Privacy Policy

This privacy policy explains how personal data is processed when using Projectory and which rights data subjects have.

Controller

Responsible organization / person: Guarded Data Solutions / Theresa Meiksner

Address: Rechte Wienzeile 229

Email: support@guarded-data.at

What data is processed in Projectory

  • Account data (e.g. display name, email address, role, language, theme preferences)
  • Authentication and security data (password hash, session data, login attempts, IP addresses, user agent, MFA data, trusted-device status)
  • Project collaboration data (projects, members, work packages, comments, mentions, notifications, time bookings)
  • Uploaded files and attachments (which may contain personal data depending on user content)
  • Administrative and security logs (audit events, IP bans, system settings changes)

Purposes and legal bases

Purpose Typical data Possible legal basis
Providing user accounts and project collaboration features Account data, project/work package content, comments, time bookings Contract performance (Art. 6(1)(b) GDPR) or legitimate interests (Art. 6(1)(f) GDPR), depending on your setup
Securing the application and preventing abuse Login attempts, IP addresses, session fingerprints, audit logs, MFA data Legitimate interests (Art. 6(1)(f) GDPR) and legal obligations where applicable
System administration and support User management data, logs, configuration changes Legitimate interests (Art. 6(1)(f) GDPR)

Recipients / processors

Personal data is only shared with processors required to operate Projectory (for example hosting, infrastructure, email delivery, and backup services).

All processors are selected with appropriate privacy and security guarantees and are contractually bound where required by law.

Retention periods

  • Active account and project data is typically stored for the duration of use and deleted/anonymized according to your retention policy.
  • Security logs and audit records may be retained longer to investigate abuse and meet accountability requirements.
  • Backups may continue to contain personal data until overwritten according to the backup cycle.

Data is deleted or anonymized when it is no longer required for service provision, security, or legal obligations.

Data subject rights

  • Right of access, rectification, and erasure
  • Right to restriction of processing
  • Right to data portability
  • Right to object (where processing is based on legitimate interests)
  • Right to lodge a complaint with a supervisory authority

Cookies and local storage

Projectory currently uses technical/functional cookies and browser storage for authentication, security, and UI preferences. A current overview is available on the imprint page.

Open imprint (technical cookies & storage overview)

Security measures

Projectory includes technical and organizational measures such as authenticated access controls, role-based permissions, session security checks, audit logging, and optional multi-factor authentication.

Changes to this privacy policy

This privacy policy should be reviewed and updated whenever processing activities, service providers, or legal requirements change.

Last reviewed: 2026-07-27