Privacy Policy for the Software "Fairhour" and the Website fairhour.ch
⚠️ Important Notice
This is a non-binding template and does not constitute legal advice. The text must be adapted to your specific situation and reviewed by a qualified lawyer before productive use. No warranty is given as to completeness, accuracy or currency.
This English version is a translation for convenience. In the event of discrepancies, the German version prevails.
Version of: [DATE]
This privacy policy covers two areas:
- Part A: the Windows application "Fairhour"
- Part B: the website fairhour.ch and sales made through it
1. Controller and Contact
The controller for the processing of personal data within the meaning of the Swiss Federal Act on Data Protection (revFADP) and the General Data Protection Regulation (GDPR) is:
[COMPANY NAME] [STREET AND NUMBER] [POSTAL CODE CITY], Switzerland Email: [EMAIL] Phone: [PHONE]
EU representative: [NAME AND ADDRESS OF THE REPRESENTATIVE UNDER ART. 27 GDPR OR: "No EU representative has been appointed, as in our assessment the conditions of Art. 27 GDPR are not met. This assessment should be verified legally."]
Data protection advisor / officer: [NAME AND CONTACT OR: "There is no statutory obligation to appoint one; no person has been appointed."]
2. Core Principle: Your Usage Data Stays on Your Device
2.1 "Fairhour" works without a user account and without a cloud service. All data the Software collects about your program usage is stored exclusively locally on your device.
2.2 By default, storage takes place in an SQLite database file in the directory %LOCALAPPDATA%\PcZeit.
2.3 The Provider has no access to this data. No usage data is transmitted to the Provider, to a cloud service or to third parties. The Software contains no telemetry, no analytics libraries, no advertising identifiers and no crash reporting system that sends data to the Provider.
2.4 The only outside connection: the Software can check whether a newer version is available. This check is switched off by default and only becomes active if you enable it in the settings or trigger it manually. Only the technically unavoidable connection data is transmitted (see section 8). No usage data is transmitted even then. Apart from this check, the Software makes no network connections.
2.5 The Software does not record keystrokes (no keylogging) and does not capture screenshots.
2.6 During operation, the notification area icon in the taskbar is always visible. There is no hidden mode.
Part A – The "Fairhour" Application
3. What Data the App Processes
3.1 The Software processes locally:
| Data category | Description | Default |
|---|---|---|
| Program / process name | Name of the executable, e.g. msedge.exe |
on |
| Display name and path of the program | Label and storage location of the application | on |
| Foreground times | Timestamps for start and end of foreground use | on |
| Usage duration | Aggregated duration per program and day | on |
| Launch count | How often a program was started | on |
| Window titles | Title bar text of the respective window | off |
| Settings | Your configuration, e.g. limits, block lists, language | on |
| Parental module password hash | Verification value of the password you set | only if used |
| Block lists | Websites and programs you have entered | only if used |
| Time requests | Extra minutes requested by the child, with a self-written reason and timestamp | only if used |
| Change log | When which rule was changed, granted or declined | only if used |
| Reports | Generated weekly HTML reports | only if used |
3.2 Window titles: This option is switched off by default. If you switch it on, additional and possibly sensitive information may be stored, for example document names, search terms, subject lines or addresses of visited websites. Enable this option only deliberately and only if all people sharing the device have been informed.
3.3 Blocker: To block websites, the Software writes entries into the system hosts file. This file is on your device. No traffic is routed to the Provider and no visited websites are logged, unless you have enabled the storage of window titles.
3.4 Parental module: Password and settings are stored locally. The password is not stored in plain text. The Provider does not know it and cannot reset it.
3.5 Time requests: If the person using the device asks for extra minutes on the "My time" page, the requested duration, the timestamp and a freely written reason are stored locally. The text is written by the affected person themselves and is visible to the parents. Both the request and the answer appear in the change log, which the person using the device can view without a password. Nothing is transmitted; the request appears as a notification on the same device.
3.6 Reports: Weekly reports are generated and stored locally as HTML files. There is no automatic sending. If you share a report yourself, the data leaves your device at your own instigation.
3.7 Focus mode: Only the end time of the current session and the number of sessions completed today are stored. This information does not leave the device.
4. Purposes and Legal Bases
4.1 The purpose of processing is to provide the contractually agreed functions: measuring usage time, evaluation, limits, reports and blocking.
4.2 Switzerland: Processing is governed by the Federal Act on Data Protection (revFADP). Since the data never leaves your device and the Provider has no access, the Provider does not process personal data about you in connection with your use of the app. You are responsible for the processing that takes place on your own device.
4.3 EU/EEA: Insofar as the GDPR applies: - Processing by you for purely personal or household purposes is generally outside the scope of the GDPR under Art. 2(2)(c) GDPR (household exemption). This exemption does not apply if you use the Software professionally or in relation to third parties outside your private sphere. - Insofar as the Provider processes data itself, for example in connection with the purchase contract or support, it relies on Art. 6(1)(b) GDPR (performance of a contract), Art. 6(1)(c) GDPR (legal obligation, in particular retention duties) and Art. 6(1)(f) GDPR (legitimate interest in secure and functional operation). - Optional features that you enable yourself are based on your own decision; where consent is required, this is Art. 6(1)(a) GDPR. You may withdraw consent at any time with effect for the future by disabling the option.
5. Responsibility When Using the Parental Module
5.1 If you use the parental module to record the device usage of your child or another person, you are yourself the controller within the meaning of data protection law – not the software provider. You determine the purposes and means of processing. The Provider merely supplies a tool and has neither access to the data nor influence over its use.
5.2 As controller, your duties include in particular: a) informing the person concerned transparently and in advance about what is recorded, for how long, and who can view the data; b) collecting only as much data as is necessary for your purpose (proportionality and data minimisation) – enable window titles only if you genuinely need them; c) protecting the data appropriately and deleting it once it is no longer needed; d) respecting the rights of the person concerned, in particular access and erasure.
5.3 Covert surveillance is not permitted. Using the Software to covertly monitor partners, family members, flatmates or employees breaches the license agreement and may be unlawful.
5.4 Depending on the child's age and capacity of judgement, the child's own consent may be required. Practical guidance is provided in the document "Guidance for Parents".
5.5 Use in relation to employees is subject to additional employment law requirements. Covert monitoring of employee conduct and performance is generally not permitted under Swiss employment law. Obtain legal advice before any such use.
6. Retention and Deletion of App Data
6.1 The data remains on your device until you delete it. The Provider can neither view nor delete it.
6.2 In the settings you can define an automatic retention period ([DEFAULT RETENTION PERIOD, e.g. 90 days]). Older entries are then removed automatically.
6.3 You can delete individual entries, specific periods or the entire data set at any time through the settings.
6.4 When the Software is uninstalled, the stored data [IS / IS NOT] removed automatically. For complete removal, additionally delete the directory %LOCALAPPDATA%\PcZeit.
6.5 Data can be exported through the export function in the formats [FORMATS, e.g. CSV, JSON].
7. Security of the App Data
7.1 The data resides in the profile of your Windows user account and is therefore subject to the access rights of the operating system.
7.2 You are responsible for protecting the device. We recommend a password-protected user account, current security updates and, where appropriate, full disk encryption (BitLocker).
7.3 [OPTIONAL: The database file is additionally protected using [METHOD].]
7.4 The password protection of the parental module protects against access via the Software's user interface. It does not replace encryption of the storage medium.
8. App Updates
8.1 When obtained through the Microsoft Store, updates are delivered by the Store. Microsoft processes data in that context as its own controller under its own terms.
8.2 When obtained from fairhour.ch, the Software can check once a week whether a new version is available. This check is switched off as delivered. It is only performed if you enable it under "Settings → Updates" or trigger it manually there.
8.3 How the check works: the Software retrieves a static text file at [ADDRESS OF THE CHECK FILE, e.g. https://updates.fairhour.ch/win/latest.json]. The request deliberately contains no device identifier, no license number and no version number in the query string. The comparison with your installed version happens exclusively on your device.
8.4 As with any web page request, technically unavoidable connection data is transmitted to the server and recorded in its log files: IP address, timestamp, the file requested and the identifier "PcZeit-Update". These log files are deleted after [RETENTION PERIOD, e.g. 30 days] (see section 9). The legal basis is Art. 6(1)(f) GDPR, legitimate interest in current and secure software.
8.5 Nothing is downloaded or installed automatically. If a newer version is found you receive a notice; the decision to download it is yours.
8.6 An online license check [DOES NOT TAKE PLACE]. License keys are verified offline on your device; no connection is made. [SHOULD THIS CHANGE: The license key, an anonymous device identifier and the IP address are transmitted and stored for [PERIOD]. The purpose is the prevention of misuse; the legal bases are Art. 6(1)(b) and (f) GDPR.]
Part B – Website and Sales
9. Server Log Files
9.1 When you access fairhour.ch, the hosting provider automatically records data in log files: - IP address of the requesting device - date and time of access - page or file requested - volume of data transferred and status code - referrer URL - browser type, browser version and operating system
9.2 The purpose is the secure and stable operation of the website and the defence against attacks.
9.3 The legal basis is Art. 6(1)(f) GDPR, legitimate interest in secure operation; in Switzerland, processing is based on the overriding interest in ensuring operation under the revFADP.
9.4 Log files are deleted after [RETENTION PERIOD, e.g. 30 days], unless a security incident requires longer retention.
9.5 Hosting provider: [HOSTING PROVIDER, NAME AND LOCATION]. A data processing agreement in accordance with Art. 28 GDPR is in place with this provider.
10. Cookies and Web Analytics
10.1 [IF ONLY STRICTLY NECESSARY COOKIES: The website uses only technically necessary cookies. These are required for operation and do not store information for analytics or advertising purposes.]
10.2 [IF ANALYTICS IS USED: The website uses [ANALYTICS SERVICE, e.g. Matomo, Plausible] for web analytics. Provider: [NAME AND LOCATION]. Data collected: [DATA CATEGORIES]. Retention: [PERIOD]. Legal basis: consent under Art. 6(1)(a) GDPR, given through the cookie banner, revocable at any time at [LINK TO COOKIE SETTINGS].]
10.3 You can delete cookies in your browser and disable their storage. This may limit the functionality of the website.
10.4 [EMBEDDED SERVICES, if any: fonts, videos, maps, chat. For each service, state the provider, purpose, data, legal basis and retention period. Recommendation: host fonts locally so that no connection to third parties is established.]
11. Purchase and Payment Processing
11.1 Sales via fairhour.ch are processed through [PADDLE OR LEMON SQUEEZY]. This provider acts as merchant of record, meaning it is your contractual partner for the payment transaction and is responsible for invoicing and remitting taxes.
11.2 [PADDLE OR LEMON SQUEEZY] processes payment data as an independent controller. The Provider has no access to full credit card numbers or bank details.
11.3 Payment service provider: [NAME AND FULL ADDRESS OF THE PAYMENT SERVICE PROVIDER] Privacy policy: [LINK TO THE PAYMENT SERVICE PROVIDER'S PRIVACY POLICY]
11.4 The Provider receives from the payment service provider only the information required to perform the contract, as a rule: name, email address, country, order number, product, amount and payment status.
11.5 The purpose is the performance of the purchase contract, delivery of the license key and compliance with statutory retention obligations. The legal bases are Art. 6(1)(b) and (c) GDPR and the corresponding provisions of the revFADP.
11.6 Receipts and business records are retained for ten years under Swiss commercial law.
11.7 For purchases through the Microsoft Store, Microsoft is your contractual partner for the purchase transaction and processes the resulting data as its own controller. Microsoft's privacy terms apply. The Provider receives only aggregated sales reports from Microsoft with no reference to individual persons.
12. Contact and Support
12.1 If you contact us by email at [EMAIL] or through the contact form, we process your details in order to answer your enquiry.
12.2 Data processed: name, email address, content of the message, any attachments and the order number.
12.3 The legal basis is Art. 6(1)(b) GDPR for contract-related enquiries and Art. 6(1)(f) GDPR for other enquiries.
12.4 Enquiries are deleted once they have been conclusively dealt with and no retention obligations apply, at the latest after [RETENTION PERIOD, e.g. 24 months].
12.5 Please do not send us database files or reports from the app unless we expressly ask you to. If you send diagnostic data, remove window titles and other sensitive content beforehand.
13. Newsletter
13.1 [IF NO NEWSLETTER: No newsletter is offered.]
13.2 [IF NEWSLETTER: Dispatch takes place using the double opt-in procedure through [PROVIDER, NAME AND LOCATION]. The legal basis is your consent under Art. 6(1)(a) GDPR. You can unsubscribe at any time using the link in every email or by writing to [EMAIL]. Data processed: email address, time of subscription and IP address used for subscription.]
14. Data Sharing and International Transfers
14.1 Data is shared only where necessary to perform the contract, where you have consented, or where a legal obligation applies.
14.2 Categories of recipients: hosting provider, payment service provider, email service provider, store operators and, where required, accountants and legal advisors.
14.3 This may involve transfers abroad, in particular to EU states and the United States. Transfers are based on an adequacy decision, the European Commission's standard contractual clauses, or another permissible safeguard under the GDPR and the revFADP.
14.4 An overview of the service providers used and their country of establishment is available at fairhour.ch/service-providers or on request.
14.5 No automated individual decision-making or profiling within the meaning of Art. 22 GDPR takes place.
15. Your Rights
15.1 Under the revFADP and, where applicable, the GDPR, you have the following rights:
| Right | Meaning |
|---|---|
| Access | You can find out whether and which personal data we process about you (Art. 15 GDPR; right of access under the revFADP). |
| Rectification | You can have inaccurate data corrected (Art. 16 GDPR). |
| Erasure | You can request deletion of your data, unless a retention obligation applies (Art. 17 GDPR). |
| Restriction | You can request restriction of processing (Art. 18 GDPR). |
| Data portability | You can receive your data in a common, machine-readable format (Art. 20 GDPR; data release and transfer under the revFADP). |
| Objection | You can object to processing based on a legitimate interest (Art. 21 GDPR). |
| Withdrawal of consent | You can withdraw consent at any time with effect for the future. |
| Complaint | You can lodge a complaint with a supervisory authority (Art. 77 GDPR). |
15.2 To exercise your rights, a message to [EMAIL] is sufficient. To prevent misuse, we may request proof of identity.
15.3 Important: These rights relate to data processed by the Provider, essentially purchase, support and website data. The usage data in the app resides exclusively on your device. You exercise access, export and deletion directly in the Software.
15.4 If another person uses the parental module on a device you share, your rights are directed against that person as controller, not against the Provider.
16. Supervisory Authorities
16.1 Switzerland: Federal Data Protection and Information Commissioner (FDPIC / EDÖB) Feldeggweg 1, 3003 Bern www.edoeb.admin.ch
16.2 EU/EEA: The competent authority is the data protection supervisory authority of your country of residence, place of work, or the place of the alleged infringement.
17. Children
17.1 The website is not directed at children. No data of children is knowingly collected through the website.
17.2 The app may be used on devices used by children. In that case, the person who sets up the recording, usually a parent, is the controller (see section 5).
18. Changes to this Privacy Policy
18.1 We update this privacy policy when our processing activities or the legal situation change.
18.2 The version published at fairhour.ch/privacy is authoritative.
Contact for data protection matters
[COMPANY NAME] [STREET AND NUMBER] [POSTAL CODE CITY], Switzerland Email: [EMAIL] Phone: [PHONE]
Version of [DATE]