Why a task list deserves more care than most files
A task list looks harmless. In practice it is often the most honest document in the whole business. It records which client pays and which does not, which application is still open, which appointment with the lawyer is coming up. Anyone working alone or in a small firm also keeps personal data about third parties there, more or less by accident.
That makes the choice of tool more than a matter of taste. It decides which legal order that data flows into.
Where the data actually sits
| What | Where | Provider |
|---|---|---|
| Website aevo.so | Germany | our own server in a Hetzner Online GmbH data centre, Gunzenhausen |
| Application, database, files | EU (Ireland) | Supabase, Inc. |
| Payment processing | UK, USA | Paddle.com Market Ltd as Merchant of Record |
| Calendar and mailbox | only with the integration enabled | your provider; for Microsoft 365, Microsoft Corporation |
The website loads nothing from foreign servers. Fonts and images sit on the same machine, there is no content delivery network and no embedded services. When you open this page your browser talks to exactly one computer, and it stands in Bavaria.
The uncomfortable parts
A provider who writes only "servers in the EU" at this point is leaving something out. So here are the three places where it is not entirely simple:
Supabase. The database sits in the EU region Ireland, and user data does not leave the EU in normal operation. Supabase, Inc. is however headquartered outside the EU. Access by support and maintenance staff from a third country therefore cannot be ruled out. This is covered by a processing agreement under Art. 28 GDPR and standard contractual clauses under Art. 46 GDPR.
Paddle. Pro is sold through Paddle as Merchant of Record, based in the United Kingdom with processing also in the United States. The UK has an adequacy decision from the European Commission; for the US, Paddle relies on standard contractual clauses and the EU-US Data Privacy Framework. This concerns billing and payment data only, not your tasks and notes.
Microsoft 365. If you connect a Microsoft account, Microsoft Corporation is the independent controller for processing inside that account. That is a decision you make, and you can withdraw it in the settings at any time.
All of this is set out in full in the privacy policy, sections 3, 8, 11 and 12. If you have to document processing on behalf of your own clients under Art. 28 GDPR, the entries for your record of processing activities are there.
What does not happen
- No third-party tracking. No ad networks, no social media plugins, no profiling, no automated decision-making.
- No measurement inside the application. There is no counter at aevo.so/app. Website traffic is measured with Matomo on our own server, without cookies and with a shortened IP address; Do Not Track is respected. Because nothing is stored on or read from your device, no consent banner is required.
- No AI. Your content is not used to train models and is not passed to AI services. That is a product decision, not a form of words: task management without AI.
- No sale of data. Not to advertisers, not to anyone.
Deleting and exporting
The account can be deleted inside the application, without emailing support. Content can be exported beforehand as JSON, CSV or Markdown. Note that exporting is your job, not ours: after the account is deleted the content is gone.
One exception remains, and it is imposed by law: invoices and tax records are subject to retention periods of up to ten years under § 147 AO and § 257 HGB. They stay stored even after an account is deleted. No provider can solve that differently.
What this means in practice
If you want a task manager whose processing chain you can name without guessing, every figure you need is above. If your requirement is instead that no processor outside the EU may have even theoretical access, Aevo is the wrong tool because of where Supabase is based. In that case you need a self-hosted solution, and somebody should tell you that before you start.