WorkTime for Nextcloud

Privacy Policy – WorkTime Mobile (App) · Last updated: 25 July 2026

1. Who is responsible?

Responsibility for this app is split:

  • For your working-time, project and absence data, your employer or the operator of the Nextcloud instance the app connects to is responsible. That is where this data is stored and processed (via the Nextcloud app “WorkTime”). For access, correction or deletion of this data, please contact your employer or the controller named there.
  • For providing the app itself, the responsible party is:
    cpcMomentum GmbH, Guttenbrunnstraße 7, 71067 Sindelfingen, Germany, email: info@cpcmomentum.com
    (full details in the legal notice).

cpcMomentum operates no servers of its own for this app and neither receives nor stores any of your working-time data.

2. What data does the app process – and where?

The app is a pure client to your Nextcloud. Only the following is stored on your device:

  • Connection token (app password): When you sign in via the Nextcloud login flow, the app receives an access token. It is stored OS-encrypted in the iOS keychain / Android keystore. It does not replace a password and can be revoked at any time in your Nextcloud security settings.
  • App settings (e.g. server address, last selected month) – not personal data.
  • Working-time data for display: Time entries, absences and reports are loaded from your Nextcloud on demand, used only for display and not stored permanently in the app.

When you sign out, all local data (token and caches) is completely deleted from the device.

3. Data transfers

  • The app communicates exclusively with the Nextcloud instance you specify, encrypted via HTTPS.
  • There is no transfer to cpcMomentum, to third-party servers, or to analytics/advertising services.
  • The app contains no tracking, no analytics tools and no advertising.

4. Biometric app lock (Face ID / Touch ID / device passcode)

To protect the app, it can require unlocking with Face ID / Touch ID or your device passcode when opened. This check is performed entirely by your device's operating system. The app only receives “unlocked successfully: yes/no”. Biometric data never leaves the device and is neither stored nor processed by the app.

5. Legal basis

Where the app processes personal data (essentially the connection token), it does so to carry out the function you requested – connecting to your Nextcloud (Art. 6(1)(b) and (f) GDPR). The actual processing of the working-time data is carried out by the controller named in section 1.

6. Retention

Local data is stored for as long as you are signed in and is deleted when you sign out. The token can additionally be revoked server-side in your Nextcloud security settings.

7. Your rights

You have the rights granted by the GDPR (access, rectification, erasure, restriction, data portability, objection).

  • For your working-time data, contact the operator of your Nextcloud (section 1).
  • For the app-related local processing, signing out is normally sufficient; if you have questions, contact cpcMomentum (section 1).

You also have the right to lodge a complaint with a data protection supervisory authority.

8. App stores

The app is obtained via the Apple App Store or Google Play. When you download and use these platforms, Apple and Google process data as controllers in their own right under their own privacy policies. cpcMomentum has no influence over this.

9. Changes

This privacy policy will be adapted as needed to changed functionality or legal requirements. The version published at this address applies.

10. Language

This English text is a translation provided for your convenience. The German version is the authoritative one; in case of any discrepancy or dispute, the German wording prevails. The German version is available at https://cpcmomentum.com/datenschutzworktimeapp.html.