Privacy Policy
Last updated: 29 August 2026
This Privacy Policy explains how SchelloLabs processes personal data when providing its website and apps. It also describes which data is processed exclusively under the user's control on the end device or in the user's Apple iCloud area.
1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
SchelloLabs - Marcus Schellstede
Pirschweg 22
26160 Bad Zwischenahn
Germany
Telephone: +49 4486 3684202
Email: support@schellolabs.de
Website: https://www.schellolabs.de
2. Scope
This Privacy Policy applies to the SchelloLabs website and to the following apps where the relevant app refers to this Policy:
- AufmassPro|tokolle
- HOAI-Rechner
- E|Rechner
- AbÄppelApp
- ÜbergabePro|tokolle
- PrüfPro|tokolle
- BauDokuPro|tokolle
- KüchenHopping
- RegiePro|tokolle
- RechnungsPro|tokolle
- StundenPro|tokolle
The functions and data processing operations actually available depend on the relevant app version, the operating system used, purchased feature entitlements and the user's settings.
3. Privacy at a glance
SchelloLabs follows the principle of data minimisation:
- In its current configuration, the website does not use analytics, marketing or tracking services or externally embedded web fonts.
- Content entered by users in the apps is primarily processed locally on the end device.
- SchelloLabs does not maintain its own app user accounts and does not operate a central server database for app content.
- SchelloLabs does not use app content for advertising, profiling, AI training or automated decision-making.
- Where an app supports iCloud or CloudKit and the user enables that function, the selected app data is stored or synchronised through Apple services.
- Entering content locally in an app does not, by itself, transmit that content to SchelloLabs. Support content is transmitted only after the user initiates contact.
- Data is exported or disclosed only when the user selects the corresponding function.
4. Roles and responsibility for app content
The apps provide technical tools. The purposes, content and recipients of professional, community or organisational processing are generally determined by the user or by the organisation deploying the app.
Where personal data relating to other individuals is recorded, photographed, imported, synchronised, signed or shared in an app, the user or deploying organisation is generally responsible for ensuring that a legal basis exists and that applicable data protection obligations are met. This Privacy Policy does not replace the separate information duties of an employer, contractor, client, landlord, stable operator, event organiser or any other responsible organisation towards the individuals concerned.
This applies in particular where StundenPro|tokolle or another app is used in an employment context. Employers and other responsible bodies must independently assess, among other matters, the purpose, necessity, legal basis, access permissions, retention period, deletion and any participation rights of employee representatives. Section 26 of the German Federal Data Protection Act (Bundesdatenschutzgesetz - BDSG), in conjunction with Article 6 GDPR, may in particular be relevant to employee data. The legal basis that actually applies depends on the specific use case.
For exclusively personal or household use, the household exemption in Article 2(2)(c) GDPR may apply. Once data is processed for professional, commercial, association-related or organisational purposes, or is disclosed to a wider group of persons, the applicability of that exemption must be assessed separately.
SchelloLabs is responsible for the technical provision of the website and apps determined by SchelloLabs and for processing operations for which SchelloLabs determines the purposes and means. Where data is processed solely locally under the user's control and SchelloLabs does not receive it, SchelloLabs generally cannot view that content or attribute it to a particular individual.
5. Website provision and hosting
The website is hosted by:
STRATO GmbH
Otto-Ostrowski-Straße 7
10249 Berlin
Germany
SchelloLabs has entered into a data processing agreement with STRATO.
When the website is accessed, technically necessary access data is processed. This may include, in particular:
- IP address of the accessing device
- date and time of access
- page or file requested
- amount of data transferred
- browser type and browser version
- operating system and device information
- referring URL
- hostname
- HTTP status code and technical error messages
This processing is necessary to deliver the website, ensure its stability and security, and detect attacks or technical malfunctions. The legal basis is Article 6(1)(f) GDPR. The legitimate interest is the secure, reliable and economical operation of the website.
According to STRATO's current product information, STRATO anonymises hostnames or IP addresses in the access logs made available to the website operator. Logs for access during the preceding six weeks may be available. For internal security and operational logs, STRATO states retention periods ranging from a few days to a maximum of 60 to 90 days, depending on the specific purpose. Data may be retained for longer where this is necessary to investigate a specific security incident, pursue or defend legal claims, or comply with legal obligations.
Further information:
https://www.strato.de/datenschutz/
6. Encryption, cookies, terminal-device access and external content
The website is delivered through an SSL/TLS-encrypted connection.
In its current configuration, SchelloLabs does not use analytics or marketing cookies requiring consent, advertising networks, social-media plugins or comparable tracking technologies.
Where strictly necessary cookies, local storage or comparable access is used, it serves solely to provide a function expressly requested by the user. Storing information on a user's terminal equipment or accessing information already stored there is governed by section 25 of the German Telecommunications Digital Services Data Protection Act (Telekommunikation-Digitale-Dienste-Datenschutz-Gesetz - TDDDG). Section 25(2) no. 2 TDDDG may apply to access that is strictly necessary; access that is not necessary generally requires consent under section 25(1) TDDDG.
The assessment under section 25 TDDDG and the data protection legal basis for any subsequent processing of personal data are separate matters. Where personal data is processed, the applicable basis may, depending on the purpose, be Article 6(1)(b) or (f) GDPR or, where valid consent has been obtained, Article 6(1)(a) GDPR.
An operating-system permission, for example for camera, photos, files or location, initially controls the app's technical access. It does not automatically constitute consent under data protection law. Where processing is based on consent, the additional requirements of Articles 4(11) and 7 GDPR must be met.
External websites, particularly Apple or App Store pages, are opened only when the user selects the relevant link. From that point onwards, the external provider processes data under its own responsibility and in accordance with its own privacy information.
7. Contact and support
Where users contact SchelloLabs by email, telephone or a contact function provided by an app, the data voluntarily supplied is processed to handle the request.
This may include, in particular:
- name and contact details
- content of the request
- name and version of the relevant app
- device type and operating-system version
- language and regional settings
- technical status of app functions
- error description
- voluntarily attached screenshots, documents, exported files or diagnostic information
The legal basis is Article 6(1)(b) GDPR where the request relates to a contract, purchase, subscription or pre-contractual measure. For general questions, bug reports and suggestions, the legal basis is Article 6(1)(f) GDPR. The legitimate interest is to handle requests and improve security, stability and usability. Where a legal obligation to retain or process the communication applies, Article 6(1)(c) GDPR may also be relevant.
Some apps may offer a minimal support template described as “anonymous” and a more detailed technical support template. In this context, “anonymous” means that the app does not automatically insert project, personal, photo, document or complete usage data into the message. If the request is sent through a personal email account, the sender address and any content added by the user are nevertheless visible to SchelloLabs and the email service providers involved.
Before sending, the user can review and edit the generated message and its attachments. Project content, third-party personal data, photos, documents or complete records are transmitted only if the user selects or attaches them. Email communication may be processed through STRATO's technical infrastructure. Ordinary email is generally not end-to-end encrypted. Particularly sensitive or unnecessary data should therefore not be sent by email.
Support data is erased once the request has been fully handled unless statutory retention duties or legitimate grounds require further storage. If a message qualifies as business or contractual correspondence subject to statutory retention, the applicable legal retention period applies.
8. Principles and legal bases for processing in the apps
Projects, calculations, measurements, invoice reviews, working-time records, evidence, protocols, photos, documents, notes and other work content entered by the user are not automatically transmitted to a server operated by SchelloLabs.
Depending on the app, version and settings, data may be:
- stored exclusively locally on the end device;
- stored in an iCloud or CloudKit area or synchronised between devices;
- shared with expressly invited persons through CloudKit Sharing;
- exported as a file; or
- transmitted through the operating system's sharing functions to a recipient selected by the user.
Local storage and access to saved app state that is strictly necessary for the app function serves to provide a digital service expressly requested by the user within the meaning of section 25(2) no. 2 TDDDG. Where SchelloLabs is responsible for associated processing of personal data, it is generally performed to provide the app user relationship on the basis of Article 6(1)(b) GDPR.
Optional functions become available only after the user makes the relevant selection or grants the necessary operating-system permission. The operating-system permission is not automatically the legal basis under the GDPR. Depending on the purpose and allocation of responsibility, processing may be based in particular on Article 6(1)(b), (c) or (f) GDPR, section 26 BDSG or - where valid consent has been obtained - Article 6(1)(a) GDPR. Special categories of personal data may be processed only where an exception under Article 9(2) GDPR and, where applicable, a supplementary national legal basis also applies.
Professional or organisational users processing data relating to other individuals must identify and document their own applicable legal basis. They must enter only necessary data and comply in particular with information, access, security, retention and deletion obligations.
9. Data categories of the individual apps
AufmassPro|tokolle
AufmassPro|tokolle may process, in particular, project and property data, project numbers, customer and contact-person data, bills of quantities, GAEB data, items, short and long descriptions, quantities, units, measurement records, target and actual values, formulas, variations, notes, photos, change information and PDF, CSV and GAEB export files.
HOAI-Rechner
HOAI-Rechner may process, in particular, project names, project, office and customer data, chargeable costs, service profiles and service phases, fee zones and rates, surcharges and reductions, incidental expenses, calculation variants, templates and PDF output.
E|Rechner
E|Rechner may process, in particular, technical input and calculation values, project labels, saved calculations, favourites, technical table values, notes and PDF output.
AbÄppelApp
AbÄppelApp may process, in particular, names of stable communities, names and roles of members, horse data, tasks and duties, appointments, absences, cover and swap requests, notes, photos, documents, invitations and technical synchronisation data. In shared use, authorised members may, depending on their role, access and edit released data.
ÜbergabePro|tokolle
ÜbergabePro|tokolle may process, in particular, project and property data, names and contact details of participating individuals or organisations, room and condition information, defects, meter readings, key details, appointments, notes, photos, signatures, change information and PDF handover records.
PrüfPro|tokolle
PrüfPro|tokolle may process, in particular, project and property data, information about clients, contact persons and inspectors, technical test and measurement data, test results, findings, defects, deadlines, notes, photos, change information and PDF inspection reports.
BauDokuPro|tokolle
BauDokuPro|tokolle may process, in particular, project, construction-site, client and contact-person data, information about companies and deployed personnel, activities and services, weather and time information, obstructions, defects, notes, photos, daily, weekly and monthly reports and PDF or CSV output.
KüchenHopping
KüchenHopping may process, in particular, event, participant and team data, names, addresses, doorbell instructions, contact and invitation details, course and route assignments, and voluntary information about dietary preferences, intolerances or allergies.
Information about allergies or intolerances may constitute health data within the meaning of Article 9 GDPR. Where the GDPR applies, such information may be processed and shared with other participants only on an appropriate legal basis. Where voluntary processing is based on consent, explicit consent from the individual concerned under Article 9(2)(a) GDPR is generally required. Withdrawal takes effect for the future; copies already exported or otherwise stored by recipients are not automatically erased.
RegiePro|tokolle
RegiePro|tokolle may process, in particular, project, construction-site, client and contact-person data, details about performing and reviewing persons, working hours, activities, services, materials, equipment, notes, photos, attachments, optional location details recorded by the user, signatures, completion and change information, technical checksums and PDF records.
The optional location function is used only when selected by the user and after the required operating-system permission has been granted. Location information is used only for the documentation function chosen by the user and is not analysed by SchelloLabs for advertising, movement profiles or tracking.
RechnungsPro|tokolle
RechnungsPro|tokolle may process, in particular, project, client, contractor and contact-person data, contract and bill-of-quantities values, GAEB data, invoice numbers and periods, cumulative invoice status, quantities, prices, discounts, variations, deductions, retentions, tax procedures and rates, review notes, attachments, status and change information and PDF review sheets. This data may contain financial, contractual and commercially confidential information.
StundenPro|tokolle
StundenPro|tokolle may process, in particular, labels for employment relationships, employers, projects, cost centres or activities, personal or profile labels entered by the user, start and end of work, breaks and break segments, target and actual time, positive and negative time balances, working-time accounts, leave, sickness and other absences, special time categories, notes, correction and change information, weekly, monthly and annual reports, PDF and, where available, CSV export files, and technical synchronisation data.
Under its current feature set, StundenPro|tokolle follows a local-first approach and may optionally use private synchronisation through the Apple Account's CloudKit Private Database. The app does not provide SchelloLabs user accounts, location collection, advertising tracking or cross-provider tracking. Recording working-time data does not, by itself, transmit that data to SchelloLabs.
Working-time, break, absence, leave and time-account data may constitute employee data. Information about sickness, medical reasons or diagnoses may constitute health data under Article 9 GDPR. Before processing such data, employers and other responsible organisations must assess, in particular, Articles 6 and 9 GDPR, section 26 BDSG, necessity, any collective agreements and participation rights, and appropriate access and deletion arrangements. Diagnoses and other unnecessary health information should not be entered in free-text fields.
SchelloLabs does not use the app content described in this section for its own advertising, profiling, AI training or content analysis for unrelated purposes.
10. Data relating to other individuals and special protection needs
Data relating to other individuals may concern, in particular:
- customers, clients, contractors and contact persons
- employees and persons performing, reviewing or signing work
- tenants, owners and other parties to a handover
- members of a stable community
- event participants
- individuals, vehicle registration plates, plans or documents visible in photos
- signatures and location details
- contract, invoice, measurement, inspection, working-time and employment data
- information about allergies, intolerances, sickness or other sensitive matters
Before processing such data, the legal basis, purpose, data minimisation, information duties, access rights, confidentiality, retention period and permitted recipients must be assessed. Unnecessary or particularly sensitive data should not be stored in the apps.
A signature captured with a finger or stylus is stored as graphical signature information. SchelloLabs does not use it for biometric identification. Users must ensure that the signature is lawfully collected, used and disclosed only to authorised recipients.
11. iCloud, CloudKit and allocation of responsibility
Depending on the app version and settings, some apps offer storage or synchronisation through Apple iCloud or CloudKit. App data may be stored in a CloudKit area associated with the user's Apple Account and synchronised between devices.
SchelloLabs does not operate its own cloud servers for this purpose. In ordinary app and support operations, SchelloLabs has no routine access to the content of private CloudKit databases. This does not alter the fact that SchelloLabs remains responsible for the CloudKit integration and its purposes where SchelloLabs determines the purposes and means of that processing.
Under the currently published Apple Developer Program terms, Apple acts as a technical service provider or agent for the processing, storage and handling of personal data stored through the iCloud Storage APIs or CloudKit APIs. Those terms include, among other matters, processing on instructions, confidentiality, assistance with data-subject rights and personal-data breaches, information supporting obligations under Article 28 GDPR, and safeguards for international transfers. Apple may process the data within the scope of those terms to provide and improve the iCloud service.
Apple separately acts under its own responsibility in relation to the Apple Account, the general provision of iCloud, the App Store and other Apple services. Apple may also process technical and diagnostic information about the use of iCloud services in accordance with Apple's terms.
CloudKit processing serves the storage, synchronisation and, where available, collaboration selected by the user. Where SchelloLabs is responsible, Article 6(1)(b) GDPR is generally the legal basis. For data relating to other individuals, the legal basis must be determined by the relevant user or responsible organisation. Special categories of personal data additionally require an applicable condition under Article 9(2) GDPR and, where relevant, national law.
Use requires an Apple Account, active iCloud configuration, sufficient storage and, where applicable, an internet connection. The user can manage iCloud functions through the system or app settings. Disabling them may limit synchronisation or collaboration functions.
Further information:
Apple Privacy Policy:
https://www.apple.com/legal/privacy/en-ww/
iCloud Terms and Conditions:
https://www.apple.com/legal/internet-services/icloud/en/terms.html
Apple Developer Program License Agreement, in particular Attachment 4:
https://developer.apple.com/support/terms/apple-developer-program-license-agreement/
12. CloudKit Sharing and collaboration
Some apps may use expressly provided sharing or collaboration functions through CloudKit Sharing. Other apps, in particular RegiePro|tokolle and StundenPro|tokolle in their currently intended versions, use CloudKit solely for private synchronisation between the user's own devices and do not offer team sharing through CloudKit.
With CloudKit Sharing, selected data may be shared with invited Apple users. Depending on the assigned role, invited persons may view, add, change or delete content. The creator or administrator decides whom to invite and what data to share.
Before issuing an invitation, the user must verify that sharing is lawful and that invited persons receive only the data required for their role. When sharing is ended, other participants generally lose access provided through CloudKit. Content already exported, photographed, copied or otherwise stored may, however, continue to exist outside the app.
13. Apple App Store, StoreKit, purchases and subscriptions
Downloads, updates, in-app purchases, one-off purchases and subscriptions are processed through the Apple App Store and StoreKit. In doing so, Apple processes Apple Account, device, purchase, payment, subscription, security and fraud-prevention data under its own responsibility and in accordance with Apple's terms.
The relevant app receives only the information required to verify and provide purchased features. This may include, in particular:
- product identifier
- transaction identifier and original transaction identifier
- purchase, expiry, renewal, revocation and entitlement status
- status of a purchase restoration
SchelloLabs does not receive complete credit-card, bank-account or other payment details. According to Apple's current information, purchase receipts accessible to development teams generally do not contain directly identifying payment information. For subscriptions, Apple may provide a subscriber identifier specific to the user and development team and reports concerning the subscription and country or region.
Where SchelloLabs processes entitlement status within the app, the legal basis is Article 6(1)(b) GDPR for performance of the app user agreement. Where statutory evidence or retention duties apply, Article 6(1)(c) GDPR is the legal basis.
The “Restore Purchases” function initiates a renewed check with Apple for existing restorable entitlements. Subscriptions are managed, changed and cancelled through the Apple Account.
Further information:
https://www.apple.com/legal/privacy/data/en/app-store/
14. Device permissions, camera, photos, files, location and notifications
Depending on the app and the function selected by the user, the operating system may request access to the camera, photo library, files, location or notifications.
An operating-system permission does not automatically transmit data to SchelloLabs and does not automatically constitute consent under data protection law. It initially enables the app to perform the selected function on the device. Data is transmitted to Apple only where an enabled iCloud or CloudKit function provides for this; disclosure to other recipients occurs only after selection by the user.
- Camera and photo library: Photos may be added to projects, protocols, reports, records, stable communities or events.
- Files: Depending on the app, documents and PDF, CSV or GAEB files may be imported, opened, stored or exported.
- Location: RegiePro|tokolle may, at the user's request, capture a place or location for a record. Under its current feature set, StundenPro|tokolle does not use location data.
- Notifications: Where an app provides local reminders, these are generally scheduled on the device. SchelloLabs does not receive the reminder's content as a result.
Permissions can be changed or withdrawn at any time in the system settings. The relevant function may then be restricted. Where processing is exceptionally based on consent under data protection law, that consent can also be withdrawn at any time with effect for the future; withdrawal does not affect the lawfulness of processing carried out before withdrawal.
Photos, documents, location details and file contents may contain personal, confidential or security-relevant information. Before recording, storing or sharing them, users must verify that the individuals concerned have been appropriately informed and that the processing is lawful.
15. Importing, exporting and sharing data
Depending on the app, data may be imported or exported, in particular as PDF, CSV or GAEB files. System functions such as AirDrop, Mail, Messages, Print, Files or other installed apps may also be used.
An export or disclosure occurs only after the user makes the relevant selection. The user determines the content, recipient and transmission method.
Once data has been transferred to a selected recipient, cloud-storage provider or third party, further processing is governed by that recipient's or service provider's responsibility, terms and privacy information. SchelloLabs has no control over such further processing.
Exported, sent or copied files may continue to exist after the original app data has been deleted. They must be deleted separately at their respective storage location or by the recipient.
16. Completion information, signatures, checksums and change histories
Some apps may process status information, signature images, completion times, snapshots, change information or technical checksums to make a documented state traceable and reduce unintended changes to completed records.
This information is processed for the documentation and integrity functions of the relevant app. Where SchelloLabs is responsible for the technical processing, Article 6(1)(b) GDPR is generally the legal basis. Professional users must determine the legal basis on which they process signatures and personal record or change data relating to participants and how long that data may be retained.
Technical checksums are not used for biometric identification, advertising or profiling.
17. Diagnostic, crash and App Store analytics data
Apple may provide SchelloLabs with technical crash, diagnostic or App Store analytics data where the user has enabled the relevant sharing setting in Apple's privacy and analytics settings or where Apple provides aggregated reports.
Such data may include, in particular, the app version, operating-system version, device type, time, technical state information, a crash report and aggregated usage or store information. It is used to investigate errors and improve stability, security and usability. SchelloLabs does not intentionally add project, document, photo or free-text content to automatic diagnostic reports. For logs or attachments voluntarily sent to support, the user must review the content before sending.
Where SchelloLabs receives and uses diagnostic or analytics data provided by Apple, the legal basis is Article 6(1)(f) GDPR. The legitimate interest is troubleshooting and the secure and stable provision of the apps. The sharing of device analytics with Apple is separately governed by the user's Apple settings and Apple's privacy information. If SchelloLabs requests separate consent for an additional diagnostic transmission in a particular case, the legal basis is Article 6(1)(a) GDPR; consent may be withdrawn with effect for the future.
Diagnostic information is retained only for as long as needed to investigate, remedy and document the relevant problem. The user can control whether and to what extent Apple collects diagnostic data and shares it with developers through the device settings.
18. Recipients of personal data
Personal data is disclosed only where necessary for the purposes described, where the user initiates the disclosure or where a legal obligation applies.
Potential recipients include:
- STRATO as processor for website hosting and email communication
- Apple as technical service provider for iCloud and CloudKit where provided for by Apple's terms
- Apple under its own responsibility for the Apple Account, App Store, StoreKit, payments, device backups and Apple's own analytics services
- participants invited by the user to a CloudKit share
- recipients and third-party providers selected by the user through import, export and sharing functions
- public authorities, courts or other authorised bodies where disclosure is legally required
SchelloLabs does not sell personal data and does not disclose app content to advertising networks or data brokers.
19. Transfers to third countries
Under the agreed hosting model, STRATO provides the website hosting in Germany or within the European Union. Processing by subprocessors is governed by the data processing agreement with STRATO.
For Apple services, it cannot be ruled out that Apple entities or subprocessors process data outside the European Union or European Economic Area. According to Apple's current privacy information, international transfers from the European Economic Area are based in particular on adequacy decisions or standard contractual clauses. Apple's current developer terms also provide for an adequate level of protection or appropriate contractual transfer mechanisms for personal data processed through the iCloud Storage APIs and CloudKit APIs.
Details and options for requesting further information are set out in Apple's privacy information and contractual terms linked in sections 11 and 13.
Where the user independently selects a recipient, cloud-storage service or third party outside the European Economic Area, the user or responsible organisation must assess the lawfulness of that transfer.
20. Retention and deletion
SchelloLabs retains personal data only for as long as required for the relevant purpose or for as long as statutory duties require continued storage.
In particular:
- Website and hosting logs are retained as described in section 5.
- Contact and support data is retained as described in section 7.
- Technical diagnostic and analytics data is retained as described in section 17.
- Locally stored app content remains on the end device until the user deletes it in the app, removes the app data or uninstalls the app.
- iCloud or CloudKit data remains stored in accordance with the relevant app function, user settings and Apple's terms until removed by the user or through an available deletion function.
- Purchase, payment and subscription data is retained by Apple in accordance with Apple's legal and contractual requirements.
- Exported, sent or shared files must be deleted separately at the relevant storage location or by the recipient.
Deleting an app does not necessarily terminate or erase existing iCloud backups, CloudKit data, shares or previously exported files. Where necessary, these must also be deleted through the app, iCloud settings, the Apple Account or by the relevant recipient.
Where an app offers a function to delete its iCloud data, that function covers only the data of the relevant app. Other iCloud content, data from other SchelloLabs apps, the Apple Account, App Store purchases, subscriptions and restorable purchase entitlements remain unaffected. Synchronisation of a deletion to other devices may be delayed.
Because SchelloLabs generally cannot view local or private CloudKit content, SchelloLabs cannot directly delete that content for the user. It is generally managed through the relevant app, the device, or Apple's privacy and iCloud tools.
Before deletion, users should review any export or retention obligations. Evidence required by law or contract should first be secured in an appropriate location. Copies already stored by other persons are not removed by deleting data in the app.
21. Requirement to provide data
Technical access data generated when the website is accessed is required to transmit and securely provide the website. Without that processing, the website cannot be accessed.
Providing information in a contact or support request is voluntary. Without a contact method and a sufficient description, the request may not be capable of being handled.
Entering content in the apps is generally voluntary. Certain information may nevertheless be required to perform a function selected by the user or generate a meaningful document. Optional camera, photo, file, location and notification functions may be unavailable or restricted without the corresponding operating-system permission.
Apple's technical and contractual requirements also apply to App Store purchases, subscriptions, purchase restoration and iCloud functions.
22. Rights of data subjects
Subject to the statutory requirements, data subjects have, in particular, the following rights:
- access to personal data processed by SchelloLabs under Article 15 GDPR
- rectification of inaccurate data under Article 16 GDPR
- erasure under Article 17 GDPR
- restriction of processing under Article 18 GDPR
- data portability under Article 20 GDPR
- objection to processing based on Article 6(1)(e) or (f) GDPR under Article 21 GDPR
- withdrawal of consent with effect for the future under Article 7(3) GDPR
- complaint to a data protection supervisory authority under Article 77 GDPR
An objection to processing under Article 6(1)(f) GDPR may be made on grounds relating to the data subject's particular situation. SchelloLabs will then no longer process the data unless compelling legitimate grounds or grounds for the establishment, exercise or defence of legal claims override the objection.
To exercise these rights, send a message to:
support@schellolabs.de
Where necessary, SchelloLabs may request additional information to reasonably verify the applicant's identity and entitlement. SchelloLabs will not collect additional personal data solely for identification where this is not necessary.
Because SchelloLabs does not operate app user accounts and has no routine access to local or private CloudKit content in ordinary operations, the applicant may need to identify the relevant app, data record and authority to act. Local data can generally be managed within the relevant app or by removing the app data. For data processed by Apple under Apple's own responsibility, Apple's privacy tools and contact channels must be used.
The competent supervisory authority is, in particular:
Der Landesbeauftragte für den Datenschutz Niedersachsen
Prinzenstraße 5
30159 Hannover
Germany
Telephone: +49 511 120-4500
Email: poststelle@lfd.niedersachsen.de
Website: https://www.lfd.niedersachsen.de
Data subjects may also lodge a complaint with any other supervisory authority competent under Article 77 GDPR.
23. Data security
Taking into account the state of the art, implementation costs and the nature, scope, context and purposes of processing, SchelloLabs implements appropriate technical and organisational measures to protect processing for which SchelloLabs is responsible against loss, alteration, unauthorised access and unauthorised disclosure.
These measures include, in particular:
- data minimisation and primarily local processing
- encrypted transmission of the website
- use of Apple's security and permission mechanisms
- separation of data areas between the individual apps
- app-specific deletion functions where provided
- limitation of SchelloLabs' own server-side processing
- no SchelloLabs app user accounts and no central SchelloLabs server database for app content
- protection of completed records and technical integrity checks where provided in the relevant app
- regular maintenance and updating of the apps
Complete protection during data transmission or on end devices cannot, however, be guaranteed. Users should protect their device and Apple Account by using an up-to-date operating system, a secure device passcode, Face ID or Touch ID, two-factor authentication, careful access allocation and appropriate backups.
24. No advertising, tracking, AI analysis or profiling by SchelloLabs
SchelloLabs does not use app content for personalised advertising, cross-provider tracking, user profiles or automated decision-making, including profiling within the meaning of Article 22 GDPR.
Under the current feature set, the apps covered by this Privacy Policy do not transmit app content to an AI service, and SchelloLabs does not perform AI analysis of app content. SchelloLabs does not use app content to train its own or third-party AI models.
This statement concerns app processing determined by SchelloLabs. Independent processing by Apple in the App Store, Apple Account or other Apple services is governed by the user's settings and Apple's terms and privacy information.
25. Updates to this Privacy Policy
This Privacy Policy will be updated where legal requirements, the website, service providers or the actual data processing of an app change.
The current version is available at:
https://www.schellolabs.de/datenschutz/
For material changes to an app's data processing, additional information may be provided within the relevant app or through the App Store.
© 2026 Marcus Schellstede - SchelloLabs . Alle Rechte vorbehalten.
APPS MADE IN PETERSFEHN - GERMANY