1. Controller and Scope
1.1
The controller responsible for the processing of personal data described in this Privacy Policy is:
1.2
For the purposes of applicable data protection law, tinyworker UG (haftungsbeschränkt) is the controller of your personal data.
1.3
This Privacy Policy explains how we process personal data that we collect from you, that you provide to us, or that is generated when you use our website or our mobile applications.
1.4
This Privacy Policy applies to our website and our mobile applications.
1.5
Where this Privacy Policy refers to “website” or “mobile apps”, this refers to the respective services operated by tinyworker UG (haftungsbeschränkt), unless stated otherwise.
2. What Data Do We Collect?
2.1
In connection with your use of our website and mobile apps, we may collect the following categories of personal data:
2.1.1
Contact and communication data that you provide when you contact us, including by email to support@tinyworker.com or otherwise contact us (for example your name, email address, the content of your message, and any other information you choose to provide).
2.1.2
Technical data and server log data generated when you access our website or our mobile apps, including IP address, date and time of access, requested content, device or browser information, operating system, language settings, referrer URL, and other log information required to provide and secure our services.
2.1.3
Usage data relating to how you use our website or our mobile apps, such as pages or screens viewed, interactions with content, session information, app usage events, and similar information about how our services are accessed and used.
2.1.4
Analytics and diagnostic data, including information collected through analytics or crash-reporting tools, such as Google Analytics, Firebase Analytics, Firebase Crashlytics, or similar services, where such tools are enabled.
2.1.5
Advertising-related data, including information that may be collected in connection with advertising services or campaigns for our apps or services, for example through Google Ads, Meta advertising services, or similar providers, where such services are used.
2.1.6
Account and profile data, where a mobile app offers user accounts or login functionality, such as username, email address, account identifiers, authentication information, and other data required to create, maintain, and secure an account.
2.1.7
Transaction data, where a mobile app offers in-app purchases or subscriptions, such as information about purchases, subscription status, transaction identifiers, and information received from platform providers such as Apple or Google in connection with payment processing and purchase validation.
2.1.8
Content and permission-based data, where required by a specific app feature, including photos, camera input, microphone input, and related files or media that you choose to provide or make accessible to the app.
2.1.9
Data relating to the use of embedded third-party content, where such content is included on our website or in our mobile apps, for example YouTube videos.
2.1.10
Data processed through external infrastructure and service providers used in connection with our services, including providers for communication, hosting, backend, analytics, and productivity services, such as Microsoft 365, Google Workspace, Amazon Web Services (AWS), Firebase, or similar providers, where applicable.
2.2
We generally receive personal data directly from you, from your device when you use our services, from platform providers such as Apple or Google, and from service providers that support the operation, analysis, security, advertising, or delivery of our website and mobile apps.
2.3
Some data is only collected if a particular website function, mobile app feature, third-party service, login system, purchase flow, or permission-based feature is actually enabled and used.
3. For What Purposes Do We Process Your Data?
3.1
We process personal data for the following purposes, as applicable to our website and mobile apps:
3.1.1
To provide, operate, maintain, and improve our website and mobile apps.
3.1.2
To ensure the security, stability, performance, and integrity of our website, mobile apps, systems, and infrastructure.
3.1.3
To respond to support requests, user inquiries, and other communications sent to us, including via support@tinyworker.com.
3.1.4
To analyze usage of our website and mobile apps, diagnose technical issues, detect errors, and improve user experience, functionality, and content.
3.1.5
To provide account-related features, authenticate users, manage user profiles, and enable login functionality where such features are offered.
3.1.6
To provide app-specific features that require access to user-provided content or device permissions, including features involving photos, camera access, microphone access, or media files, where such features are enabled by the user.
3.1.7
To process and validate in-app purchases, subscriptions, and related transactions, including communicating with platform providers such as Apple and Google where required.
3.1.8
To deliver, host, support, and administer our services using external infrastructure and service providers, including providers for hosting, backend services, communication, analytics, diagnostics, and productivity tools.
3.1.9
To display or enable embedded third-party content, such as YouTube videos, where such content is included in our website or mobile apps.
3.1.10
To promote our apps and services, support advertising campaigns, measure the performance of advertising activities where applicable, and improve the visibility and reach of our offerings.
3.1.11
To comply with legal obligations, enforce our rights, prevent misuse, and establish, exercise, or defend legal claims.
4. On What Legal Basis Do We Process Your Data?
4.1
We process personal data on one or more of the following legal bases, depending on the specific processing activity:
4.1.1
Art. 6 (1) sentence 1 lit. (a) GDPR, where you have given your consent.
4.1.2
Art. 6 (1) sentence 1 lit. (b) GDPR, where processing is necessary for the performance of a contract with you or in order to take steps at your request before entering into a contract.
4.1.3
Art. 6 (1) sentence 1 lit. (c) GDPR, where processing is necessary for compliance with a legal obligation to which we are subject.
4.1.4
Art. 6 (1) sentence 1 lit. (f) GDPR, where processing is necessary for the purposes of our legitimate interests or those of a third party, provided that your interests or fundamental rights and freedoms do not override those interests.
4.2
In particular, we generally rely on Art. 6 (1) sentence 1 lit. (f) GDPR for the operation, security, technical provision, administration, and improvement of our website, mobile apps, systems, and infrastructure, as well as for support handling, fraud prevention, misuse prevention, and the establishment, exercise, or defense of legal claims.
4.3
We generally rely on Art. 6 (1) sentence 1 lit. (b) GDPR where processing is necessary to provide app functionalities requested by you, to manage user accounts, to provide login functionality, or to process and validate in-app purchases, subscriptions, and related transactions.
4.4
We generally rely on Art. 6 (1) sentence 1 lit. (a) GDPR where consent is required, in particular for certain analytics, advertising-related processing, or permission-based features, where applicable.
4.5
We generally rely on Art. 6 (1) sentence 1 lit. (c) GDPR where we are legally required to retain or disclose certain data, for example under commercial, tax, or other applicable legal obligations.
5. Disclosure of Your Data
5.1
We may disclose personal data to third parties where this is legally permitted and necessary for the purposes described in this Privacy Policy, in particular in the following cases:
5.1.1
where you have given your consent pursuant to Art. 6 (1) sentence 1 lit. (a) GDPR;
5.1.2
where the disclosure is necessary for the performance of a contract with you or for steps taken at your request before entering into a contract pursuant to Art. 6 (1) sentence 1 lit. (b) GDPR;
5.1.3
where the disclosure is necessary for compliance with a legal obligation pursuant to Art. 6 (1) sentence 1 lit. (c) GDPR;
5.1.4
where the disclosure is necessary for our legitimate interests pursuant to Art. 6 (1) sentence 1 lit. (f) GDPR, including for the establishment, exercise, or defense of legal claims, provided that your interests or fundamental rights and freedoms do not override those interests.
5.2
We may share personal data with service providers and processors that support the operation of our website and mobile apps, including providers for email and communication services, hosting, cloud infrastructure, backend services, analytics, diagnostics, customer support, app functionality, productivity tools, embedded content, and advertising-related services.
5.3
Depending on the service used, recipients may include, in particular, providers such as Microsoft 365, Google Workspace, Amazon Web Services (AWS), Firebase, Google, Meta, YouTube, Apple, and Google Play, or comparable providers engaged by us from time to time.
5.4
Where personal data is transferred to recipients located outside the European Union (EU) or the European Economic Area (EEA), we take appropriate measures to ensure an adequate level of data protection in accordance with applicable law. Such measures may include an adequacy decision of the European Commission or the use of standard contractual clauses or comparable safeguards, where required. Additional information on data processing by specific providers may be available in the respective provider privacy notices, for example:
5.5
We may also disclose personal data to courts, authorities, advisors, or other third parties where necessary to comply with legal obligations, enforce our rights, investigate misuse, or establish, exercise, or defend legal claims.
7. Storage and Deletion of Your Data
7.1
We store personal data only for as long as necessary for the purposes described in this Privacy Policy, including to provide our services, respond to inquiries, operate our website and mobile apps, comply with legal obligations, resolve disputes, and enforce our rights.
7.2
The actual storage period may vary depending on the type of data and the purpose of processing, including whether we are required to retain data for legal, tax, accounting, commercial, or security-related reasons.
7.3
If personal data is no longer required for the purposes for which it was collected, we will delete it or restrict its processing, unless continued retention is required or permitted by applicable law.
7.4
In some cases, we may anonymize personal data so that it can no longer be associated with an identified or identifiable individual. In that case, we may continue to use such anonymized data without further notice.
8. Cookies
8.1
Our website may use cookies and similar technologies where this is technically necessary or otherwise legally permitted.
8.2
At present, we do not use cookies on our website for general analytics or advertising purposes unless such functionality is specifically enabled.
8.3
If cookies or similar technologies are used in connection with embedded third-party content, analytics tools, or other optional website features, the related processing will only take place where such functionality is active and, where required, after any necessary consent has been obtained.
8.4
You can generally configure your browser to block or delete cookies. Please note that some website functions may not work properly if cookies are disabled.
9. Analytics and Diagnostics
9.1
We may use analytics and diagnostic tools in connection with our website and mobile apps in order to understand usage, improve functionality, detect technical problems, and maintain the performance and reliability of our services.
9.2
For our website, this may include tools such as Google Analytics, where enabled.
9.3
For our mobile apps, this may include tools such as Firebase Analytics and Firebase Crashlytics, or similar analytics and crash-reporting services, where enabled.
9.4
Such tools may process technical data, device information, usage data, app events, crash information, and similar diagnostic or statistical information.
9.5
Where required by applicable law, we will obtain any necessary consent before using analytics technologies.
13. Your Rights
Subject to the applicable legal requirements, you have the following rights under data protection law:
13.1
The right to request access to your personal data processed by us pursuant to Art. 15 GDPR.
13.2
The right to request the rectification of inaccurate personal data or the completion of incomplete personal data pursuant to Art. 16 GDPR.
13.3
The right to request the erasure of your personal data pursuant to Art. 17 GDPR.
13.4
The right to request the restriction of processing of your personal data pursuant to Art. 18 GDPR.
13.5
The right to receive the personal data you have provided to us in a structured, commonly used, and machine-readable format, or to request its transmission to another controller, pursuant to Art. 20 GDPR.
13.6
Where processing is based on your consent, the right to withdraw your consent at any time with effect for the future pursuant to Art. 7 (3) GDPR.
13.7
The right to lodge a complaint with a supervisory authority pursuant to Art. 77 GDPR.