Privacy Policy
This privacy policy explains how personal data is processed when using Projectory and which rights data subjects have.
Controller
Responsible organization / person: Guarded Data Solutions / Theresa Meiksner
Address: Rechte Wienzeile 229
Email: support@guarded-data.at
What data is processed in Projectory
- Account data (e.g. display name, email address, role, language, theme preferences)
- Authentication and security data (password hash, session data, login attempts, IP addresses, user agent, MFA data, trusted-device status)
- Project collaboration data (projects, members, work packages, comments, mentions, notifications, time bookings)
- Uploaded files and attachments (which may contain personal data depending on user content)
- Administrative and security logs (audit events, IP bans, system settings changes)
Purposes and legal bases
| Purpose | Typical data | Possible legal basis |
|---|---|---|
| Providing user accounts and project collaboration features | Account data, project/work package content, comments, time bookings | Contract performance (Art. 6(1)(b) GDPR) or legitimate interests (Art. 6(1)(f) GDPR), depending on your setup |
| Securing the application and preventing abuse | Login attempts, IP addresses, session fingerprints, audit logs, MFA data | Legitimate interests (Art. 6(1)(f) GDPR) and legal obligations where applicable |
| System administration and support | User management data, logs, configuration changes | Legitimate interests (Art. 6(1)(f) GDPR) |
Recipients / processors
Personal data is only shared with processors required to operate Projectory (for example hosting, infrastructure, email delivery, and backup services).
All processors are selected with appropriate privacy and security guarantees and are contractually bound where required by law.
Retention periods
- Active account and project data is typically stored for the duration of use and deleted/anonymized according to your retention policy.
- Security logs and audit records may be retained longer to investigate abuse and meet accountability requirements.
- Backups may continue to contain personal data until overwritten according to the backup cycle.
Data is deleted or anonymized when it is no longer required for service provision, security, or legal obligations.
Data subject rights
- Right of access, rectification, and erasure
- Right to restriction of processing
- Right to data portability
- Right to object (where processing is based on legitimate interests)
- Right to lodge a complaint with a supervisory authority
Cookies and local storage
Projectory currently uses technical/functional cookies and browser storage for authentication, security, and UI preferences. A current overview is available on the imprint page.
Security measures
Projectory includes technical and organizational measures such as authenticated access controls, role-based permissions, session security checks, audit logging, and optional multi-factor authentication.
Changes to this privacy policy
This privacy policy should be reviewed and updated whenever processing activities, service providers, or legal requirements change.
Last reviewed: 2026-07-27