Privacy Policy

Data Protection Declaration (GDPR)

Unless stated otherwise below, providing your personal data is neither legally nor contractually obligatory, nor required for conclusion of a contract. You are not obliged to provide your data; not providing it will have no consequences. "Personal data" is any information relating to an identified or identifiable natural person.

Controller

Steffen Fahrenbach
c/o Postflex #9683
Emsdettener Str. 10
48268 Greven
Germany

E-Mail: [email protected]

Server Log Files & Retention

Each time you access our website, a server log file is created. This may include your IP address, request timestamp, requested URL, user-agent string and referrer URL. We retain these logs for a minimum of 7 and a maximum of 14 days, after which they are automatically deleted.

Data Subject Rights

Under Articles 15–21 of the EU General Data Protection Regulation (GDPR), you have the right to:

  • Request confirmation as to whether and what personal data we process about you (Art. 15 GDPR)
  • Obtain correction of inaccurate data or completion of incomplete data (Art. 16 GDPR)
  • Request deletion ("right to be forgotten") (Art. 17 GDPR)
  • Request restriction of processing (Art. 18 GDPR)
  • Receive your personal data in a structured, commonly used and machine-readable format — data portability (Art. 20 GDPR)
  • Object at any time to processing based on our legitimate interests (Art. 21 (1) GDPR)

To exercise any of these rights, please contact us at [email protected].

Cookies & Browser Storage

On this website (klokk.me) we do not use analytics or tracking cookies. Any site preferences (e.g. dark/light mode) are stored locally in your browser's localStorage and are deleted whenever you clear your browser data.

In the self-service portal of our billing service (my.klokk.me), a strictly necessary session cookie (klokk_portal) is set after you sign in. It solely secures your authenticated session, is not used for analytics, and is deleted on sign-out or expiry. The legal basis is Art. 6(1)(b) GDPR (performance of the contract).

Cloudflare may set its own technical cookies (e.g. __cf_bm) for bot detection and security purposes. These are strictly necessary cookies. For details, see Cloudflare's privacy policy.

Self-Hosted Installations

Klokk is self-hosted: you install and run the application on your own infrastructure. For the personal data processed in your own installation (e.g. your employees' time records) you are the controller (Art. 4 No. 7 GDPR); we have no access to that data and do not act as your processor. This Privacy Policy covers only the data we process ourselves (this website, the order/billing process, and the license check-in). For optional services hosted by us (e.g. the hosted Ledger) we conclude a Data Processing Agreement (Art. 28 GDPR) where required.

Web Hosting

This website runs on servers rented from Hetzner Online GmbH (data centres in Germany/Finland, EU; ISO 27001 certified). A Data Processing Agreement under Art. 28 GDPR is in place; data is processed within the EU.

Orders, Billing & License Management

When you take out a paid subscription via the pricing page or manage your subscription in the self-service portal (my.klokk.me), we process the data required for this: company name, billing address, VAT ID (if any), email address, and order, billing and license data (chosen number of users, extensions, payment and license status).

The legal basis is Art. 6(1)(b) GDPR (performance of the contract or pre-contractual measures) and, for invoicing and accounting data, Art. 6(1)(c) GDPR together with statutory tax and commercial retention obligations. Invoice-relevant data is retained for the statutory periods (generally 10 years under § 147 AO and § 14b UStG) and deleted afterwards. Other contract data is deleted once it is no longer required for the purposes stated.

Personal order data (in particular address and VAT ID) is stored encrypted in our database. This data is processed only within the billing service and is not passed to the Klokk application itself or to the license server; the license server only receives a non-personal license key and its entitlement scope.

Payment Service Provider (Mollie)

To process payments we use Mollie B.V. (Keizersgracht 126, 1015 CW Amsterdam, Netherlands). When you make a purchase, the data required for the payment (e.g. name, email address, amount and payment method) is transmitted to and processed by Mollie. Payment details are entered directly on Mollie's secure payment page; we neither receive nor store full payment instrument data (e.g. card numbers).

The legal basis is Art. 6(1)(b) GDPR (performance of the contract). Mollie acts as an independent controller / recipient in this respect. For details see Mollie's privacy policy at mollie.com/privacy.

Email

In connection with your subscription we send transactional emails to the address you provide — for example the license key, the portal sign-in link, payment reminders, and the confirmation of a cancellation. The legal basis is Art. 6(1)(b) GDPR. These emails are necessary to perform the contract and contain no advertising.

Intrusion Prevention (CrowdSec)

To protect our infrastructure against automated attacks, brute-force attempts and other malicious traffic, we use CrowdSec. CrowdSec analyses server log data to detect abusive behaviour and may temporarily block the IP addresses involved.

For this purpose CrowdSec processes IP addresses and request metadata (such as requested URLs, timestamps and user-agent strings) on our behalf. Processing runs on our own infrastructure. The legal basis is our legitimate interest in the security and integrity of our systems (Art. 6(1)(f) GDPR).

Content Delivery Network (Cloudflare)

To speed up delivery and protect our infrastructure, we use Cloudflare, Inc. (101 Townsend St, San Francisco, CA 94107, USA) as our CDN. Cloudflare acts as a reverse proxy between visitors and our web server — all requests to this website are routed through Cloudflare's network first.

Cloudflare processes on our behalf: IP address, requested URLs, HTTP status codes, referrer URL, browser type, operating system, and request timestamps.

Cloudflare is certified under the EU–US Data Privacy Framework. A Data Processing Addendum (DPA) under Art. 28 GDPR has been concluded. See cloudflare.com/privacypolicy.

Analytics & Tracking

This website uses no analytics or tracking tools. No user profiles are created.

Data Protection Officer

No Data Protection Officer has been appointed, as one is not required by law for the processing activities described.

Supervisory Authority

The competent supervisory authority under GDPR is determined by the location of the controller:

The Hessian Commissioner for Data Protection and Freedom of Information
Gustav-Stresemann-Ring 1
65189 Wiesbaden
Germany