Privacy Policy
Last updated: June 2026 · Version 1.0
Controller
Controller for the processing of personal data under the GDPR:
innoX-IT GmbH, Kapellenweg 8, 4651 Stadl-Paura, Austria · [email protected].
Overview: two roles
This policy covers two situations. Part A concerns visiting this website — here innoX-IT is the controller. Part B concerns using the iXTime software — for account and billing data innoX-IT is controller, while for the time and employee data entered by customers innoX-IT acts as a processor on behalf of the respective customer.
Part A — Visiting this website
Server log files
When you access the site, technically necessary data is processed (IP address, date/time, page, browser/OS, referrer). Legal basis: Art. 6(1)(f) GDPR (legitimate interest in secure, stable operation). Processing takes place in the EU region (Microsoft Azure, West Europe); the data is deleted after 30 days at the latest.
Hosting
This website is hosted in the EU region of Microsoft Azure (West Europe). A data processing agreement is in place.
Cloudflare (Cloudflare, Inc., USA) sits in front of the hosting as a CDN/reverse proxy and DNS provider; it processes technical connection data including the IP address. The third-country transfer is based on a data processing agreement and the EU-US Data Privacy Framework / Standard Contractual Clauses.
Cookies & fonts
This website sets no cookies of its own and embeds no analytics or tracking services. Fonts are served locally from our own server; nothing is transmitted to third parties (such as Google Fonts).
Contact
If you contact us by email, we process your details to handle the request (Art. 6(1)(b)/(f) GDPR).
Payments
Payments are handled via Stripe. Payment data is processed directly by Stripe; we do not store full card data.
Part B — Using the iXTime software
Account & billing data (controller)
For registration and billing we process name, email, workspace data, role and billing information. Legal basis: contract performance (Art. 6(1)(b)) and legal obligations (lit. c).
Sign-in via Microsoft Entra
Sign-in uses Microsoft Entra ID. Authentication data is exchanged between you, Microsoft and us. We do not store passwords.
Time & employee data (processor)
Content that customers enter into iXTime — tracked time, projects, activities and employee details — is processed strictly on the customer’s instructions. The customer is the controller. The basis is a data processing agreement (see Terms & DPA).
Location & retention
Processing takes place in the EU region (Microsoft Azure, West Europe). Account data is stored for the term of the contract; customer data is deleted or returned after termination per the DPA. Statutory retention periods remain unaffected.
Sub-processors
We use the following providers to deliver the service. Data processing agreements are in place with all of them:
| Provider | Purpose | Region |
|---|---|---|
| Microsoft Azure | Hosting, database, authentication (Entra) | EU — West Europe |
| Stripe | Payment processing | EU / USA (SCCs) |
| Microsoft Azure Communication Services | Transactional & invitation emails | EU — Germany |
| Cloudflare, Inc. | CDN/reverse proxy, DNS, bot protection (Turnstile), email forwarding (info@) | USA (DPF/SCCs) |
Your rights
You have the right to access, rectification, erasure, restriction, data portability and objection (Art. 15–21 GDPR) and to lodge a complaint with the supervisory authority. For data processed on a customer’s behalf, please address your request to that customer (controller); we support them.
Supervisory authority
Austrian Data Protection Authority, Barichgasse 40–42, 1030 Vienna · dsb.gv.at.