Datenschutzerklärung — Turnia
Stand: [Datum einfügen]
1. Verantwortlicher
[Dein vollständiger Name / Firmenname]
[Straße, Hausnummer]
[PLZ, Ort]
Deutschland
E-Mail: [deine E-Mail-Adresse]
2. Grundprinzip: standardmäßig nur lokal
Turnia speichert alles, was du einträgst, standardmäßig ausschließlich lokal auf deinem Gerät (im „localStorage" deines Browsers). Ohne weiteres Zutun werden keine Daten an einen Server übertragen und beim Öffnen der App wird keine Verbindung zu Google-Diensten aufgebaut.
Turnia enthält keine Analyse- oder Trackingtools (auch kein Firebase Analytics / Google Analytics), keine Werbung und keine Marketing-Cookies.
3. Lokal gespeicherte Daten
- Arbeitszeiten (Datum, Beginn, Ende, Pausen), Notizen und Schlagwörter (#Tags)
- Von dir angelegte Jobs/Arbeitgeber, Stundenlohn und Zuschläge
- Markierungen zu Arbeitsunfähigkeit/Krankschreibung (Gesundheitsdaten, Art. 9 DSGVO)
- Einstellungen (Soll-Stunden, Rundung, Urlaubstage)
- Optionale steuerliche Angaben (Steuerklasse, Kinderfreibeträge, Krankenkasse/Bundesland) — rein informativ, für keine Berechnung der App nötig, werden nie synchronisiert
4. Optionale Synchronisierung zwischen Geräten
Du kannst in den Einstellungen freiwillig ein Konto anlegen und die Synchronisierung aktivieren. Erst dann gilt Folgendes:
- Konto: E-Mail-Adresse und Passwort (Firebase Authentication). Das Passwort speichert Google nur in geschützter Form; wir sehen es nicht.
- Synchronisierte Daten: Jobs, Arbeitszeiten inkl. Notizen und Krankschreibungs-Markierungen sowie die Einstellungen aus Punkt 3. Nicht synchronisiert werden die steuerlichen Angaben.
- Speicherort/Dienstleister: Google Firebase (Authentication und Cloud Firestore), betrieben von Google Cloud EMEA Limited bzw. Google Ireland Limited; Datenbank-Standort: [Region einfügen, z. B. eur3 (EU) oder europe-west3 (Frankfurt)]. Mit Google besteht eine Auftragsverarbeitung nach Art. 28 DSGVO. Eine Übermittlung in Drittländer (z. B. USA) kann nicht ausgeschlossen werden; sie wird nach Angaben von Google durch EU-Standardvertragsklauseln bzw. ein Angemessenheitsbeschluss abgesichert.
- Zugriff: Die Daten sind per Sicherheitsregeln so geschützt, dass nur dein Konto sie lesen und ändern kann. Als Betreiber des Firebase-Projekts haben wir technisch Zugriff über die Firebase-Konsole; diesen nutzen wir ausschließlich für Betrieb und Fehlerbehebung.
- Bei der Anmeldung verarbeitet Google technisch notwendige Verbindungsdaten (z. B. IP-Adresse) zur Sicherheit und Bereitstellung des Dienstes.
5. Rechtsgrundlagen
- Konto und Synchronisierung: Art. 6 Abs. 1 lit. b DSGVO (Bereitstellung der von dir gewünschten Funktion).
- Gesundheitsdaten (Krankschreibungs-Markierungen): ausdrückliche Einwilligung, Art. 9 Abs. 2 lit. a DSGVO, die du per Häkchen vor der Kontoerstellung/Anmeldung erteilst. Du kannst sie jederzeit mit Wirkung für die Zukunft widerrufen, indem du dein Konto löschst.
- Hosting der Web-App (Server-Logdaten): Art. 6 Abs. 1 lit. f DSGVO (sicherer und stabiler Betrieb).
6. Speicherdauer und Löschung
- Lokale Daten bleiben, bis du sie löschst: einzelne Einträge über „✕“, alles über Einstellungen → „Alle Daten löschen“ oder über die Browser-/App-Daten deines Geräts.
- Cloud-Daten bleiben bis zur Löschung deines Kontos. In Einstellungen → Synchronisierung → „Konto und Cloud-Daten löschen“ entfernst du Konto und alle Cloud-Daten dauerhaft; die lokale Kopie bleibt erhalten. Achtung: „Alle Daten löschen“ löscht bei aktiver Synchronisierung auch die Cloud-Daten.
- Nach dem Abmelden bleiben die Daten auf dem Gerät; in der Cloud bleiben sie bis zur Kontolöschung.
7. Weitergabe an Dritte
Außer an die oben genannten Dienstleister (Google für die optionale Synchronisierung, Hosting-Anbieter) erfolgt keine Weitergabe deiner Daten.
8. Deine Rechte
Du hast das Recht auf Auskunft, Berichtigung, Löschung, Einschränkung der Verarbeitung, Datenübertragbarkeit (Export als JSON/CSV/Excel in der App) und Widerspruch sowie das Recht, dich bei einer Datenschutzaufsichtsbehörde zu beschweren. Wende dich dazu an die oben genannte E-Mail-Adresse.
9. Turnia Pro (Zahlungen)
Wenn du Turnia Pro kaufst, wird die Zahlung von Stripe (Stripe Payments Europe, Ltd.) abgewickelt. Deine Zahlungsdaten (Kartennummer usw.) werden direkt von Stripe verarbeitet — sie erreichen niemals unsere Server. Wir erhalten von Stripe nur die Bestätigung, dass die Zahlung erfolgreich war, sowie eine interne Transaktions-ID, um „pro: true" in deinem Konto zu aktivieren. Siehe die Datenschutzerklärung von Stripe: stripe.com/de/privacy.
10. Hosting der Web-App
Diese Web-App wird gehostet über [Vercel Inc. / Hosting-Anbieter einfügen]. Beim Aufruf verarbeitet der Hosting-Anbieter technisch notwendige Zugriffsdaten (z. B. IP-Adresse) zur Auslieferung der Seite. Details entnimmst du der Datenschutzerklärung des Anbieters.
Política de privacidad — Turnia
Última actualización: [fecha]
1. Responsable
[Tu nombre completo / nombre de la empresa]
[Calle, número]
[Código postal, ciudad]
Alemania
Correo: [tu correo de contacto]
2. Principio base: por defecto, solo en tu dispositivo
Turnia guarda todo lo que ingresas por defecto únicamente en tu propio dispositivo (en el "localStorage" del navegador). Sin que hagas nada más, no se envía ningún dato a un servidor y al abrir la app no se establece conexión con servicios de Google.
Turnia no incluye herramientas de análisis o rastreo (tampoco Firebase Analytics ni Google Analytics), no muestra publicidad y no usa cookies de marketing.
3. Datos guardados localmente
- Horarios de trabajo (fecha, inicio, fin, descansos), notas y etiquetas (#)
- Trabajos/empleadores que crees, salario por hora y recargos
- Marcas de incapacidad médica (dato de salud, Art. 9 RGPD)
- Preferencias (horas objetivo, redondeo, días de vacaciones)
- Datos fiscales opcionales (Steuerklasse, Kinderfreibeträge, caja de salud/estado federado): solo de referencia, ningún cálculo depende de ellos y nunca se sincronizan
4. Sincronización opcional entre dispositivos
En Ajustes puedes crear voluntariamente una cuenta y activar la sincronización. Solo entonces se aplica lo siguiente:
- Cuenta: correo y contraseña (Firebase Authentication). Google guarda la contraseña solo de forma protegida; nosotros no la vemos.
- Datos sincronizados: trabajos, jornadas con notas y marcas de incapacidad médica, y las preferencias del punto 3. No se sincronizan los datos fiscales.
- Ubicación y proveedor: Google Firebase (Authentication y Cloud Firestore), operado por Google Cloud EMEA Limited / Google Ireland Limited; ubicación de la base de datos: [indicar región, p. ej. eur3 (UE) o europe-west3 (Fráncfort)]. Existe un contrato de encargado de tratamiento con Google conforme al Art. 28 RGPD. No se puede excluir una transferencia a terceros países (p. ej. EE. UU.); según Google se ampara en cláusulas contractuales tipo de la UE o en una decisión de adecuación.
- Acceso: las reglas de seguridad permiten que solo tu cuenta lea y modifique tus datos. Como administrador del proyecto Firebase, técnicamente tenemos acceso desde la consola de Firebase; lo usamos únicamente para operación y solución de fallos.
- Al iniciar sesión, Google trata datos de conexión técnicamente necesarios (p. ej. la IP) por seguridad y para prestar el servicio.
5. Bases legales
- Cuenta y sincronización: Art. 6(1)(b) RGPD (prestar la función que solicitas).
- Datos de salud (marcas de incapacidad): consentimiento explícito, Art. 9(2)(a) RGPD, que otorgas marcando la casilla antes de crear la cuenta/iniciar sesión. Puedes revocarlo en cualquier momento, con efecto futuro, borrando tu cuenta.
- Alojamiento de la app web (registros del servidor): Art. 6(1)(f) RGPD (funcionamiento seguro y estable).
6. Conservación y eliminación
- Los datos locales permanecen hasta que los borres: registros individuales con "✕", todo desde Ajustes → "Borrar todos los datos", o borrando los datos del navegador/app.
- Los datos en la nube permanecen hasta que borres tu cuenta. En Ajustes → Sincronización → "Borrar cuenta y datos de la nube" eliminas de forma permanente la cuenta y todos los datos de la nube; la copia local se conserva. Ojo: con la sincronización activa, "Borrar todos los datos" también borra los datos de la nube.
- Al cerrar sesión, los datos siguen en el dispositivo; en la nube permanecen hasta que borres la cuenta.
7. Cesión a terceros
Salvo los proveedores mencionados (Google para la sincronización opcional y el proveedor de hosting), no se ceden tus datos.
8. Tus derechos
Tienes derecho de acceso, rectificación, supresión, limitación, portabilidad (exportación a JSON/CSV/Excel en la app) y oposición, así como a presentar una queja ante una autoridad de protección de datos. Escríbenos al correo indicado arriba.
9. Turnia Pro (pagos)
Si compras Turnia Pro, el pago lo procesa Stripe (Stripe Payments Europe, Ltd.). Tus datos de pago (número de tarjeta, etc.) los maneja Stripe directamente — nunca llegan a nuestros servidores. Nosotros solo recibimos de Stripe la confirmación de que el pago fue exitoso y un identificador interno de la transacción, para activar "pro: true" en tu cuenta. Consulta la política de privacidad de Stripe: stripe.com/es/privacy.
10. Alojamiento de la app web
Esta app web está alojada en [Vercel Inc. / proveedor de hosting]. Al visitarla, el proveedor procesa datos técnicos necesarios (p. ej. la IP) para entregar la página. Consulta su política de privacidad para más detalles.
Privacy Policy — Turnia
Last updated: [date]
1. Data controller
[Your full name / business name]
[Street, number]
[Postal code, city]
Germany
Email: [your contact email]
2. Core principle: local only by default
Turnia stores everything you enter by default only on your own device (in the browser's "localStorage"). Without further action, no data is sent to any server and opening the app makes no connection to Google services.
Turnia contains no analytics or tracking tools (including no Firebase Analytics / Google Analytics), no ads and no marketing cookies.
3. Data stored locally
- Work sessions (date, start, end, breaks), notes and hashtags (#)
- Jobs/employers you create, hourly wage and surcharges
- Sick-leave markers (health data, Art. 9 GDPR)
- Preferences (target hours, rounding, vacation days)
- Optional tax data (tax class, child allowances, health insurer/federal state): for reference only, no calculation depends on it, and it is never synced
4. Optional sync between devices
In Settings you can voluntarily create an account and turn on sync. Only then does the following apply:
- Account: email and password (Firebase Authentication). Google stores the password only in protected form; we cannot see it.
- Synced data: jobs, shifts including notes and sick-leave markers, and the preferences from section 3. Tax data is not synced.
- Location and provider: Google Firebase (Authentication and Cloud Firestore), operated by Google Cloud EMEA Limited / Google Ireland Limited; database location: [state region, e.g. eur3 (EU) or europe-west3 (Frankfurt)]. A data processing agreement under Art. 28 GDPR exists with Google. Transfers to third countries (e.g. the USA) cannot be ruled out; according to Google they are safeguarded by EU standard contractual clauses or an adequacy decision.
- Access: security rules ensure only your account can read and change your data. As administrator of the Firebase project we technically have access through the Firebase console; we use it solely for operation and troubleshooting.
- When you sign in, Google processes technically necessary connection data (e.g. IP address) for security and to provide the service.
5. Legal bases
- Account and sync: Art. 6(1)(b) GDPR (providing the function you request).
- Health data (sick-leave markers): explicit consent, Art. 9(2)(a) GDPR, which you give by ticking the box before creating the account/signing in. You can withdraw it at any time, with effect for the future, by deleting your account.
- Hosting of the web app (server logs): Art. 6(1)(f) GDPR (secure and stable operation).
6. Retention and deletion
- Local data stays until you delete it: single entries with "✕", everything via Settings → "Delete all data", or by clearing the browser/app data.
- Cloud data stays until you delete your account. In Settings → Sync → "Delete account and cloud data" you permanently remove the account and all cloud data; the local copy is kept. Note: with sync on, "Delete all data" also deletes the cloud data.
- After signing out, data stays on the device; in the cloud it stays until you delete the account.
7. Sharing with third parties
Apart from the providers named above (Google for the optional sync, the hosting provider), your data is not shared.
8. Your rights
You have the right of access, rectification, erasure, restriction, data portability (export as JSON/CSV/Excel in the app) and objection, and the right to lodge a complaint with a data protection authority. Contact us at the email above.
9. Turnia Pro (payments)
If you purchase Turnia Pro, the payment is processed by Stripe (Stripe Payments Europe, Ltd.). Your payment details (card number, etc.) are handled directly by Stripe — they never reach our servers. We only receive confirmation from Stripe that the payment succeeded, plus an internal transaction ID, to activate "pro: true" on your account. See Stripe's privacy policy: stripe.com/privacy.
10. Hosting of the web app
This web app is hosted on [Vercel Inc. / hosting provider]. When you visit it, the provider processes technically necessary access data (e.g. IP address) to deliver the page. See the provider's privacy policy for details.