. Supervisory authority
For customers established in Ireland and for employees at locations in Ireland the competent authority is the Data Protection Commission (DPC), 21 Fitzwilliam Square South, Dublin 2, D02 RD28, www.dataprotection.ie (section 11 of Part A).