Privacy Policy

This Privacy Policy explains what types of personal data are collected, how they are used, and to what extent they are processed. The policy applies to all data processing activities related to this website and associated online presence, such as social media profiles.

1. Data Protection Measures

Traffic between your device and this service is encrypted in transit. Access to the database is limited to the operator named in section 8. Anonymous accounts and everything attached to them are deleted automatically as described in section 3.2, so data is not kept beyond the period it is needed for.

2. Data Collection, Processing, and Usage

2.1 Website Visitors

This website is accessible to all internet users, and when you visit this website (https://maestrotimer.com/), specific data is collected.

2.1.1 Server Log Files

Processed Data: When you visit this website, data related to your access of the servers hosting the website (referred to as server log files) is gathered. This access data includes the date and time of the request, the requested resource, the HTTP status code, the volume of data transferred, the referrer URL, browser type and version, operating system, and IP address.

Purpose: Delivering the website, ensuring stability and security, diagnosing faults, and defending against attacks.

Legal Basis: Art. 6(1)(f) GDPR – legitimate interest in a functioning and secure service.

Third-Party Service Providers: Cloudflare and Digital Ocean (see section 4.1) are used for hosting this website.

2.2 The Timer Application

The timer application is provided at https://app.maestrotimer.com/. When you open the application, an anonymous account is created automatically. It has no name, no email address, and no password, and you do not register. It consists of a randomly generated identifier.

Processed Data:

  • Account: a pseudonymous user identifier, the time of creation, and the time of last activity
  • Session: a session token, IP address, browser user agent, and expiry timestamps
  • Content you create

Purpose: Providing the service you requested, keeping your session attached to your data across requests, synchronising timers between operators and viewers, protecting sessions against hijacking and abuse, and enforcing rate limits.

Legal Basis: Art. 6(1)(b) GDPR for delivering the service you requested, and Art. 6(1)(f) GDPR for session integrity, abuse prevention, and rate limiting.

Third-Party Service Providers: Digital Ocean (see section 4.1) hosts the application servers and the database in which this data is stored.

2.3 Cookies and Local Storage

This service sets exactly one cookie: a session cookie that identifies your session and keeps your timers and rooms attached to your anonymous account between requests.

This cookie is strictly necessary to provide the service you have requested. Under § 165 TKG 2021 it therefore requires no consent, and no cookie banner is shown. It contains no tracking identifier and is not used to recognise you across other websites.

Deleting this cookie ends your session. Because anonymous accounts have no password, a deleted cookie cannot be restored, and the associated data will expire as described in section 3.2.

3. Data Retention Periods

3.1 Automatically Collected Data

Log Files and Usage Information are retained for up to 30 days.

3.2 Application Data

Anonymous accounts expire 90 days after your last activity. Every request that resolves your session moves this deadline forward. When an account expires, it is deleted together with all associated sessions, rooms, timers, messages, outputs, access records, and rate-limit entries.

3.3 Legal Claims

Data required for legal purposes, including defense against potential claims or pursuit of claims, will be stored as long as legally necessary.

4. Data Sharing Practices

Personal data is never sold, leased, or traded for monetary gains.

This website uses certain service providers to maintain its operations. These providers assist with website hosting, email services, and technical maintenance. All service providers are carefully selected and bound by data protection agreements.

4.1 Service Providers and Data Processing

Personal data may be shared with service providers who assist in website operations, technical maintenance, and communication functions.

Each service provider undergoes thorough vetting to ensure responsible data handling. This includes assessment of data sharing scope, security practices, external certifications, and privacy compliance.

Some service providers operate outside the European Economic Area (EEA). Data transfers outside the EEA follow appropriate legal safeguards. All service providers, regardless of location, must maintain strict data security standards in compliance with applicable regulations.

Digital Ocean

Address: DigitalOcean, LLC, 105 Edgeview Drive, Ste. 425, Broomfield, CO 80021, United States

Activity: Cloud Infrastructure

Transfer: To the United States. DigitalOcean is certified under the EU-U.S. Data Privacy Framework, which the European Commission has recognised as providing an adequate level of protection. The data processing agreement linked below applies the Standard Contractual Clauses should that certification end.

Website: https://www.digitalocean.com/

Privacy: https://www.digitalocean.com/legal/privacy-policy

DPA: https://www.digitalocean.com/legal/data-processing-agreement

Cloudflare

Address: Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107 USA

Activity: Cloud Infrastructure

Transfer: To the United States. Cloudflare is certified under the EU-U.S. Data Privacy Framework, which the European Commission has recognised as providing an adequate level of protection. The data processing agreement linked below applies the Standard Contractual Clauses should that certification end.

Website: https://www.cloudflare.com/

Privacy: https://www.cloudflare.com/en-gb/privacypolicy/

DPA: https://www.cloudflare.com/en-gb/cloudflare-customer-dpa/

Protonmail

Address: Proton AG, Route de la Galaise 32, 1228 Plan-les-Ouates, Geneva, Switzerland

Activity: Management of email addresses and email communication

Transfer: To Switzerland, which the European Commission has recognised as providing an adequate level of protection.

Website: https://proton.me/

Privacy: https://proton.me/legal/privacy

DPA: https://proton.me/legal/dpa

4.2 Data Sharing with Third Parties

Personal data may be shared with the following categories of third parties:

4.2.1 Disclosures with Your Permission

Your personal information may be shared with unaffiliated third parties not otherwise described in this Privacy Policy only with your explicit consent.

4.2.2 Legal Obligations and Rights

Personal data may be disclosed to comply with legal obligations, including sharing with attorneys, anti-money laundering bodies, tax consultants, auditors, banks, insurers, courts, and other parties involved in legal proceedings. Data may also be disclosed to protect legal rights, counter claims, or investigate potential illegal activities, suspected fraud, threats to individuals or property, or contract violations.

5. What are your data protection rights?

Under the provisions of the GDPR, you, as a data subject, have the following data protection rights:

  1. Right to be Informed: Data subjects have the right to know how their data will be used. This privacy policy provides clear and transparent information about data processing activities.
  1. Right of Access: Data subjects can ask data controllers to provide a copy of the personal data they hold about them. This is often referred to as a Subject Access Request (SAR).
  1. Right to Rectification: If personal data is inaccurate or incomplete, data subjects can ask for it to be corrected or completed.
  1. Right to Erasure (or 'Right to be Forgotten'): In certain circumstances, data subjects can ask for their personal data to be deleted. For instance, if the data is no longer necessary for the purpose it was collected or if the data subject withdraws their consent (provided there's no other legitimate reason to keep it).
  1. Right to Restrict Processing: Data subjects can request that processing of their personal data be restricted, which means the data can still be held but not used.
  1. Right to Data Portability: Data subjects have the right to receive their personal data in a structured, commonly-used and machine-readable format, and to transmit this data to another data controller without hindrance.
  1. Right to Object: Data subjects can object to their personal data being processed for direct marketing purposes, including profiling. They can also object to processing based on legitimate interests or the performance of a task in the public interest/exercise of official authority, and for research or statistical purposes.
  1. Right to Withdraw Consent: If processing is based on consent, data subjects can withdraw this consent at any time.
  1. Right to Lodge a Complaint: Data subjects have the right to lodge a complaint with a supervisory authority, particularly in the member state of their habitual residence, place of work, or place of the alleged infringement, if they believe that processing of their personal data infringes the GDPR.

6. Changes to Privacy Policy

This privacy policy may be updated periodically. Changes will be posted on this page, and significant changes will be announced with a prominent notice. Your consent will be requested for any changes that require it under data protection laws.

7. Privacy Policies of Other Websites

This website contains links to other websites. This privacy policy applies only to this website. When following links to other websites, please refer to their respective privacy policies.

8. Contact Information

For questions about this privacy policy, stored personal data, or to exercise data protection rights, please contact:

Gregor Redinger

E-Mail: [email protected]

9. Right to Lodge a Complaint

If you feel your concern has not been adequately addressed, you have the right to lodge a complaint with a data protection supervisory authority, in particular in the Member State of your habitual residence, place of work, or the place of the alleged infringement.

Ada pertanyaan, usulan fitur, atau bug untuk dilaporkan?
Mari terhubung!
© 2026 maestrotimer.com