Privacy Policy
Last updated: 2026-05-31
Purpose of this policy
This Privacy Policy explains how, when and why timeghost Solutions GmbH collects information about individuals, how, for what purposes and on what basis this personal data is subsequently processed, who processes it and what rights individuals have regarding their personal data. It also explains our use of cookies and similar technologies. The terms used here (e.g. "controller", "processor", "data subject") have the meaning given to them in the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR").
Controller
The controller within the meaning of the GDPR is timeghost Solutions GmbH, Reichenaustr. 11a, 78467 Konstanz, Germany. Telephone: +49 7531 9783000, email: info@timeghost.io.
Where you, as a Workspace Owner, process content and data within a workspace, you are the controller of that Workspace Data; timeghost Solutions GmbH processes such data on your behalf as a processor.
Data Protection Officer
In accordance with Article 37 GDPR and § 38 of the German Federal Data Protection Act (BDSG), we have appointed a Data Protection Officer:
E.O.
timeghost Solutions GmbH, Reichenaustr. 11a, 78467 Konstanz, Germany
Telephone: +49 7531 9783000 · Email: info@timeghost.io
What data we collect
Depending on how you use the service, we process the following categories of information:
- Profile data: data you provide in the context of agreements and use of the service (e.g. name, email address, profile picture) as well as invitation email addresses.
- Billing data: for paid plans, the name and address of the payer, and optionally email address and VAT number. Payment data is processed by the payment service provider Paddle.
- Usage data: automatically collected data such as IP address, approximate location, time of login, application type and version, and log data.
- Cookie data: information collected via cookies and similar technologies (see Cookies section).
- Third-party data: data processed as part of the Microsoft 365 integration, as well as other information you provide.
Purposes and legal grounds
We process personal data in particular to provide and develop the service, to perform contracts, to communicate with you, to ensure security and to comply with legal obligations. Depending on the case, the legal grounds are the performance of a contract (Art. 6 (1) (b) GDPR), compliance with legal obligations (Art. 6 (1) (c) GDPR), our legitimate interests (Art. 6 (1) (f) GDPR) or your consent (Art. 6 (1) (a) GDPR).
AI features
For the AI-assisted creation, expansion and refinement of mind maps, the content you enter (prompts) and, where applicable, selected nodes are transmitted to Azure OpenAI and processed there. Processing takes place in a region within the European Union. Only the content required for the respective request is transmitted, and the transmitted data is not used to train the AI models. The legal basis is the performance of a contract (Art. 6 (1) (b) GDPR) or our legitimate interest in providing the AI features (Art. 6 (1) (f) GDPR).
Cookies
When using our web and cloud applications and our websites, we use technically necessary (first-party) cookies that are required for the operation, login and security of the service. If cookies are additionally used for analytics or marketing purposes, this is done exclusively on the basis of your consent (Art. 6 (1) (a) GDPR), which you can withdraw at any time with effect for the future. You can manage or delete cookies via your browser settings; if necessary cookies are disabled, the service may not function fully.
Disclosure to third parties
To provide the service, we engage carefully selected processors and service providers, in particular:
- Microsoft Azure / Entra ID (authentication, Microsoft 365 and data storage)
- Azure OpenAI (AI-assisted generation of mind maps)
- Sentry (error and performance monitoring)
- Paddle (subscriptions and payment processing)
- Email delivery service (e.g. Brevo/Resend) for sending service notifications
- Hosting and infrastructure providers for operating the application
This list names the main recipients by way of example and is not exhaustive. We will provide a current list of subprocessors on request. Your personal data is only disclosed to the extent necessary, to comply with legal obligations or with your consent. Your data is not passed on to third parties for advertising purposes.
International data transfers
Your personal data is generally processed within the European Union or the European Economic Area (EEA) – this also applies to the AI features, which run in an EU region of Azure OpenAI. If, by way of exception, a transfer to a country outside the EEA is necessary, it only takes place if an adequate level of data protection is ensured or appropriate safeguards within the meaning of the GDPR (e.g. standard contractual clauses) are in place.
Retention period
We store personal data only for as long as necessary for the respective purposes and for periods required by law. Data relevant for tax and commercial law is stored in accordance with statutory retention periods (generally up to ten years).
Data security
We take appropriate technical and organizational measures to protect your data against unauthorized processing and against loss, alteration or destruction. All communication with the service is encrypted via the HTTPS protocol.
Your rights as a data subject
Under the GDPR, you have in particular the following rights:
- Right of access (Art. 15 GDPR)
- Right to rectification (Art. 16 GDPR)
- Right to erasure (Art. 17 GDPR)
- Right to restriction of processing (Art. 18 GDPR)
- Right to data portability (Art. 20 GDPR)
- Right to object (Art. 21 GDPR)
- Right to withdraw consent (Art. 7 (3) GDPR)
You also have the right to lodge a complaint with a data protection supervisory authority.
Changes to this policy
We may revise this Privacy Policy from time to time to reflect changes to the service, the websites, applicable laws or our business. The current version is always published on this page.
Contact
If you have any questions about this policy or wish to exercise your rights, you can reach us at:
timeghost Solutions GmbH, Reichenaustraße 11a, 78467 Konstanz, Germany
Email: support@timeghost.io · Telephone: +49 (0) 7531 – 9783000