Task management and the GDPR

Tasks and notes hold client names, fee negotiations and half-finished thoughts. This page says where that data sits and who can touch it, including where the answer is not comfortable.

Why a task list deserves more care than most files

A task list looks harmless. In practice it is often the most honest document in the whole business. It records which client pays and which does not, which application is still open, which appointment with the lawyer is coming up. Anyone working alone or in a small firm also keeps personal data about third parties there, more or less by accident.

That makes the choice of tool more than a matter of taste. It decides which legal order that data flows into.

Where the data actually sits

What Where Provider
Website aevo.soGermanyour own server in a Hetzner Online GmbH data centre, Gunzenhausen
Application, database, filesEU (Ireland)Supabase, Inc.
Payment processingUK, USAPaddle.com Market Ltd as Merchant of Record
Calendar and mailboxonly with the integration enabledyour provider; for Microsoft 365, Microsoft Corporation

The website loads nothing from foreign servers. Fonts and images sit on the same machine, there is no content delivery network and no embedded services. When you open this page your browser talks to exactly one computer, and it stands in Bavaria.

The uncomfortable parts

A provider who writes only "servers in the EU" at this point is leaving something out. So here are the three places where it is not entirely simple:

Supabase. The database sits in the EU region Ireland, and user data does not leave the EU in normal operation. Supabase, Inc. is however headquartered outside the EU. Access by support and maintenance staff from a third country therefore cannot be ruled out. This is covered by a processing agreement under Art. 28 GDPR and standard contractual clauses under Art. 46 GDPR.

Paddle. Pro is sold through Paddle as Merchant of Record, based in the United Kingdom with processing also in the United States. The UK has an adequacy decision from the European Commission; for the US, Paddle relies on standard contractual clauses and the EU-US Data Privacy Framework. This concerns billing and payment data only, not your tasks and notes.

Microsoft 365. If you connect a Microsoft account, Microsoft Corporation is the independent controller for processing inside that account. That is a decision you make, and you can withdraw it in the settings at any time.

All of this is set out in full in the privacy policy, sections 3, 8, 11 and 12. If you have to document processing on behalf of your own clients under Art. 28 GDPR, the entries for your record of processing activities are there.

What does not happen

Deleting and exporting

The account can be deleted inside the application, without emailing support. Content can be exported beforehand as JSON, CSV or Markdown. Note that exporting is your job, not ours: after the account is deleted the content is gone.

One exception remains, and it is imposed by law: invoices and tax records are subject to retention periods of up to ten years under § 147 AO and § 257 HGB. They stay stored even after an account is deleted. No provider can solve that differently.

What this means in practice

If you want a task manager whose processing chain you can name without guessing, every figure you need is above. If your requirement is instead that no processor outside the EU may have even theoretical access, Aevo is the wrong tool because of where Supabase is based. In that case you need a self-hosted solution, and somebody should tell you that before you start.

Frequently asked questions

Is Aevo GDPR-compliant?

Operations are built for the GDPR: processing in the EU, Art. 28 processing agreements with every provider, Art. 46 standard contractual clauses for third-country links, no tracking, no profiling. Whether your particular use is compliant also depends on what you store and on your own duties as a controller.

Where are my tasks and notes stored?

In the EU region Ireland, with Supabase. The website itself runs on our own server in a German data centre operated by Hetzner Online GmbH.

Can staff in third countries access my data?

It cannot be ruled out. Supabase, Inc. is headquartered outside the EU, so support and maintenance staff in a third country may in theory have access. This is covered by a processing agreement and standard contractual clauses.

Do I need a cookie banner if I use Aevo?

Not for Aevo. The application is not measured, and website traffic measurement works without cookies and without touching your device. No consent under § 25 TDDDG is required.

Can I get a data processing agreement?

Write to support@abacado.com. The details of every processor used are listed in section 12 of the privacy policy.

Read on