PRIVACY
Privacy notice
This notice explains how Droopy On Web SRL processes personal data when you visit Hourline, contact us or create and use a workspace.
Controller and contact
Droopy On Web SRL, Strada Islazului nr. 18A, Sibiu, Romania, VAT ID RO38637443, is responsible for the account, website, security and support data described here.
Privacy questions and rights requests can be sent to contact@hourline.eu or through the Hourline contact form.
Data we process
- Account details such as your name, company, email address and password hash.
- Workspace information you enter, including clients, projects, time entries, invoice details and business identifiers.
- Contact-form messages and the details you provide with them.
- Short-lived session, password-reset and security information needed to protect accounts and forms.
- Daily aggregate page, referral, language and device-class counters that do not store raw IP addresses or persistent visitor identifiers.
Why we use it
We process account and workspace information to provide the service and take steps requested by you. We use limited security information and aggregate product measurements for our legitimate interests in protecting Hourline, preventing abuse and improving the product. Contact details are used to answer your request.
Hourline does not sell personal data and does not use advertising cookies.
Service providers and official sources
Data is made available only where needed to operate the service:
- Easyhost provides website, database and backup infrastructure.
- Brevo delivers contact-form and password-reset emails.
- EU VIES and supported official company registries receive VAT or company identifiers when you explicitly request validation or autofill.
These providers and public authorities process information under their applicable terms, legal duties and data-protection safeguards.
Retention and your rights
Account and workspace information is kept while the account remains active and as needed to provide the service, comply with legal duties, resolve disputes and maintain security. Contact messages are reviewed and removed when they are no longer reasonably needed for support. Password-reset links expire after 30 minutes, and rate-limit identifiers are stored as hashes and removed within 24 hours.
You may request access, correction, deletion, restriction, portability or objection where the GDPR provides those rights. You may also complain to the Romanian data-protection authority. Use the contact form to make a request.
Cookies and device storage
See the separate Cookie information page for the essential session and preference technologies used by Hourline.