Privacy Policy
Last updated: July 29, 2026

The protection of your personal data is important to us. This privacy policy informs you pursuant to the General Data Protection Regulation (GDPR) and the Austrian Data Protection Act (DSG) about which personal data we process in connection with jidAI and for what purposes.

1. Controller

  • Silvertip IT-Solutions GmbH
  • Grabenweg 68, 6020 Innsbruck, Austria
  • Commercial Register Number: FN 599795b
  • VAT Number: ATU79178079
  • Email: info@silvertip-it.at
  • Phone: +43 664 9111 489

For all data protection questions, you can reach us at the contact details above.

2. General Information on Data Processing

We process personal data only to the extent necessary to provide jidAI, operate our website, and handle your requests. Processing is based on statutory provisions, in particular the GDPR and DSG.

Personal data means any information relating to an identified or identifiable natural person (e.g., name, email address, IP address, or work-related time entries).

3. Data We Process

Depending on how you use jidAI, we process the following categories of data:

  • Account data: Email address, display name, password (stored only as a bcrypt hash), profile photo URL, locale and UI preferences, authentication method (email/password and/or Google sign-in), email verification and password-reset tokens.
  • Organization data: Company name, address, city, postal code, country, VAT number, billing contact details, subscription tier, license count, timezone, and industry information.
  • Time-tracking data: Time bookings (start/end times, project, task, notes), approval status, work profiles, schedules, vacation balances, and related workforce data entered by or about users within an organization.
  • Voice recordings: If you use voice input, audio recordings are processed to transcribe your spoken work descriptions.
  • Invite/waitlist requests: Email addresses and roles for invitations; email and notes for invite/waitlist requests.
  • Security audit log (reCAPTCHA): Non-personal verification outcomes on public forms (action, route, HTTP method, success, score, error codes, correlation ID, timestamp). No IP addresses, emails, or tokens are stored.
  • Server log files: IP address, date and time of access, requested URL, browser type and version, operating system, and referrer URL.
  • Email logs: Recipient identifier and client IP address for rate limiting and abuse prevention when sending transactional emails.

4. Purposes and Legal Bases

  • Providing the service: Art. 6 para. 1 lit. b GDPR (contract performance) and Art. 6 para. 1 lit. f GDPR (legitimate interest in operating a secure SaaS platform).
  • Account registration and authentication: Art. 6 para. 1 lit. b GDPR.
  • Transactional emails (verification, invitations, password reset): Art. 6 para. 1 lit. b GDPR and Art. 6 para. 1 lit. f GDPR.
  • AI-assisted features (parsing, transcription, onboarding, compliance checks): Art. 6 para. 1 lit. b GDPR (service delivery) and, where applicable, Art. 6 para. 1 lit. f GDPR (legitimate interest in efficient service operation).
  • reCAPTCHA on public forms: Art. 6 para. 1 lit. a GDPR (consent via cookie banner; withdrawable at any time).
  • Security audit log (reCAPTCHA outcomes): Art. 6 para. 1 lit. f GDPR (legitimate interest in monitoring abuse and debugging security controls).
  • Server logs and security: Art. 6 para. 1 lit. f GDPR.

5. AI Processing (Google Gemini)

jidAI uses artificial intelligence to help users create structured time entries from natural language, transcribe voice input, support organization onboarding, and run optional compliance checks.

For these features, relevant user content may be transmitted to Google (Gemini API), including:

  • Free-text work descriptions and revision instructions
  • Voice/audio recordings for transcription
  • Recent time bookings and project names for context
  • Organization industry, country, and team-size information for onboarding recommendations

Legal basis: Art. 6 para. 1 lit. b GDPR (providing requested AI features) and Art. 6 para. 1 lit. f GDPR where applicable.

AI-generated output may be inaccurate. Users and organizations remain responsible for reviewing entries before relying on them.

6. reCAPTCHA on Public Forms

We use Google reCAPTCHA v3 on public-facing forms (including registration, login, password reset, organization registration, and invite requests) to detect and prevent automated abuse. Google acts as our data processor under Art. 28 GDPR.

When you consent, Google may process device and browser metadata and interaction signals for abuse detection and risk scoring. The reCAPTCHA script is loaded from google.com/recaptcha only after consent and may remain active across jidAI during your browser session; our servers verify tokens via Google's siteverify API.

Legal basis: Art. 6 para. 1 lit. a GDPR (consent). You can withdraw consent at any time via the manage-consent option on protected forms.

See also our Cookie Policy.

7. Recipients and Sub-processors

We use the following categories of recipients and sub-processors to operate jidAI:

  • Google Cloud Platform (hosting, database, storage): Infrastructure in europe-west3 (Frankfurt, Germany).
  • Google Gemini API: AI processing as described above.
  • Google reCAPTCHA: Bot detection on public forms (data processor under Art. 28 GDPR).
  • Google Workspace / Gmail API: Sending transactional emails.
  • EU VIES REST API: VAT number validation (country code and VAT number only).
  • nager.date: Public holiday data (country and year only; no personal data).

Sub-processors are engaged under data processing agreements pursuant to Art. 28 GDPR where required.

8. International Transfers

Primary hosting and database storage are in the EU (Google Cloud, region europe-west3). Some Google services (including Gemini API and reCAPTCHA) may involve processing outside the EU/EEA, in particular in the United States.

Where required, transfers are safeguarded by appropriate measures under Art. 44 et seq. GDPR, such as EU Standard Contractual Clauses and Google's data protection terms.

9. Controller and Processor Roles (Business Customers)

When an organization uses jidAI for its employees' time tracking, the organization is generally the controller for employee personal data processed within the service. Silvertip IT-Solutions GmbH acts as a processor for that data, processing it on the organization's instructions to provide jidAI.

For account, billing, and website-related processing, Silvertip IT-Solutions GmbH may act as controller. A data processing agreement (DPA) is available for business customers on request.

10. Storage Duration

  • Account and organization data: Stored for the duration of the contractual relationship and deleted or anonymized thereafter, subject to statutory retention obligations.
  • Time-tracking data: Stored for as long as the organization maintains the account and as required by the organization's policies and applicable law.
  • Server log files: Stored for up to 14 days for security purposes, then deleted.
  • Email send logs: Retained as needed for rate limiting and security, then deleted.
  • Invite/waitlist requests: Retained until processed and no longer needed, then deleted.
  • reCAPTCHA security audit log: Non-personal verification outcomes retained for up to 90 days for abuse monitoring and debugging, then deleted.

11. Your Rights

You have the following rights regarding your personal data, subject to legal conditions:

  • Access (Art. 15 GDPR)
  • Rectification (Art. 16 GDPR)
  • Erasure (Art. 17 GDPR)
  • Restriction of processing (Art. 18 GDPR)
  • Data portability (Art. 20 GDPR)
  • Objection (Art. 21 GDPR) to processing based on legitimate interests

To exercise your rights, contact us at info@silvertip-it.at. If you are an employee user, your organization may also be the controller — contact your employer where appropriate.

12. Right to Lodge a Complaint

You may lodge a complaint with a supervisory authority. In Austria, the competent authority is:

  • Austrian Data Protection Authority (Österreichische Datenschutzbehörde)
  • Barichgasse 40–42, 1030 Vienna
  • Email: dsb@dsb.gv.at | Web: www.dsb.gv.at

13. Data Security

We implement appropriate technical and organizational measures to protect personal data, including TLS encryption in transit, password hashing (bcrypt), access controls, and infrastructure security on Google Cloud. Security measures are reviewed and updated as technology evolves.

14. Cookies and Local Storage

We use strictly necessary cookies and browser storage for language selection (NEXT_LOCALE), storing your reCAPTCHA consent decision (jidai_recaptcha_consent), authentication (refresh_token), and theme/session preferences. After your consent, jidAI also uses Google reCAPTCHA for abuse detection and session-based risk scoring. Details are in our Cookie Policy.

15. Changes to This Privacy Policy

We may update this privacy policy to reflect legal requirements or changes to jidAI. The current version applies on your next visit or use of the service after publication.