Privacy policy
As at September 2026 · applies to this website and to irot Time in the cloud (addresses such as your-company.time.irot.com). The demonstration at demo.time.irot.com has its own policy.
1. Controller
Jasmann Werk 52, owner Muhammad Saeed, Elberfelder Straße 72, 42553 Velbert, Germany. E-mail: time@irot.com. No data protection officer has been appointed; § 38 of the German Federal Data Protection Act does not require one.
2. In short
This website sets no cookies — except one technically necessary cookie during trial registration (section 5) — uses no analytics and no tracking, and loads no fonts, scripts or images from third-party servers. When you visit, your IP address reaches only our own server.
3. Visiting the website
To deliver the page, our server processes your IP address and technically transmitted information such as the address requested and the browser type. Access logs containing IP addresses are not stored for this website. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is delivering the website.
The server stands in a data centre of Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, at the Falkenstein site in Germany. Hetzner processes the data on our behalf under an Art. 28 GDPR processing agreement.
4. Contact by e-mail
If you write to us, we process what you send in order to answer (Art. 6(1)(b) GDPR for enquiries about a contract, otherwise (f)). Our mailbox is operated on our behalf by mailbox.org (Heinlein Hosting GmbH, Schwedter Straße 8/9A, 10119 Berlin) under a processing agreement. We delete enquiries once they are dealt with, unless a retention obligation applies.
5. Free trial (registration)
If you try irot Time through the registration, we process your e-mail address, your password — only as a hash, never in clear text — the time you agreed to the terms and this policy, and your IP address. The IP address serves only to prevent abuse (too many attempts); it is not stored but counted in memory and forgotten after an hour at most. The confirmation code is sent through our mailbox at mailbox.org (section 4).
So that registration can run over several steps, this page sets a session cookie, only for the registration and for at most seven days. It is technically necessary (§ 25(2)(2) TDDDG). The legal basis for registration is Art. 6(1)(b) GDPR (the trial agreement, terms § 3).
From the registration we set up your own irot Time on our server at Hetzner in Falkenstein; for the data held there the data processing agreement applies. Unfinished registrations are deleted after seven days, completed ones 30 days after setup. Which e-mail address belongs to which irot Time address remains stored for as long as that irot Time exists — so that each company gets one trial, and anyone registering a second time finds their existing installation again.
6. Your irot Time in the cloud
Who is responsible. For the data inside an irot Time — clockings, working hours, absences, rotas, accounts and employee photographs — the company using it is the controller; if you are an employee, that is your employer. They decide what is recorded and how long it stays. We process that data only on their instructions, under the data processing agreement. Please address questions and requests to your employer; anything that reaches us is passed on to them. We are ourselves responsible for the contract with the company and for its account (sections 5 and 7).
Where the data is. Each irot Time runs on its own, with its own database, on our server at Hetzner in Falkenstein (section 3). Passwords are stored only as a verification value from which they cannot be recovered. E-mails from irot Time, for instance to reset a password, are sent through mailbox.org (section 4). Every night all data is backed up encrypted; backups are deleted after 30 days and the decryption key is not kept on the server.
In the browser. irot Time sets no cookies. The browser’s local storage holds the login state (removed on logout) and the chosen language, and on a terminal additionally the device pairing, any clockings not yet transmitted during a connection failure, and the list of identity cards. This is technically necessary (§ 25(2)(2) TDDDG). irot Time loads nothing from third-party servers and has no tracking. For weather and public holidays at the company location, our server — not your browser — queries Open-Meteo, OpenStreetMap (Nominatim) and Nager.Date, using only the company’s postcode or town. We do not transfer personal data to countries outside the European Union.
How long. An irot Time used free of charge is not deleted while it is in use; before any deletion for prolonged non-use we give at least 30 days’ notice. After a contract ends it remains available for export for 30 days and is then deleted (terms).
7. Purchase
For payment you are forwarded to Stripe (Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Dublin 2, Ireland), where Stripe’s privacy policy applies. We receive what is needed for the invoice and the licence (company, name, e-mail address, payment confirmation) and no card details. The legal basis is Art. 6(1)(b) GDPR; invoice data is retained under § 147 of the German Fiscal Code and § 257 of the German Commercial Code.
8. Your rights
You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection to processing based on Art. 6(1)(f) GDPR (Art. 21). An e-mail is enough. You may also complain to the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia, Kavalleriestraße 2-4, 40213 Düsseldorf, poststelle@ldi.nrw.de.