v1.0 · 08.08.2026
Status: 08.08.2026 Scope: GDPR Art. 13, 14, LOPDGDD (Spain) Controller: flowgeist
The Controller within the meaning of the General Data Protection Regulation (GDPR) and the Spanish Data Protection Act (LOPDGDD — Ley Orgánica de Protección de Datos Personales y Garantía de los Derechos Digitales) is:
flowgeist Owner: Ralf Carsjens Eidamshauser Straße 13 40822 Mettmann Germany
Email: info@flowgeist.de Web: https://combijornada.es
Data Protection Officer: Pursuant to Art. 37 GDPR and § 38 BDSG, no Data Protection Officer has been appointed at this time. Internal contact person for data protection matters: datenschutz@flowgeist.de (interim).
This Privacy Policy informs about the processing of personal data by the CombiJornada platform (working time and shift planning / Jornada management). The platform is designed for companies based in Spain and is operated by flowgeist as the Controller.
Regulation (EU) 2016/679 (General Data Protection Regulation — GDPR) and the Spanish Data Protection Act Ley Orgánica 3/2018 de Protección de Datos Personales y Garantía de los Derechos Digitales (LOPDGDD) apply. Where employee data is processed, Art. 88 GDPR and Spanish labor law (Estatuto de los Trabajadores, in particular Art. 34) also apply.
The CombiJornada platform processes the following categories of personal data:
| Category | Description | Examples |
|---|---|---|
| Master data | Basic identification and contact data | Name, first name, email address, company name, address, telephone number |
| Working time data | Data for working time recording | Start of work, end of work, break times, overtime, flextime |
| Shift and duty schedule data | Data for shift and duty planning | Shift times, duty assignments, assignment of employee ↔ shift |
| Vacation and absence data | Data for vacation and absence management | Vacation requests, approval status, sick/absence days |
| Access data | Authentication data | NextAuth + JWT, password hash, session token, user roles |
| Documents | Uploaded files | Employment contracts, shift schedules as PDF, absence certificates |
| Audit data | Logging of system accesses | Login times, executed actions, IP addresses, user identifiers |
| Billing data | Payment and billing data | Stripe Customer ID, billing address, transaction references |
The processing of personal data serves the following purposes:
The processing of personal data is based on the following legal grounds:
| Legal basis | Scope of application |
|---|---|
| Art. 6(1)(b) GDPR | Contract performance — processing for the fulfillment of the SaaS contract (working time recording, shift planning, vacation management, reporting) |
| Art. 6(1)(f) GDPR | Legitimate interest — audit logging, security, abuse detection, system stability |
| Art. 88 GDPR | Employee data — processing of employee data in the employment context in accordance with national law (LOPDGDD / Spanish labor law) |
| Art. 22 LOPDGDD | Spanish implementation of employee data processing pursuant to Art. 88 GDPR |
Where special categories of personal data (Art. 9 GDPR) are processed (e.g. sick/absence data), this is done on the basis of Art. 9(2)(b) GDPR in conjunction with Art. 88 GDPR and Art. 22 LOPDGDD (employment and social security law).
Personal data is disclosed to the following recipients:
| Recipient | Registered office | Purpose | Third-country transfer |
|---|---|---|---|
| Hetzner Online GmbH | Germany (Falkenstein) | Hosting, PostgreSQL database, Redis, backup | None (EU) |
| Stripe Payments Europe, Ltd. | Ireland (IE) / USA (US parent company) | Payment processing, invoicing | EU-US Data Privacy Framework + SCC |
| AWS S3 (Amazon Web Services) | USA / EU | File storage (documents, PDFs) | EU-US Data Privacy Framework + SCC |
Further recipients may include: tax advisors, tax authorities (within the framework of statutory retention obligations), IT service providers within the framework of technical operations management (each with a DPA).
The primary processing of personal data takes place in Germany (Hetzner Online GmbH, Falkenstein). A transfer to third countries (outside the EU/EEA) occurs in the following cases:
AWS S3 (USA): File storage is handled via AWS S3. AWS is certified under the EU-US Data Privacy Framework (DPF). In addition, Standard Contractual Clauses (SCC) of the European Commission are concluded. The data transfer is carried out on the basis of Art. 46(2)(c) GDPR (SCC) and Art. 46(2)(f) GDPR (DPF).
Stripe (USA): Payment processing is handled via Stripe Payments Europe, Ltd. (Ireland). Stripe Inc. (USA) as the parent company is certified under the EU-US Data Privacy Framework. In addition, Standard Contractual Clauses (SCC) are applied.
A Transfer Impact Assessment (TIA) was conducted for both third-country transfers. The results of the TIA confirm that there are no reasons to doubt an adequate level of protection.
The retention and deletion periods are based on statutory requirements (GDPR, LOPDGDD, Spanish labor and tax law) as well as on contractual agreements:
| Data category | Storage duration | Legal basis |
|---|---|---|
| Master data | 30 days after end of contract/termination | Termination of contract, GDPR Art. 5(1)(e) |
| Working time data | 4 years | Art. 34 Estatuto de los Trabajadores (Spanish retention obligation for working time records) |
| Shift and duty schedule data | 4 years | Art. 34 Estatuto de los Trabajadores |
| Vacation and absence data | 4 years | Spanish labor law (retention by analogy) |
| Audit logs | 3 years | Art. 6(1)(f) GDPR (security interest) |
| Billing data | 10 years | § 147 AO or Spanish tax law (Art. 67 LGT — Ley General Tributaria) |
| Access data / password hashes | 30 days after end of contract | GDPR Art. 5(1)(e) |
After expiry of the respective period, the data is deleted or anonymized, unless further statutory retention obligations conflict with such deletion.
As a data subject, you have the following rights under the GDPR and the LOPDGDD:
You have the right to request information about the data processed about you, the purposes of processing, the recipients and the planned storage duration.
You have the right to request the rectification of inaccurate or the completion of incomplete personal data.
You have the right to request the erasure of your personal data, provided that the processing is not necessary for the fulfillment of a legal obligation (e.g. retention obligations under Spanish labor law).
You have the right to request the restriction of the processing of your personal data, in particular while a request for rectification or objection is being reviewed.
You have the right to receive the personal data concerning you in a structured, commonly used and machine-readable format and to transmit it to another Controller.
You have the right, on grounds relating to your particular situation, to object to the processing of personal data concerning you which is based on Art. 6(1)(f) GDPR.
You have the right to lodge a complaint with a supervisory authority. The competent authority is either the Spanish Data Protection Authority (AEPD — Agencia Española de Protección de Datos) or the German supervisory authority responsible for flowgeist (LDI NRW — Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen).
To exercise the rights mentioned above, you may contact the Controller at any time:
Please include sufficient identification information with your request to prevent confusion. The Controller will respond to your request within the statutory period of one month (Art. 12(3) GDPR). In exceptional cases, this period may be extended by a further two months, of which you will be informed in due time.
No automated decision-making within the meaning of Art. 22 GDPR takes place. No profiling procedures are used that produce legal effects concerning you or similarly significantly affect you.
The CombiJornada platform uses exclusively technically necessary cookies (session and authentication cookies). These are required to ensure the functionality of the platform (login, session management via NextAuth + JWT).
No analytics cookies, no marketing cookies and no tracking tools are used. There is no tracking by third parties.
The Controller has implemented appropriate technical and organizational measures (TOMs) in accordance with Art. 32 GDPR to ensure a level of security appropriate to the risk:
A detailed register of the TOMs is available on request.
The data protection authority responsible for Spain is:
Agencia Española de Protección de Datos (AEPD) Calle Jorge Juan, 6 28001 Madrid Spain Web: https://www.aepd.es
The AEPD is the supervisory authority responsible for compliance with data protection regulations in Spain pursuant to the LOPDGDD.
The Controller reserves the right to adapt this Privacy Policy to reflect changes in the legal situation (in particular changes to the GDPR, the LOPDGDD or Spanish labor law), court rulings or technical developments. The current version is available on the website at https://combijornada.es/datenschutz.
Customers and their employees will be informed in due time through the platform of material changes that affect the rights of data subjects.
If you have questions about data protection, the processing of your personal data or the exercise of your data subject rights, please contact:
flowgeist Owner: Ralf Carsjens Eidamshauser Straße 13 40822 Mettmann Germany
Email: info@flowgeist.de Data protection: datenschutz@flowgeist.de
If you believe that the processing of your personal data infringes the GDPR or the LOPDGDD, you have the right to lodge a complaint with a data protection supervisory authority:
Germany: Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW) Kavalleriestraße 2-4 40213 Düsseldorf Web: https://www.ldi.nrw.de
Spain: Agencia Española de Protección de Datos (AEPD) Calle Jorge Juan, 6 28001 Madrid Web: https://www.aepd.es
You also have the right to seek a judicial remedy against a decision of the supervisory authority (Art. 78 GDPR).
| Version | Date | Material Changes |
|---|---|---|
| 1.0 | 08.08.2026 | Initial version for CombiJornada |
© 2026 flowgeist – Ralf Carsjens · All rights reserved