Teamwork: Privacy.
Information about the processing of personal data in the app.
Scope and responsibilities
Teamwork is an internal team app for iPhone and iPad. It is available only to our own team. Accounts are created by invitation only; there is no open registration. This policy covers the app and its server services. The website privacy policy applies to this website.
The team or company that invited you decides on the purposes and means of processing account data and team content such as messages, files, events and forms, and is the controller for that processing. Please ask them for the responsible contact person and your team's supplementary privacy information.
Daniel Piculjan, page artist, operates the app and servers for the respective team as a processor under a data processing agreement (Art. 28 GDPR) and in accordance with its instructions.
Where page artist processes data for its own purposes in providing the app or handling direct support enquiries, page artist may itself be a controller. App Store transactions are handled by Apple; Apple processes the resulting store and Apple account data under its own responsibility. [[OFFEN: Determine responsibilities and the data processing agreement based on actual operation]]
Daniel Piculjan · page artist
Leverkusen, North Rhine-Westphalia, Germany
Email: info@pageartist.de
Phone: 0214 / 86097937
Full address provided upon request. Further provider information is available in the legal notice.
What data is processed
- Account data: Name, email address, password as a hash and an optional profile picture. Passwords are not stored in plain text.
- Team content: Messages including voice messages, uploaded files, events, and forms and their responses. Content is accessible according to the access rights assigned by the team.
- Device and session data: Device name, sign-in times and data used to manage your session. The refresh token for signing in again is stored on the device in the iOS Keychain; the data required for session management is processed on the server.
- Push token: When push notifications are enabled, a device-specific token for the Apple Push Notification service (APNs) is processed to deliver notifications.
- Technical logs: Server logs may contain IP addresses, access times and technical errors. They are used for secure operation and troubleshooting and are retained for the following period: [[OFFEN: Server log retention period, e.g. 14 days]].
Purposes and legal bases
The data enables sign-in, group collaboration, chats, event planning, file sharing, forms, notifications and secure operation. The respective team or company determines and informs you of the legal bases for processing on behalf of the team. Depending on the usage relationship, performance of a contract, legitimate interests or consent may be relevant in particular.
Where page artist is itself a controller, Art. 6(1)(b) GDPR may apply to providing agreed services, and Art. 6(1)(f) GDPR may apply to handling support enquiries and secure operation. The legitimate interest is in a functioning, secure app and answering your enquiry. [[OFFEN: Confirm legal bases for actual operation]]
Camera, microphone, photos and local app lock
The camera, microphone and photos are used only when you actively use a corresponding feature, such as sending a photo or recording a voice message, and allow the required access. You can change permissions in your device settings. Only content you select or send is transmitted.
The app lock uses Face ID/Touch ID and PIN, only locally on the device. The biometric check is performed by iOS; page artist receives no biometric data, and such data is not transmitted to the app server.
Recipients, Apple and absence of tracking
The app has no tracking, advertising or analytics SDKs. Data is neither sold nor shared for advertising purposes. In addition to Apple, possible email delivery providers and external AI agents requested by you need to be clarified separately; their involvement is marked as unresolved below.
Apple is involved in distribution through the App Store and push delivery through APNs. For push notifications, the push token and the notification data required for delivery are transmitted to Apple. Apple's privacy information also applies. Processing by Apple outside the EU or EEA cannot be ruled out; [[OFFEN: Determine transfer bases and safeguards for Apple outside the EU/EEA]].
Email delivery
Emails are sent to your email address for confirmations, invitations and password resets. Your email address and the account data required for the respective message are processed for this purpose. [[OFFEN: Email delivery – own mail server or email delivery provider]]
Second factor
If you enable a second factor, the app processes the data required for time-based one-time passwords (TOTP) and recovery codes to secure your sign-in. Keep recovery codes confidential.
Sign in with Apple
[[OFFEN: only if enabled]]
External AI agents (MCP)
[[OFFEN: only if active in the app]] External AI agents access your data through MCP only at your request. [[OFFEN: Determine data scope, recipients and access rights for MCP]]
Hosting and security
App data is hosted on our own server in Germany at netcup. The hosting infrastructure is used within the scope of data processing on behalf of the controller. Data is encrypted in transit using TLS. Backups support recovery from technical failures and are also subject to access restrictions.
Retention and deletion
Account data is stored for the duration of use. You can delete your account in the app through the profile menu under Settings → Account. Personal account values are removed or anonymised and sessions are ended. Shared messages, files, events and forms may remain in accordance with the responsible team's instructions; deleting an account does not automatically remove all team content.
Retention of team content depends on the team's purposes and deletion instructions and, where applicable, statutory retention obligations. Session data and push tokens are needed only while the relevant session or notification feature is active. Technical logs are deleted after [[OFFEN: Server log retention period, e.g. 14 days]] unless needed to investigate a specific security incident.
Deleted data may remain in backups until regular overwriting. It is not restored for ongoing use; if recovery is necessary, deletions must be reapplied. The backup overwriting period is: [[OFFEN: Backup retention period and overwriting cycle]].
Your rights and contact
Subject to the GDPR, you have rights in particular to access, rectification, erasure, restriction of processing and data portability, as well as a right to object. You can withdraw consent at any time with effect for the future.
For your team's data, please contact the responsible team or company first. If you cannot reach the responsible party or have questions about technical operation or processing by page artist, you can contact Daniel using the details above. page artist supports the team in handling your enquiry.
You also have the right to lodge a complaint with a data protection supervisory authority, in particular in the EU Member State of your habitual residence, place of work or the place of the alleged infringement. The European Commission provides information about these rights.
Last updated: 1 October 2026.