GDPR

Roles, rights and retention

What we are responsible for, what you are responsible for, and what actually happens when you ask for data to be deleted.

Who is what

For the budget data inside your workspace, you are the controller and itbudgit is the processor. You decide what goes in; we process it on your instructions in order to provide the service.

For your own account and billing data (the person who signed up, the company being invoiced) itbudgit is the controller.

That split matters for staffing data in particular. A workspace can contain positions with names and salary figures. Those are your employees, entered on your lawful basis, and we hold them only to run the service.

Lawful basis

  • Contract. Providing the service you subscribed to, and billing you for it.
  • Legal obligation. Retaining invoices and financial records for the period tax law requires.
  • Legitimate interest. Keeping the service secure and operable, and contacting you about it.

No processing is based on consent, because there is no marketing tracking to consent to. See Cookies.

Where the data is

Application in Falkenstein, Germany. Database in Frankfurt. Both EU. Two sub-processors are US-headquartered, Stripe and Clerk, and appear on the Sub-processors page with what each one is for.

How long it is kept

  • Your current workspace, for as long as your subscription is active.
  • Revision history. 12 months. The newest revision is never pruned, whatever its age, because an empty trail and a wiped workspace are different facts and must not look the same.
  • Billing records. Excluded from pruning. They are financial records kept under a legal obligation, and that obligation outlives a request to erase.

Your rights, and how erasure really works

Access, rectification, erasure, restriction, portability and objection all apply. Portability is immediate and needs no request: Export a workbook writes everything to an .xlsx file that is yours, opens in Excel, and restores completely.

Erasure is run by a person against the live database, deliberately. It is not an endpoint a browser can call, for the same reason provisioning is not: it is an irreversible act with money and obligations attached. Three guards:

  • The workspace name must be typed back exactly. A yes/no prompt is one people answer without reading.
  • A final export is taken first, and if that export fails, the erasure aborts.
  • A live subscription refuses to erase unless explicitly forced.

It cannot erase Stripe, and it says so every time it runs. The customer record can be deleted there; the invoices cannot and should not be, because a legal retention obligation outlives a request to erase. Nobody will be told everything is gone while an invoice carrying their address is on file.

Breach notification

Customers are notified without undue delay, and within 72 hours of us becoming aware, where a breach is likely to affect their data.

Contact

Data protection requests: get in touch. There is no separate DPO. itbudgit is below the threshold that requires one, and saying otherwise would be an invention.


Security & compliance: Trust · Security · GDPR · Sub-processors · DPA · Privacy · Terms · Cookies

Questions a page here does not answer: get in touch.