You are offline. New time records can only be saved when the connection returns.

Legal

Security and Data Retention

All documents Dansk
Version
owner-decision-draft-2026-07-07
Last updated
2026-07-07
Contact
support@fejlgoblin.ovh
SHA-256
2fcd8f855187b3d4477144a75480d5b97f64382d76c54032f15e154274e57a42

Security and Data Retention

Plain-language summary

The app includes several technical security measures, but no digital service is risk-free. Data is kept only as long as needed for its purposes or for periods decided and implemented by the owner.

Security measures found in code/documentation

  • password hashing with Argon2 as the primary hasher;
  • CSRF protection;
  • secure production cookies, HttpOnly sessions and SameSite protection;
  • rate limits for login, registration, password reset, MFA, export and more;
  • session rotation and session revocation;
  • optional TOTP MFA;
  • encrypted MFA secret based on the app secret;
  • no-store headers for export downloads and protected responses;
  • CSP and other security headers;
  • trusted-proxy client IP handling;
  • audit log and hash chain;
  • Docker/non-root and private PostgreSQL in the documented deployment;
  • encrypted backups in the documented operator process.

These measures reduce risk but cannot guarantee that data will never be lost, changed, leaked or unavailable.

Retention

DataRetentionStatus/action
Account and profileUntil account deletionDeleted during account deletion after 7-day grace period
Time records and notesUntil account deletion or user-controlled deletionUser data; export before deletion if it must be kept
Breaks and manual correctionsUntil account deletion or user-controlled deletionSame principle as time records
GPS coordinatesUntil account deletion or separate GPS deletionExact coordinates are deleted; a minimal non-identifying event may be kept
GPS outcome/statusUntil account deletion or user-controlled deletionMay show that GPS was denied, unavailable or deleted
IP/client metadataUntil account deletion or separate IP deletionExact IP is deleted completely on request/deletion unless a minimal anonymised audit reference is necessary
Pay, tax, job and agreement settingsUntil account deletion or user-controlled deletionDeleted with the account
Calculation snapshotsUntil account deletion or user-controlled deletionDeleted with the account
Export metadataUntil account deletionExport file bytes are not retained after download unless the app is later changed
Audit logUntil account deletion; then personal details are deleted or anonymisedAdmin/security events may require minimal anonymised logging
Email verification metadata30 daysExpired/used data is cleaned
Password reset metadata90 daysExpired/used data is cleaned
Inactive accountsWarn after 12 months; delete/anonymise after 24 monthsRequires cleanup/notice flow
Deleted accounts7-day grace period, then hard delete/anonymisationDeletion normally cannot be undone after grace period
Backups12 months, encryptedDeletion actions must be replayed after restore

Backups

Backups are kept encrypted for up to 12 months on another self-hosted server, preferably in Denmark/EU/EEA.

Backups may temporarily contain data that has been deleted or anonymised in the active database. If a backup is restored, deletion and anonymisation actions must be replayed so deleted data does not return to active operation.

Backup access must be limited to necessary administrators, and backup keys should be kept separate from backup files where practical.

Security incidents

If a personal data breach occurs, the owner must assess the risk, document the incident and, where required, notify Datatilsynet and/or affected users. An internal incident procedure should be created before public launch.

Contact

Security contact: support@fejlgoblin.ovh Replies may come from: admin@fejlgoblin.ovh

Terms Privacy Cookies Data rights GPS/IP Disclaimer Contact Subprocessors Security and retention