Privacy policy
This privacy policy explains which personal data is processed when you visit yourtinyoffice.com and when you use the application at app.yourtinyoffice.com (the "Service"). Version: 2026-09-19.
1. Controller
CMaier GmbHWebersiedlung 11, 8402 Werndorf, Austria
E-mail: office@cmaier.tech
A data protection officer is not legally required and has not been appointed.
2. Two roles: controller and processor
For the data of website visitors and for the account and contract data of our customers we act as controller within the meaning of Art. 4(7) GDPR.
For the data our customers enter into the Service (in particular data about their own customers and contacts, service and time records, invoice and offer content) we act as processor within the meaning of Art. 28 GDPR. The respective customer is the controller of that data. The legal basis is the Data Processing Agreement, which forms part of our Terms of Service. Data subjects whose data a customer processes with us should direct their requests to that customer; we support the customer in responding.
3. Visiting the website
3.1 Server logs
When you open the website or the Service, the following data is processed as technically necessary: IP address, date and time, requested URL, HTTP status code, browser type and version, operating system, referrer. This data serves secure operation, error analysis and protection against attacks (rate limiting). The legal basis is Art. 6(1)(f) GDPR. Logs are deleted after 14 days.
3.2 Cookies
We only use strictly necessary cookies: an encrypted session cookie (sb_session) for the login and a cookie protecting against cross-site request forgery (csrf_token). They are not used for analytics or advertising and do not require consent (§ 165(3) Austrian Telecommunications Act 2021). We do not use any analytics, tracking or advertising services.
3.3 External content
All fonts, scripts and stylesheets are delivered from our own servers. Opening our pages does not establish connections to third parties (such as Google Fonts or content delivery networks).
4. Registration, account and contract
On registration we process your e-mail address, password (as a hash only), time of registration, the accepted version of the Terms and the company data stored in the account (company name, address, VAT ID, bank details, logo, invoice settings, optionally your own SMTP credentials). The purpose is providing the Service and performing the contract; the legal basis is Art. 6(1)(b) GDPR. Bank details are only printed on the documents you create. SMTP passwords are stored encrypted (AES-256-GCM).
Transactional e-mails (registration confirmation, password reset) are sent through the authentication services of our hosting partner Supabase.
5. Payments
Paid plans are billed through Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Dublin 2, Ireland. We transmit your e-mail address, company or display name and an internal account identifier to Stripe. Stripe collects payment details, billing address and VAT identification number (Stripe Tax) directly from you and is an independent controller for that processing. We never receive full payment details, only a customer identifier and the subscription status. The legal basis is Art. 6(1)(b) GDPR. Stripe's privacy notice: stripe.com/privacy.
6. Service features that query external systems
- VAT ID check: At the customer's request a VAT identification number is sent to the European Commission's VIES system and the result (valid/invalid, registered name and address) is stored. The legal basis is the customer's instruction under the Data Processing Agreement.
- Exchange rates: Reference rates are fetched from the European Central Bank. No personal data is transmitted.
- E-mail dispatch: Invoices and offers are sent by e-mail to the customer's recipients on the customer's instruction, either through our mail server (Hetzner Online GmbH (web hosting mail server)) or through the customer's own SMTP server.
7. Recipients and processors
We use the following service providers, which are bound to us as processors under Art. 28 GDPR:
| Provider | Purpose | Location of processing |
|---|---|---|
| Supabase, Inc., 970 Toa Payoh North #07-04, Singapore 318992 (billing entity: San Francisco, USA) | Authentication, database, file storage, auth e-mails | Data centre eu-west-1 (Ireland) (Amazon Web Services) |
| Amazon Web Services EMEA SARL, Luxembourg (as sub-processor of Supabase) | Infrastructure | eu-west-1 (Ireland) |
| Hetzner Online GmbH, Industriestraße 25, 91710 Gunzenhausen, Germany | Operation of the application (cloud server), PDF generation, server logs; dispatch of invoice and offer e-mails through the web hosting mail server (Free plan) | Germany (EU) |
Transfers to third countries only occur insofar as Supabase, Inc. as a US company has access for support and operational purposes. Such transfers are safeguarded by the EU Commission's Standard Contractual Clauses (Art. 46(2)(c) GDPR) and certification under the EU-US Data Privacy Framework. The data itself is stored in the region named above.
Beyond that, we only disclose data where legally obliged to do so.
8. Retention
- Account and contract data: for the duration of the contract; when the account is deleted, all data of the account including stored documents is removed from the Service immediately and deleted from backups within 30 days unless statutory retention duties require otherwise.
- Billing records (our invoices to customers): 7 years pursuant to § 132 Austrian Federal Fiscal Code (BAO).
- Server logs: 14 days.
- Documents created by the customer: as long as the customer keeps them in the Service; the customer is responsible for meeting their own retention duties (e.g. 7 years under § 132 BAO, 10 years under § 147 German Fiscal Code) and can export documents as PDF at any time.
9. Your rights
You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection (Art. 21 GDPR). Please send requests to office@cmaier.tech. You may also lodge a complaint with the supervisory authority: Austrian Data Protection Authority, Barichgasse 40–42, 1030 Vienna, dsb.gv.at.
10. Security
All transmissions are encrypted (TLS). Customer data is separated per tenant at the database level (row level security), sessions are encrypted and bound to HttpOnly cookies, and stored credentials are encrypted. Further technical and organisational measures are described in Annex 2 of the Data Processing Agreement.
11. No automated decision-making
No automated decision-making, including profiling, within the meaning of Art. 22 GDPR takes place.
12. Changes
We update this policy when the Service or the legal situation changes. The current version is always available at this address.