Skip to content
SchnurSolutions SchnurSolutions
DEENFRES
Back to website

Legal

Privacy policy

The German version is legally authoritative.

This page has not been released yet.

The following mandatory provider details are not on file yet. As long as they are missing, the go-live of these legal pages is refused; no placeholder and no default value is shown on purpose.

Mandatory details on file: 0 / 11

  • Company name
  • Street and number
  • Postal code
  • City
  • Country of registered office
  • Email address
  • Phone number
  • VAT identification number
  • Responsible for the content
  • Legal basis of the provider identification
  • Applicable law (Terms)

Controller

Company name: not provided yet
Street and number: not provided yet
Postal code: not provided yet City: not provided yet Country of registered office: not provided yet
Email: not provided yet

What data we process

Account: Email address, first and last name, company and VAT identification number (mandatory — SchnurPlan is aimed at businesses), postal address (street, house number, postal code, city, country), phone number, password (stored only as an Argon2id hash), sign-in timestamps. Legal basis: performance of contract (Art. 6(1)(b) GDPR).

Sessions: Five technically necessary cookies, nothing more. Your login is held by the session cookie (sp_session, HttpOnly, 30 days). In addition there are sp_lang (the chosen page language, one year), sp_pending and sp_signup_email (waiting for the confirmation of your e-mail address, 24 hours each, HttpOnly) and sp_active_org (the organisation chosen last, one year, HttpOnly). No tracking, no advertising cookies, no analytics services.

Payment: Processing via Stripe Payments Europe Ltd. We do not store card data; Stripe receives the details required for the payment. Legal basis: performance of contract. Details: stripe.com/de/privacy.

License check: When signing in and checking the license, the desktop app transmits the account identifier, a device identifier and the app version. This is required to unlock the license automatically and to enforce the device limit (Art. 6(1)(b) and (f) GDPR).

Project synchronization (optional): If the customer uses server-based synchronization, project data is stored encrypted on servers operated by us and synchronized between the organization’s devices. Processing takes place as data processing on behalf of the controller under Art. 28 GDPR; without this feature, project data remains exclusively local with the customer. Legal basis: performance of contract (Art. 6(1)(b) GDPR).

Server logs & security: IP addresses in audit logs (sign-in attempts, downloads) to prevent abuse, retained for not provided yet. Delivery via Cloudflare (proxy/CDN); for technical reasons Cloudflare processes IP addresses in doing so.

Data from the app at work

If a company uses the app to record the attendance of its staff, the company as the employer decides on the purpose and the scope of that processing; it is the controller for it. We process this data on its behalf (processing on behalf of the controller, Art. 28 GDPR). Questions about purpose, scope and retention are answered by the company.

Attendance and working time: Time of clocking in and out, recorded breaks, the assigned site or project, the working times derived from them (target, actual, difference), absences, and correction requests with their reason.

Location: If the company uses location, the device transmits latitude and longitude when clocking, the accuracy of the location, the distance to the assigned site and the resulting verdict (inside or outside the area). Without the location permission on the device no location is transmitted; the company can additionally tie location to a consent.

Device and sign-in: A device id, device and browser details, the app version and the raw message sent by the device. Signing in additionally creates audit entries with IP address, country and city, device and browser identification.

Photos and documents: Files uploaded to a project — site photos, plans and attachments, for example — are stored encrypted on our servers and are only delivered to authorized members of the organization. A photo can show a place, a time and people.

Messages, calendar, notices: Chat messages including attachments and read state, calendar entries with participants and reminders, and notices to the members of the organization.

Notifications: If someone turns on push notifications in the app, we store the address of the notification service of their browser or device, two associated keys, the platform and the device identifier. The notification itself is delivered through the service of the browser or device manufacturer. It can be switched off in the app at any time.

Consent and signature: If the company requires a consent, the signature as an image, the signed text, the time, the IP address and the browser identification are stored. The consent can be withdrawn in the app; the record of the earlier signature remains as evidence.

In the app, the self-disclosure shows the stored attendance data — clock entries, working times, corrections, consent status and retention period — and exports them as a file. For messages, calendar entries, uploaded files and sign-in logs, please contact the company. The company decides on the deletion of this data — not least because working times can be subject to statutory retention obligations. Employees therefore address deletion requests to their company; we carry them out on its behalf.

Recipients

Stripe (payments), Cloudflare (DNS/proxy/Turnstile bot protection, R2 download storage), the notification service of the respective browser or device manufacturer (only if push notifications are switched on), not provided yet.

Retention

Account data until the account is deleted; invoice data according to statutory retention obligations (10 years); audit logs not provided yet.

Your rights

Access, rectification, erasure, restriction, data portability, objection (Art. 15 to 21 GDPR) and complaint to a supervisory authority. Requests to: not provided yet. An export of your account data is available on request at any time.

SchnurSolutions
Legal notice Privacy Terms Support: not provided yet

© 2026 not provided yet · SchnurPlan