Privacy Policy
Last updated: August 27, 2026

The protection of your personal data is important to us. This privacy policy informs you pursuant to the General Data Protection Regulation (GDPR) and the Austrian Data Protection Act (DSG) about which personal data we process in connection with jidAI and for what purposes.

1. Controller

  • Silvertip IT-Solutions GmbH
  • Grabenweg 68, 6020 Innsbruck, Austria
  • Commercial Register Number: FN 599795b
  • VAT Number: ATU79178079
  • Email: info@silvertip-it.at
  • Phone: +43 664 9111 489

For all data protection questions, you can reach us at the contact details above.

2. General Information on Data Processing

We process personal data only to the extent necessary to provide jidAI, operate our website, and handle your requests. Processing is based on statutory provisions, in particular the GDPR and DSG.

Personal data means any information relating to an identified or identifiable natural person (e.g., name, email address, IP address, or work-related time entries).

3. Data We Process

Depending on how you use jidAI, we process the following categories of data:

  • Account data: Email address, display name, password (stored only as a bcrypt hash), profile photo URL, locale and UI preferences, authentication method (email/password and/or Google sign-in), email verification and password-reset tokens.
  • Organization data: Company name, address, city, postal code, country, VAT number, billing contact details, subscription tier, license count, timezone, and industry information.
  • Time-tracking data: Time bookings (start/end times, project, task, notes), approval status, work profiles, schedules, vacation balances, and related workforce data entered by or about users within an organization.
  • Voice recordings: If you use voice input, audio recordings are processed to transcribe your spoken work descriptions.
  • Invite/waitlist requests: Email addresses and roles for invitations; email and notes for invite/waitlist requests.
  • Security audit log (reCAPTCHA): Non-personal verification outcomes on public forms (action, route, HTTP method, success, score, error codes, correlation ID, timestamp). No IP addresses, emails, or tokens are stored. Retained for up to 90 days.
  • Application request logs: HTTP method, path, status code, request duration, and correlation ID. Application middleware does not log IP address or user-agent.
  • Email send logs: Recipient identifier and client IP address for rate limiting and abuse prevention when sending transactional emails.
  • Browser extension data: If you install the jidAI browser extension, we process extension session authentication tokens, the selected organization id, and a cached active booking state stored in the extension via the WebExtension Storage API. The production extension communicates with https://jidai.eu/* (web app and API). Extension sessions are independent of website sessions: logging out of the website does not log out the extension, and logging out of the extension does not end your website session.
  • Admin operator audit logs: Records of privileged platform-operator actions (actor user id and optional email, action, organization and target identifiers, reason, before/after snapshots where applicable, correlation id, source IP, and user-agent). [Counsel: confirm retention and access controls before publication.]
  • Admin support access sessions: Time-boxed support access windows into a customer organization (actor user id, organization id, reason, start/expiry/end timestamps, and how the session ended). Used only for authorized support troubleshooting. [Counsel: confirm retention.]
  • Data-subject request case files: Case-management records for GDPR rights requests (request type, role context as controller or processor-assist, subject email and optional user id, organization id where relevant, status, deadlines, identity-verification metadata, notes, refusal grounds, fulfilment timestamps, and optional package storage references). [Counsel: confirm retention aligned with Art. 12 GDPR and statutory limitation periods.]

4. Purposes and Legal Bases

  • Providing the service: Art. 6 para. 1 lit. b GDPR (contract performance) and Art. 6 para. 1 lit. f GDPR (legitimate interest in operating a secure SaaS platform).
  • Account registration and authentication: Art. 6 para. 1 lit. b GDPR.
  • Transactional emails (verification, invitations, password reset): Art. 6 para. 1 lit. b GDPR and Art. 6 para. 1 lit. f GDPR.
  • AI-assisted features (parsing, transcription, onboarding; optional flag-gated compliance checks): Art. 6 para. 1 lit. b GDPR (service delivery) and, where applicable, Art. 6 para. 1 lit. f GDPR (legitimate interest in efficient service operation).
  • reCAPTCHA on public forms: Art. 6 para. 1 lit. a GDPR (consent via cookie banner; withdrawable at any time).
  • Security audit log (reCAPTCHA outcomes): Art. 6 para. 1 lit. f GDPR (legitimate interest in monitoring abuse and debugging security controls).
  • Application request logs and security: Art. 6 para. 1 lit. f GDPR.
  • Admin operator audit and support access: Art. 6 para. 1 lit. f GDPR (legitimate interest in secure platform operation, abuse prevention, and accountable support access) and, where processing employee data on a customer’s instructions, Art. 28 GDPR as processor. [Counsel: confirm bases per role.]
  • Data-subject request handling: Art. 6 para. 1 lit. c GDPR (legal obligation to respond to rights requests) and Art. 6 para. 1 lit. f GDPR where we assist customers as processor. [Counsel: confirm.]

5. AI Processing (Google Gemini)

jidAI uses artificial intelligence (Google Gemini via the Gemini API) to help users create structured time entries from natural language, transcribe voice input, support organization onboarding and work-profile drafts, and — when explicitly enabled by a system feature flag — run optional assistive compliance checks. Compliance checks are not intended for employment decisions.

For these features, relevant user content may be transmitted to Google (Gemini API), including:

  • Free-text work descriptions and revision instructions
  • Voice/audio recordings for transcription (processed for the request; not stored in the jidAI database)
  • Recent time bookings and project names for context
  • Organization industry, country, and team-size information for onboarding recommendations

Some onboarding and work-profile generation requests may use Google Search grounding. Per Google's Gemini API terms for Grounding with Google Search, Google may store prompts, contextual information, and generated output for approximately 30 days for grounded results and related debugging. jidAI does not claim Vertex AI EU residency for Gemini processing.

Legal basis: Art. 6 para. 1 lit. b GDPR (providing requested AI features) and Art. 6 para. 1 lit. f GDPR where applicable.

AI-generated output may be inaccurate. Users and organizations remain responsible for reviewing entries before relying on them.

Further details on how we inform users about AI under the EU AI Act are available on our AI Transparency page.

6. reCAPTCHA on Public Forms

We use Google reCAPTCHA v3 on public-facing forms (including registration, login, password reset, organization registration, and invite requests) to detect and prevent automated abuse. Google acts as our data processor under Art. 28 GDPR.

When you consent, Google may process device and browser metadata and interaction signals for abuse detection and risk scoring. The reCAPTCHA script is loaded from google.com/recaptcha only after consent and may remain active across jidAI during your browser session; our servers verify tokens via Google's siteverify API.

Legal basis: Art. 6 para. 1 lit. a GDPR (consent). You can withdraw consent at any time via the manage-consent option on protected forms.

See also our Cookie Policy.

7. Recipients and Sub-processors

We use the following categories of recipients and sub-processors to operate jidAI:

  • Google Cloud Platform (hosting, database, storage): Infrastructure in europe-west3 (Frankfurt, Germany).
  • Google Gemini API: AI processing as described above.
  • Google reCAPTCHA: Bot detection on public forms (data processor under Art. 28 GDPR).
  • Google Workspace / Gmail API: Sending transactional emails.
  • EU VIES REST API: VAT number validation (country code and VAT number only).
  • nager.date: Public holiday data (country and year only; no personal data).

Sub-processors are engaged under data processing agreements pursuant to Art. 28 GDPR where required.

8. International Transfers

Primary hosting and database storage are in the EU (Google Cloud, region europe-west3). Some Google services (including Gemini API and reCAPTCHA) may involve processing outside the EU/EEA, in particular in the United States.

Where required, transfers are safeguarded by appropriate measures under Art. 44 et seq. GDPR, such as EU Standard Contractual Clauses and Google's data protection terms.

9. Controller and Processor Roles (Business Customers)

When an organization uses jidAI for its employees' time tracking, the organization is generally the controller for employee personal data processed within the service. Silvertip IT-Solutions GmbH acts as a processor for that data, processing it on the organization's instructions to provide jidAI.

For account, billing, and website-related processing, Silvertip IT-Solutions GmbH may act as controller. A data processing agreement (DPA) is available for business customers on request.

10. Storage Duration

  • Account and organization data: Stored for the duration of the contractual relationship and deleted or anonymized thereafter, subject to statutory retention obligations.
  • Time-tracking data: Stored for as long as the organization maintains the account and as required by the organization's policies and applicable law.
  • Application request logs: Retained as needed for operations and security troubleshooting (method, path, status, duration, correlation ID), then deleted.
  • Email send logs: Recipient and client IP retained as needed for rate limiting and security, then deleted.
  • Invite/waitlist requests: Retained until processed and no longer needed, then deleted.
  • reCAPTCHA security audit log: Non-personal verification outcomes retained for up to 90 days for abuse monitoring and debugging, then deleted.
  • Google Gemini / Search grounding: Prompts and audio may be processed by Google for the request. Where Search grounding is used, Google may retain prompts and related output for approximately 30 days under Gemini API terms; see section 5.
  • Admin operator audit logs: Retained as needed for security, accountability, and dispute handling, then deleted or anonymized. Exact periods are set by internal policy. [Counsel: set concrete retention.]
  • Admin support access sessions: Retained for the duration of the support need and a limited period thereafter for auditability, then deleted. [Counsel: set concrete retention.]
  • Data-subject request case files: Retained for the handling of the request and as long as needed to demonstrate compliance with Art. 12 GDPR and related obligations, then deleted or anonymized. [Counsel: set concrete retention.]

11. Your Rights

You have the following rights regarding your personal data, subject to legal conditions:

  • Access (Art. 15 GDPR)
  • Rectification (Art. 16 GDPR)
  • Erasure (Art. 17 GDPR)
  • Restriction of processing (Art. 18 GDPR)
  • Data portability (Art. 20 GDPR)
  • Objection (Art. 21 GDPR) to processing based on legitimate interests

To exercise your rights, contact us at info@silvertip-it.at. If you are an employee user, your organization may also be the controller — contact your employer where appropriate.

12. Right to Lodge a Complaint

You may lodge a complaint with a supervisory authority. In Austria, the competent authority is:

  • Austrian Data Protection Authority (Österreichische Datenschutzbehörde)
  • Barichgasse 40–42, 1030 Vienna
  • Email: dsb@dsb.gv.at | Web: www.dsb.gv.at

13. Data Security

We implement appropriate technical and organizational measures to protect personal data, including TLS encryption in transit, password hashing (bcrypt), access controls, and infrastructure security on Google Cloud. Security measures are reviewed and updated as technology evolves.

14. Cookies and Local Storage

We use strictly necessary cookies and browser storage for language selection (NEXT_LOCALE), storing your reCAPTCHA consent decision (jidai_recaptcha_consent), authentication (refresh_token), and theme/session preferences. The optional browser extension additionally stores session auth tokens, organization selection, and active booking cache in extension storage, and may use host access to https://jidai.eu/*. After your consent, jidAI also uses Google reCAPTCHA for abuse detection and session-based risk scoring. Details are in our Cookie Policy.

15. Changes to This Privacy Policy

We may update this privacy policy to reflect legal requirements or changes to jidAI. The current version applies on your next visit or use of the service after publication.