1. Introduction
Kendoo Tech Consulting LTD ("Company", "we", "us"), a company registered in Israel, operates Timero.work ("Service"). This Privacy Policy explains how we collect, use, store, and protect your personal data when you use the Service.
2. Data We Collect
We collect the following categories of data:
- Account data: Name, email address, and profile picture provided by your authentication provider (Google).
- Workspace data: Workspace names, client names, project names, time entries, budgets, and related business data you enter into the Service.
- Usage data: Browser type, IP address, pages visited, and timestamps for the purpose of error monitoring and service improvement.
- Cookies: Session cookies for authentication and workspace selection. We do not use tracking or advertising cookies.
3. How We Use Your Data
- To provide, maintain, and improve the Service.
- To authenticate your identity and manage your account.
- To monitor errors and ensure the reliability of the Service (via Sentry).
- To communicate with you about the Service (e.g., security alerts, updates).
- To comply with legal obligations.
4. Legal Basis for Processing
We process your personal data based on:
- Contract performance: Processing necessary to provide the Service you signed up for.
- Legitimate interest: Error monitoring, security, and service improvement.
- Legal obligation: Where required by applicable law.
5. Third-Party Services
We use the following third-party services that may process your data:
- Google OAuth: For authentication. Subject to Google's Privacy Policy.
- Sentry: For error monitoring and performance tracking. May receive error context including IP address and browser information.
- DigitalOcean: Infrastructure hosting. Data is stored on servers in Frankfurt, Germany (EU).
6. Data Storage & Security
Your data is stored on secure servers hosted by DigitalOcean in Frankfurt, Germany. We implement appropriate technical and organizational measures to protect your data, including encrypted connections (TLS/SSL), secure authentication, and access controls. However, no method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
7. Data Retention
We retain your data for as long as your account is active or as needed to provide the Service. Upon account deletion, we will delete your personal data within 30 days, except where retention is required by law. Workspace data is retained as long as the Workspace exists.
8. Your Rights
Depending on your jurisdiction, you may have the following rights:
- Access: Request a copy of the personal data we hold about you.
- Rectification: Request correction of inaccurate data.
- Erasure: Request deletion of your personal data.
- Portability: Request your data in a structured, machine-readable format.
- Objection: Object to processing based on legitimate interest.
- Restriction: Request restriction of processing in certain circumstances.
To exercise these rights, contact us at privacy@kendoo.co.
9. Children's Privacy
The Service is not directed at individuals under 16 years of age. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child, we will take steps to delete it promptly.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by updating the "Last updated" date and, where appropriate, by email notification. Your continued use of the Service after changes take effect constitutes acceptance.
11. Contact
For privacy-related inquiries:
Kendoo Tech Consulting LTD
Email: privacy@kendoo.co