Privacy policy¶
Last updated: 5 October 2026
This policy describes which personal data Earlybyte GmbH processes when you use mTime. It is governed by the Swiss Federal Act on Data Protection (FADP) and, where it applies, the EU General Data Protection Regulation (GDPR).
Controller¶
Earlybyte GmbH, Tössuferweg 25, 8406 Winterthur, Switzerland
E-mail: info@earlybyte.ch · Phone: +41 78 883 10 29
Send all questions about data protection to this address.
What mTime is¶
mTime is a tool for booking your working time into your bexio account. You sign in with your bexio account; mTime reads and writes your time entries directly in bexio.
mTime does not store time entries. They are read from bexio when you look at a week and written to bexio when you book.
Data we store¶
- Account data from bexio: your bexio user number, the number of your company at bexio, your name and your e-mail address.
- The connection to bexio: access and refresh tokens, stored encrypted.
- Sessions: a non-reversible hash of your session identifier with an expiry date (30 days).
- Your settings: language, colour scheme, rounding of durations, format of notes, your working hours per weekday.
- Usage figures: how many entries you created with mTime (the number only, not their content) when you first and last signed in, and when you last used mTime (to the hour).
- A running timer: the number of the bexio entry it counts for, the day and the time it was started. It is deleted when you stop it; timers never stopped expire after twelve months.
Earlybyte GmbH as the operator can see a list of users: name, e-mail address, number of the bexio company, sign-in times, last use and number of entries created. In addition mTime keeps one total of all entries created, which is not linked to any person.
In memory only, and for at most ten minutes, mTime holds names of projects, work packages, activities and contacts from bexio and your recently used combinations. This data is never written to disk.
The server log records the time and kind of sign-ins and errors with an internal user number. It contains no tokens, no passwords and no time entries. The web server in front of mTime may log IP addresses for technical reasons.
Purposes and legal bases¶
- To provide mTime to you, recognise you and talk to bexio on your behalf (performance of the agreement on its use).
- To run the service securely and reliably, for example to detect abuse and errors (legitimate interest).
We do not build profiles, do not analyse how you use mTime and do not use your data for advertising.
Cookies¶
mTime sets strictly necessary cookies only. They need no consent, which is why there is no cookie banner.
- Session cookie: keeps you signed in (30 days).
- Sign-in cookie: protects the sign-in at bexio (10 minutes).
- Language cookie: remembers the language you chose (1 year), once you change it.
- Depending on how mTime is run, a load balancer cookie may be added that keeps you on the same server.
mTime uses no analytics or tracking services and loads no scripts, fonts or images from third parties.
Who receives data¶
- bexio AG, Rapperswil: your time entries are kept there. mTime sends to bexio what you book, change or delete, and reads there what it displays. The processing inside your bexio account is governed by bexio’s terms.
- The hosting provider of mTime and the location of its servers will be named here before mTime is released to the public.
Beyond that we pass on no data unless the law obliges us to.
How long we keep data¶
Account data, tokens and settings are kept until you delete your account. Sessions expire after 30 days. Server logs are overwritten after a short time.
Deleting your account and data¶
Under "Settings" you can delete your account yourself at any time. mTime then immediately removes everything it stores about you – account data, tokens, sessions and settings –, revokes the connection at bexio and deletes its cookies in your browser.
Your time entries in bexio are not affected; they belong to your bexio account. The only thing that remains is the total of all entries created with mTime – a number with no link to you.
Your rights¶
You can ask for access to your data, have it corrected or deleted, ask for a copy of it and object to its processing. Write to info@earlybyte.ch.
You can also turn to the Federal Data Protection and Information Commissioner (FDPIC) or, where the GDPR applies, to the competent supervisory authority.
Security¶
The connection to mTime is encrypted. Tokens are stored encrypted; the key is kept apart from the database. Your browser never receives a bexio token.
Changes¶
We may adapt this policy. The version published here applies.