Privacy for apps
1. Scope
This privacy policy applies to digital applications (apps) and related online services of werk2 UG (haftungsbeschränkt) that expressly refer to this policy or incorporate it as a basis.
Product-specific privacy policies (e.g. Evenly, PetRoutine) supplement this baseline where they describe different or additional processing. In the event of a conflict, the product-specific information for the respective app takes precedence.
LocalLoop is subject to its own privacy policy at /apps/localloop/privacy.html and is not covered by this document.
For the company website werk2.group, the separate policy at /datenschutz.html applies.
2. Controller
werk2 UG (haftungsbeschränkt)
Von-Schildeck-Str. 15
36043 Fulda
Germany
Email: info@werk2.group
Commercial register: Amtsgericht Fulda, HRB 9279
No data protection officer has been appointed. Please send privacy enquiries to the email address above.
3. Definitions
The terms used (e.g. “personal data”, “processing”, “controller”) correspond to Art. 4 GDPR.
4. Data we process
Depending on the app and use, the following categories may be processed — only insofar as they actually arise for the specific app:
- Account and identification data — e.g. email address, display name, authentication data (including hashes of access secrets or tokens of the auth service), account ID
- User content — content you create or enter in the app (e.g. tasks, plans, labels, settings, invitation/sharing codes)
- Usage and device data — e.g. app version, operating system/device information, timestamps of sign-in and synchronisation, technical logs for error diagnosis and security
- Push and notification data — e.g. device push token, if you allow notifications
- Payment and subscription status — e.g. information about subscription or purchase status where paid features are used; payment processing itself is handled by the respective app store
- Support communication — content of your enquiries to info@werk2.group
The specific allocation per app is set out in the product-specific privacy policy of the respective app.
5. Purposes and legal bases
- Providing and operating the app (performance of contract) — Art. 6(1)(b) GDPR
- Account, authentication, synchronisation, support — Art. 6(1)(b) GDPR
- Security, abuse prevention, error diagnosis (legitimate interest) — Art. 6(1)(f) GDPR
- Optional push notifications — consent, Art. 6(1)(a) GDPR in conjunction with the requirements of the respective operating system; withdrawal at any time via device settings or in the app where provided
- Processing paid services via app stores — Art. 6(1)(b) GDPR; store providers process payment data under their own responsibility according to their terms
- Compliance with legal obligations (e.g. retention) — Art. 6(1)(c) GDPR
6. Obligation to provide data
Use of account-based features requires the necessary account data. Without this data we cannot perform the contract for the app. Purely optional information is marked as such.
7. Recipients and processors
Personal data is disclosed to recipients only where necessary for the stated purposes, where you have consented, or where a legal basis exists. Typical recipient categories:
- Hosting, database, and authentication service providers (processors)
- Push delivery providers (where push is used)
- Apple Inc. or Google LLC in connection with app store purchases and subscriptions
- IT, support, and communication service providers, where engaged
Contracts pursuant to Art. 28 GDPR exist with processors. The product-specific privacy policy names the service providers actually used for the respective app.
8. Transfers to third countries
Where service providers process data outside the European Economic Area, this occurs only where an adequacy decision (Art. 45 GDPR) or appropriate safeguards (in particular standard contractual clauses under Art. 46 GDPR) or another legal basis exist. Details are set out in the product-specific policy.
9. Retention
We store personal data only as long as necessary for the stated purposes or as required by statutory retention obligations. After deletion or termination of the account, we remove associated app data unless retention or evidentiary obligations prevent this. Support correspondence may be retained for the duration of handling and thereafter within the scope of legitimate interests or statutory periods.
10. Security
We take appropriate technical and organisational measures to protect personal data (Art. 32 GDPR). Absolute security cannot be guaranteed for internet transmissions.
11. No automated decision-making
No automated decision-making including profiling within the meaning of Art. 22 GDPR takes place that produces legal effects concerning you or similarly significantly affects you.
12. Children and young people
Our apps are not directed at children under 16 years of age. We do not knowingly collect personal data from persons under 16. If such data becomes known to us, we delete it without delay.
13. Your rights
Under the GDPR — where the conditions are met — you have the right to:
- Access (Art. 15 GDPR)
- Rectification (Art. 16 GDPR)
- Erasure (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Object to processing based on Art. 6(1)(f) GDPR (Art. 21 GDPR)
- Withdraw consents given with effect for the future (Art. 7(3) GDPR)
To exercise your rights, a message to info@werk2.group is sufficient.
You also have the right to lodge a complaint with a data protection supervisory authority. Competent among others is the Hessian Commissioner for Data Protection and Freedom of Information (HBDI), Gustav-Stresemann-Ring 1, 65189 Wiesbaden, datenschutz.hessen.de.
14. Changes
We update this policy when the legal situation, technology, or our apps change. The version published on this page with the date shown above is authoritative.
15. Contact
Privacy and other enquiries: info@werk2.group