Privacy Policy
Version 2026-07-31
Dieses Dokument ist derzeit nur auf EN verfügbar.
Version 2026-07-31. This policy replaces the version of January 2024, which described the website only.
1. Who are we?
The party responsible for the processing of personal data on this website and in the Done-it applications is:
Done-it International BV
Adriaan Brouwerstraat 27, 2000 Antwerp, Belgium
VAT number 0863.363.148
Managing Director: Eric Van Tilburg
Phone: +32 473 73 57 94
E-mail: info@done-it.app
The controller is the natural or legal person who alone or jointly with others determines the purposes and means of the processing of personal data.
1a. Who is the controller of the data in the app?
This distinction matters, because for most of the data in Done-it we are not the controller.
- Your employer is the controller for the working time, locations, trips, absences and attachments recorded in the app. They decide that Done-it is used, which features are switched on, and what is done with the results. We process that data on their instructions, as their processor, under a data processing agreement.
- We are the controller for our own website, for the accounts and billing data of the customer who subscribes, and for the technical data we need to keep the service running and secure.
If you are an employee using the app and want your data corrected or erased, address your employer first: they hold the record, and we act on their instruction.
2. General information on data processing
a. Scope and purpose
As a rule we process personal data only to the extent necessary to provide a functional website and application, to keep them secure and stable, and for administrative purposes. Personal data within the meaning of Art. 4 GDPR means any data by which you can be personally identified.
Part of the processing happens automatically when you visit https://www.done-it.app/. This information is temporarily stored in a log file: the IP address of your device, the date and time of access, the name and URL of the file retrieved, the referring website, the browser used and, where applicable, the operating system and access provider. Other personal data is processed only with your consent.
b. Legal basis
The legal basis follows primarily from Art. 6(1)(a) GDPR where you have given consent. Where processing serves the performance of a contract to which you are a party — or pre-contractual measures — the basis is Art. 6(1)(b) GDPR. Where processing is necessary to comply with a legal obligation, Art. 6(1)(c) GDPR applies. Where it is necessary to protect vital interests, Art. 6(1)(d) GDPR applies. Where it is necessary for a legitimate interest of ours or of a third party, and your interests and fundamental rights do not override it, Art. 6(1)(f) GDPR applies.
For working time and location data recorded through the app, the basis is the employment relationship between you and your employer and, in Belgium, the legal obligations that apply to registration of presence on certain work sites. Your employer is responsible for establishing that basis.
c. Deletion and storage period
Personal data is deleted or blocked as soon as the purpose of storage no longer applies, or as soon as you ask us to delete it or withdraw your consent. An informal e-mail is enough to withdraw consent; the lawfulness of processing carried out before the withdrawal is unaffected. Mandatory retention periods remain unaffected.
Records created in the app are kept for the retention period agreed with the customer, which depends on the plan and on the legal retention obligations of the country concerned. When a person is removed, their records are retained for that period and then anonymised rather than kept identifiable.
3. The Done-it mobile app
The app is the part of the service that asks for the most sensitive permissions, so this section sets out exactly what is asked, why, and what leaves the device. Every permission below is requested at the moment it is first needed and can be refused or withdrawn at any time in the operating system settings — refusing one disables the feature that needs it, and nothing else.
a. Location
The app asks for location in two distinct steps.
- While you are using the app. Used to show the work sites near you, and to record where you were when you check in or out. On a check-in or check-out we record the coordinates, the accuracy of the reading, and whether the operating system supplied a precise or an approximate position.
- In the background. Asked for separately, and only if your employer uses Track & Trace for vehicle trips. It is used solely while a trip is running, so that the route driven is recorded accurately even when the screen is off. Both platforms show their own indicator while this is active, and the app displays a persistent notification on Android for the duration of the trip.
Each recorded point consists of latitude, longitude, a timestamp and the accuracy of the reading; during a trip it also carries the speed and the identifier of the trip. Points are sent in batches. If the device is offline they are held on the device — at most 5 000 points and at most three days — and sent when a connection returns, after which they are removed from the device.
Location is not collected when no trip is running and you are not checking in or out. There is no continuous tracking of employees outside those cases.
b. Motion and activity (iOS)
Used only to detect whether the vehicle is moving, so that location updates can be spaced out while it is stationary. Its purpose is to save battery during trip tracking; motion data is not stored and does not leave the device.
c. Camera and photos
Used when you attach a photograph to a record — an absence, a mileage entry, or extra work and materials on a project. The app asks for access to the camera when you take a picture and to the photo library when you choose an existing one. Only the images you actively select are uploaded; the app does not read your photo library otherwise.
d. Notifications
Used to send you messages from your employer and reminders related to your work, such as an unfinished registration. To deliver them, the app registers a push token issued by Google Firebase Cloud Messaging together with the platform name. The token identifies the installation, not you personally, and is removed when you log out or uninstall.
e. Diagnostics
When the app encounters an error it sends a crash report to our error-tracking service so the fault can be found and fixed. Reports contain technical information — the error, the screen it occurred on, the app version, the device model and operating system — and an identifier derived from the installation. They are not used to build a profile of you.
f. Permissions the app declares but does not use
We list this rather than leave it unexplained. The Android build declares the microphone permission because it ships a camera component that can record video. Done-it records no audio; the permission is never requested at runtime and no audio is captured, stored or transmitted.
4. Disclosure to third parties and processors
Personal data is transferred only where you have consented (Art. 6(1)(a) GDPR), where it is necessary to perform the contract with you (Art. 6(1)(b) GDPR), where there is a legal obligation (Art. 6(1)(c) GDPR), or where it is necessary to handle your request and no overriding interest of yours prevents it (Art. 6(1)(f) GDPR).
We use the following processors to deliver the service. Each is bound by a data processing agreement.
| Processor | Purpose | Where the data is processed |
|---|---|---|
| Amazon Web Services | Hosting of the application, the API and the database | European Union (Stockholm) |
| Combell | Hosting and domain services for the website | Belgium |
| Google (Firebase Cloud Messaging) | Delivery of push notifications | European Union / United States |
| Sentry | Error and crash reporting | European Union (Germany) |
| Stripe | Subscription payments and invoicing | European Union / United States |
| SendGrid (Twilio) | Transactional e-mail | European Union / United States |
| Belgian Social Security (Smals) | Statutory presence registration, where the customer uses Check In and Out at Work | Belgium |
Transfers outside the EU. Where a processor may handle data outside the European Union, that transfer is covered by the European Commission's standard contractual clauses, so that the data continues to be protected to European standards.
5. Payment data
Subscriptions are paid through Stripe. Card details are entered on Stripe's own payment page and are never received or stored by us: we keep only the brand and the last four digits of the card, so the customer can recognise which card is on file, together with the invoices and the amounts.
6. Communication
If you contact us by e-mail, by telephone or through a form on the website, your details are stored so that the enquiry can be handled and any follow-up questions answered. The legal basis is Art. 6(1)(b) GDPR, for the performance of the contract or pre-contractual measures. The data remains with us until you ask for its deletion or the purpose no longer applies; mandatory retention periods are unaffected.
7. Data on our website
The website stores a log file as described in section 2a, and uses cookies that are necessary for it to function. Where we would use anything beyond what is strictly necessary, we ask for your consent first and you can withdraw it at any time.
8. Your rights
You have the right to obtain confirmation of whether we process personal data about you and to receive a copy of it; to have inaccurate data corrected; to have data erased; to have processing restricted; to receive your data in a portable form; and to object to processing carried out on the basis of a legitimate interest. Where processing is based on consent, you may withdraw it at any time with effect for the future.
To exercise any of these, write to info@done-it.app. If the data concerns your work records, please see section 1a — your employer is the controller and we will refer the request to them.
You also have the right to lodge a complaint with a supervisory authority. In Belgium this is the Data Protection Authority, gegevensbeschermingsautoriteit.be.
9. Data security
Traffic between your device and our servers is encrypted in transit. Access to production data is restricted to the people who need it to operate the service and is logged. Credentials stored on your device are held in the operating system's secure storage.
10. Timeliness and entry into force
This privacy policy applies in its present form from 31 July 2026. We update it when the service changes; the version above tells you which one you are reading.