Legal
Privacy Policy
1. Who we are
The Service is provided by Arongame OÜ, registration number 12798262, registered at Pirita tee 26f-11, 12011 Tallinn, Estonia (“Tuntiva”, “we”, “us”).
Privacy contact: arongame.studio@gmail.com
General support: arongame.studio@gmail.com
2. Our role and your employer's role
Customer-controlled workforce data
When an employer or other organisation uses Tuntiva to manage workers, sites, shifts, approvals, advances or reports, that customer determines why and how this workforce data is used. The customer is normally the data controller and Tuntiva acts as its data processor. Workers should first direct requests concerning employment records, corrections, approvals or legally required retention to their employer.
Data controlled by Tuntiva
Tuntiva is the controller for data needed to create and secure Service accounts, administer customer relationships and subscriptions, communicate about the Service, prevent abuse, comply with law and operate this public website.
3. Information we process
| Category | Examples |
|---|---|
| Account and identity | Name, email address, password hash, profile image, language, user ID, email-verification state and Google account identifier when Google Sign-In is chosen. |
| Organisation | Organisation name, business ID, country, contact email, preferred language, time zone, currency, subscription plan and member roles. |
| Worker profile | Name, work email, phone, language, role, status, internal worker number, Finnish tax number and employment dates when supplied by the customer. |
| Work sites and assignments | Site name, code, address, city, client name, instructions, assigned workers, roles and assignment dates. |
| Working-time records | Work date, start and end time, breaks, site, work description, travel details, status, corrections, rejection reasons, approver and revision history. |
| Financial workflow data | Advance amount, currency, date, comment, attachment reference and approval/payment status. Tuntiva does not currently store payment-card details. |
| Security and technical data | Session tokens, IP address, user agent, timestamps, request rate-limit records, audit events, synchronisation events and diagnostic logs. |
| Communications | Invitation emails and messages sent to support or privacy contacts. |
| Local device data | The mobile app stores authentication credentials securely and keeps an offline working copy of relevant sites and time entries on the device for synchronisation. |
4. Where information comes from
- you, when you register, sign in, record work or contact us;
- the customer organisation, such as an employer inviting a worker or assigning a work site;
- Google, if you choose Google Sign-In;
- devices and network infrastructure, through necessary security and service logs.
5. Why we process information and our legal bases
| Purpose | Typical legal basis |
|---|---|
| Create accounts, authenticate users, synchronise data and provide requested Service features. | Performance of a contract or steps requested before entering a contract; for workforce data, the customer's documented instructions. |
| Record and review working time, assignments, advances and reports. | The customer's legal basis as controller, which may include employment law, legal obligation, contract or legitimate interests. |
| Secure accounts, prevent fraud and abuse, troubleshoot failures and maintain auditability. | Legitimate interests in providing a secure and reliable Service and, where applicable, legal obligations. |
| Manage subscriptions, customer support and operational communications. | Contract, legitimate interests and legal obligations. |
| Comply with binding legal requests, accounting duties and the establishment, exercise or defence of legal claims. | Legal obligation and legitimate interests. |
Where we rely on legitimate interests, we consider necessity, proportionality and the effect on individuals. Where consent is legally required, it may be withdrawn without affecting earlier lawful processing.
6. Google Sign-In
If you choose Google Sign-In, Tuntiva receives only information needed for authentication: a stable Google account identifier, name, email address, email-verification status and, if available, profile image. Tuntiva requests only openid, email and profile. We do not request access to Gmail, Google Drive, contacts or calendars.
Google processes information under its own Privacy Policy. Disconnecting Google does not automatically delete Tuntiva records; use the account-deletion process below.
7. Service providers and disclosures
We do not sell personal data and do not use it for third-party advertising. We disclose information only as necessary to operate the Service, follow customer instructions, complete a corporate transaction or comply with law.
- Cloudflare — edge hosting, Workers compute, D1 database, R2 object storage, security and operational logs;
- Resend — delivery and limited retention of transactional email metadata;
- Google — authentication when Google Sign-In is selected;
- Apple and Google Play — app distribution and store-level diagnostics according to the user's store settings;
- professional advisers and competent authorities where legally required.
Customer organisations can make workforce data available to authorised owners, administrators, foremen, accountants and workers according to role-based permissions.
8. International transfers
Our providers may process information in countries outside the European Economic Area. Where a destination does not benefit from an adequacy decision, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses and supplementary security measures, as applicable. Further information can be requested from arongame.studio@gmail.com.
9. Retention
- Account and customer content is retained while the relevant account or customer agreement remains active.
- After a valid deletion or contract-termination request, data scheduled for deletion is removed from active systems within 30 days unless the customer or law requires retention.
- Residual encrypted backups and disaster-recovery copies may remain for up to 90 additional days before being overwritten.
- Security and audit records may be retained for up to 12 months where necessary to investigate abuse, demonstrate actions or protect legal claims.
- Transactional email metadata is retained according to the configured email provider plan and no longer than needed for delivery and troubleshooting.
- Records required by accounting, employment or other law are retained for the applicable statutory period. They may be restricted rather than immediately erased.
A customer organisation may set longer retention rules for workforce records for which it is controller.
10. Security
We use HTTPS encryption in transit, access controls, role-based permissions, password hashing, restricted production secrets, session expiry, audit logging, rate limiting and managed cloud infrastructure. Sensitive credentials are stored using platform security facilities. No service can guarantee absolute security; suspected incidents should be reported promptly to arongame.studio@gmail.com.
11. Cookies and analytics
This public website does not currently use advertising cookies, behavioural analytics or third-party tracking scripts. The authenticated Service uses strictly necessary authentication and security technologies. If optional analytics or marketing technologies are introduced, this Policy and any required consent controls will be updated before use.
12. Your rights
Subject to applicable law, you may request access, correction, deletion, restriction, portability or objection to processing. You may withdraw consent where processing is based on consent and may complain to a data-protection authority.
For employer-controlled workforce data, contact the employer first. Tuntiva will assist customer controllers with verified requests. For Tuntiva-controlled data, contact arongame.studio@gmail.com. We may request information needed to verify identity and authority.
Our lead supervisory authority is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon). You may also contact the authority in the EEA country where you live or work or where the alleged infringement occurred.
13. Account and data deletion
Instructions are available on the Tuntiva account-deletion page. Deleting a user account may not automatically erase employer-controlled working-time records that the employer must retain. In such cases the account is removed or de-identified where appropriate and retained records remain under the customer's responsibility and access controls.
14. Children
Tuntiva is a workforce service and is not directed to children. Customer organisations are responsible for ensuring that any employment of minors and related processing is lawful and that required guardian notices or permissions are provided.
15. Automated decision-making
Tuntiva does not use personal data to make solely automated decisions that produce legal or similarly significant effects. Time approvals and employment decisions remain with authorised people in the customer organisation.
16. Changes to this Policy
We may update this Policy when the Service, providers or law changes. We will change the “Last updated” date and provide reasonable notice of material changes through the Service or customer contact channels.
17. Contact
Arongame OÜ
Pirita tee 26f-11, 12011 Tallinn, Estonia
Registration number: 12798262
Privacy: arongame.studio@gmail.com
Support: arongame.studio@gmail.com