Privacy Policy
Last updated: 20 July 2026.
Translation notice: This English version is provided for convenience. The German version is legally authoritative.
1. Controller
Fa. Rücker Computersysteme | Fa. Rückergruppe, proprietor Magnus Rücker, Dorfstr. 9, 56769 Retterath OT Salcherath, Germany. Telephone: +49 2657 9428962. Email: info@kalenderabgleich.de.
2. Data protection officer
No data protection officer has been appointed because there is currently no statutory obligation to do so.
3. General information
We process personal data only where necessary to provide the service, perform a contract, comply with legal obligations or protect legitimate interests. Legal bases include Article 6(1)(a), (b), (c) and (f) GDPR.
4. Website access and server logs
The server may process IP address, date and time, requested resource, referrer, browser, operating system and response status for secure and reliable operation under Article 6(1)(f) GDPR.
5. Hosting
An external hosting provider processes data on our behalf where necessary to deliver and secure the service.
6. Account and service emails
We process name, email address, password hash, verification status, settings and subscription information to provide the service under Article 6(1)(b) GDPR. Passwords are not stored in plain text. Email addresses and temporary tokens are used for verification, password resets and necessary service messages.
7. Contact and support
We process information and contact details submitted through contact or support channels to handle the request under Article 6(1)(b) or (f) GDPR.
We protect the contact, withdrawal and cancellation forms against automated submissions using temporary form tokens, hidden fields and rate limits. For rate limiting, the IP address and, where applicable, the target email address are stored only as hashes. Records older than seven days are regularly deleted.
We also use Cloudflare Turnstile, provided by Cloudflare, Inc., to distinguish legitimate requests from automated access. Cloudflare processes technical signals such as IP address, user agent, TLS characteristics, sitekey and origin. Processing is based on Article 6(1)(f) GDPR for form and service security. See the Cloudflare Turnstile Privacy Addendum for further information.
8. Property and calendar data
We process property details, calendar sources, events, source identifiers, dates, internal notes and synchronisation logs to provide the service. Users should not enter unnecessary personal or sensitive data.
9. iCal import and export
The service retrieves user-supplied iCal feeds and provides token-protected export feeds. Anyone who knows an export URL may retrieve it, so feed URLs must remain confidential. Exports do not contain internal notes or portal names.
10. Payments
Payments and subscriptions are processed by Lemon Squeezy. Necessary account, transaction, tax and subscription information may be exchanged for contract performance, billing and legal compliance. Lemon Squeezy’s privacy information also applies.
11. Cookies and sessions
Necessary session cookies are used for login and security. When “Stay logged in” is selected, a random persistent token is stored for up to 30 days; only a hash of its validator is stored on the server.
12. Internal conversion and usage events
To improve the service and understand whether setup works successfully, we record selected internal events server-side. These may include registration completed, trial started, property created, source created, first successful calendar retrieval and successful source retrieval.
This is done without external tracking providers and without marketing cookies. We store the event name, time, account where applicable, affected internal object ID and limited technical information. IP address and user agent are stored only as hashes. Processing is based on Article 6(1)(f) GDPR; our legitimate interest is service functionality control, error analysis and improvement.
13. Recipients and international transfers
Data is shared only where necessary, particularly with hosting, email and payment providers, authorities where legally required and professional advisers. Transfers outside the EEA use the safeguards required by law.
14. Retention
Data is retained only as long as required for its purpose, the contract and statutory retention periods. Deletion may be delayed in backups or where legal retention duties apply.
15. Your rights
Subject to statutory requirements, you have rights of access, rectification, erasure, restriction, portability, objection and withdrawal of consent.
16. Complaints and updates
You may complain to a competent data protection authority. This policy may be updated when processing, providers, technical processes or legal requirements change.