Legal
Privacy Policy
Privacy Policy
Plain-language summary
Fejlgoblin Tidsregistrering is a personal time-registration and documentation tool. The app processes account, time, work, estimate, tax-estimate, export, security and optional GPS/IP-related data so users can keep their own work records.
The app is not an employer system, payroll provider, tax authority, union, accountant, lawyer, public authority or court. Time records, GPS, IP addresses, notes and exports can help with documentation, but they do not guarantee legal proof, correct pay, correct tax or any specific outcome.
Controller
Controller: Frederik Juul Olsen Operating model: personal operation / no CVR number at launch Contact: support@fejlgoblin.ovh Replies normally sent from: admin@fejlgoblin.ovh Contact address or contact method: physical address is not published unless legally required or provided after a relevant lawful request. Use support@fejlgoblin.ovh. App: Fejlgoblin Tidsregistrering Domain: https://time.fejlgoblin.ovh
If the app is later operated through a company, or if a CVR number is created, this document, the terms, contact information and subprocessor list must be updated before the changed operation is used publicly.
What data does the app process?
| Category | Examples | Required or optional | Purpose | Preliminary legal basis | Retention |
|---|---|---|---|---|---|
| Account | Name, email, language, timezone, password hash, preferences | Required for account; many preferences optional | Account, login, display, support, security | Contract/service necessity and legitimate security interests | Until account deletion |
| Security and sessions | Sessions, login/session IP, user agent, rate-limit hashes, MFA data | Automatic | Login, abuse protection, session review and security | Legitimate interests and service necessity | Short technical periods; otherwise until account deletion |
| Time records | Clock-in/out, start/end, breaks, manual records, job, category | Core app data | Personal work record | Contract/service necessity | Until account deletion or user-controlled deletion |
| Notes | Work notes, categories, manual reasons | Optional except some manual edits | User documentation | Contract/service necessity | With the time record |
| GPS | Browser location, accuracy, collection time and GPS outcome, if recorded | Optional; app works without GPS | Extra context for user records | Optional browser permission/user choice and clear notice | Until account deletion or separate GPS deletion |
| Clock/security IP | Public IP or client IP and technical client metadata | Automatic, with clear information and opt-out/deletion where implemented | Security, abuse protection and context | Legitimate interests/security | Until account deletion or separate IP deletion |
| Pay/job data | Job name, currency, hourly/monthly pay, supplements, pension, overtime | Optional | Approximate pay reports/estimates | Contract/service necessity when enabled | Until account deletion or user-controlled deletion |
| Tax/municipality data | Municipality, church tax flag, tax values/overrides | Optional | Approximate Danish tax/net estimates | Contract/service necessity when enabled | Until account deletion or user-controlled deletion |
| Agreement data | Selected agreement template and user overrides | Optional | Estimate support and documentation | Contract/service necessity | Until account deletion or user-controlled deletion |
| Calculation snapshots | Saved estimate inputs/results | Optional | Historical estimate snapshots | Contract/service necessity | Until account deletion or user-controlled deletion |
| Export metadata | Format, period, whether GPS/IP was included, row count, file hash | Created when exporting | Export accountability/integrity | Legitimate interests/accountability and service | Metadata until account deletion; export bytes are not retained after download |
| Audit log | Account, security, export, correction and admin events | Automatic | Security, operations and accountability | Legitimate interests/accountability | Until account deletion; then personal details are deleted or anonymised |
| Recipient, subject/body for verification/reset, delivery metadata | Only if email delivery is enabled | Verification and password reset | Service/security necessity | OVH/Zimbra and app audit/token retention |
GPS and IP
GPS is off by default. The app may ask the browser for GPS only after a clear in-app notice, normally during first login or first clock-in/out. GPS is optional, and you can clock in and out without GPS.
The app must save the GPS outcome, not only coordinates. Possible outcomes are: gps_success, gps_disabled_by_user, gps_denied_by_browser, gps_unavailable, gps_timeout, gps_error and gps_deleted_by_user.
If GPS succeeds, the app may store exact coordinates, accuracy and collection time. Exact GPS coordinates are kept until account deletion, or until you delete/request deletion of GPS data. You must be able to delete GPS coordinates without deleting the time record itself. When GPS is deleted, the app should keep only a minimal non-identifying event, for example that GPS was deleted.
IP/client metadata is recorded automatically for security, abuse prevention and context. Users must receive clear information about this, and the app must provide opt-out/deletion where implemented. Exact IP addresses are kept until account deletion, or until you delete/request deletion of IP data. When deleted, the exact IP must be deleted completely unless a minimal anonymised security/audit reference is necessary.
GPS and IP are context data only. They do not by themselves prove where you were, that you worked, that you are entitled to payment, or that an authority, union, employer or court will accept the documentation.
Pay, tax and agreement estimates
All pay, tax, collective-agreement, pension, supplement and net-pay amounts are estimates only. They may be wrong, incomplete, outdated or based on information entered by you. The app does not provide payroll advice, tax advice, legal advice, accounting advice, union advice or binding calculations.
Sharing and recipients
The app does not sell personal data and is not intended for advertising tracking or targeted marketing.
Possible recipients/processors:
| Recipient | Purpose | Status |
|---|---|---|
| Self-hosted server | Hosting app and database | Owner decision applied — verify implementation before public launch |
| OVH / Zimbra | Verification/password-reset email | Owner decision applied — verify implementation before public launch |
| Encrypted backups on another self-hosted server | Backups | Owner decision applied — verify implementation before public launch |
| OVHcloud DNS and Let’s Encrypt TLS; no production reverse proxy/CDN provider | Traffic, TLS, DNS or proxy | Owner decision applied — verify implementation before public launch |
| See subprocessor list | See subprocessor list | Owner decision applied — verify implementation before public launch |
Data is not actively shared with employers, unions, statistics bodies or other third parties unless you export/share it yourself or a valid legal request requires it. Future anonymised/statistical sharing must not be activated without separate information and voluntary opt-in.
Transfers outside the EU/EEA
Owner decision applied — verify implementation before public launch — This depends on hosting, email, backup and support providers. If personal data is transferred outside the EU/EEA, the transfer basis, safeguards and providers must be described here.
Security
The code supports password hashing, CSRF protection, secure production sessions, rate limits, session inventory, optional MFA, audit logs, no-store export downloads and limited third-party scripts. No security measure can be guaranteed to prevent every incident.
Retention and deletion
You can delete your account through the account-deletion flow if enabled in production. Account deletion removes the account, time records, GPS/IP linked to clock events, job/pay/tax/agreement settings and export metadata from the active database, and redacts relevant audit details.
Backups may not be rewritten immediately. They must follow 12 months encrypted and must not restore deleted accounts into active use without reapplying deletion.
A separate feature for deleting only GPS/IP without deleting the whole account is planned/wanted but must not be described as active until implemented. Current method: Users must be able to delete exact GPS coordinates and exact IP/client metadata without deleting the time record. The app should keep only a minimal non-identifying outcome/deletion event where needed for integrity..
Your rights
Under GDPR, you may have rights of access, rectification, erasure, restriction, objection, portability and withdrawal of consent where processing is based on consent. These rights do not apply in the same way in every situation.
Contact support@fejlgoblin.ovh or use available self-service tools. A response should normally be provided within one month unless the request is complex or lawful extensions apply.
You can complain to the Danish Data Protection Agency (Datatilsynet). See contact-and-complaints-en.md.
Children and young users
The app may be relevant to apprentices. You must be at least 13 years old to use the app. If you are under 18, read the explanations carefully and ask a parent/guardian, union, employer or another relevant adult/adviser if you are unsure about pay, tax, employment or legal questions.
Contact
Privacy contact: support@fejlgoblin.ovh Support: support@fejlgoblin.ovh
Sources used when drafting
These documents were drafted after reviewing the repository FerretLord68/timereg.fejlgoblin.ovh and the owner instructions. Official reference sources that should be rechecked during final legal review:
- European Data Protection Board, SME guide: data protection basics, individual rights, security and data breaches.
- European Data Protection Board, Guidelines 05/2020 on consent under Regulation 2016/679.
- Digitaliseringsstyrelsen, Danish cookie guidance, last updated 16 May 2025.
- Erhvervsstyrelsen, cookie information and reference to Digitaliseringsstyrelsen’s cookie guidance.
The documents do not copy generic templates. They are written specifically for the reviewed code and owner context.
Providers and transfers
Active launch decisions:
| Category | Choice |
|---|---|
| Hosting | Self-hosted server in Denmark / EU/EEA |
| Database | Self-hosted in the same Danish/EU/EEA operating environment |
| Email/SMTP | OVH / Zimbra |
| Backup | Encrypted backups on another self-hosted server, preferably Denmark/EU/EEA |
| DNS | OVHcloud |
| TLS | Let’s Encrypt |
| Reverse proxy/CDN | No external reverse proxy/CDN for the production app |
| Monitoring/logging | Local server logs |
| Error reporting | No external error reporting in v1 |
| Payments | No payments at launch; future donations require an update |
Final provider agreements, DPA status and regions must be checked before public launch.