Privacy policy

This translation is only meant for informational purposes, please switch to german for the original version.

General information

The following gives a simple overview of what happens to your personal information when you visit our website. Personal information is any data with which you could be personally identified. Detailed information on the subject of data protection can be found in our privacy policy found below.

Who is responsible for the data collection on this website?

The data collected on this website are processed by the website operator. The operator's contact details can be found in the website's required legal notice.

How do we collect your data?

Some data are collected when you provide it to us. This could, for example, be data that you sent us with an email. Other data are collected automatically by our IT systems when you visit the website. These data are primarily technical data such as the requested URL or when you accessed the page. These data are collected automatically as soon as you enter our website.

What do we use your data for?

Part of the data is collected to ensure the proper functioning of the website. Other data can be used to analyze how visitors use the site.

What rights do you have regarding your data?

You always have the right to request information about your stored data, its origin, its recipients, and the purpose of its collection at no charge. You also have the right to request that it be corrected, blocked, or deleted. You can contact us at any time using the address given in the legal notice if you have further questions about the issue of privacy and data protection. You may also, of course, file a complaint with the competent regulatory authorities.

General information and mandatory information

Data protection

We treat your personal data as confidential and in accordance with the statutory data protection regulations and this privacy policy. If you use this website, various pieces of personal data will be collected. Personal information is any data with which you could be personally identified. This privacy policy explains what information we collect and what we use it for. It also explains how and for what purpose this happens. Please note that data transmitted via the internet (e.g. via email communication) may be subject to security breaches. Complete protection of your data from third-party access is not possible.

Notice concerning the party responsible for this website

The party responsible for processing data on this website is:

Kevin Papst, Elfenstraße 27, 81739 München
Telephone: +49 (0) 30 / 120 872 29

The responsible party is the natural or legal person who alone or jointly with others decides on the purposes and means of processing personal data (names, email addresses, etc.).

Revocation of your consent to the processing of your data

Many data processing operations are only possible with your express consent. Y ou may revoke your consent at any time with future effect. An informal email making this request is sufficient. The data processed before we receive your request may still be legally processed.

Right to file complaints with regulatory authorities

If there has been a breach of data protection legislation, the person affected may file a complaint with the competent regulatory authorities. The competent regulatory authority for matters related to data protection legislation is the data protection officer of the German state in which our company is headquartered. A list of data protection officers and their contact details can be found at the following link:

Right to data portability

You have the right to have data which we process based on your consent or in fulfillment of a contract automatically delivered to yourself or to a third party in a standard, machine-readable format. If you require the direct transfer of data to another responsible party, this will only be done to the extent technically feasible.

SSL or TLS encryption

This site uses SSL or TLS encryption for security reasons and for the protection of the transmission of confidential content, such as the inquiries you send to us as the site operator. You can recognize an encrypted connection in your browser's address line when it changes from "http://" to "https://" and the lock icon is displayed in your browser's address bar.

If SSL or TLS encryption is activated, the data you transfer to us cannot be read by third parties.

Information, blocking, deletion

As permitted by law, you have the right to be provided at any time with information free of charge about any of your personal data that is stored as well as its origin, the recipient and the purpose for which it has been processed. You also have the right to have this data corrected, blocked or deleted. You can contact us at any time using the address given in our legal notice if you have further questions on the topic of personal data.

Opposition to promotional emails

We hereby expressly prohibit the use of contact data published in the context of website legal notice requirements with regard to sending promotional and informational materials not expressly requested. The website operator reserves the right to take specific legal action if unsolicited advertising material, such as email spam, is received.

Data collection on our website


Some of our web pages use cookies. Cookies help make our website more user-friendly, efficient, and secure. Cookies are small text files that are stored on your computer and saved by your browser. Most of the cookies we use are so-called "session cookies." They are automatically deleted after your visit. Other cookies remain in your device's memory until you delete them. These cookies make it possible to recognize your browser when you next visit the site. You can configure your browser to inform you about the use of cookies so that you can decide on a case-by-case basis whether to accept or reject a cookie. Alternatively, your browser can be configured to automatically accept cookies under certain conditions or to always reject them, or to automatically delete cookies when closing your browser. Disabling cookies may limit the functionality of this website. Cookies which are necessary to allow electronic communications or to provide certain functions you wish to use (such as the shopping cart) are stored pursuant to Art. 6 paragraph 1, letter f of DSGVO. The website operator has a legitimate interest in the storage of cookies to ensure an optimized service provided free of technical errors. If other cookies (such as those used to analyze your surfing behavior) are also stored, they will be treated separately in this privacy policy.

Server log files

The website provider does not collects or store any personal information in "server log files". Only in cases of errors we store the request time and error reason. This data will be automatically deleted after 7 days. This data will not be combined with data from other sources. The basis for data processing is Art. 6 (1) (b) DSGVO, which allows the processing of data to fulfill a contract or for measures preliminary to a contract.


The article pages of non-free plugins are offered via the software sales platform Gumroad, Inc., 548 Market St, San Francisco, CA 94104-5401. In accordance with European data protection legislation, Gumroad, Inc. is responsible for personal data collected during the purchase and payment process for its own business purposes. For more information, please see Gumroad's Privacy Policy, where you can also find out which data is collected and for what purposes: We will have access to your billing and payment information for the purpose of fulfilling the contract. These data will not be merged with other data sources. Insofar as this is necessary for the fulfilment of the contract, data will also be transmitted by Gumroad to third parties (e.g. the payment service provider). The legal basis for data processing is Art. 6 Para. 1 S. 1 b DSGVO.


In order to use our Kimai time tracking software, you must register via the website. The information required for registration can be found in the registration form. The provision of the data, which is marked as mandatory, is mandatory for the registration to be completed. If you register via an authentication provider (such as Google or GitHub), the data will be automatically transferred to us by this provider, through a process called OAuth. The authentication provider used will be notified of each login process on our website that you perform using this provider. The data provided will be processed for the purpose of providing the service. The processing is based on the legal basis of Art. 6 para. 1 sentence. 1 b DSGVO.

Order of a Kimai-Cloud plan

If you should decide for a chargeable plan, we process your invoice and payment data for the purpose of contract fulfilment. The provision of invoice and payment data is mandatory for the conclusion of the contract. Insofar as it is necessary for the fulfilment of the contract, data is also transmitted to third parties (e.g. to our payment service provider or the commissioned credit institution). The legal basis for data processing is Art. 6 Para. 1 S. 1 b DSGVO.

Our payment service provider is Stripe, Inc., 510 Townsend Street, San Francisco, CA 94103, USA.


By logging into our system and creating a Kimai Cloud, we process your email address and name for the purpose of fulfilling the contract. Insofar as it is necessary for the fulfilment of the contract, data is also transmitted to third parties (e.g. to our email provider). The legal basis for data processing is Art. 6 Para. 1 S. 1 b DSGVO.

Our email provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Irland.


Our website uses plugins from YouTube, which is operated by Google. The operator of the pages is YouTube LLC, 901 Cherry Ave., San Bruno, CA 94066, USA. If you visit one of our pages featuring a YouTube plugin, a connection to the YouTube servers is established. Here the YouTube server is informed about which of our pages you have visited. If you're logged in to your YouTube account, YouTube allows you to associate your browsing behavior directly with your personal profile. You can prevent this by logging out of your YouTube account. YouTube is used to help make our website appealing. Further information about handling user data, can be found in the data protection declaration of YouTube under This constitutes a justified interest pursuant to Art. 6 (1) (f) DSGVO.

Duration of storage

Unless otherwise stated in previous notices, we will only store your data for as long as is necessary to achieve the processing purpose or to fulfil our contractual or statutory obligations. Such legal storage obligations may arise from commercial or tax law regulations.


In order to support us in the provision of our services, we commission third parties to assist us in data processing. When we as data processors work with these service providers, the third party service provider is a subprocessor.

We use the following subprocessors:

  • Hetzner, Cloud Hosting, Germany
  • Stripe, Payment and contract management, USA
  • Google, OAuth login & email shipping, Ireland
  • GitHub, OAuth login, USA
  • Gumroad, Sale of plugins, USA

Version 1.1 - Release: 02. December 2019