RetroJoy
Privacy Policy for RetroJoy
This is a courtesy translation. The German version is legally binding.
This privacy policy applies to the web application RetroJoy (collaborative agile retrospectives) by Deari Software. Our company website is covered by the website privacy policy; the Time Tracker app has its own app privacy policy. Provider details are in the imprint. Product page: RetroJoy.
1. Controller
Deari Software
Festim Deari
Friedrich-Ebert-Straße 55
42103 Wuppertal
Germany
Email: kontakt@deari.de
2. Principles
RetroJoy contains no advertising, no analytics or tracking tools (no Google Analytics, no Facebook pixel, no third-party crash tracking) and no profiling for advertising. We do not sell your data and do not share it for advertising purposes.
3. Hosting and server log files
The web application is operated by a professional hosting provider. Access generates technically necessary server log files transmitted by your browser, in particular:
- IP address of the requesting device
- date and time of access
- page or file accessed
- browser type and version and operating system
- referrer URL (previously visited page)
Processing is based on Art. 6(1)(f) GDPR (legitimate interest in secure, stable operation). Log files are deleted after a short period once they are no longer needed for security and troubleshooting. A data processing agreement pursuant to Art. 28 GDPR is or will be in place with the hosting provider.
4. Account and sign-in
Creating rooms requires an account. Sign-in is passwordless via a magic link sent to your email address. We process:
- your email address and the one-time sign-in link
- a technical user identifier (UUID)
- optional profile details (display name, profile image URL if provided)
- timestamps of account creation, sign-in and last changes
- your virtual coin balance used to activate sessions (see section 7)
The purpose is to provide your account and the application. The legal basis is Art. 6(1)(b) GDPR (performance of the usage agreement). Sign-in emails are sent by our processor Supabase.
Rooms can also be joined without your own account via a shared link; processing is then limited to what is technically necessary to take part in that room.
5. Data in retro rooms
When you use RetroJoy we store the content you and your team create:
- Rooms: name, optional description, selected columns, timer and session status, facilitator identifier
- Cards: text, column, author, timestamps, optional anonymity and visibility, reactions, comments, facilitator notes, assignees, votes
- Activities: polls, mood checks, one-word rounds, kudos, two-truths games and similar in-room tools
- Custom columns: column definitions created by facilitators
Anonymous cards are shown to other participants without a name. Technically the author identifier remains stored so you can edit or delete your card.
The legal basis is Art. 6(1)(b) GDPR. Content of a room is visible to invited participants — that is the purpose of the application.
6. Real-time collaboration
So several people can write, vote and see the timer at the same time, we use realtime channels. Display names or initials and online status of people in the room may be visible to other participants. Typing indicators on a card are shown briefly and not stored permanently.
7. Coins and payments
Facilitators unlock a time-limited session with virtual coins. The balance is stored on your profile. New accounts receive a starting balance.
Paid coin packs can be bought with PayPal. Checkout happens on PayPal’s servers. We receive a payment confirmation (PayPal order id, amount, package, and your account id) so we can credit coins. We do not collect or store card numbers or bank details. The legal basis is Art. 6(1)(b) GDPR (performance of the purchase contract). PayPal acts as an independent controller for the payment itself; see PayPal’s privacy statement for that processing.
8. Cookies and local storage
We only use technically necessary storage:
- Sign-in session (cookie or browser local storage) so you stay signed in
- Theme preference (light/dark) in your browser’s local storage
- briefly the email address after sending the magic link, so sign-in can be completed
There is no tracking cookie and no marketing-cookie banner because we do not use such cookies. The legal basis for necessary storage is Art. 6(1)(b) and (f) GDPR and § 25(2) TDDDG.
9. Recipients and processors
- Supabase, Inc. — database, authentication and realtime. Your data is stored in the EU: the server location is Ireland (AWS region eu-west-1). A data processing agreement pursuant to Art. 28 GDPR is in place with Supabase. Where, exceptionally, support or maintenance access originates in the USA, we rely on the EU standard contractual clauses (Art. 46 GDPR).
- Hosting provider of the web application — operation and delivery of the interface, including the log files described in section 3.
- PayPal (Europe) S.à r.l. et Cie, S.C.A. — payment processing when you buy coins. PayPal receives the data needed to complete checkout and is an independent controller for that processing. We store the PayPal order id, package and amount so we can credit your coin balance once and prevent duplicate credits.
Fonts are served by us and are not loaded by the browser from Google or another font CDN.
10. Retention and deletion
Account data is kept for as long as your account exists. Rooms and cards remain until the facilitator deletes the room in the application or you request deletion of your account. After account deletion we remove your profile; associated content still needed by others in a room may continue in anonymised form until the room itself is deleted. Purchase records (PayPal order id, package, amount, timestamp) are kept as long as needed to credit coins, prevent duplicate credits, and meet commercial and tax retention duties.
You can have your account and data deleted at any time by emailing kontakt@deari.de. We will confirm once deletion is complete.
11. SSL/TLS encryption
Transmission is encrypted (HTTPS). You can recognise an encrypted connection by the “https://” prefix in the address bar.
12. Your rights
As a data subject, you have the following rights:
- access (Art. 15 GDPR)
- rectification (Art. 16 GDPR)
- erasure (Art. 17 GDPR)
- restriction of processing (Art. 18 GDPR)
- data portability (Art. 20 GDPR)
- objection (Art. 21 GDPR, see section 13)
- withdrawal of consent with effect for the future (Art. 7(3) GDPR)
- lodging a complaint with a supervisory authority (Art. 77 GDPR)
To exercise these rights, write to kontakt@deari.de.
13. Right to object (Art. 21 GDPR)
Insofar as we process personal data on the basis of Art. 6(1)(f) GDPR (legitimate interest), you have the right to object at any time, on grounds relating to your particular situation, to such processing. We will then no longer process the data concerned unless we can demonstrate compelling legitimate grounds which override your interests, or the processing serves to assert, exercise or defend legal claims.
14. Children
RetroJoy is intended for adults in professional teams and does not knowingly collect data from children under 16.
15. Changes to this privacy policy
Last updated: September 2026. We will update this policy as soon as the functionality or the data processing changes. The current version is available at this address and in the RetroJoy application.