Legal
Privacy policy
In short: we host in Germany, use no tracking tools, and process only what is necessary to run Certondo.
Note: this page still contains placeholders and will be completed before publication.
1. Controller
The controller for data processing on certondo.com and app.certondo.com is FM Holding GmbH, TODO Straße und Hausnummer, TODO PLZ TODO Ort, Österreich. Privacy requests: TODO Datenschutz-E-Mail (z. B. datenschutz@certondo.com).
2. Hosting and infrastructure
Certondo runs on servers of Hetzner Online GmbH (Industriestr. 25, 91710 Gunzenhausen, Deutschland) in Nürnberg, Deutschland. A data processing agreement under Art. 28 GDPR is in place with Hetzner. When you access the website, technically necessary connection data (IP address, time, page requested, browser) is processed in server logs to ensure operation. The legal basis is Art. 6(1)(f) GDPR.
Database backups are created automatically every day and additionally transferred to a cloud storage (Google Drive, Google Ireland Limited). The transfer is based on the EU standard contractual clauses.
3. Cookies
Website and app use only technically necessary cookies: a session cookie for logging in to the app and a cookie storing your chosen website language. No tracking, analytics, or advertising cookies are used.
4. Registration and use of the app
During registration we process company name, first and last name, email address, and a password of your choice (stored only as a hash). In the app we process the data your organization enters for time tracking: employee master data, working hours, breaks, absences, leave quotas, target hours, and the evaluations calculated from them.
For your employees’ data you, as the employer, are the controller under GDPR; we process it as a processor under Art. 28 GDPR. A data processing agreement is available on request. The legal basis for contract performance is Art. 6(1)(b) GDPR.
5. Email delivery
Transactional emails (invitations, password resets, confirmations, booking confirmations) are sent via Google Workspace (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland). The recipient address and the content of the respective message are processed.
6. Demo requests and bookings
When you request or book a demo, we process name, company, email address, optionally phone number, team size, and your message in order to arrange and hold the appointment. Booked appointments are entered in our Google Calendar (Google Workspace); you receive a calendar invitation with a Google Meet link. The legal basis is Art. 6(1)(b) GDPR (pre-contractual measures). The data is deleted after the demo phase, at the latest after twelve months if no contract is concluded.
7. Payment processing
Paid plans are billed via Stripe Payments Europe Ltd. (1 Grand Canal Street Lower, Dublin 2, Ireland). Payment data is collected directly by Stripe; we do not store full card details. The legal basis is Art. 6(1)(b) GDPR.
8. Retention
We store your organization’s data for the duration of use. After termination of the contract it is deleted within 90 days unless statutory retention obligations apply. You can export your data to Excel at any time.
9. Your rights
You have the right to access, rectification, erasure, restriction of processing, data portability, and objection. Please contact TODO Datenschutz-E-Mail (z. B. datenschutz@certondo.com). You also have the right to lodge a complaint with a supervisory authority; in Austria this is the Datenschutzbehörde, Barichgasse 40–42, 1030 Vienna.
10. Security
All connections to Certondo are TLS encrypted. Passwords are stored only as hashes. Data access is separated per organization and restricted by role.
Last updated: 2026-09-11
