Privacy Policy
Last updated: 20 August 2026. The legally binding version is available in German at kalender-sync.de/datenschutz.
We, PPJ Venture Labs UG (haftungsbeschränkt) (hereinafter: “we” or “us”), take the protection of your personal data seriously. This privacy policy informs you about the manner in which your personal data is processed when you use our website (kalender-sync.de) and our application (app.kalender-sync.de, hereinafter: “Kalender-Sync”).
1. Controller
Controller within the meaning of Art. 4(7) GDPR:
PPJ Venture Labs UG (haftungsbeschränkt)
Hohenzollernstraße 30, 80801 Munich, Germany
Email: support@kalender-sync.de
Phone: +49 174 3361564
A data protection officer has not been appointed, as we are not legally obliged to do so (Art. 37 GDPR in conjunction with § 38 BDSG, the German Federal Data Protection Act). If you have any questions, please contact: support@kalender-sync.de
2. Website (kalender-sync.de)
Hosting
The website is hosted externally at Netlify, Inc., 2325 3rd Street, Suite 296, San Francisco, CA 94107 USA. The data processing takes place on the basis of Art. 6(1)(f) GDPR (legitimate interest in the secure provision of the online offering). The data transfer to the USA is based on EU Standard Contractual Clauses (SCCs).
Transport security: All connections to this website are made exclusively via TLS 1.2+ with AEAD ciphers (ChaCha20-Poly1305 / AES-GCM) and forward secrecy. HSTS preload is enabled (max-age 2 years). Technical and organisational measures of the Kalender-Sync app (encryption at rest, OAuth scopes, sub-processors) are documented under For IT admins.
Server log files
The provider automatically collects information in server log files (browser type, operating system, referrer URL, time, IP address). This data is processed on the basis of Art. 6(1)(f) GDPR for the technically error-free provision of the website and is not merged with other data sources.
Cookies & consent management (Klaro)
We use Klaro (self-hosted, open source) as our consent management tool. Klaro stores your cookie preferences in a cookie named klaro. This cookie is technically necessary for storing your consent decision and falls under § 25(2) no. 2 TTDSG (strictly necessary). No data is transmitted to third parties. You can change your cookie settings at any time via the “Cookie settings” link in the footer.
Web analytics: Google Analytics 4
We use Google Analytics 4 (GA4) to analyse website usage. GA4 is activated only after your explicit consent (Basic Consent Mode — before your consent, no data whatsoever is sent to Google and no script is loaded).
Legal basis: Art. 6(1)(a) GDPR (consent) in conjunction with § 25(1) TTDSG.
Data collected: IP address (automatically anonymised by GA4), device and browser information, pages visited, time spent, referrer URL, interaction events, cookie identifiers (_ga, lifetime: up to 2 years).
Recipients: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. As sub-processor: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA, USA.
Data transfer to the USA: On the basis of the adequacy decision of the EU Commission pursuant to Art. 45 GDPR (EU-US Data Privacy Framework). Google LLC is certified under the DPF.
Processing on behalf: Data processing terms with Google pursuant to Art. 28 GDPR are in place (accepted on 1 April 2026).
Retention period: Data retention in Google Analytics is set to 2 months. Google Signals is disabled. Personalised advertising is disabled.
Withdrawal: You can withdraw your consent at any time via the “Cookie settings” in the footer. The lawfulness of the processing carried out up to the withdrawal remains unaffected. In addition, you can use the Google Analytics Opt-Out Browser Add-On.
Marketing measurement: Microsoft Advertising (UET)
We use Universal Event Tracking (UET) from Microsoft Advertising to measure the effectiveness of our advertisements on Bing and in the Microsoft Audience Network. The UET tag is loaded only after your explicit consent (Consent Mode — before your consent, no data is transmitted to Microsoft and no script is loaded).
Legal basis: Art. 6(1)(a) GDPR (consent) in conjunction with § 25(1) TTDSG.
Data collected: IP address, device and browser information, pages visited, conversion events (e. g. signup, conclusion of contract), Microsoft click ID (msclkid) when an advertisement is clicked, cookie identifiers (_uetsid, _uetvid, MUID).
Recipients: Microsoft Corporation, One Microsoft Way, Redmond, WA 98052, USA. EU representative: Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland.
Data transfer to the USA: On the basis of the adequacy decision of the EU Commission pursuant to Art. 45 GDPR (EU-US Data Privacy Framework). Microsoft Corporation is certified under the DPF.
Conversion measurement with enhanced accuracy (Enhanced Conversions): For conversion events (signup, start of the trial period, conclusion of contract) we transmit, in addition to the standard tracking data, a SHA-256 hashed form of your email address to Microsoft. The hash is computed entirely in your browser or on our server; your email address itself never leaves our server in plaintext form. Microsoft uses the hash in order to be able to attribute the advertising conversion to an ad delivery even when browser cookies do not permit this (e. g. Safari ITP, cross-device clicks). These transmissions take place exclusively if you have previously consented to marketing tracking.
Storage of the Microsoft click ID (msclkid): If you reach our site via a Microsoft advertisement (Bing), Microsoft appends the parameter msclkid to the URL. With your marketing consent, we store this identifier in your user account in order to be able to attribute later conversion events (in particular the conclusion of a contract) to the original advertisement. Storage follows the “first-touch” principle (only the first click counts) and only for the maximum conversion window duration of 90 days. Upon conclusion of a contract, we transmit the msclkid server-side to Microsoft. If you withdraw your consent or delete your account, the msclkid is deleted from our database; conversion data already transmitted to Microsoft cannot be recalled by us.
Cookie retention period: _uetsid 24 hours, _uetvid 16 months, MUID 13 months.
Withdrawal: You can withdraw your consent at any time via the “Cookie settings” in the footer. The lawfulness of the processing carried out up to the withdrawal remains unaffected. In addition, you can use the Microsoft advertising opt-out.
Marketing measurement: Google Ads
We use Google Ads conversion tracking to measure the effectiveness of our advertisements on Google properties (Google Search, Google Display Network, YouTube). The Google Ads tag is loaded only after your explicit consent (Consent Mode v2 — before your consent, no data is transmitted to Google and no script is loaded).
Legal basis: Art. 6(1)(a) GDPR (consent) in conjunction with § 25(1) TTDSG.
Data collected: IP address, device and browser information, pages visited, conversion events (e. g. signup, conclusion of contract), Google click identifiers (gclid for web ads, gbraid/wbraid for iOS app and web-to-iOS ads under Apple’s Restricted Data Processing), cookie identifiers (_gcl_au, _gcl_aw, _gcl_dc).
Recipients: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (controller for users in the EEA). Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (technical processing).
Data transfer to the USA: On the basis of the adequacy decision of the EU Commission pursuant to Art. 45 GDPR (EU-US Data Privacy Framework). Google LLC is certified under the DPF.
Conversion measurement with enhanced accuracy (Enhanced Conversions for Web): For conversion events (signup, start of the trial period) we transmit, in addition to the standard tracking data, a SHA-256 hashed form of your email address to Google. The hash is computed entirely in your browser; your email address itself never leaves our server in plaintext form. Google uses the hash in order to be able to attribute the advertising conversion to an ad delivery even when browser cookies do not permit this (e. g. Safari ITP, cross-device clicks). These transmissions take place exclusively if you have previously consented to marketing tracking.
Storage of the Google click identifiers (gclid/gbraid/wbraid): If you reach our site via a Google advertisement, Google appends one of the parameters gclid, gbraid or wbraid to the URL. With your marketing consent, we store this identifier in your user account in order to be able to attribute later conversion events (in particular the conclusion of a contract) to the original advertisement. Storage follows the “first-touch” principle (only the first click per identifier type counts) and only for the maximum conversion window duration of 90 days. If you withdraw your consent or delete your account, the stored identifiers are deleted from our database; conversion data already transmitted to Google cannot be recalled by us.
Cookie retention period: _gcl_au, _gcl_aw, _gcl_dc 90 days each.
Withdrawal: You can withdraw your consent at any time via the “Cookie settings” in the footer. The lawfulness of the processing carried out up to the withdrawal remains unaffected. In addition, you can adjust the Google ad settings.
Marketing measurement: Meta Pixel (Facebook/Instagram Ads)
We use the Meta Pixel to measure the effectiveness of our advertisements on the Meta platforms (Facebook, Instagram) as well as to build advertising audiences (e. g. addressing website visitors). The Meta Pixel is loaded only after your explicit consent — before your consent, no data is transmitted to Meta and no script is loaded.
Legal basis: Art. 6(1)(a) GDPR (consent) in conjunction with § 25(1) TTDSG.
Data collected: IP address, device and browser information, pages visited, conversion events (e. g. signup, start of the trial period, conclusion of contract/purchase), Meta click ID (fbclid) when an advertisement is clicked, cookie identifiers (_fbp, _fbc).
Recipients: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland (controller for users in the EEA). Meta Platforms, Inc., 1 Meta Way, Menlo Park, CA 94025, USA (technical processing). For the collection and transmission of data via the Meta Pixel, a joint controllership agreement pursuant to Art. 26 GDPR (Controller Addendum) is in place with Meta.
Data transfer to the USA: On the basis of the adequacy decision of the EU Commission pursuant to Art. 45 GDPR (EU-US Data Privacy Framework). Meta Platforms, Inc. is certified under the DPF.
Conversion measurement with enhanced accuracy (Advanced Matching): For conversion events (signup, start of the trial period) we transmit, in addition to the standard tracking data, a SHA-256 hashed form of your email address to Meta. The hash is computed in your browser or on our server; your email address itself never leaves our server in plaintext form. Meta uses the hash in order to be able to attribute the advertising conversion to an ad delivery even when browser cookies do not permit this (e. g. Safari ITP, cross-device clicks). These transmissions take place exclusively if you have previously consented to marketing tracking.
Server-side conversion transmission (Conversions API): In addition to the browser-based Meta Pixel, we transmit certain conversion events — in particular the conclusion of a paid subscription (purchase) — directly from our server to Meta (Meta Conversions API). In doing so we transmit the event including the purchase value, a SHA-256 hashed form of your email address and the Meta click ID (fbclid/fbc) of your original ad click. This serves the more accurate attribution of advertising conversions when browser-side tracking (cookies) does not permit it. To avoid double counting, browser and server events are reconciled via a shared event ID (deduplication). This server-side transmission takes place exclusively if you have previously consented to marketing tracking; without consent the Meta click ID is not stored and no event is transmitted.
Cookie retention period: _fbp and _fbc 90 days each.
Withdrawal: You can withdraw your consent at any time via the “Cookie settings” in the footer. The lawfulness of the processing carried out up to the withdrawal remains unaffected. In addition, you can adjust your Meta ad settings.
Embedded videos: YouTube (enhanced privacy mode)
On our website we embed videos from the video portal YouTube. For this we use YouTube’s enhanced privacy mode (embedding via the domain youtube-nocookie.com). The embedding takes place only after you actively click the preview image and after your explicit consent. Before your consent, no YouTube script is loaded, no connection to YouTube servers is established and no cookies or local storage entries are set.
Legal basis: Art. 6(1)(a) GDPR (consent) in conjunction with § 25(1) TTDSG.
Data collected (after consent and clicking play): IP address, device and browser information, date and time, where applicable the URL of the page accessed, information on video playback (position, duration). For logged-in YouTube users, YouTube may associate the information with the respective account. We ourselves do not receive any personal data from YouTube.
Recipients: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (controller for users in the EEA). Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (technical processing).
Data transfer to the USA: On the basis of the adequacy decision of the EU Commission pursuant to Art. 45 GDPR (EU-US Data Privacy Framework). Google LLC is certified under the DPF.
Retention period: Determined by YouTube/Google; we have no influence over this. For details, see Google’s privacy policy.
Withdrawal: You can withdraw your consent at any time via the “Cookie settings” in the footer. The lawfulness of the processing carried out up to the withdrawal remains unaffected. Further information can be found in the Google privacy policy.
Appointment booking: Cal.com (only after consent)
In the contact dialog on our website we offer the option to arrange a call directly via an embedded booking widget from Cal.com. The widget is loaded only after you actively click “Activate booking” and after your explicit consent. Before your consent, no Cal.com content is loaded, no connection to Cal.com servers is established and no cookies or local storage entries are set. Alternatively, you can reach us by email at any time without consent.
Legal basis: Art. 6(1)(a) GDPR (consent) in conjunction with § 25(1) TTDSG. For a concrete booking request, additionally Art. 6(1)(b) GDPR (pre-contractual measure).
Data collected (after consent): IP address, device and browser information as well as the data you provide in the booking form (name, email address, where applicable message and chosen time slot).
Recipients: Cal.com, Inc., 530 Divisadero St #225, San Francisco, CA 94117, USA.
Data transfer to the USA: The transfer takes place on the basis of EU Standard Contractual Clauses (SCCs) pursuant to Art. 46(2)(c) GDPR.
Withdrawal: You can withdraw your consent at any time via the “Cookie settings” in the footer. The lawfulness of the processing carried out up to the withdrawal remains unaffected. Further information can be found in the Cal.com privacy policy.
First-touch attribution (UTM parameters & referrer)
If you reach our site via a tagged marketing link (UTM parameters such as utm_source, utm_medium, utm_campaign, utm_term, utm_content) or via a referring website (document.referrer), we record this source information in order to be able to evaluate the effectiveness of our acquisition channels (search, newsletter, referrals).
Legal basis: Art. 6(1)(a) GDPR (consent) in conjunction with § 25(1) TTDSG.
Data collected: Up to five UTM parameters from the landing page URL as well as the document.referrer value (address of the previously visited web page).
Processing on the landing page: At runtime, the parameters are held exclusively in the browser’s memory and inserted into CTA links to the application (app.kalender-sync.de). No storage takes place in cookies, localStorage or sessionStorage on the landing page (TTDSG-compliant).
Processing in the application: After the redirect, the application stores the values temporarily for a maximum of 24 hours in sessionStorage, until you have registered and consented to marketing tracking. Only after your consent are the values stored server-side in your user account, following the “first-touch” principle and for a maximum of 90 days. Without consent, no permanent storage takes place.
Recipients: No transmission to third parties. The data remains in our database (PostgreSQL, hosted at Hetzner, Falkenstein, Germany) and serves exclusively our internal evaluation.
Retention period: 90 days from first contact; thereafter the values are overwritten or updated upon a new first contact. Upon withdrawal of marketing consent or deletion of the user account, the values are deleted immediately.
Withdrawal: You can withdraw your marketing consent at any time via the “Cookie settings” in the footer or via your settings in the application. The lawfulness of the processing carried out up to the withdrawal remains unaffected.
Campaign source at registration
If you reach our website via one of our advertisements or via a link with a channel marker published by us (for example in the descriptions on our YouTube channel), we pass on, when you switch to the application, an indication of which platform or which channel you came from. If you subsequently create an account, this indication is stored in your user account. It serves us exclusively to recognise which of our advertising and marketing activities actually lead to registrations.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in an economical use of our advertising budget). Unlike the click identifiers described above, no consent is required for this, because it is a coarse indication of the platform or channel and not an identifier by which individual clicks or persons could be recognised, and because no transmission to third parties takes place. § 25 TTDSG does not apply to the collection, because no information is stored on or read from your device in the process.
Data collected: Exactly one of ten possible values — google_ads, ms_ads, meta_ads, youtube, mcp_registry, uwait, smithery, mcp_so, claude_directory or chatgpt_directory. Deviating values are discarded and not stored.
Directory entries: The last two values mentioned do not arise via a link on this website, but when you connect our service directly from the directory of an AI assistant (Claude or ChatGPT). In this case you reach the application without passing through this website; the value is derived there server-side from the pending connection request. It names only the directory, not your person, your account with the respective provider or the specific installation.
Processing on the landing page: At runtime, the value is held exclusively in the browser’s memory and inserted into CTA links to the application (app.kalender-sync.de). No storage takes place in cookies, localStorage or sessionStorage.
Processing in the application: The value is taken from the address accessed and held in memory until registration is complete — unlike with the UTM parameters, no intermediate storage in sessionStorage takes place. If you sign in via a sign-in service from Google or Microsoft, the value is carried along during the redirect to that service for a maximum of ten minutes in the encrypted, technically necessary sign-in cookie, since the redirect back cannot otherwise establish any reference to the starting point. After the sign-in is complete, this cookie is deleted.
Point in time of storage: The indication is set exclusively at the moment of account creation and is not changed thereafter (“first-touch”). If you later reach us again via an advertisement, the original value remains unchanged. Without account creation, no storage takes place.
Recipients: No transmission to third parties. The value remains in our database (PostgreSQL, hosted at Hetzner, Falkenstein, Germany) and serves exclusively our internal evaluation.
Retention period: For the duration of the existence of your user account. When your account is deleted, the indication is deleted along with it.
Right to object: As the processing is based on a legitimate interest, you can object to it at any time under Art. 21 GDPR (see section 5). An informal message to support@kalender-sync.de is sufficient; we will then remove the indication from your account.
Reach measurement on ad landing pages
On our landing page variants that are reachable only via advertisements, as well as on pages that are opened via an advertisement or via a link with a channel marker published by us (ref parameter in the address), we count server-side how many visits and how many distinct visitors per day arrive via the respective channel. For this, the page requests an invisible counting pixel of our application (app.kalender-sync.de). The count serves exclusively to assess the effectiveness of our advertising and marketing channels.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in an economical use of our advertising budget). § 25 TTDSG does not apply, because no information is stored on or read from your device in the process — in particular, no cookies are set.
Data processed: The channel value of the page visited (one of the values listed in the preceding section) as well as — exclusively transiently, to avoid double counting — your IP address and browser identifier. From both, a day-scoped check value is formed using a server-side secret key; the IP address and browser identifier themselves are not stored. Without this key, the check value allows no inference about your person and, due to its day scope, is also not linkable across several days.
Retention period: The check values are deleted automatically after 48 hours at the latest. Only aggregated daily totals (visits and unique visitors per advertising platform) without any personal reference are stored permanently.
Recipients: No transmission to third parties. The processing takes place on our servers (Hetzner, Falkenstein, Germany).
Right to object: As the processing is based on a legitimate interest, you can object to it at any time under Art. 21 GDPR (see section 5).
Newsletter signup (funnel)
If you sign up via the form on the website, your email address as well as, optionally, your details about your use case and the calendar providers you use are transmitted to Brevo (Sendinblue SAS, France, EU). The processing takes place on the basis of your consent (Art. 6(1)(a) GDPR). You will first receive a confirmation email (double opt-in). After confirmation you will receive information about the service. The consent can be withdrawn at any time via the unsubscribe link in every email.
If you reach our website via a marketing link, the source information (UTM parameters: source, medium, campaign) is stored together with your email address as contact attributes at Brevo. This serves to evaluate through which channel you became aware of our service. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in optimising our marketing activities). This data is held exclusively in the browser’s memory and is transmitted only when the form is submitted.
Contacting us by email
If you contact us by email, your details are processed in order to handle the request (Art. 6(1)(b) GDPR for contract-related requests, otherwise Art. 6(1)(f) GDPR). The data is deleted as soon as the purpose ceases to apply, provided that no statutory retention obligations exist.
3. Kalender-Sync application (app.kalender-sync.de)
3.1 Which data is processed?
- Email address — for signing in via a one-time login code and for account management
- OAuth tokens — stored encrypted (ChaCha20-Poly1305), in order to access your calendars at Google and Microsoft
- CalDAV credentials — stored encrypted (ChaCha20-Poly1305), for Apple iCloud, GMX, WEB.DE and KSuite calendars
- iCal feed URLs — for retrieving external calendar feeds (read only)
- Payment data — is processed exclusively by Stripe; we do not store any credit card or bank details. We store only the Stripe customer ID and subscription ID.
- Calendar metadata — name and colour of your calendars
- Event ID mappings — exclusively IDs for mapping synchronised appointments; no event content is stored
- Browser identifier (user agent) per session — the user agent transmitted by your browser is assigned to the respective login session, in order to be able to manage sessions and distinguish device types (Art. 6(1)(f) GDPR); the storage is bound to the session (max. 30 days, deleted immediately upon account deletion)
3.2 What is NOT stored?
- No event content (title, description, location, attachments)
- No attendee emails (protection of third parties’ personal data)
- Analytics cookies (Google Analytics) only after explicit consent; no advertising cookies
- No IP addresses beyond the duration necessary to establish the connection
3.3 Purpose and legal basis
- Art. 6(1) sentence 1 (a) GDPR (consent) — Upon your first login you consent to the processing of your data as described here.
- Art. 6(1) sentence 1 (b) GDPR (performance of a contract) — The processing is necessary in order to provide the calendar synchronisation service.
- Art. 6(1) sentence 1 (f) GDPR (legitimate interests) — To ensure the security and stability of the service.
3.4 Cookies and local storage
The following table lists all cookies and localStorage entries that are used on our website and in our application. localStorage, just like cookies, falls under § 25 TTDSG.
| Name | Type | Provider | Purpose | Duration | Legal basis |
|---|---|---|---|---|---|
__Host-session | Cookie (httpOnly, secure, sameSite: lax) | Own (app) | Authentication / session management | 30 days | § 25(2) no. 2 TTDSG (strictly necessary) |
klaro | Cookie | Own (self-hosted) | Storage of your cookie consent decision | 1 year | § 25(2) no. 2 TTDSG (strictly necessary for demonstrating consent pursuant to Art. 7(1) GDPR) |
_ga, _ga_* | Cookie | Google Ireland Ltd. / Google LLC (USA) | Web analytics — distinguishing users | Up to 2 years | Art. 6(1)(a) GDPR + § 25(1) TTDSG (consent) |
_gid | Cookie | Google Ireland Ltd. / Google LLC (USA) | Web analytics — session identifier | 24 hours | Art. 6(1)(a) GDPR + § 25(1) TTDSG (consent) |
pending-invite | localStorage | Own (app) | Temporary storage of an invitation token during the sign-in process | 24 hours (client-side) | § 25(2) no. 2 TTDSG (strictly necessary) |
ks_onboarding_dismissed | localStorage | Own (app) | Remembering whether the onboarding checklist was closed | Unlimited | § 25(2) no. 2 TTDSG (strictly necessary) |
changelog_last_seen | localStorage | Own (app) | Display of new changelog entries | Unlimited | § 25(2) no. 2 TTDSG (strictly necessary) |
The Google Analytics cookies (_ga, _gid) are set only after your explicit consent. Without consent, no analytics cookies whatsoever are set and no script is loaded. For details see section 2 “Web analytics: Google Analytics 4”.
3.5 Email communication and marketing
Kalender-Sync sends transactional emails (login codes, invitations, sync notifications) via Lettermint (Lettermint B.V., Netherlands, EU — sending exclusively via EU infrastructure) as well as, on a transitional basis, via Brevo SMTP. These emails are necessary for the use of the service (Art. 6(1)(b) GDPR). For deliverability monitoring, Lettermint processes the recipient address and delivery status; we store delivery and failure events (without mail content) for error diagnosis.
After signing up in the app, you receive automated onboarding emails that help you with the setup. These emails are based on your usage status (e.g. whether a calendar has been connected). The legal basis is Art. 6(1)(f) GDPR (legitimate interest in the successful activation of the service).
Optionally, you can consent during registration to receiving feature updates and tips by email (Art. 6(1)(a) GDPR). This consent can be withdrawn at any time via the unsubscribe link in every email.
To control the email communication, the following attributes are stored at Brevo: email address, time of registration, whether a calendar has been connected, whether a sharing has been created, which providers are connected (Google, Microsoft, Apple, iCloud), and the number of active sharings. The legal basis for these attributes is Art. 6(1)(f) GDPR (legitimate interest in personalising the onboarding communication). Upon account deletion, the associated Brevo contact is deleted automatically.
3.6 Payment processing (Stripe)
For the processing of payments we use Stripe, Inc. (510 Townsend Street, San Francisco, CA 94103, USA). If you take out a paid subscription, you are redirected to a checkout page hosted by Stripe. Stripe processes your payment data (e.g. credit card number, IBAN) directly — we have no access to this data and do not store it.
We store only the customer ID and subscription ID assigned by Stripe, in order to be able to associate your subscription with your account.
Legal basis: Art. 6(1)(b) GDPR (performance of a contract).
Data transfer to the USA: On the basis of EU Standard Contractual Clauses (SCCs) pursuant to Art. 46(2)(c) GDPR as well as the EU-US Data Privacy Framework pursuant to Art. 45 GDPR. Stripe is certified under the DPF.
Stripe privacy information: stripe.com/privacy
3.7 Retention period
- Account data and OAuth tokens: until the account is deleted by the user
- Event ID mappings: until the associated sharing is ended
- Sessions: 30 days, then deleted automatically
- Log data: a maximum of 30 days
Storage beyond the stated period takes place only in the event of an (imminent) legal dispute or if statutory retention obligations exist (e.g. § 257 HGB, § 147 AO — the German Commercial Code and Fiscal Code).
3.8 Data security
- OAuth tokens and CalDAV credentials are stored encrypted with ChaCha20-Poly1305 (authenticated encryption)
- All connections are TLS-encrypted (HTTPS)
- Event content is processed exclusively in memory and is not persisted
- Attendee emails are as a matter of principle not processed or passed on
3.9 Use of Google API data (Google API Services User Data Policy)
Kalender-Sync uses Google API services in order to access your Google calendars. The use of the data received from Google is subject to the Google API Services User Data Policy, including the Limited Use requirements.
Sharing, transfer and disclosure:
- Google user data is not sold and not passed on to advertisers, data brokers or other third parties.
- Within the synchronisation function, the transfer of calendar data takes place exclusively between the calendar accounts you have connected yourself. Any transfer beyond that takes place only if you yourself connect an AI assistant and release it per calendar (see section 3.10); it then takes place on your explicit instruction to a tool chosen by you.
- Google user data is not used by us to train or improve generalised AI/ML models and is not passed on for that purpose.
Limited Use:
- Google user data is used exclusively to provide the calendar synchronisation as well as — insofar as you explicitly release it — to answer queries from the AI assistant you have connected (see section 3.10).
- Event content (title, description, location, attendees) is processed in memory only and is not stored permanently.
- Google user data is not used by us for advertising and not for training generalised AI/ML models. Provision to an AI assistant takes place solely upon your release and serves to answer your own queries, not model training.
- Only the Google API permissions required for the synchronisation are requested.
3.10 AI assistant connection (optional)
You can optionally connect an AI assistant (e. g. Claude by Anthropic or ChatGPT by OpenAI) with your calendars. The feature is disabled by default and comes into being exclusively through your explicit release.
In doing so, you connect your own account with the respective AI provider to Kalender-Sync and determine, per calendar, which information the assistant may read (only your busy times, title and time, or all details) and whether it may create events. If your assistant makes a query at your request, Kalender-Sync reads the calendars you have released and transmits the released availability to the provider of the assistant you have chosen. This transfer takes place on your instruction to a tool chosen by you yourself; for the further processing by the AI provider, that provider’s own terms and privacy policy apply, over which we have no influence once the data has arrived there.
Depending on the provider, this may mean a transfer to a third country (e. g. the USA). The basis and safeguards for this transfer lie in your relationship with the respective AI provider (their standard contractual clauses, certifications or similar). Some providers, in particular on free or private plans, process data in the USA and/or use inputs under their own terms to improve their models. Please review the terms of your assistant before you release sensitive calendars.
Not transmitted are the attendees, attachments and links of your events; at the “busy only” level, no titles either. We log each query exclusively as metadata (time, calendar concerned, type of query, result) — never the content of your events. The retention of this log is 0, 7 or 90 days depending on the plan. If you ask your assistant to send us feedback (e. g. about a missing feature), we store your message as well as — only if you explicitly agree to this — the permission to reply to you about it once (Art. 6(1)(b) and (f) GDPR); both are deleted with your account.
The legal basis is your consent (Art. 6(1)(a) GDPR), which you grant through the release and can withdraw at any time — individually or for all connections at once — under “AI assistant” in Kalender-Sync. An unused connection additionally expires automatically after 90 days. Removing the connector at the provider only severs the connection there; what governs is the withdrawal in Kalender-Sync.
Note for persons bound by professional secrecy: If your calendars contain information subject to a professional duty of confidentiality (e. g. § 203 StGB, the German Criminal Code), please assess on your own responsibility whether and to what extent a release to an AI provider is compatible with it.
4. Processors and connected providers
To provide the service we use the following external service providers, who are contractually bound as processors pursuant to Art. 28 GDPR:
| Service | Provider | Location | Purpose |
|---|---|---|---|
| Payment processing | Stripe, Inc. | USA (SCCs + DPF) | Subscription management, payment processing |
| Lettermint (transactional email) | Lettermint B.V. | Netherlands (EU) | Transactional emails & service notifications, delivery status |
| Brevo (SMTP + contacts) | Sendinblue SAS | France (EU) | Email sending, onboarding automations, contact attributes |
| Google Analytics 4 | Google Ireland Ltd / Google LLC | Ireland / USA (DPF) | Web analytics (only after consent) |
| Microsoft Advertising (UET) | Microsoft Ireland Operations Ltd / Microsoft Corporation | Ireland / USA (DPF) | Conversion tracking (only after consent) |
| Google Ads | Google Ireland Ltd / Google LLC | Ireland / USA (DPF) | Conversion tracking (only after consent) |
| Meta Pixel | Meta Platforms Ireland Ltd / Meta Platforms, Inc. | Ireland / USA (DPF) | Conversion tracking & advertising audiences (only after consent) |
| Website hosting | Netlify, Inc. | USA (SCCs) | Hosting of the website kalender-sync.de |
| App hosting | Hetzner Online GmbH | Germany | Server infrastructure for Kalender-Sync |
Calendar providers you connect yourself
The following providers are not our processors. You connect your own account there to Kalender Sync and thereby grant us access to your calendars. The contractual relationship exists between you and the respective provider, whose privacy terms continue to apply. We access those calendars solely with the credentials you granted us, and only to the extent you released. You can disconnect at any time in your account.
| Service | Provider | Location | Purpose |
|---|---|---|---|
| Google Calendar API | Google LLC | USA (SCCs) | Read/write calendars |
| Microsoft Graph API | Microsoft Corp | USA (SCCs) | Read/write calendars |
| Apple iCloud (CalDAV) | Apple Inc. | USA (SCCs) | Read/write calendars |
| GMX / WEB.DE (CalDAV) | 1&1 Mail & Media GmbH | Germany | Read/write calendars |
| mailbox.org (CalDAV) | Heinlein Support GmbH | Deutschland | Reading/writing calendars |
| Posteo (CalDAV) | Posteo e. K. | Deutschland | Reading/writing calendars |
| Infomaniak kSuite (CalDAV) | Infomaniak Network SA | Switzerland (adequacy decision) | Reading/writing calendars |
In the case of the US providers (Google, Microsoft, Apple, Meta, Netlify), the data transfer takes place on the basis of EU Standard Contractual Clauses (SCCs) pursuant to Art. 46(2)(c) GDPR or on the basis of the adequacy decision for the EU-US Data Privacy Framework pursuant to Art. 45 GDPR.
5. Your rights (GDPR Art. 15–22)
As a data subject you have the following rights, which you can assert at any time using the contact details given above:
- Access (Art. 15) — Information about the data we store about you
- Rectification (Art. 16) — Rectification of inaccurate data
- Erasure (Art. 17) — Deletion of your data (in the app under Settings → “Delete account”)
- Restriction (Art. 18) — Restriction of processing
- Data portability (Art. 20) — Export of your data as JSON (in the app under Settings → “Export data”)
- Objection (Art. 21) — Objection to the processing
- Withdrawal of consent (Art. 7(3)) — At any time, e.g. by deleting your account. The lawfulness of the processing carried out up to the withdrawal remains unaffected.
Right to object (Art. 21 GDPR)
If the data processing takes place on the basis of Art. 6(1)(f) GDPR, you have the right at any time to object, on grounds relating to your particular situation, to the processing of your personal data. If your personal data is processed for the purposes of direct marketing, you have the right to object to the processing at any time.
You also have the right to lodge a complaint with a data protection supervisory authority. The supervisory authority competent for us is the Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Promenade 18, 91522 Ansbach, Germany.
6. Automated decision-making
No automated decision-making, including profiling, within the meaning of Art. 22 GDPR takes place.
7. SSL / TLS encryption
For security reasons, all our pages use SSL or TLS encryption. You can recognise an encrypted connection by the fact that the address bar of the browser changes from “http://” to “https://” and by the padlock symbol in your browser bar.
8. Data processing agreement (DPA)
If you use Kalender Sync commercially and we thereby process personal data on your behalf, we will conclude a data processing agreement with you pursuant to Art. 28 GDPR. Request it informally at support@kalender-sync.de.
9. Changes to this privacy policy
In the course of the further development of data protection law as well as of technological or organisational changes, this privacy information is reviewed regularly. You will be informed about changes the next time you use the service. This privacy policy is dated 20 August 2026.