§ Law & obligations · 7 min read
What Zeitflex stores about me — the data access report
Why you do not have to ask anyone for it
The right of access under Art. 15 GDPR is a personal right. Anyone working as a kitchen assistant, carer or journeyman who wants to know what is stored about them should not have to ask the boss for it — that is, precisely the person whose curiosity the right also protects against.
That is why in Zeitflex every account can trigger its own access report, regardless of the role. Your employer remains responsible for your employee data; Zeitflex processes it on the employer's behalf (Art. 28 GDPR). The access report is the technical support Zeitflex has committed to in the data processing agreement — see data processing agreement (in German).
How to get your access report
In the browser:
- Open Settings → Data & deletion tab.
- In the My data access request (Art. 15 GDPR) card, click Download data copy.
- The browser saves two files: a readable version for printing (Markdown) and a JSON file for further processing.
In the phone app:
- Open More → My data.
- Tap Create data report.
- The app opens the phone's share dialogue with the readable version. This lets you email the text to yourself or save it in your files. The JSON file is only available in the browser.
Both are limited to three access reports per hour; after that, Zeitflex waits 30 minutes. Building the report reads the complete data set about you — this is not a button for continuous use. Every access report is noted in the change log, because it contains everything about one person in one place.
What the access report contains
The access report is divided into eleven sections. Each one states purpose, legal basis and storage period — as required by Art. 15(1)(a) and (d) GDPR.
| Section | Content | Storage period |
|---|---|---|
| Master data | Name, email, role, personnel number, date of birth (youth employment protection only), type of employment, hourly wage or monthly salary, weekly target time, vacation days, start and leaving date | Duration of employment, then anonymisation after 3 months |
| Working times | Clock-in, clock-out, type, source, status, whether a location was recorded, reason for correction | 2 years |
| Location data | Coordinates when clocking in and out, if the business has activated GPS | 6 months |
| Absences | Vacation, sickness, other, with status, comment, whether supporting evidence is stored | 2 years |
| Health data — documents | Only the metadata of your documents — sick notes as well as other files stored about you: category, file name, size, upload and deletion date | Sick notes 2 years after the end of the absence |
| Access to health data | Who viewed your documents and when, including denied attempts | 3 years |
| Shift plan | Your shifts and the number of your shift swap processes | 2 years |
| Payroll preparation | Per payroll period: working time, breaks, overtime, base pay, premiums, gross pay | 6 years from the end of the year |
| Log and usage data | What you did and what was done with your data, with IP address | 3 years |
| Devices and sign-ins | Push devices and app sign-ins, device identifier and times only | 30 days after expiry |
| Team chat | Your group memberships and your own messages in full text | between 7 and 90 days, depending on the group |
Corrections to working times never replace an entry, but create a new version with a reason. The JSON file contains both versions — this is the legally required protection against manipulation, and it protects you too.
What is deliberately not included
- Password and terminal PIN. Both exist only as an irreversible hash. Even the operator cannot read the value.
- The files themselves. A medical certificate is not attached to the access report. Experience shows an access report gets forwarded by email; a health document should not be. The file remains stored encrypted and can only be reached via the logged download.
- Other people's messages from the team chat. Only your own lines are listed — even if the business requested the access report.
- A payslip. Zeitflex prepares payroll and exports the transaction data; the final payroll is produced by the employer or their payroll office, and separate retention periods apply there.
Who receives your data
Art. 15(1)(c) GDPR requires the recipients to be named. Every access report lists the same four groups:
- Management and supervisors of your own business, role-based.
- The business's tax adviser or payroll office — only pay and time data, no documents and no health data.
- Hosting and infrastructure providers as processors (Annex 2 of the data processing agreement).
- Authorities, where legally required — for example customs (FKS, German financial control of undeclared work) under § 17 MiLoG (German Minimum Wage Act).
Who has viewed my medical certificate?
This is the most interesting line in the entire access report, and you do not need to download a file for it. In the My data at a glance card (browser) or under More → My data → Who has viewed my documents? (app) you can see the most recent accesses to your documents: time, name, role and whether the document was viewed, access was denied or the document was deleted.
This works because every retrieval of a sick note is logged — the successful one as well as the denied one. Only you, the owner and management may see your medical certificates. The tax adviser has no access to documents.
Rectification, erasure, deleting your account
Rectification and erasure (Art. 16 and 17 GDPR) are requests you address to your employer — it is the controller within the meaning of the GDPR. Where statutory retention obligations prevent erasure (working times under § 16 Abs. 2 ArbZG (German Working Hours Act) and § 17 Abs. 1 MiLoG, payroll records under § 41 EStG (German Income Tax Act)), the data is instead anonymised and blocked. The individual periods are set out under Retention periods.
You request Delete account in the phone app under More → Delete account. The request receives a case number and goes to Zeitflex and your business. A response within 30 days is promised (Art. 12(3) GDPR). Nothing is deleted immediately — the business must retain working-time records; name, email and access are anonymised after the retention periods. This request is not available in the browser; there you find instead the deletion of the entire business, which only the owner can trigger.
Further rights listed in every access report: restriction of processing (Art. 18), objection (Art. 21) and complaint to a supervisory authority (Art. 77 GDPR).
When the business creates the access report for you
If a person makes the request outside the app — for example after leaving, when their access has already been deactivated — the employer must still be able to respond. Owners and management can therefore trigger the same access report for a person under Employees. This is logged, and the person concerned receives a push notification “Data access report created” that cannot be switched off. The tax adviser cannot create access reports.
Cookies and storage in the browser
The access report above covers the data on our server. In the browser itself, Zeitflex only stores what is needed for sign-in, security and your own settings — such as language, light or dark appearance and clock-ins made without a connection until they have been sent. Anything else only with your consent: today that is only the referral code from a referral link (cookie stempo_ref, 30 days). No tracking or advertising tools are included.
The complete list with purpose, provider and storage period is under Cookie settings at the bottom of every page. You can change your choice there at any time; if you withdraw your consent, your referral code is deleted immediately.
Still stuck?
Questions about the content of your data are clarified by your business; for technical problems, support can help. How long which data is kept is set out under Retention periods; what happens when someone leaves, under An employee leaves.
Last checked on . We check every article against the application — if something no longer matches, that is a bug and not a difference of opinion.
Was this helpful?
Related articles
- Retention periodsHow long working-time data, sick notes and payroll records must be kept, which periods Zeitflex has set for each type of data, and what the nightly deletion run does.
- Employment contract, records, photos: documents in ZeitflexFour document types, clear visibility, fixed deletion periods — and why the tax adviser sees nothing here.
- An employee leaves: deactivate, leaving date, what remainsDeactivate instead of delete — from the next billing period the seat costs nothing, the times remain auditable, and after three months the person disappears from the names.