22. febrero 2025
Annex 1 to the Data Processing Agreement
Categories of Personal Data Processed, Data Subjects, Processing Purposes and Storage Periods
Threema Work App
1. Categories of Personal Data Processed
1.1. Depending on the use of the current version of the Threema Work App, the following personal data will be processed by Threema:
Personal Data | Personal Data | Personal Data | Personal Data | Personal Data |
---|---|---|---|---|
1. Username | 2. Threema ID | 3. Push token of Google and Apple | 4. IP address |
1.2. The following personal data is optional for the use of the Threema Work App and will only be processed by Threema on behalf of the Controller if it is provided voluntarily:
Personal Data | Personal Data | Personal Data | Personal Data | Personal Data |
---|---|---|---|---|
1. Telephone number | 2. Email address | 3. First name | 4. Last name | 5. Nickname |
6. Job title ¹ | 7. Department ¹ | 8. Category ¹ | 9. Customer Specific Identifier («CSI») ¹ | 10. Logfiles ² |
¹ May be freely defined by the Controller.
² Part of the “Debug Logs” of the Threema Work App, provided that “Logging” has been activated within the Threema Work App. Debug Logs are never automatically sent to Threema.
2. Categories of Data Subjects
Data Subject | Data Subject | Data Subject | Data Subject | Data Subject |
---|---|---|---|---|
1. Users of the Threema Work App ³ |
³ Persons for whom the Controller has created access authorizations in the Threema Work Management Cockpit to use the Threema Work App (one access authorization per license).
3. Processing Purposes
Personal data is processed by Threema for the following purposes:
Purpose | Purpose | Purpose | Purpose | Purpose |
---|---|---|---|---|
1. Contract performance | 2. License verification | 3. Bug fixing and product improvement ⁴ |
⁴ If users of the Threema Work App send Debug Logs to Threema, they are analyzed for this purpose.
4. Storage Periods
4.1. The following personal data is processed by Threema only temporarily during an ongoing data transmission:
Personal Data | Personal Data | Personal Data | Personal Data | Personal Data |
---|---|---|---|---|
1. IP Address |
4.2. The following personal data is stored by Threema for 180 days, calculated from the time of the last connection to the Threema Servers:
Personal Data | Personal Data | Personal Data | Personal Data | Personal Data |
---|---|---|---|---|
1. Push token of Google and Apple |
4.3. The following personal data is stored by Threema until it is analyzed:
Personal Data | Personal Data | Personal Data | Personal Data | Personal Data |
---|---|---|---|---|
1. Logfiles |
4.4. The following personal data is stored by Threema until revocation, i.e. change or deletion, by the Controller:
Personal Data | Personal Data | Personal Data | Personal Data | Personal Data |
---|---|---|---|---|
1. Telephone number ⁵ | 2. Email address ⁵ | 3. Username | 4. First name | 5. Last name |
6. Nickname | 7. Job title | 8. Department | 9. Category | 10. CSI |
⁵ This personal data is stored exclusively in one-way encrypted form as a hash value.
Threema Work Management Cockpit
1. Categories of Personal Data Processed
1.1. Depending on the use of the Threema Work Management Cockpit, the following personal data will be processed by Threema:
Personal Data | Personal Data | Personal Data | Personal Data | Personal Data |
---|---|---|---|---|
1. IP address | 2. Email address | 3. Customer number | 4. Company | 5. Address |
6. Username | 7. Threema ID |
1.2. The following personal data is optional for the use of the Threema Work Management Cockpit and will only be processed by Threema on behalf of the Controller if it is provided voluntarily:
Personal Data | Personal Data | Personal Data | Personal Data | Personal Data |
---|---|---|---|---|
1. First name | 2. Last name | 3. Nickname | 4. Job title ¹ | 5. Department ¹ |
6. Category ¹ | 7. CSI ¹ |
¹ May be freely defined by the Controller.
2. Categories of Data Subjects
Data Subject | Data Subject | Data Subject | Data Subject | Data Subject |
---|---|---|---|---|
1. Customer ² | 2. Administrators | 3. Additional Recipients ³ | 4. Users of the Threema Work App ⁴ | 5. External users of the Threema Apps ⁵ |
² This refers to the person of the Controller itself, provided they personally create and manage the customer account.
³ Recipients of system emails in the Threema Work Management Cockpit (e.g. invoices) who do not have administrator rights.
⁴ Persons for whom the Controller has created access authorizations in the Threema Work Management Cockpit to use the Threema Work App (one access authorization per license).
⁵ Persons who do not use the Threema App or Threema Work App with access authorizations of the Controller, but whose personal data has been entered by the Controller in the Threema Work Management Cockpit.
3. Processing Purposes
Personal data is processed by Threema for the following purposes:
Purpose | Purpose | Purpose | Purpose | Purpose |
---|---|---|---|---|
1. Delivery of the Threema Work Management Cockpit | 2. Contract performance | 3. Marketing with existing customers (voluntary and optional) ⁶ | 4. Information security |
⁶ This applies exclusively to administrators of the Threema Work Management Cockpit in the context of “Product Updates”. Threema invokes the existing customer privilege when sending Product Updates without the prior consent of an administrator of the Controller.
4. Storage Periods
4.1. The following personal data is stored by Threema for 10 days if an error has occurred when calling up the Threema Work Management Cockpit:
Personal Data | Personal Data | Personal Data | Personal Data | Personal Data |
---|---|---|---|---|
1. IP Address |
4.2. 4.2. The following personal data of users of the Threema Work App is stored until the successful activation of the Threema Work App by the respective user:
Personal Data | Personal Data | Personal Data | Personal Data | Personal Data |
---|---|---|---|---|
1. Email address ⁷ |
4.3. The following personal data is stored by Threema until revocation, i.e. change or deletion, by the Controller:
Personal Data | Personal Data | Personal Data | Personal Data | Personal Data |
---|---|---|---|---|
1. Email Address | 2. Customer number | 3. Company | 4. Address | 5. Threema ID |
4.4. The following personal data will be stored linked to the Threema ID by Threema until revocation, i.e. change or deletion, by the Controller:
Personal Data | Personal Data | Personal Data | Personal Data | Personal Data |
---|---|---|---|---|
1. First name | 2. Last name | 3. Username | 4. Nickname | 5. Job title |
6. Department | 7. Category | 8. CSI |
⁷ This only applies to users of the Threema Work App whose credentials were sent by administrators directly from the Threema Work Management Cockpit by email. This is optional, and administrators may change or delete the user’s email address at any time.
Threema Broadcast
1. Categories of Personal Data Processed
1.1. Depending on the use of Threema Broadcast, the following personal data will be processed by Threema:
Personal Data | Personal Data | Personal Data | Personal Data | Personal Data |
---|---|---|---|---|
1. IP Address | 2. Email Address | 3. Customer number | 4. Company | 5. Address |
6. Username | 7. Threema ID | 8. Certain message contents of Broadcast IDs ¹ |
¹ Incoming message contents to Broadcast IDs: Text messages and votes in polls from users of the Threema App or the Threema Work App; message contents are temporarily unencrypted when received by the Broadcast ID on the Threema Servers. Outgoing message contents from Broadcast IDs: Text messages and media files.
1.2. The following personal data is optional for the use of Threema Broadcast and will only be processed by Threema on behalf of the Controller if it is provided voluntarily:
Personal Data | Personal Data | Personal Data | Personal Data | Personal Data |
---|---|---|---|---|
1. Status of outgoing messages of a Broadcast ID | 2. First name | 3. Last name | 4. Nickname |
2. Categories of Data Subjects
Data Subject | Data Subject | Data Subject | Data Subject | Data Subject |
---|---|---|---|---|
1. Customer ² | 2. Administrators | 3. Users of the Threema Apps ³ |
² This refers to the person of the Controller itself, provided they personally create and manage the customer account.
³ Persons who use the Threema App or Threema Work App and whose personal data has been entered by the Controller in Threema Broadcast.
3. Processing Purposes
Personal data is processed by Threema for the following purposes:
Purpose | Purpose | Purpose | Purpose | Purpose |
---|---|---|---|---|
1. Delivery of Threema Broadcast | 2. Contract performance | 3. Information security |
4. Storage Periods
4.1. The following personal data is stored by Threema for 10 days if an error has occurred when calling up Threema Broadcast:
Personal Data | Personal Data | Personal Data | Personal Data | Personal Data |
---|---|---|---|---|
1. IP Address |
4.2. The following personal data is stored by Threema until revocation, i.e. change or deletion, by the Controller:
Personal Data | Personal Data | Personal Data | Personal Data | Personal Data |
---|---|---|---|---|
1. Email Address | 2. Customer number | 3. Company | 4. Address | 5. Username |
6. Threema ID |
4.3. The following personal data will be stored linked to the Threema ID by Threema until revocation, i.e. change or deletion, by the Controller:
Personal Data | Personal Data | Personal Data | Personal Data | Personal Data |
---|---|---|---|---|
1. First name | 2. Last name | 3. Nickname |
4.4. The following personal data will be stored linked to the Threema ID by Threema in connection with incoming message contents to a Broadcast ID (storage period in brackets):
Personal Data | Personal Data | Personal Data | Personal Data | Personal Data |
---|---|---|---|---|
1. Text messages (180 days) ⁴ | 2. Votes in polls (maximum of 180 days) ⁴ ⁵ |
⁴ These message contents are only stored if the Controller has activated the “Save Chat History” function in groups of Broadcast IDs. Once they have been received, message contents are stored in encrypted form.
⁵ The maximum storage period of 180 days is calculated from the time the poll has been sent by the Broadcast ID.
4.5. The following personal data will be stored linked to the Threema ID by Threema in connection with outgoing message contents of a Broadcast ID (storage period in brackets):
Personal Data | Personal Data | Personal Data | Personal Data | Personal Data |
---|---|---|---|---|
1. Text messages (180 days or earlier until revocation) ⁶ | 2. Media files (30 days or earlier until revocation) ⁶ | 3. Status of outgoing messages of Broadcast IDs (depending on the storage period of the respective message) ⁷ |
⁶ Revocation means deletion by the Controller. Without prior deletion, outgoing text messages are automatically deleted from the Threema Servers after 180 days and media files after 30 days.
⁷ The status of outgoing messages from Broadcast IDs is only stored if the Controller has activated the function for tracking outgoing messages.
Threema Gateway
1. Categories of Personal Data Processed
Depending on the use of Threema Gateway, the following personal data will be processed by Threema:
Personal Data | Personal Data | Personal Data | Personal Data | Personal Data |
---|---|---|---|---|
1. IP Address | 2. Email Address | 3. Customer number | 4. Name | 5. Company (voluntary and optional) |
6. Address | 7. Outgoing message contents ¹ |
¹ Outgoing message contents of Gateway IDs in the “Basic” option are only encrypted on the Threema Servers and are temporarily unencrypted; in the “End-to-End” option, such messages are already encrypted on the IT systems of the Controller and cannot be decrypted by Threema.
2. Categories of Data Subjects
Data Subject | Data Subject | Data Subject | Data Subject | Data Subject |
---|---|---|---|---|
1. The person who creates and manages the customer account with the Controller. |
3. Processing Purposes
Personal data is processed by Threema for the following purposes:
Purpose | Purpose | Purpose | Purpose | Purpose |
---|---|---|---|---|
1. Delivery of the des Threema Gateway Cockpit | 2. Contract performance | 3. Information security |
4. Storage Periods
4.1. The following personal data is processed by Threema only temporarily during an ongoing data transmission:
Personal Data | Personal Data | Personal Data | Personal Data | Personal Data |
---|---|---|---|---|
1. Outgoing message contents |
4.2. The following personal data is stored by Threema for 10 days if an error has occurred when calling up the Threema Gateway Cockpit:
Personal Data | Personal Data | Personal Data | Personal Data | Personal Data |
---|---|---|---|---|
1. IP Address |
4.3. The following personal data is stored by Threema until revocation, i.e. change or deletion, by the Controller:
Personal Data | Personal Data | Personal Data | Personal Data | Personal Data |
---|---|---|---|---|
1. Email Address | 2. Customer number | 3. Name | 4. Company | 5. Address |