You are offline. New time records can only be saved when the connection returns.

Legal

Privacy Policy

All documents Dansk
Version
owner-decision-draft-2026-07-07
Last updated
2026-07-07
Contact
support@fejlgoblin.ovh
SHA-256
e65edc6c1de928dc0625a2cd328b9ab3174e70cd4a96352dffbe975fc89baace

Privacy Policy

Plain-language summary

Fejlgoblin Tidsregistrering is a personal time-registration and documentation tool. The app processes account, time, work, estimate, tax-estimate, export, security and optional GPS/IP-related data so users can keep their own work records.

The app is not an employer system, payroll provider, tax authority, union, accountant, lawyer, public authority or court. Time records, GPS, IP addresses, notes and exports can help with documentation, but they do not guarantee legal proof, correct pay, correct tax or any specific outcome.

Controller

Controller: Frederik Juul Olsen Operating model: personal operation / no CVR number at launch Contact: support@fejlgoblin.ovh Replies normally sent from: admin@fejlgoblin.ovh Contact address or contact method: physical address is not published unless legally required or provided after a relevant lawful request. Use support@fejlgoblin.ovh. App: Fejlgoblin Tidsregistrering Domain: https://time.fejlgoblin.ovh

If the app is later operated through a company, or if a CVR number is created, this document, the terms, contact information and subprocessor list must be updated before the changed operation is used publicly.

What data does the app process?

CategoryExamplesRequired or optionalPurposePreliminary legal basisRetention
AccountName, email, language, timezone, password hash, preferencesRequired for account; many preferences optionalAccount, login, display, support, securityContract/service necessity and legitimate security interestsUntil account deletion
Security and sessionsSessions, login/session IP, user agent, rate-limit hashes, MFA dataAutomaticLogin, abuse protection, session review and securityLegitimate interests and service necessityShort technical periods; otherwise until account deletion
Time recordsClock-in/out, start/end, breaks, manual records, job, categoryCore app dataPersonal work recordContract/service necessityUntil account deletion or user-controlled deletion
NotesWork notes, categories, manual reasonsOptional except some manual editsUser documentationContract/service necessityWith the time record
GPSBrowser location, accuracy, collection time and GPS outcome, if recordedOptional; app works without GPSExtra context for user recordsOptional browser permission/user choice and clear noticeUntil account deletion or separate GPS deletion
Clock/security IPPublic IP or client IP and technical client metadataAutomatic, with clear information and opt-out/deletion where implementedSecurity, abuse protection and contextLegitimate interests/securityUntil account deletion or separate IP deletion
Pay/job dataJob name, currency, hourly/monthly pay, supplements, pension, overtimeOptionalApproximate pay reports/estimatesContract/service necessity when enabledUntil account deletion or user-controlled deletion
Tax/municipality dataMunicipality, church tax flag, tax values/overridesOptionalApproximate Danish tax/net estimatesContract/service necessity when enabledUntil account deletion or user-controlled deletion
Agreement dataSelected agreement template and user overridesOptionalEstimate support and documentationContract/service necessityUntil account deletion or user-controlled deletion
Calculation snapshotsSaved estimate inputs/resultsOptionalHistorical estimate snapshotsContract/service necessityUntil account deletion or user-controlled deletion
Export metadataFormat, period, whether GPS/IP was included, row count, file hashCreated when exportingExport accountability/integrityLegitimate interests/accountability and serviceMetadata until account deletion; export bytes are not retained after download
Audit logAccount, security, export, correction and admin eventsAutomaticSecurity, operations and accountabilityLegitimate interests/accountabilityUntil account deletion; then personal details are deleted or anonymised
EmailRecipient, subject/body for verification/reset, delivery metadataOnly if email delivery is enabledVerification and password resetService/security necessityOVH/Zimbra and app audit/token retention

GPS and IP

GPS is off by default. The app may ask the browser for GPS only after a clear in-app notice, normally during first login or first clock-in/out. GPS is optional, and you can clock in and out without GPS.

The app must save the GPS outcome, not only coordinates. Possible outcomes are: gps_success, gps_disabled_by_user, gps_denied_by_browser, gps_unavailable, gps_timeout, gps_error and gps_deleted_by_user.

If GPS succeeds, the app may store exact coordinates, accuracy and collection time. Exact GPS coordinates are kept until account deletion, or until you delete/request deletion of GPS data. You must be able to delete GPS coordinates without deleting the time record itself. When GPS is deleted, the app should keep only a minimal non-identifying event, for example that GPS was deleted.

IP/client metadata is recorded automatically for security, abuse prevention and context. Users must receive clear information about this, and the app must provide opt-out/deletion where implemented. Exact IP addresses are kept until account deletion, or until you delete/request deletion of IP data. When deleted, the exact IP must be deleted completely unless a minimal anonymised security/audit reference is necessary.

GPS and IP are context data only. They do not by themselves prove where you were, that you worked, that you are entitled to payment, or that an authority, union, employer or court will accept the documentation.

Pay, tax and agreement estimates

All pay, tax, collective-agreement, pension, supplement and net-pay amounts are estimates only. They may be wrong, incomplete, outdated or based on information entered by you. The app does not provide payroll advice, tax advice, legal advice, accounting advice, union advice or binding calculations.

Sharing and recipients

The app does not sell personal data and is not intended for advertising tracking or targeted marketing.

Possible recipients/processors:

RecipientPurposeStatus
Self-hosted serverHosting app and databaseOwner decision applied — verify implementation before public launch
OVH / ZimbraVerification/password-reset emailOwner decision applied — verify implementation before public launch
Encrypted backups on another self-hosted serverBackupsOwner decision applied — verify implementation before public launch
OVHcloud DNS and Let’s Encrypt TLS; no production reverse proxy/CDN providerTraffic, TLS, DNS or proxyOwner decision applied — verify implementation before public launch
See subprocessor listSee subprocessor listOwner decision applied — verify implementation before public launch

Data is not actively shared with employers, unions, statistics bodies or other third parties unless you export/share it yourself or a valid legal request requires it. Future anonymised/statistical sharing must not be activated without separate information and voluntary opt-in.

Transfers outside the EU/EEA

Owner decision applied — verify implementation before public launch — This depends on hosting, email, backup and support providers. If personal data is transferred outside the EU/EEA, the transfer basis, safeguards and providers must be described here.

Security

The code supports password hashing, CSRF protection, secure production sessions, rate limits, session inventory, optional MFA, audit logs, no-store export downloads and limited third-party scripts. No security measure can be guaranteed to prevent every incident.

Retention and deletion

You can delete your account through the account-deletion flow if enabled in production. Account deletion removes the account, time records, GPS/IP linked to clock events, job/pay/tax/agreement settings and export metadata from the active database, and redacts relevant audit details.

Backups may not be rewritten immediately. They must follow 12 months encrypted and must not restore deleted accounts into active use without reapplying deletion.

A separate feature for deleting only GPS/IP without deleting the whole account is planned/wanted but must not be described as active until implemented. Current method: Users must be able to delete exact GPS coordinates and exact IP/client metadata without deleting the time record. The app should keep only a minimal non-identifying outcome/deletion event where needed for integrity..

Your rights

Under GDPR, you may have rights of access, rectification, erasure, restriction, objection, portability and withdrawal of consent where processing is based on consent. These rights do not apply in the same way in every situation.

Contact support@fejlgoblin.ovh or use available self-service tools. A response should normally be provided within one month unless the request is complex or lawful extensions apply.

You can complain to the Danish Data Protection Agency (Datatilsynet). See contact-and-complaints-en.md.

Children and young users

The app may be relevant to apprentices. You must be at least 13 years old to use the app. If you are under 18, read the explanations carefully and ask a parent/guardian, union, employer or another relevant adult/adviser if you are unsure about pay, tax, employment or legal questions.

Contact

Privacy contact: support@fejlgoblin.ovh Support: support@fejlgoblin.ovh

Sources used when drafting

These documents were drafted after reviewing the repository FerretLord68/timereg.fejlgoblin.ovh and the owner instructions. Official reference sources that should be rechecked during final legal review:

  • European Data Protection Board, SME guide: data protection basics, individual rights, security and data breaches.
  • European Data Protection Board, Guidelines 05/2020 on consent under Regulation 2016/679.
  • Digitaliseringsstyrelsen, Danish cookie guidance, last updated 16 May 2025.
  • Erhvervsstyrelsen, cookie information and reference to Digitaliseringsstyrelsen’s cookie guidance.

The documents do not copy generic templates. They are written specifically for the reviewed code and owner context.

Providers and transfers

Active launch decisions:

CategoryChoice
HostingSelf-hosted server in Denmark / EU/EEA
DatabaseSelf-hosted in the same Danish/EU/EEA operating environment
Email/SMTPOVH / Zimbra
BackupEncrypted backups on another self-hosted server, preferably Denmark/EU/EEA
DNSOVHcloud
TLSLet’s Encrypt
Reverse proxy/CDNNo external reverse proxy/CDN for the production app
Monitoring/loggingLocal server logs
Error reportingNo external error reporting in v1
PaymentsNo payments at launch; future donations require an update

Final provider agreements, DPA status and regions must be checked before public launch.

Terms Privacy Cookies Data rights GPS/IP Disclaimer Contact Subprocessors Security and retention