Privacy notice
This notice describes the marketing website at holmo.app and use of the application at app.holmo.app.
1. Controller and contact
Brian Zielinski
Schwalbenweg 9
47546 Kalkar, Germany
Privacy contact: info@holmo.app
2. Website delivery and security
The website is delivered through Cloudflare Workers and the Cloudflare network. Technically necessary connection data is processed, including your IP address, the address requested, the time of access, browser and device information, and transmission details. This is necessary to deliver the website, maintain its stability and prevent misuse. The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is operating the website reliably and securely.
Recipient / contracting party: Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA.
The website Worker is configured not to retain its own persisted Worker request logs in production. The application has separate Worker logs, described in the application section below. This does not rule out technical connection data or security processing by the hosting provider. For the app Worker named holmo, Workers Logs and persisted request logs are enabled; Traces are disabled. Cloudflare states that Workers Free logs are retained for up to 3 days. This period applies only to Worker logs, not to operational data in D1, photos in R2 or emails. Observability logs are disabled in the Wrangler configuration for the website Worker holmo-website; this does not affect technical connection data processed by the hosting provider.
Cloudflare operates a global network, so processing outside the EU / EEA may occur. The applicable transfer basis and safeguards are as follows: Cloudflare’s standard DPA version 6.4 (effective 3 April 2026) forms part of the Self-Serve contract. For transfers outside the EEA that are necessary, it provides for the EU Standard Contractual Clauses and, where applicable, other recognised transfer mechanisms. Holmo’s D1 and R2 resources are configured in Cloudflare’s EU jurisdiction; this does not mean that all processing takes place exclusively in the EU. Cloudflare Privacy Policy.
3. Demo requests and other enquiries
The enquiry page has a form that prepares an email in your email application. The information you enter is not sent to or stored on our web server. We receive your information only if you send the email yourself. This may include your name, business, business email address, team size, selected package, selected modules and message. We use it to respond to your enquiry and arrange a demo or prepare an offer. Please do not send sensitive employee or customer information.
Where you make an enquiry to take steps before entering into a contract, the legal basis is Article 6(1)(b) GDPR. We handle other business enquiries under Article 6(1)(f) GDPR, based on our legitimate interest in communicating with you. Providing the information is voluntary, but we need a working contact address to reply.
Email provider / other recipients: Google Workspace for info@holmo.app. Google processes email content and account data as a service provider; the terms and privacy conditions applicable to the specific subscription apply.
We delete non-binding demo enquiries that do not result in a contract six months after the last contact. Business correspondence needed for contractual or statutory records is handled separately and retained only as long as necessary. Google Workspace processes email content and account data under the Cloud Data Processing Addendum applicable to the subscription. Google may use subprocessors and systems outside the EEA. Where necessary, international transfers are covered by the safeguards in the current Workspace contract and addendum, including EU Standard Contractual Clauses where required. Processing exclusively in Europe is not promised.
4. Fonts, video, cookies and audience measurement
This website loads its fonts, logos and product images. The AI-generated video is labelled as illustrative. The video is delivered as a media file from this website through Cloudflare Workers. When it loads and plays, technical connection data such as IP address and browser information is processed. No external third-party video player is embedded. The website does not connect to Google Fonts or an external advertising video service. No external analytics, advertising or newsletter services are integrated.
The website itself sets no cookies. Your light or dark colour-scheme choice is stored in your browser’s local storage. Cloudflare may use technically necessary cookies for security features; these provider functions must be considered separately from website functions.
A counter in the footer shows the total number of page views since it was activated. When JavaScript is enabled, your browser sends a request to this website as a page loads; only the aggregate total is stored for the counter. We do not store IP addresses, browser identifiers or cookies for the counter. Cloudflare’s technical processing of the connection is described in section 2.
5. Use of the Holmo application
Each business has its own workspace. The application processes employee account data, including names, usernames, roles and assigned job sites, as well as tool, material, vehicle and job-site data, updates, bookings and timestamps. Updates may include customer requests and uploaded photos. Password hashes, session data and security-related login attempts are processed for authentication; sessions use a technically necessary cookie. Working-time corrections and administrative actions are recorded for traceability.
The respective customer business is the controller for employee, customer and operational data it enters into Holmo. Zielinski Software & Automatisierung processes that data as a processor on documented instructions. Zielinski Software & Automatisierung is an independent controller for its own contract, contact, account-security and platform-administration data. Holmo does not offer self-registration. Before a new customer business is activated and before personal employee or customer data is entered, a data processing agreement is concluded. The signed agreement is provided and filed during manual onboarding; until then, no live personal data for that business is processed.
The application uses Cloudflare Workers, a D1 database and R2 for uploaded photos. The information about Cloudflare, logs and possible international transfers in section 2 also applies to the application; the specific processing and agreements must be checked against the applicable contract. For offline use, the browser stores a copy of the most recently loaded business workspace and pending tool bookings or updates without photos on the device. Pending actions are transmitted after the connection returns; conflicts require a decision in the application. The browser also stores recently used login identifiers. On shared devices, local data may remain accessible until you sign out or clear the browser data.
Brian Zielinski is currently the only platform administrator. Access to an active business workspace is granted only following a specific request and documented approval by that business’s administrator. The business, reason, action and time are logged. Platform access ends when the support task is complete and the administrator manually exits the workspace or signs out; the technical session expires after no more than 7 days. These approval and expiry rules are followed organisationally but are not currently enforced by an automatic technical approval lock.
Retention periods:
- Accounts and sessions: When an employee leaves, the customer administrator deactivates their account, blocking access and revoking the session. The account is not automatically deleted because it is linked to working-time and booking records. After export and on the customer’s documented instruction, profile data that is no longer needed is manually deleted or anonymised. Sessions expire after 30 days (platform accounts after 7 days); expired database rows are not removed by a regular cleanup job.
- Operational and job-site data: Tool, material, vehicle, job-site and update data are processed for the term of the customer contract. When the contract ends, the customer has 30 days to export the data. After that, the data is manually deleted on the customer’s instruction within a further 60 days. Data needed for specific legal claims or a documented statutory obligation is retained separately and only to the extent required. There is currently no automatic deletion routine.
- Working-time data and corrections: The customer business, as employer, is responsible for legally compliant retention and export of its working-time records. Holmo makes time events and approved corrections available during the contract and the 30-day export period. Before later deletion, the employer must secure the records it needs. Records covered by section 16(2) of the German Working Time Act (ArbZG) must be retained by the employer for at least the statutory two-year period; longer obligations and legal claims remain unaffected.
- Photos: Report photos are stored in Cloudflare R2 under the relevant business identifier. They remain available during the customer contract and, when the contract ends, are manually deleted on instruction within 60 days after the 30-day export period. Individual photos are not currently deleted automatically when a report is deleted or changed. No separate R2 backup is configured.
- Backups: According to Cloudflare, D1 Time Travel is available by default on Workers Free and allows restoration to a point up to 7 days in the past. There are currently no additional regular D1 exports or independent copies of R2 photos as backups. A restore may bring back D1 data that was already deleted; deletions must be applied again after a restore. The local browser copy can be removed by signing out of the application or clearing browser data. Pending offline actions should be synchronised first.
6. Your rights
Where statutory conditions are met, you may request access to your data, rectification, erasure, restriction of processing and data portability. If you have given consent, you may withdraw it at any time with effect for the future.
Right to object: If processing is based on Article 6(1)(f) GDPR, you may object on grounds relating to your particular situation. You may object to processing for direct marketing at any time.
You may lodge a complaint with a data protection supervisory authority, in particular in the place where you usually live, work or where the alleged infringement occurred. The authority responsible for the controller is the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia (Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen), Kavalleriestraße 2–4, 40213 Düsseldorf, Germany. ldi.nrw.de.
This website does not carry out automated decision-making, including profiling, within the meaning of Article 22 GDPR.
7. Date
3 October 2026. This notice will be updated if hosting, contact channels, the application or analytics functions change.