Privacy Policy

Last updated: 2026-07-26

About this policy

This Privacy Policy explains how timeghost Solutions GmbH ("we", "us", "our") processes personal data in connection with our Company Contacts CRM application (the "Service"), embedded in Microsoft Teams, and our websites.

1. Controller

timeghost Solutions GmbH
Reichenaustr. 11a, 78467 Konstanz, Germany
Email: info@timeghost.io | Phone: +49 7531 9783000
(Registered: Amtsgericht Freiburg, HRB 729216)

2. Data Protection Officer

In accordance with Art. 37 GDPR and Sec. 38 BDSG we have appointed a Data Protection Officer: Sven Weiser – c/o timeghost Solutions GmbH, Reichenaustr. 11a, 78467 Konstanz, Germany. Email: info@timeghost.io

3. Controller vs. processor

  • Data you and your colleagues store in a workspace (contacts, companies, comments, tags = "Customer Data") is controlled by your organisation. We process it as a processor under a Data Processing Agreement (Art. 28 GDPR). A DPA is available on request.
  • For account, billing, website and security data we act as controller. This Policy mainly describes that controller processing.

4. Categories of personal data

  • Account & profile data: name, business email, profile photo, language, Microsoft 365 user ID, workspace roles. Where your organisation provides it, optionally birthdate and hire date.
  • Authentication data: Microsoft 365 / Azure AD SSO (we never receive your Microsoft password, only OAuth tokens for the access you authorise).
  • Microsoft Graph data (see Section 5).
  • Contact & company data you import, create or sync ("Customer Data").
  • Email campaign data: recipient lists, content, send status.
  • Log & usage data: server log files (browser type/version, OS, referrer URL, hostname, request time, IP address).
  • Billing data (paid plans): billing name, address, VAT number; payment data is handled by our payment provider (see Section 8).
  • Support communications.

5. Microsoft 365 integration and permissions

The Service integrates with Microsoft 365 via Microsoft Graph. Depending on the features your organisation enables and consents to, we request the following scopes for the stated purpose only:

  • Sign-in & basic profile (openid, email, profile, offline_access, User.Read): authentication and profile display.
  • Read directory users: import/synchronise Active Directory / Microsoft 365 users as contacts.
  • Read/write Outlook contacts (Contacts): synchronise contacts with Outlook.
  • Read email (Mail.Read): to show your email history with contacts, for the optional email signature scan (Section 6), and — if the AI mail feature is used — to detect whether an AI-drafted email was sent from your mailbox and whether replies have arrived (Section 6a).
  • Create email drafts (Mail.ReadWrite) and send email (Mail.Send): only for the email campaign feature; emails are created/sent via your own mailbox.
  • Read mailbox settings (MailboxSettings.Read): to respect your mailbox configuration.

You can withdraw these permissions at any time via Microsoft 365, your administrator, or the app's profile/Microsoft settings. OAuth tokens obtained through these permissions are stored encrypted (AES-256-GCM) in our database.

6. Email signature scan (optional)

If enabled, the scan reads the emails of your own inbox for the selected period (including the message text) to extract contact data from email signatures. The extraction is performed within the Service; only the extracted contact fields and the detected signature text are stored, and scan results are deleted automatically after 90 days. Only you decide whether extracted data is applied to a contact. External AI analysis is used for this feature only if it is explicitly enabled for your environment and you have stored your own OpenAI API key; in that case, the signature text or up to 2,000 characters of the end of a message may be transmitted to OpenAI for extraction.

6a. AI mail drafting and send/reply tracking (optional)

If your workspace administrator configures an AI provider, members can draft emails from topic conversations. For draft generation, topic content (including contact and company names) is transmitted to the AI provider selected and contracted by your organisation; your organisation is responsible for the related agreements with that provider.

If a member has additionally granted the Mail.Read permission, the Service checks that member's own mailbox to detect whether a handed-off draft was actually sent and whether replies from the contact have arrived. The subject and body of the detected emails (the sent mail and replies belonging to the same conversation) are stored as part of the related topic and are visible to workspace members who have access to that contact. Scanning is limited to the member's own mailbox, to conversations started via the AI mail feature, and stops when the topic is resolved or archived.

7. Purposes and legal bases (Art. 6 GDPR)

  • Providing/operating the Service and the Microsoft 365 integration — Art. 6(1)(b).
  • Contact/user sync and campaign emails you initiate — Art. 6(1)(b); processing on behalf of your organisation under Art. 28.
  • Security, abuse prevention, logging, monitoring — Art. 6(1)(f).
  • Billing, accounting, tax — Art. 6(1)(b) and (c).
  • Service notifications (Teams bot / email) — Art. 6(1)(b)/(f).
  • Marketing communications and marketing/analytics cookies — Art. 6(1)(a) (consent), revocable any time.
  • Support — Art. 6(1)(b)/(f).

8. Recipients and sub-processors

We use the following service providers under data processing agreements (unless stated otherwise):

  • Microsoft (Microsoft Ireland Operations Ltd. / Microsoft Corporation, USA): Microsoft Azure hosting, Azure AD identity, Microsoft Graph and Microsoft Teams. Essential. Transfers to the USA are based on EU Standard Contractual Clauses.
  • Paddle (Paddle.com Market Limited, 18-29 Mora Street, Judd House, London EC1V 8BT, UK): payment processing / reseller (Merchant of Record) for paid plans. We have no access to your full payment data. Transfer to the UK is based on the EU adequacy decision.
  • Brevo (Sendinblue GmbH, Köpenicker Straße 126, 10179 Berlin, Germany): transactional and notification emails; data stored on servers in Germany.
  • Sentry: error tracking. Per our setup this runs self-hosted within our own infrastructure; data is not shared with a third party.

This list names the main recipients and is not exhaustive; a current list of our sub-processors is available on request.

We may also disclose data to authorities where legally required, and to advisers/auditors or in a corporate transaction, subject to confidentiality.

9. International data transfers

Some recipients (e.g. Microsoft) process data outside the EEA. Such transfers are safeguarded by an adequacy decision (e.g. UK for Paddle) and/or EU Standard Contractual Clauses with supplementary measures. We note that third countries such as the USA may not offer a level of data protection equivalent to the EU.

10. Retention

We retain personal data only as long as necessary for the stated purposes or as legally required. When you delete your account, your personal data is deleted; backups may retain data for up to 14 days before permanent deletion. Accounting-relevant data is retained for the statutory period. Customer Data is retained per your organisation's instructions and deleted upon termination.

11. Your rights

Subject to legal conditions, you have the rights to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and to object (Art. 21). Where processing is based on consent, you may withdraw it at any time (Art. 7(3)).

You also have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR). The competent authority for us is: Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg (LfDI BW), Lautenschlagerstraße 20, 70173 Stuttgart, Germany — https://www.baden-wuerttemberg.datenschutz.de

To exercise your rights, contact info@timeghost.io.

12. Obligation to provide data

A Microsoft 365 account and certain account data are required to use the Service or specific features.

13. Automated decision-making

We do not carry out automated decision-making, including profiling, that produces legal or similarly significant effects (Art. 22 GDPR).

14. Cookies and tracking

The application uses strictly necessary cookies (e.g. session/login) on the basis of Art. 6(1)(f). Our marketing website uses Cookiebot (Cybot A/S, Denmark) for consent management, and — only with your consent — analytics tools such as Google Analytics (Google Ireland Ltd.) and Microsoft Clarity. You can manage or withdraw consent at any time via the cookie settings. We also use Frill.co for product feedback, where Frill.co acts as an independent controller.

15. Security

We maintain appropriate technical and organisational measures, including TLS/SSL encryption. Our information security management system complies with the requirements of ISO 27001.

16. Changes

We may update this Policy. The current version with its "last updated" date is always available on this page.

17. Contact

timeghost Solutions GmbH, Reichenaustr. 11a, 78467 Konstanz, Germany
Email: info@timeghost.io / support@timeghost.io — Phone: +49 7531 9783000