Last updated: 27 September 2026

This notice informs you under Articles 13 and 14 GDPR how Alexander Funk u. Daniel Amzovski GbR processes personal data when you use the website jomawo.com, the application at my.jomawo.com or the related apps. Before an account is created, you must confirm that you have taken note of this notice. That happens together with acceptance of the terms, in one step. That confirmation is not consent. Where we need consent, we ask for it separately.

1. Controller

The controller under Article 4(7) GDPR for the processing described in this notice as our own is:

Alexander Funk u. Daniel Amzovski GbR
Widdersteinstraße 128
88400 Biberach an der Riß
Germany
Email: impressum@jomawo.com

No data protection officer is appointed. Send privacy requests to the address above.

2. Which role we have

We are controller where we decide the purposes ourselves. That covers in particular the website, account data, contract and payment, support, product notices, the referral programme, platform security and our own audience measurement. The same applies to content a private person stores only about themselves.

Content a business enters in TimeTracker is processed by us as a processor under Article 28 GDPR for the customer. That includes time entries, projects, client and employee data, absences and approvals, files, location data of travel-time calculation, online status and activity log inside the account, and voice or text inputs used only to carry out an operation the customer requested. That includes sole traders. For those data the customer is controller. The customer informs the people concerned. The contract is in section 3.2 of the terms.

3. Website and server logs

When you open the website, the server processes IP address, date and time, the address requested, referrer, the amount of data transferred and browser or device identifiers to the extent your browser sends them. Our legitimate interest is to deliver the page, keep it stable and prevent abuse. The legal basis is Article 6(1)(f) GDPR. We delete logs after 30 days unless we need them longer to investigate a specific security incident.

4. Account, contract and payment

For an account we process the details you provide at registration and in the contract, in particular name, email address, password in hashed form, plan, billing details and communications required to perform the contract. The legal basis is Article 6(1)(b) GDPR and, for tax and commercial-law duties, Article 6(1)(c) GDPR.

Card and SEPA direct debit are collected by Stripe Payments Europe, Limited, One Wilton Park, Wilton Place, Dublin 2, D02 FX04, Ireland. We receive the details needed to allocate the payment, such as a customer reference, payment status, amount and, where usual, a truncated account identifier. The full card or account number stays with Stripe. The legal basis is Article 6(1)(b) and (c) GDPR.

We keep account data for the term of the contract. Invoices and accounting records are kept for the statutory period, currently generally eight years, and annual financial statements for ten years (section 147 of the German Fiscal Code, section 257 of the German Commercial Code). We then delete or anonymise them.

We log acceptance of the terms, confirmation of this notice, consents and their changes with version and time so that we can evidence them. The legal basis is Article 6(1)(c) GDPR together with Articles 5(2) and 7(1) GDPR, and Article 6(1)(f) GDPR. Our legitimate interest is evidence and the defence of claims. We keep that log for the life of the account and then until the end of the regular limitation period of three years, counted from the end of the year in which the account ends.

5. Support and contact form

When you write to us, we process contact details, the content of the request and the technical transmission in order to answer it and to evidence the matter. The legal basis is Article 6(1)(b) GDPR where the matter concerns a contract or pre-contractual steps, otherwise Article 6(1)(f) GDPR. Our legitimate interest is then handling and evidencing the correspondence. We keep the matter for the time needed to handle it and then until the end of the regular limitation period of three years (section 195 of the German Civil Code), counted from the end of the year in which the matter was closed, unless a longer statutory duty applies.

We check the contact form with Cloudflare Turnstile in order to prevent automated abuse. The recipient is Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA. The processing covers technical signals of the request, in particular IP address, TLS characteristic and browser identifier, only to tell humans from bots. Cloudflare states that it cannot directly identify a person from those signals. That is required to provide the form you asked for. The legal basis is Article 6(1)(f) GDPR and, where information is processed on your device, section 25(2) no. 2 TDDDG. Where data is transferred to the United States in the course of that, the safeguards in section 12 apply.

6. Product notices

Notices without which the contract cannot be performed (for example outages, security, or changes to features or prices) are sent on the basis of Article 6(1)(b) GDPR.

Set-up and usage tips about your account, for example in the first days after registration or when you have not recorded anything for some time, are part of the service under section 2.1 of the terms. For that we process name, email address, language, registration date and the time of last use. The legal basis is Article 6(1)(b) GDPR. Every such email contains a link to unsubscribe. After that we send you no further tips of that kind.

We may email existing customers who have taken out a paid subscription about our own similar services. The legal basis is Article 6(1)(f) GDPR together with section 7(3) of the German Act Against Unfair Competition. We do so only if we pointed out the right to object when we collected the email address. Every such message contains a way to object, via the link in the email or at the address above. If that notice was missing when we collected the address, we do not send the message. That sending ends when the paid contract ends. Any other advertising is sent only with consent under Article 6(1)(a) GDPR and section 7(2) of that Act.

7. Content in the application

Time entries, projects, clients, employees, comments, files and similar content data of a business are processed only to provide TimeTracker, to back it up and to export it on request. The legal basis towards the customer is the contract, Article 6(1)(b) GDPR, and towards the people whose data the customer enters, the customer’s instruction as controller, Article 28 GDPR.

We do not use this content to train general models of our own or of third parties, and we do not sell it. We may improve suggestions for the same account under section 8. Use for general models happens only where the customer expressly releases model improvement under section 8 and the person concerned agrees themselves.

If you open a view in which an address can be searched or a route calculated, such as the dialog of a time entry or the address details in the profile, the application loads Google Maps. The IP address is transmitted at that point. The address you enter is transmitted only when you search or start the calculation. If you tap the location icon next to the starting address, your device asks for your permission and then passes your current location as the starting point; it is transmitted with the calculation. The recipient is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google may use Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA, for that. The legal basis is Article 6(1)(b) GDPR where you use the function for yourself, and Article 28 GDPR where a business enters a third party’s address. For the United States the safeguards in section 12 apply.

8. AI features

If your plan includes an AI feature and you invoke it, for example voice input or the assistant, we process the input (including voice and transcript) and the master data needed to carry out that specific request, such as proposing a time entry. By invoking the feature you instruct us to process that content for that request and, where a provider is required, to transmit it to that provider. The provider is bound as a processor. We oblige it not to use the content to train its models.

The legal basis for performing the feature is Article 6(1)(b) GDPR and, where third-party data is affected, Article 28 GDPR. No additional consent is required for that. The output is a suggestion. You review time entries before using them for billing, payroll or tax.

After registration a set-up assistant may propose features, clients and projects, also in the free plan. For that we transmit team size, where given the company name, your description of your work and, if you name a website, its publicly accessible text to the AI provider. We retrieve the website once for that purpose. You see every proposal before anything is created. Legal basis and roles follow the previous paragraphs.

If you install and start the desktop AI tracker, it records on your device the program name and window title of the active window, whether there has been input since the last analysis (no keystrokes and no content) and, only if you switch on text recognition, an extract of the visible screen text recognised on the device. Excluded programs and keywords are skipped or masked before transmission; incognito mode stops recording. The log goes to us and to the AI provider in order to propose or create time entries. The log is kept no longer than the voice or text input of a single request, and in any case no longer than 90 days. Legal basis and roles follow the previous paragraphs. If your employer or principal uses the AI tracker, it is the controller for it.

Unless model improvement is switched on, we do not keep the voice or text input of a single request longer than needed to perform it, for a short error analysis of that request and for statutory duties, and in any case no longer than 90 days. We do not compile it into a general training set. If model improvement is switched on, that period does not run for stored training examples; they are deleted within 30 days after withdrawal as described below.

From the content of the account and from corrections to suggestions we may improve later suggestions only for the same account. We keep that data for the term of the contract and delete it with the other content data. Other customers and general models do not receive it. No additional consent is required. The legal basis is Article 6(1)(b) GDPR and, where third-party data is affected, Article 28 GDPR.

General models only with release and your own consent

Training of general models takes place only if the customer for whom you use TimeTracker has released model improvement in the account and you have agreed yourself. Only your own inputs, outputs, corrections and ratings from AI features are used. Both are off by default, voluntary and not a condition of the account, the contract or the AI feature. We are the controller for this training.

The legal basis for your data is your consent under Article 6(1)(a) GDPR. You give it to us yourself; your employer or principal cannot give it on your behalf. Where your inputs contain third-party data, such as names of clients or contact persons, the legal basis for that data is our legitimate interest in better AI features under Article 6(1)(f) GDPR, based on the customer’s release. Data subjects may object under Article 21 GDPR.

You may withdraw your consent, and the customer its release, at any time with effect for the future in the settings. From withdrawal we do not use the affected content for further training of general models and we delete the affected stored training examples within 30 days unless a statutory duty requires otherwise. Weights already absorbed into a model cannot be removed.

Independently of that, we may use aggregated and irreversibly anonymised statistics and technical operations data (such as feature calls, error messages, plan and approximate time) to operate, secure and develop the service. That does not include time entries, voice recordings or client or employee data. Our legitimate interest is a secure and working service. The legal basis is Article 6(1)(f) GDPR. You may object to this use on grounds relating to your particular situation, insofar as it is not required to provide the service. We then stop, unless we can demonstrate compelling legitimate grounds.

9. Referral programme

If you arrive via a referral link, the referral code is in the address as the parameter “ref”. So that the code reaches registration, we remember it for this browser tab until you close the tab, and we add it to the links of that visit, including the registration link. That is required to attribute the referral you opened, section 25(2) no. 2 TDDDG. The legal basis of the attribution is Article 6(1)(b) GDPR where a referral programme exists with the referring customer, otherwise Article 6(1)(f) GDPR. Our legitimate interest is running the programme. Without the code on the registration, no attribution takes place. The referring customer sees the abbreviated name, registration date and plan of the referred account, and no contact details.

For referring customers we process balance, credited and reversed commissions, payout requests including account holder, IBAN and BIC, and a log of status changes. Operating the programme and the payout is based on Article 6(1)(b) GDPR. Abuse checks, including supporting automatic signals, are based on Article 6(1)(f) GDPR. Our legitimate interest is protecting the programme against abuse. A decision on a payout is not made solely by an automated system. You may request review by a person. Bank details are passed only to the bank executing the transfer. Payout records are kept for the statutory retention periods.

10. Cookies and audience measurement

Information that is technically required for the website, or for a setting you expressly request, is stored without consent (section 25(2) TDDDG). Details are in the cookie policy.

On the website we use Google Analytics only if you accept all cookies in the cookie notice. In the application we use Google Analytics and Google Ads conversion tracking only if you switch on the “Analytics and improvement” setting there. Conversion tracking measures whether a visit through one of our ads led to a registration or booking. It is voluntary and not preselected. The measurement is not anonymous: an online identifier is processed and, if you are signed in, an account reference. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, with the involvement of Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. Processing includes, among other things, an online identifier, pages visited, approximate origin and device information. The purpose is analysing use, measuring the success of our ads and improving Jomawo. The legal basis is your consent, Article 6(1)(a) GDPR and section 25(1) TDDDG. Storage in Google Analytics does not exceed 14 months. You may withdraw consent at any time in the cookie settings, without affecting the lawfulness of processing before withdrawal. For the United States the safeguards in section 12 apply.

We do not currently set marketing cookies on the website. In the application the previous paragraph applies.

11. Recipients

Recipients are the parties that process data for us or receive it on their own legal basis:

  • Hosting and email providers of the website and the application. We name them on request.
  • Stripe Payments Europe, Limited, One Wilton Park, Wilton Place, Dublin 2, D02 FX04, Ireland, for card and SEPA
  • OpenAI Ireland Ltd., 1st Floor, The Liffey Trust Centre, 117–126 Sheriff Street Upper, Dublin 1, Ireland, for the AI features in TimeTracker, where you use them or have switched on model improvement. OpenAI is contractually obliged not to use that content to train its models. Further processors of OpenAI, including Microsoft, may be involved.
  • SpaceXAI LLC (xAI), 800 W Cesar Chavez St., Austin, TX 78701, USA, for the AI features in TimeTracker, where you use them or have switched on model improvement. xAI is contractually obliged not to use that content to train its models.
  • Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, and Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. Google Analytics on the website only after your consent in the cookie notice, and Google Analytics and Google Ads conversion tracking in the application only if audience measurement is switched on. Google Maps when you open an input for an address or a route; the address itself only when you search or start the calculation. Google Gemini for the AI features in TimeTracker, where you use them or have switched on model improvement. Google is contractually obliged not to use that AI content to train its models.
  • Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA, for bot protection of the contact form. The processing covers technical signals of the request. Where data is transferred to the United States in the course of that, the safeguards in section 12 apply
  • Stripe may use further parties under its own contract in order to carry out the payment. The recipient towards us remains Stripe Payments Europe, Limited
  • Tax advisers, lawyers, courts, banks for payouts under the referral programme, and authorities where a statutory duty or the defence of a claim requires it

Processors are bound by a contract under Article 28 GDPR. We announce a change as the terms of service provide. Data is not disclosed for third parties’ own advertising.

12. Third countries

Where a provider is located outside the European Economic Area, we transfer data only if there is an adequacy decision under Article 45 GDPR or appropriate safeguards under Article 46 GDPR, in particular standard contractual clauses. At present that concerns processing by Google LLC, Cloudflare, Inc., further processors of OpenAI outside the European Economic Area, and SpaceXAI LLC (xAI), in each case only to the extent described in section 11. Google Ireland Limited and OpenAI Ireland Ltd. are established in the European Economic Area. For the United States there is an adequacy decision (EU-US Data Privacy Framework) where the recipient is certified under it. If it ceases to apply, we use standard contractual clauses. A copy of the safeguards is available on request at the address above.

13. Whether you must provide data

Name and email address are required for the contract. Without them we cannot open an account. All other details, consent to Google Analytics on the website, audience measurement in the application, and release of and consent to model improvement are voluntary. If you omit them, only the function concerned is unavailable. Confirming that you have taken note of this notice is required for the account and is done together with acceptance of the terms. Without it we do not open an account. It is not consent and not a legal basis. Taking it back does not affect processing that rests on the contract, a statutory duty or a legitimate interest.

14. Automated decisions

No decision based solely on automated processing which produces legal effects or similarly significantly affects you under Article 22 GDPR takes place. Automatic checks in the referral programme only prepare a decision.

15. Your rights

Towards us as controller you have the right to:

  • access, Article 15 GDPR
  • rectification, Article 16 GDPR
  • erasure, Article 17 GDPR
  • restriction of processing, Article 18 GDPR
  • data portability, Article 20 GDPR
  • object to processing based on Article 6(1)(f) GDPR, Article 21 GDPR, on grounds relating to your particular situation
  • withdraw consent with effect for the future, Article 7(3) GDPR

You terminate the contract through the cancellation function in the account. An email is not a termination unless the terms exceptionally allow text form. You exercise data-subject rights at the address above. We comply with an objection to processing under Article 6(1)(f) GDPR unless we can demonstrate compelling legitimate grounds or the processing is for the establishment of legal claims. You may object to advertising at any time without giving a particular reason.

If we have reasonable doubts about your identity, we may ask for additional information before we answer (Article 12(6) GDPR). We preferably answer to the email address of the account. For manifestly unfounded or excessive requests, in particular because of their repetitive character, we may charge a reasonable fee or refuse to act (Article 12(5) GDPR). Access or a copy must not adversely affect the rights and freedoms of others, including trade secrets (Article 15(4) GDPR).

Statutory retention and copies in current backups can stand in the way of immediate erasure. We overwrite backups in the ordinary cycle. Rights in content for which your employer or client is controller should be exercised there first. If someone directs such a right to us, we pass it to the customer and assist the customer.

You may lodge a complaint with a supervisory authority, in particular the authority responsible for us:

Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg
Lautenschlagerstraße 20
70173 Stuttgart
Germany
www.baden-wuerttemberg.datenschutz.de

16. Changes

If a processing activity changes, we update this notice and its date. Material changes are additionally shown to customers who have an account. A change does not silently expand the extent to which content is used for AI training.