Saltar para o conteúdo

timer://privacy

Privacy Policy.

Privacy is infrastructure, not a feature. This policy describes exactly what this website collects, what happens when you connect a Google account to Timer, why, and what your rights are.

Effective 16 July 2026

1. Who we are

This website, withtimer.com, is operated by Human Layer Technologies, the company behind Timer, headquartered in Lisbon, Portugal. Human Layer Technologies is the data controller for the personal data described in this policy.

For any privacy matter, contact us at [email protected].

2. What we collect, and why

Access requests. When you submit the Request Access form we collect the information you provide: your name, work email, organization, role, organization size, current AI usage, primary challenge, how you heard about Timer, and any message you write. We use this to evaluate and respond to your request and, if you become a customer, to prepare onboarding. Legal basis: steps taken at your request prior to entering a contract (GDPR Art. 6(1)(b)).

Analytics, only with your consent. We use Google Analytics 4 to understand how this site is used - but nothing is loaded, and no analytics cookie is set, unless you explicitly click Allow on the consent banner. If you decline, or simply ignore the banner, no request is ever made to Google. IP addresses are anonymized. Advertising features are permanently disabled. We honor the Global Privacy Control signal as an automatic decline. Legal basis: consent (GDPR Art. 6(1)(a)), withdrawable at any time via the Cookies link in the footer.

First-party analytics, only with your consent. With the same consent, we run our own first-party analytics to understand how the site is used: the pages you view, how long each section holds your attention, how far you scroll, where you click, and a coarse location (country, region and city) derived from your IP. We never store your raw IP address - it is turned into a salted, irreversible hash the moment your location is resolved, and then discarded. This is first-party only: never sold, never shared, never used to profile you across other sites, and resolved on our own servers rather than by a third party. If you decline consent, none of it is collected. Legal basis: consent (GDPR Art. 6(1)(a)), withdrawable at any time via the Cookies link in the footer.

Research updates. If you subscribe to research updates we store your email address and when you subscribed. We use it for exactly one thing: telling you when there is new research or a new Log entry. No marketing, no sharing, no profiling. Every email carries a one-click unsubscribe link, and unsubscribing takes effect immediately. Legal basis: consent (GDPR Art. 6(1)(a)).

Applications. If you apply via the Careers page we collect your name, email, the link and message you provide. We use this to evaluate your application and contact you about it, and we retain it for up to two years so we can reach out when a fit appears - unless you ask us to delete it sooner. Legal basis: steps taken at your request prior to entering a contract (GDPR Art. 6(1)(b)) and legitimate interest in future recruitment.

Email. If you email us, we keep the correspondence for as long as it remains relevant to your relationship with us. Legal basis: legitimate interest in responding to you.

Server logs. Like virtually every website, our infrastructure keeps short-lived technical logs (IP address, requested page, timestamp) used solely for security and reliability. Legal basis: legitimate interest in operating a secure service.

3. Connecting a Google account (Google Calendar)

Timer can connect to your Google Calendar, but only if you choose to connect it, and only to do what you have asked it to do. This section applies wherever you authorize that connection.

What we access. When you connect your Google account, and only then, Timer requests access to your Google Calendar to read your events and your free/busy availability, and to create and update events on your behalf. We request only the access these features need.

How it is used. This access exists for one purpose: to power the scheduling features you use in Timer. Reading your availability lets Timer show accurate open times; creating and updating events puts the meetings you book onto your calendar. Your Google Calendar data is used only to provide these features to you.

What we never do with it. Your Google Calendar data is never sold, never shared with third parties for advertising, and never sent to any artificial-intelligence or large-language-model service. It is never used to develop, improve, or train AI or machine-learning models.

How it is protected. The connection is authorized through Google OAuth, so Timer never sees your Google password. Google Calendar data and the access tokens that authorize it are transmitted over encrypted connections, stored on access-controlled servers hosted in the European Union, and scoped to the account that connected it.

How long we keep it, and how to remove it. Timer keeps this access, and the calendar data needed to provide the feature, only while your Google account stays connected. You can disconnect at any time in Timer, or revoke access from your Google Account settings. Disconnecting immediately revokes Timer's access, stops all calendar sync, and deletes the associated Google data and tokens we hold.

Limited Use. Timer's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

4. Cookies

This site sets at most three cookies, and two of them exist only to remember choices you make:

site_consent: remembers your analytics choice (Allow or Decline) for 12 months. Set only after you choose.
site_lang: remembers your language preference, if you set one. 12 months.
_ga / _ga_*: Google Analytics cookies, set only after you click Allow. Used to distinguish visits; no advertising use.

Our first-party analytics also uses two browser-storage identifiers, set only after you allow analytics: a persistent visitor id (in local storage) and a per-visit session id (in session storage). They are random values with no personal information in them. Declining, or clearing your browser storage, removes them.

You can change your analytics choice at any time using the Cookies link in the footer, and you can delete any of these cookies in your browser.

5. Where your data lives

Access-request data is stored on infrastructure in the European Union. If you consent to analytics, Google may process that data as described in Google's own privacy documentation; we have configured the integration to minimize what is shared (anonymized IP, no advertising signals).

6. What we never do

We do not sell personal data. We do not run advertising or advertising trackers. We do not profile visitors. We do not load any third-party resource on this site before you consent to it.

7. Your rights

Under the GDPR you can ask us to access, correct, delete, restrict or export the personal data we hold about you, and you can object to processing based on legitimate interest. You can withdraw analytics consent at any time via the footer Cookies link - withdrawal is as easy as consent was.

You also have the right to lodge a complaint with a supervisory authority. In Portugal this is the CNPD (Comissão Nacional de Proteção de Dados).

8. GDPR in practice

Human Layer Technologies is a European company and the GDPR is our home framework, not a foreign requirement. In practice:

Processors. This website relies on a small number of processors: Cloudflare (content delivery and security in front of the site, which processes visitor IP addresses to serve and protect it), Google (email delivery for the confirmations we send, and - only if you consent - analytics), and European hosting infrastructure for the site and its data.

International transfers. Where a processor operates globally (Cloudflare, Google), transfers outside the EEA rely on the EU-U.S. Data Privacy Framework and/or Standard Contractual Clauses.

Retention. Access-request data is kept while your request is active and for a reasonable period afterwards, then deleted. Consent choices expire after 12 months. Technical logs are short-lived. You can request earlier deletion at any time.

Data minimisation by design. The form asks only what we need to evaluate a deployment. The website's database account can read exactly two content tables and write through exactly one procedure - it is technically incapable of touching anything else.

For enterprise customers. Data processing agreements, sub-processor detail and security documentation are part of enterprise onboarding - ask during your intro conversation.

8. Changes

If this policy changes, the new version will be published here with an updated effective date. We will not weaken your protections silently.