← HomeLegal

Privacy in the TIDEFORCE app

Last updated: 1 October 2026

This notice covers the TIDEFORCE management app and school-operated booking portals. It supplements your school’s privacy notice. Visits to tideforce.de are covered by our website privacy notice.

Provider and data protection officer

TIDEFORCE UG (haftungsbeschränkt), Sterzingerstraße 34, 83024 Rosenheim, Germany. Contact: info@tideforce.de, +49 172 411 78 11.
Data protection officer: Eva Ranner, eranner@tideforce.de. You can also write to her at the company address, marked “Data protection officer”.

Who is responsible for your data?

The school identified in the booking portal determines the purposes of its bookings, participant administration, communications and team management. It generally acts as controller; TIDEFORCE processes these data on its instructions under a data processing agreement (DPA). Your school provides its contact details, legal bases, required information and retention rules in its own privacy notice. TIDEFORCE is responsible for its own contract initiation and administration with schools and its own website. For its own product analytics, measuring usage to improve the software, TIDEFORCE acts as controller and relies on your consent under Article 6(1)(a) GDPR. School-specific reporting is performed on the school’s behalf. The school’s DPA does not authorise TIDEFORCE’s own analytics or advertising purposes. Consent to optional measurement is voluntary and separate from a booking.

Accounts, sign-in and operation

Depending on your access, we process names, email addresses, account identifiers, authentication data, roles and permissions on the school’s behalf. Firebase Authentication provides sign-in. Technical access and error logs may contain IP addresses, timestamps and device/browser information. Processing supports access, secure operation and troubleshooting. Necessary browser storage supports functions such as sign-in status, the shopping cart and language selection. TIDEFORCE processes its own contractual contacts and correspondence under Article 6(1)(b) GDPR; for an organisation’s representatives, Article 6(1)(f) GDPR applies based on the legitimate interest in business communications. Statutory retention is based on Article 6(1)(c) GDPR.

Bookings, participants and check-in

The school may process contact and address details, booked services and dates, participant information, necessary details of minors and guardians, check-in answers, signatures and uploaded files. Required information depends on the form and service offered. Without necessary details, the school may be unable to process a booking or participation. Health information is not part of the general standard scope: its collection requires a specifically agreed function and an appropriate legal basis under Article 9 GDPR. Please avoid unnecessary sensitive information in free-text fields.

Payments and invoices

When online payments are enabled, information necessary for payment is sent to the provider identified at checkout. This may include email address, name, amount and currency, payment and booking references and necessary billing details. For Stripe Connect, the underlying EEA contracting entity is Stripe Payments Europe, Limited, Ireland. Depending on the service, Stripe also acts as an independent controller, particularly for statutory obligations and fraud prevention. Full card details are not part of the agreed TIDEFORCE dataset. Any other payment provider must be specifically identified in the school’s information; this notice does not provide blanket authorisation for additional providers.

Email, support and push notifications

Booking confirmations, service messages and agreed communications involve recipients, content and necessary sending/delivery metadata. The agreed delivery service is Amazon SES through Amazon Web Services EMEA SARL, Luxembourg, with the sending region Ireland (eu-west-1). Necessary delivery, error and suppression information is distinct from optional open or click tracking. Permission to send a message is not blanket permission for behavioural measurement. Push notifications require your browser/device permission; a technical push identifier, delivery token and necessary account association are stored. You can revoke permission in browser/device settings. Support processes your request and information necessary to resolve it.

Team planning and time recording

Where team management is contracted, the school processes contact, role, scheduling and working-time data. If location checks for time recording are enabled and you grant location access, a single position with coordinates, accuracy and timestamp may be collected when clocking in or out. This is not continuous location tracking. The school determines necessity, the applicable employment-law basis, access rights and retention, and informs its team before use. The DPA does not grant blanket authorisation for individual performance or behaviour monitoring.

Optional analytics and marketing

Optional measurement may begin only after your active consent. The app distinguishes analytics and marketing; optional switches start off. Use “Cookie settings” in the app to change or withdraw your choice. The legal basis is Articles 6(1)(a) and 7 GDPR; consent-required device access is governed in particular by section 25 German TDDDG or section 165(3) Austrian TKG 2021. Your choice, notice version and timestamp are stored as analytics_consent for up to 180 days; a new notice version requires a new choice.
Depending on the authorised configuration, Firebase Analytics / Google Analytics 4 by Google Ireland Limited and internal Firestore events may measure page and feature views and booking progress using pseudonymous session identifiers. Such identifiers are not automatically anonymous. Names, email addresses, free booking text and identifying URL parameters are not permitted GA4 data. Schools must identify additional marketing services, such as Meta or their own Google tags, and their purposes before seeking consent. A general category does not replace that information. Withdrawal applies to future processing without affecting earlier lawful processing.

AI features

Agreed AI modules may use the OpenAI API through OpenAI Ireland Ltd., Ireland, for extracting invoice information and assisting with text and translation. Processing covers the necessary input, submitted context and results; documents may contain names, addresses, references, amounts, bank details or signatures. An optional AI chatbot processes your message, conversation history and the context submitted for the reply. The school must separately commission it and describe it in its notice. AI answers can be incorrect and should be reviewed before binding decisions. Do not submit unnecessary health information or other particularly sensitive details.
For the agreed API functions, the DPA requires TIDEFORCE not to share customer inputs and outputs for model training and to keep voluntary data-sharing options disabled. This does not promise processing without storage or exclusively within Europe. With Chat Completions, provider abuse-monitoring logs may generally remain for up to 30 days; legal or security requirements may require longer retention. Additional files and application state follow the rules of the endpoint used. Decisions producing legal or similarly significant effects based solely on automated processing are not a standard purpose of these AI tools.

Service providers and recipients

DPA V0.3 and its annexes form the basis for agreed processing on behalf of schools. The provider profile includes Google Cloud EMEA Limited, Ireland, for Firebase Authentication, Firestore, Cloud Storage, Cloud Functions and agreed hosting services; Amazon Web Services EMEA SARL, Luxembourg, for Amazon SES; Stripe Payments Europe, Limited, Ireland, with a service-dependent role; and OpenAI Ireland Ltd., Ireland, for commissioned AI modules. Google Ireland Limited provides GA4 where its use has been validly authorised. Not every function is active at every school. Additional subprocessors are introduced only through the contractual change procedure. Other recipients include authorised staff and commissioned support providers as necessary, and authorities where disclosure is legally required. Request the current list applicable to your school from the school or our privacy contact.

Processing outside the EEA

Services may process data outside the European Economic Area, particularly in the United States. Firebase Authentication includes processing in the US; exclusively European processing is not promised. Potential provider, subprocessor and support access involving AWS, Stripe and OpenAI must also be considered. Transfers require an applicable basis under Chapter V GDPR: an adequacy decision, including a valid EU-US Data Privacy Framework certification covering the specific recipient and service, or appropriate safeguards, particularly standard contractual clauses and any necessary supplementary measures. Information about and copies of the safeguards applicable to your service are available from our privacy contact.

Retention and deletion

The school determines necessary retention periods or objective deletion criteria for data processed on its behalf. DPA V0.3 provides for deletion from active systems without undue delay following an effective deletion instruction; records required by law remain restricted to their necessary purposes. The agreed backup standard is a daily backup retained for a rolling seven days; other replicas and logs follow their own categories. Restoring a backup must not permanently reverse deletions.
Check-in content and files follow the school-configured period after the last booked day; a necessary record of submission and its time may remain separately. Email queues and delivery logs are retained for completion and necessary follow-up of delivery, with minimal suppression records. Security and error logs are deleted or genuinely anonymised when their specific purpose ends. The contractual GA4 standard is two months for user and event data, without resetting user retention upon new activity; Google’s subsequent monthly deletion cycle and differing rules for aggregated reports must be taken into account. Statutorily required data are restricted to the relevant purposes and periods. Export, transition and deletion at the end of a contract follow the agreed contract and DPA.

Your rights and contact

Subject to statutory requirements, you have rights of access, rectification, erasure, restriction, portability and withdrawal of consent. You may object to processing under Article 6(1)(f) GDPR on grounds relating to your particular situation, and to direct marketing at any time without giving reasons. For booking, participant and team data, contact your school. TIDEFORCE assists the school; you may also contact info@tideforce.de or Eva Ranner at eranner@tideforce.de. Any necessary identity checks are limited to what is required. You can complain to a supervisory authority, particularly where you live, work or believe an infringement occurred. The authority responsible for TIDEFORCE is the Bavarian State Office for Data Protection Supervision (BayLDA).

Safeguards and further information

Agreed technical and organisational measures include risk-appropriate access controls, protected transmission and storage within each service’s scope, and procedures for privacy incidents, deletion and recovery. There is no blanket promise of end-to-end encryption for all communications. Changes to functions, recipients or purposes are reflected in the relevant notices and contractual documents. Our contract and booking information explains the distinction between the school and the software provider.