In July 2020, the European Court of Justice declared the Privacy Shield agreement invalid in its “Schrems II” ruling. Since then, the USA is no longer considered a safe third country outside the EU for data protection, and it has been established that the USA does not guarantee an adequate level of protection for personal data.
Timebutler servers are operated in a secure data center near Frankfurt am Main (Germany) by a leading hosting provider.
In accordance with the General Data Protection Regulation (GDPR), data is processed exclusively within the EU. A transfer of data to third countries outside the EU takes place only in limited exceptional cases.
Transfers to third countries
Data is transferred to third countries only in specific situations and only with your explicit action or consent.
1. Single Sign-On (SSO)
You can link your Timebutler account with a:
- Google account
- Microsoft account
- Slack account
See: Single Sign-On (SSO) with Microsoft, Google, Slack, OAuth and Azure
If you choose to link your account, technical data is transmitted to these providers in the USA.
Important:
- Linking requires your explicit consent.
- Only technical authentication data is transmitted.
- No content data such as vacation requests or working time balances is shared.
You must already have an account with the selected provider to use this function.
2. Payment processing
When an administrator orders a subscription extension, various payment methods are available.
If you choose:
PayPalCredit card
you are redirected to the payment page of the respective payment service provider, which may be based in the USA.
In this case:
- You actively select the payment method.
- You are redirected to the external provider’s website.
- No content data such as vacation requests or working time balances is transmitted.
More information
We have created a dedicated section where you can find comprehensive information about data protection. Learn more about data protection at Timebutler.