1. Controller
Gelati Italiani Solution GmbH
Watmarkt 2, 93047 Regensburg, Germany
Represented by Managing Director Daniel Sanna
support@gelatisolution.com
Local Court of Regensburg · HRB 19978 · VAT ID DE255541033
2. Local and private-iCloud principle
3. Data in the app and private iCloud
The app can store business and contact details, cash register totals and movements, vouchers, bank deposits, documents, scans, OCR results, daily and monthly records, PDFs, staff names, birthdays, schedules and absences, portable settings and templates. These categories can be synchronised through Apple CloudKit in the private iCloud area of the signed-in Apple Account between iPhone, iPad and Mac. The provider has no access unless information is actively sent to it.
4. Purposes and legal bases
Local data serves the functions selected by the user. Where the provider processes personal data for purchases, support or legal obligations, the bases are principally contract performance (Art. 6(1)(b) GDPR), legal obligations (Art. 6(1)(c)) and legitimate interests in secure support and abuse prevention (Art. 6(1)(f)).
5. Camera, photos, files, OCR and biometrics
Camera, photo library and files are accessed only after the user selects the relevant feature. Text recognition runs locally using Apple system functions. Face ID or Touch ID may protect local access; biometric templates remain with Apple and are not provided to the app.
6. iCloud synchronisation, backups and iCloud Drive
When enabled in the backup settings of the respective device, private CloudKit synchronisation runs automatically, may arrive with a delay and does not replace a verified backup. The device-specific switch is not synchronised; a change takes effect after the app is fully restarted. Local data remains available when synchronisation is disabled. Face ID or Touch ID, local backup folders, external exports, the app-icon choice and the last-opened page also remain device-specific. Backups are created manually or after Auto Backup is enabled, and the user chooses the location. Apple or another chosen storage provider applies its own terms. Backups may contain sensitive business, staff and receipt data and must be protected.
7. Support and Apple
Information actively sent to support is used to answer the request. Do not send unredacted receipts, signatures, staff records or complete backups unless specifically agreed. Apple processes downloads, purchases, updates and optional diagnostics under its own privacy terms.
8. Staff data
A business entering employee names, birthdays, schedules or absences is responsible for the legal basis, staff information, access controls and deletion. TillFox OS does not replace an employment privacy assessment.
Absence notifications are scheduled only locally on the device. Employee names and the type of absence are not shown in lock-screen notification text by default; these details can be enabled deliberately in notification settings for a personally protected device.
9. Storage and deletion
Synchronised records deleted in the app are also removed from private CloudKit storage and other TillFox devices with a delay. Removing the app generally removes only its local app area; synchronised iCloud data, exports and external backups may need to be deleted separately. Support records are retained only as long as required for the request, evidence and statutory retention.
10. Rights
Where the provider processes personal data, applicable rights include access, rectification, erasure, restriction, portability and objection. A complaint may be lodged with a competent supervisory authority, including the Bavarian State Office for Data Protection Supervision.
11. Changes
This policy will be updated before introducing TillFox accounts, analytics, licensing servers or server-side OCR.
