Skip to content

New: Connect Claude & ChatGPT to your calendars – the AI assistant is here

Kalender Sync

Privacy Policy

Last updated: 28 July 2026. The legally binding version is available in German at kalender-sync.de/datenschutz.

We, PPJ Venture Labs UG (haftungsbeschränkt) (“we” or “us”), take the protection of your personal data seriously. This privacy policy informs you about how your personal data is processed when using our website (kalender-sync.de) and our application (app.kalender-sync.de, hereinafter: “Kalender Sync”).

1. Data Controller

Controller within the meaning of Art. 4 No. 7 GDPR:
PPJ Venture Labs UG (haftungsbeschränkt)
Hohenzollernstraße 30, 80801 Munich, Germany
Email: paul@kalender-sync.de
Phone: +49 174 3361564

2. What Data We Process

Calendar synchronization (core service): Kalender Sync synchronizes availability between your calendars. By default, only free/busy status is transferred; you can optionally enable a higher visibility level per sync (title + time, or full details). Event content (titles, attendees, notes, locations, descriptions) is processed in memory only and never permanently stored. We store:

  • Your email address (for account creation and login)
  • OAuth tokens for Google and Microsoft (we never see your password)
  • Encrypted app-specific passwords for iCloud/GMX/WEB.DE/KSuite (ChaCha20-Poly1305)
  • Calendar metadata (calendar names, IDs, colors)
  • Event time slots and sync mappings (event IDs); event content is not persisted
  • Stripe customer ID and subscription ID (we never see or store your payment details)

Website: When you visit our website, we process server log data (IP address, browser type, requested page, timestamp). If you consent, we use Google Analytics for anonymous usage statistics.

Contact form and emails: When you contact us, we process your name, email address, and message content to respond to your inquiry.

3. Legal Basis

  • Art. 6(1)(b) GDPR — Performance of contract: Processing your calendar data is necessary to provide the synchronization service.
  • Art. 6(1)(a) GDPR — Consent: Google Analytics (analytics), Microsoft Advertising UET, Google Ads and Meta Pixel (marketing) are only activated with your explicit consent via our cookie banner.
  • Art. 6(1)(f) GDPR — Legitimate interest: Server logs for security and error diagnosis.

4. Hosting & Sub-Processors

  • Hetzner Online GmbH (Nuremberg, Germany) — Server hosting. All data is stored and processed in Germany. Data processing agreement in place.
  • Netlify Inc. (USA, EU-US Data Privacy Framework) — Hosting of the marketing website (kalender-sync.de). No personal data from the app is processed here. All connections served exclusively over TLS 1.2+ with AEAD ciphers (ChaCha20-Poly1305 / AES-GCM) and forward secrecy; HSTS with preload enabled (max-age 2 years). Technical and organisational measures of the Kalender Sync app (encryption at rest, OAuth scopes, sub-processors) are documented at For IT admins.
  • Lettermint B.V. (Netherlands, EU) — Transactional and service emails (login codes, sync notifications), sent exclusively via EU infrastructure through mail.kalender-sync.de. Delivery and failure events are stored (without email content) for diagnostics. Data processing agreement in place.
  • Brevo (Sendinblue) (Paris, France) — Marketing and onboarding emails; transactional emails during the ongoing migration. Data processing agreement in place.
  • Stripe, Inc. (USA, EU-US Data Privacy Framework + SCCs) — Payment processing for subscriptions. Stripe processes your payment data directly; we only store the Stripe customer ID and subscription ID. Stripe Privacy Policy.
  • Google LLC (USA, SCCs) — Google Calendar API for reading/writing calendar data.
  • Microsoft Corporation (USA, SCCs) — Microsoft Graph API for reading/writing calendar data.
  • Apple Inc. (USA, SCCs) — Apple iCloud CalDAV for reading/writing calendar data.
  • 1&1 Mail & Media GmbH (Montabaur, Germany) — GMX and WEB.DE CalDAV for reading/writing calendar data; processing stays in Germany.
  • Google Analytics (optional, consent-based) — Anonymous website usage statistics. IP anonymization enabled. Only activated with explicit consent.
  • Microsoft Advertising (UET + Offline Conversion API) (Redmond, USA, EU-US Data Privacy Framework) — Conversion tracking for our ads on Bing. Only activated with explicit marketing consent. For conversion events (signup, trial start, paid subscription), we send a SHA-256 hash of your email to Microsoft (Enhanced Conversions) so the conversion can be matched even when browser cookies don't permit it. The hash is computed in your browser or on our server; your email never leaves us in plaintext. If you arrived via a Bing ad, the Microsoft click ID (msclkid) is stored on your account (first-touch attribution, max. 90 days) and sent server-side at the moment of paid subscription so Microsoft can attribute the revenue to the original click. The msclkid is deleted from our database if you withdraw marketing consent or delete your account.
  • Google Ads (Dublin, Ireland / Mountain View, USA, EU-US Data Privacy Framework) — Conversion tracking for our ads on Google Search, Google Display Network and YouTube. Only activated with explicit marketing consent. For conversion events (signup, trial start), we send a SHA-256 hash of your email to Google (Enhanced Conversions for Web) so the conversion can be matched even when browser cookies don't permit it. The hash is computed in your browser; your email never leaves us in plaintext. If you arrived via a Google ad, the Google click identifier (gclid for web, gbraid/wbraid for iOS and web-to-iOS under Apple's Restricted Data Processing) is stored on your account (first-touch attribution, max. 90 days). Stored identifiers are deleted from our database if you withdraw marketing consent or delete your account.
  • Meta Pixel + Conversions API (Facebook/Instagram Ads) (Meta Platforms Ireland Ltd., Dublin, Ireland / Meta Platforms, Inc., USA, EU-US Data Privacy Framework) — Conversion tracking and audience building for our ads on Facebook and Instagram. Only activated with explicit marketing consent; before consent no script is loaded and no data is sent to Meta. For conversion events (signup, trial start, paid subscription), we send a SHA-256 hash of your email to Meta (Advanced Matching) so the conversion can be matched even when browser cookies don't permit it. The hash is computed in your browser or on our server; your email never leaves us in plaintext. If you arrived via a Meta ad, the Meta click ID (fbclid) is stored on your account (first-touch attribution, max. 90 days) and, at the moment of paid subscription, the purchase event (including its value, the hashed email and the derived fbc identifier) is sent server-side to the Meta Conversions API so Meta can attribute the revenue to the original click. Browser and server events are reconciled via a shared event ID (deduplication). The fbclid is deleted from our database if you withdraw marketing consent or delete your account. Cookies: _fbp, _fbc (90 days each). Data collection is subject to a joint-controllership agreement with Meta pursuant to Art. 26 GDPR (Controller Addendum). You can withdraw consent at any time via the “Cookie settings” in the footer or adjust your Meta ad settings.
  • First-touch source attribution (UTM parameters & referrer) — When you arrive via a marked marketing link (UTM parameters such as utm_source, utm_medium, utm_campaign, utm_term, utm_content) or from a referring website (document.referrer), we record this source information to evaluate the effectiveness of our acquisition channels (search, newsletter, referrals). On the landing page the values are held in memory only and inserted into CTA links to the application — no cookies, localStorage or sessionStorage on the landing. In the application the values are kept temporarily in sessionStorage (max. 24 hours) until you have registered and consented to marketing tracking; only then are they stored server-side on your account (first-touch attribution, max. 90 days). No transmission to third parties. Values are deleted from our database if you withdraw marketing consent or delete your account.
  • Campaign source at registration — When you arrive via one of our ads, an indication of which advertising platform you came from is forwarded to the application, and stored on your account if you then register. It tells us which of our campaigns actually lead to registrations. Unlike the click identifiers above, this does not require consent: it is a coarse platform label rather than an identifier capable of recognising individual clicks or people, and it is never transmitted to third parties. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in spending our advertising budget sensibly). § 25 TTDSG does not apply to the capture, because no information is stored on or read from your device for it. Exactly one of three values is stored — google_ads, ms_ads or meta_ads; anything else is discarded. On the landing page and in the application the value is held in memory only, with no sessionStorage (unlike the UTM parameters above); if you sign in via Google or Microsoft, it travels for at most ten minutes inside the encrypted, strictly necessary sign-in cookie, because the redirect back from the provider carries no other link to where you started. The value is set once, at account creation, and never changed afterwards; it is deleted when you delete your account. As the processing rests on legitimate interest, you may object at any time under Art. 21 GDPR — an informal message to paul@kalender-sync.de is enough and we will remove it from your account.
  • YouTube (embedded videos, enhanced privacy mode) (Google Ireland Ltd., Dublin, Ireland / Google LLC, USA, EU-US Data Privacy Framework) — We embed videos from YouTube using the enhanced privacy mode (youtube-nocookie.com). The embed is loaded only after you actively click the preview thumbnail and give your explicit consent. Before consent no YouTube script is loaded, no connection is established to YouTube servers and no cookies or local storage entries are set. After consent and play, YouTube processes IP address, device and browser information, date/time, the URL of the page and playback metadata. If you are logged in to YouTube, YouTube may associate the data with your account. We ourselves do not receive personal data from YouTube. You can withdraw consent at any time via the “Cookie settings” in the footer. See the Google Privacy Policy for details.
  • Cal.com (booking widget, only after consent) (Cal.com, Inc., 530 Divisadero St #225, San Francisco, CA 94117, USA) — In the contact dialog on our website we offer the option to book a call directly via an embedded Cal.com booking widget. The widget is loaded only after you actively click “Activate booking” and give your explicit consent. Before consent no Cal.com content is loaded, no connection is established to Cal.com servers and no cookies or local storage entries are set. You can always reach us by email instead, without consent. Legal basis: Art. 6(1)(a) GDPR (consent) in conjunction with § 25(1) TTDSG, and additionally Art. 6(1)(b) GDPR for a concrete booking request. After consent, Cal.com processes your IP address, device/browser information and the data you enter in the booking form (name, email, message, chosen time slot). Transfer to the USA is based on EU Standard Contractual Clauses (SCCs) pursuant to Art. 46(2)(c) GDPR. You can withdraw consent at any time via the “Cookie settings” in the footer. See the Cal.com Privacy Policy for details.

5. AI Assistant Connection (optional)

You can optionally connect an AI assistant (e.g. Claude by Anthropic or ChatGPT by OpenAI) to your calendars. The feature is off by default and only comes into being through your explicit authorisation.

In doing so you connect your own account with the respective AI provider to Kalender Sync and decide, per calendar, what the assistant may read (only your busy times, title and time, or all details) and — from the Basic plan — whether it may create events. When your assistant issues a query at your request, Kalender Sync reads the calendars you have released and transmits the released availability to the provider of the assistant you have chosen. This transfer is made on your instruction to a tool you selected yourself; once the data has arrived there, the AI provider’s own terms and privacy policy govern any further processing, over which we have no influence.

Depending on the provider this may involve a transfer to a third country (e.g. the USA). The basis and safeguards for that transfer lie in your relationship with the respective AI provider (their standard contractual clauses, certifications, etc.). Some providers, particularly on free or consumer plans, process data in the USA and/or use inputs to improve their models under their own terms. Please review the terms of your assistant before releasing sensitive calendars.

Not transmitted are the attendees, attachments and links of your events; on the “busy only” level, not the titles either. We log each query solely as metadata (timestamp, calendar concerned, type of query, result) — never the content of your events. This log is retained for 0, 7 or 90 days depending on your plan.

Legal basis is your consent (Art. 6(1)(a) GDPR), which you grant through the release and can withdraw at any time — individually or for all connections at once — under “AI assistant” in Kalender Sync. An unused connection additionally expires automatically after 90 days. Removing the connector at the provider only severs the link there; the withdrawal in Kalender Sync is what governs.

We do not use data obtained via the Google or Microsoft APIs to train or improve generalised AI/ML models; any release to an AI assistant happens only on your instruction and serves to answer your own queries, not model training.

Note for persons bound by professional secrecy: If your calendars contain information subject to a professional duty of confidentiality (e.g. § 203 German Criminal Code), please assess on your own responsibility whether and to what extent a release to an AI provider is compatible with it.

6. Cookies

We use the following cookies:

  • klaro (essential) — Stores your cookie consent decision. Duration: 1 year. Provider: self-hosted.
  • session (essential) — Authentication cookie for the app. Duration: session. Provider: self-hosted at Hetzner.
  • _ga, _gid (optional, consent-based) — Google Analytics. Duration: _ga 2 years, _gid 24 hours. Only set with explicit consent.
  • _uetsid, _uetvid, MUID (optional, consent-based) — Microsoft Advertising UET. Duration: _uetsid 24 hours, _uetvid 16 months, MUID 13 months. Only set with explicit marketing consent.
  • _gcl_au, _gcl_aw, _gcl_dc (optional, consent-based) — Google Ads conversion linker. Duration: 90 days each. Only set with explicit marketing consent.
  • _fbp, _fbc (optional, consent-based) — Meta Pixel (Facebook/Instagram Ads). Duration: 90 days each. Only set with explicit marketing consent.

7. Your Rights (GDPR Art. 15–21)

You have the right to:

  • Access (Art. 15) — Request information about your stored personal data
  • Rectification (Art. 16) — Correct inaccurate data
  • Erasure (Art. 17) — Delete your account and all data (available in the app under Settings)
  • Restriction (Art. 18) — Restrict processing of your data
  • Data portability (Art. 20) — Export your data (available in the app under Settings)
  • Objection (Art. 21) — Object to processing based on legitimate interest

To exercise your rights, contact us at paul@kalender-sync.de.

8. Data Retention

Your account data is retained as long as your account is active. When you delete your account, all personal data, calendar connections, sync configurations, and event mappings are permanently deleted within 24 hours. Server logs are retained for 7 days.

9. Data Processing Agreement (DPA)

We provide a data processing agreement (Auftragsverarbeitungsvertrag) per Art. 28 GDPR upon request. Contact us at paul@kalender-sync.de.

10. Supervisory Authority

You have the right to lodge a complaint with a supervisory authority. The competent authority is:
Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
Promenade 18, 91522 Ansbach, Germany
Website: lda.bayern.de