Privacy

Your data. Handled transparently.

Here you can find out which personal data Bretira processes, why it is needed and which rights you have.

1. Controller

The controller responsible for the processing of personal data in connection with Bretira is:

Stanley Guhde
Im Blumengrund 5
04319 Leipzig
Germany

Email: support@bretira.com

2. Data Bretira processes

Bretira processes in particular account and authentication data, work schedule, absence, time-account, planning and settings data entered by the user, as well as technical data required for the respective functions that are enabled.

When functions such as beta registration are used, the provided email address, language or locale and any marketing consent that may have been given can in particular be processed.

When contacting support, the contact details and message content provided by the user are processed to the extent required to deal with the request.

For current weather, the device's current location can be used voluntarily. Bretira requests permission only after an explicit user action. There is no background tracking and no location history is created; precise device coordinates are not stored. Before the server-side weather request, coordinates are rounded to three decimal places. Alternatively, a voluntarily stored approximate weather location remains available.

3. Health-related absences

Information about absences such as "illness" or "child sick" can constitute health data and therefore special categories of personal data within the meaning of Article 9 GDPR.

Bretira does not require a diagnosis, symptoms, medical documents or the name of a child. Only the information required for absence and time-account management is processed.

The health-related function is voluntary. Processing takes place only after explicit consent pursuant to Article 6(1)(a) GDPR in conjunction with Article 9(2)(a) GDPR. Bretira can also be used without this consent; only the health-related absence categories are then unavailable.

Consent can be withdrawn at any time under More → App & Privacy → Health data. Withdrawal applies to the future and does not affect the lawfulness of processing carried out on the basis of consent before it was withdrawn.

Health-related information already stored is deleted or privacy-compliantly neutralised as part of the intended privacy procedure following withdrawal.

4. Purposes and legal bases

Account, authentication, planning, absence, settings and other functional data are processed insofar as this is necessary to provide and use Bretira. The legal basis is in particular Article 6(1)(b) GDPR.

Where processing is based on consent, Article 6(1)(a) GDPR is the legal basis. For special categories of personal data, Article 9(2)(a) GDPR additionally applies.

Voluntary consent to marketing communications can be withdrawn at any time with effect for the future.

Security, abuse prevention, error analysis and technical operating measures may be based on Article 6(1)(f) GDPR. The legitimate interest lies in the secure, stable and reliable operation of Bretira and in protecting users and systems against misuse.

5. Hosting and delivery via Netlify

Netlify is used for hosting, delivery and technical provision of the web application. Technically required connection, security and log data may be processed, in particular IP address, time, requested resource, technical browser or device information and comparable access data.

The provider is Netlify, Inc., based in the United States. Where personal data is processed outside the European Economic Area or transferred to the United States in connection with the use of Netlify, the transfer is safeguarded using the data-protection mechanisms provided for this purpose. According to Netlify, it is certified under the EU-U.S. Data Privacy Framework and additionally or supplementarily provides for European Commission Standard Contractual Clauses for relevant international transfers.

6. Backend and authentication via Supabase

Backend, database, storage and authentication functions are operated using Supabase.

The primary database of Bretira's production project is located in the European region Frankfurt. Data is stored and primarily processed there.

In connection with the operation of Supabase and the use of subprocessors incorporated under data-protection arrangements, additional processing or international data transfers may take place. These are governed by Supabase's contractual data-protection and transfer mechanisms.

7. Email delivery and support via IONOS

Bretira uses email services provided by IONOS SE for the technical delivery of authentication and security emails and for support communications.

This may include processing the email address, delivery and transmission information, technical metadata and, for support requests, the message content provided by the user.

Authentication emails include in particular registration confirmations, password recovery and comparable security-related messages. Where required for use of the account, processing is based on Article 6(1)(b) GDPR and, for security and abuse-prevention measures, on Article 6(1)(f) GDPR.

8. Address search and geocoding via Google Maps Platform

Bretira uses Google Maps Platform services for optional address and location features. Address suggestions are provided through the Places API. When a suggestion is selected, Bretira resolves the selected Place ID server-side through Google Geocoding.

In this process, Google may process in particular the entered search term or selected Place ID, language or locale and technical connection data required to provide the service. According to Google, the Maps services may process data including search terms, IP addresses and location coordinates.

Bretira does not expose the Google API key to the browser and does not send a Bretira user ID, email address or name to Google for address resolution. Communication with Google takes place through Bretira.

A confirmed address, the associated Google Place ID and, where required for the selected feature, coordinates rounded to three decimal places may be stored in association with the relevant Bretira account. This data is not used across different accounts.

For the weather feature, a weather location configured in this way can subsequently be combined with weather data from MET Norway. This combination is used only for the weather feature activated by the user.

Google-backed address search is activated only after the user has expressly consented to the processing described for this purpose. Consent can be withdrawn at any time using the withdrawal control provided with the address search. After withdrawal, Bretira sends no new address-search or geocoding requests to Google unless address search is activated again.

Locations already confirmed and stored with the Bretira account are not automatically deleted when consent is withdrawn. They remain stored until the user changes or deletes them or the account is deleted.

Further information is available in the Google Privacy Policy. Google Maps features are also subject to the Google Maps End User Additional Terms of Service.

9. Weather data via MET Norway

Bretira uses weather data from the Norwegian Meteorological Institute (MET Norway) for the optional weather function.

The request to MET Norway is made exclusively server-side through Bretira. As a result, the end device's IP address is not sent directly to MET Norway by the weather request.

For the weather request, the coordinates of the approximate weather location configured by the user or of the current device location explicitly shared by the user are rounded to three decimal places. Current-location weather and work-location weather remain separate: the current device location never silently replaces the stored work or weather location. MET Norway may log access by the Bretira server and the rounded coordinates transmitted on its own systems. According to MET Norway, API access logs are processed in its own data centre in Oslo, Norway.

10. Technically necessary cookies and local storage

Bretira uses technically necessary cookies or comparable storage mechanisms in particular for authentication, session management, security and the provision of signed-in functions.

Bretira may additionally store information locally on the device being used, for example display preferences, local app state and data required for explicitly used local or native functions. The decision whether current-location weather should be used on this device is stored only locally and does not contain coordinates. The decision to activate Google address search, the applicable notice version and timestamps for granting and withdrawing consent may also be stored locally; this consent metadata contains no address or coordinates.

Where strictly necessary in order to provide the digital service expressly requested by the user, these accesses to the terminal equipment are carried out on the basis of Section 25(2) no. 2 TDDDG.

Bretira currently does not integrate advertising, marketing or user-related tracking services such as Google Analytics, Meta Pixel or comparable external tracking systems.

11. Storage periods

Personal data is generally stored only for as long as required for the respective processing purpose or for as long as statutory retention obligations apply.

Account and profile data is generally stored for the duration of the existing Bretira account and removed as part of successful account deletion unless an overriding statutory obligation requires further retention.

Work schedule, planning, absence, time-account and settings data stored by the user is retained for use of the account until it is deleted or replaced by the user or until the associated account is deleted.

Health-related information is processed until it is deleted, the account is deleted or the associated consent is withdrawn. Upon withdrawal, the intended deletion or privacy-compliant neutralisation of the health-related information takes place.

Support communications are retained only for as long as required to process and traceably resolve the relevant request, maintain system security or comply with existing legal obligations.

Technical security, access and operational logs are retained only within the scope of the respective technical necessity and the retention mechanisms applicable at the service providers used.

Technical deletion and security records that are no longer personal data may remain. Personal records are retained further only where this is technically or legally required.

12. Account and data deletion

Users can initiate deletion of their Bretira account and the associated personal app data themselves.

Before final deletion, the current identity is confirmed and it is checked whether personal data and private files can be deleted clearly and securely. Data belonging to other users or shared organisation data is not deleted without control.

Deletion can also be completed entirely through the public browser resource; an installed app is not required.

Delete account and data

13. Your data protection rights

Subject to the statutory requirements, you have in particular the rights of access, rectification, erasure, restriction of processing and data portability.

Where processing is based on Article 6(1)(e) or (f) GDPR, a right to object may exist subject to the statutory requirements.

Consent that has been given can be withdrawn at any time with effect for the future. This does not affect the lawfulness of processing carried out before the withdrawal.

You also have the right to lodge a complaint with a competent data protection supervisory authority regarding the processing of personal data.

Data protection requests can be sent to support@bretira.com.

14. Changes to this privacy notice

This privacy notice is updated if processing activities, service providers used or legal requirements materially change. The current version is made available through Bretira.

Last updated: 16 September 2026