Privacy Policy
Last Updated: August 21, 2026
1. Introduction
Limita ("we", "our", or "us") provides time tracking and project estimation capabilities for project management platforms like Trello. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Power-Up and services.
By using Limita, you agree to the collection and use of information in accordance with this policy. If you do not agree with our policies and practices, please do not use our services.
1.1 Who is responsible for your data
Limita is a product of Dannie Hansen Consulting ApS, which is the data controller for the personal data described in this policy:
- Dannie Hansen Consulting ApS
- CVR (Danish company register): DK45631044
- Grenaa, Denmark
- [email protected]
Where we process time tracking data on behalf of a customer's organisation, that organisation is the controller and we act as processor on its instructions.
2. Information We Collect
2.1 Information from Trello
When you install and use Limita, we collect:
- Board and workspace identifiers
- Card information (names, IDs, list positions)
- Member information (usernames, member IDs)
- OAuth tokens for authenticated access to your Trello data
2.2 Time Tracking Data
We collect and store:
- Active timer information (start times, card associations, member assignments)
- Historical time ranges (logged hours, dates, durations)
- Project estimates and custom fields
- User preferences and settings
- Client information for billable hours tracking
2.3 Billing Information
For paid subscriptions:
- Business information (company name, tax ID, address)
- Payment information is processed directly by Stripe (we do not store credit card details)
- Subscription status and billing history
2.4 Technical Information
- IP addresses and user agent information
- WebSocket connection data for real-time synchronization
- API usage metrics and performance data
- Error logs and diagnostic information (via Sentry)
- Marketing website and checkout confirmation interactions used for conversion measurement via Google tag
3. How We Use Your Information
We use collected information to:
- Provide and maintain time tracking functionality
- Synchronize data in real-time across your team members
- Generate time tracking reports and analytics
- Process subscriptions and billing
- Enforce one-timer-per-member rules and business logic
- Improve and optimize service performance
- Measure the effectiveness of our website and paid acquisition campaigns
- Detect and prevent technical issues and abuse
- Comply with legal obligations
4. Data Storage and Security
4.1 Infrastructure
- Hosting: Hetzner Online GmbH, Nuremberg (nbg1), Germany. All application and database workloads run in this region.
- Backups: Encrypted and stored on Hetzner infrastructure in Falkenstein (fsn1), Germany, separately from the cluster
- Database: PostgreSQL 18 with Row-Level Security (RLS) for multi-tenant isolation
- Encryption in Transit: TLS/HTTPS for all data transmission
- Encryption at Rest: LUKS2 full disk encryption with AES-256 for all database and observability volumes
- CDN: Cloudflare for DNS and content delivery
4.2 Third-Party Services
We use a small number of providers to run the service. The complete register, including what each one processes and where, is published at limita.org/subprocessors. In summary:
- Sentry: Error tracking and monitoring (EU region only)
- PagerDuty: Incident management (EU region only)
- Stripe: Payment processing (PCI-DSS compliant)
- Google Ads: Conversion measurement for marketing website visits and successful subscription purchases. This is an advertising conversion tag; we operate no Google Analytics property and set no analytics cookies.
- Atlassian (Trello): The platform Limita runs inside. Board, card and member data reaches us through Trello's API under the authorisation you grant.
- Google Workspace: Email used for support and billing correspondence
- Visma Dinero: Bookkeeping. Billing records are recorded here to meet Danish statutory accounting obligations.
4.3 Security Measures
- JWT authentication with JWKS validation
- Rate limiting (IP and per-member)
- Parameterized SQL queries to prevent injection attacks
- Internal security audits performed at regular intervals
- Automated backups with disaster recovery procedures
5. Data Sharing and Disclosure
We do not sell, trade, or rent your personal information. We only share data in the following circumstances:
- With Your Team: Time tracking data is shared with other members of your workspace
- Service Providers: The sub-processors listed at limita.org/subprocessors, each engaged under a data processing agreement
- Legal Requirements: When required by law, court order, or government regulation
- Business Transfers: In the event of a merger, acquisition, or sale of assets
6. Data Retention
We retain your data for as long as your account is active or as needed to provide services. Specifically:
- Time tracking data: Retained for the lifetime of your subscription plus 90 days
- Billing information: Retained for 7 years for tax and accounting purposes
- Logs and diagnostic data: Retained for 90 days
7. Your Rights (GDPR)
If you are in the European Economic Area, you have the right to:
- Access: Request a copy of your personal data
- Rectification: Correct inaccurate or incomplete data
- Erasure: Request deletion of your data ("right to be forgotten")
- Portability: Receive your data in a machine-readable format
- Object: Object to processing of your personal data
- Restrict: Request restriction of processing
To exercise these rights, contact us at [email protected]
You also have the right to complain to a supervisory authority. Our lead authority is the Danish Data Protection Agency (Datatilsynet), Carl Jacobsens Vej 35, 2500 Valby, Denmark - datatilsynet.dk. You may also complain to the authority in your own country of residence.
8. Cookies and Tracking
Authentication for the Limita product is handled through JWT tokens provided by Trello. We do not rely on browser local storage for authentication.
On our public marketing website and the subscription checkout success page, we use Google tag for Google Ads conversion measurement. This helps us understand which campaigns and pages lead to signups and paid subscriptions.
Our Google tag is configured with consent mode defaults set to denied and ads data redaction enabled. As implemented today, advertising cookies are not set by default and Google receives cookieless measurement pings rather than full cookie-based advertising storage. If we later implement a consent banner, these settings may be updated based on the user's choice.
9. Children's Privacy
Limita is not intended for users under 16 years of age. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately.
10. International Data Transfers
Your time tracking data is stored and processed in Germany, and backed up in Germany. Sentry and PagerDuty are configured to their EU regions.
Some providers are established outside the EU or may support their service from outside it - notably Atlassian, Stripe and Google. Those transfers rely on the European Commission's Standard Contractual Clauses, together with each provider's own supplementary measures. The register at limita.org/subprocessors records the position for each one.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new policy on this page and updating the "Last Updated" date. Continued use of the service after changes constitutes acceptance.
12. Contact Us
For questions about this Privacy Policy, our data practices, or to exercise any of the rights in section 7, contact Dannie Hansen Consulting ApS (CVR DK45631044), Grenaa, Denmark:
- Email: [email protected]
- General Support: [email protected]