Privacy Policy
As of: October 2026 · Applies to aevo.so and the application at aevo.so/app
- Controller
- Data processing principles
- Hosting and infrastructure
- Website server log files
- Registration and user account
- Content inside the application
- Contact and updates form
- Paid subscriptions and payment processing
- Email integration (IMAP)
- Calendar integration (CalDAV)
- Microsoft 365 integration and Microsoft Teams
- Google Calendar integration
- Recipients and processors
- Cookies and local storage
- Retention period
- Your rights
- Changes to this Privacy Policy
1. Controller
abacado IT Services – Christoph Geiser
c/o Postflex #7297, Emsdettener Str. 10, 48268 Greven
Germany
E-Mail: support@abacado.com
There is no statutory obligation to appoint a data protection officer. Please direct privacy enquiries to the address above.
2. Data processing principles
We process personal data only to the extent necessary to operate Aevo. We use no advertising networks, no third-party tracking, and no social media plugins. To measure the reach of the website we run Matomo on a server of our own, without cookies and with a shortened IP address; see section 14 for details. No reach measurement runs in the application. There we only record whether an account has reached certain steps (section 5, "Usage milestones"). There is no profiling and no automated decision-making.
Aevo contains no AI features. Your content is not used to train AI models and is not passed to AI services.
We do not sell data and do not disclose it for advertising purposes. Data is shared only with the processors listed in section 13 and where required by law.
3. Hosting and infrastructure
3.1 Website aevo.so. The website runs on a server we operate ourselves in a data centre of Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The server location is Germany; a data processing agreement under Art. 28 GDPR is in place with Hetzner. No content is loaded from external content delivery networks; fonts and images are served from the same server. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in operating the website securely).
3.2 Application aevo.so/app. The application uses the Supabase platform (database, authentication, file storage, server functions) provided by Supabase, Inc., 970 Toa Payoh North, Singapore, as its backend. The instance is located in the EU region (Ireland), where user data is stored; in normal operation it does not leave the EU. Supabase, Inc. is based outside the EU, so access by support and maintenance staff from a third country cannot be ruled out; a data processing agreement under Art. 28 GDPR and standard contractual clauses under Art. 46 GDPR are in place for this. Legal basis: Art. 6(1)(b) GDPR.
3.3 Transmission between your browser and our servers is encrypted end to end using TLS.
4. Website server log files
When you visit aevo.so, the web server automatically records access data: the page requested, date and time, volume of data transferred, status code, referrer, browser type and version, operating system, and IP address. This data serves technical delivery and security purposes and is not merged with other sources. It is deleted or anonymised after 7 days at the latest. Legal basis: Art. 6(1)(f) GDPR.
5. Registration and user account
Using Aevo requires an account. We process:
- Email address – for identification and transactional e-mails (for example password resets)
- Password – stored only as a cryptographic hash, never in plain text
- Display name and, optionally, a profile picture
- Registration timestamp and time of last sign-in
Legal basis: Art. 6(1)(b) GDPR (performance of a contract).
Trial period
Every new account receives every Pro feature for 14 days, once. For this we store the start and end of the trial with your account. No payment details are collected for it. Two days before it ends we tell you once by email when the trial ends and what changes then. Legal basis: Art. 6(1)(b) GDPR.
Usage milestones
To understand where new accounts get stuck, we record with your account whether and when certain steps were reached for the first time: account created, welcome dialog finished, trial started, calendar connected, first own task created, import carried out, Pro notice seen, checkout opened, Pro active, invitation link copied. In addition we note, per calendar day, that the application was opened.
Only the name of the step and the time are stored. No content, titles, page views, device or location data are recorded. The data sits in our own database in the EU, goes to no analytics service and is only evaluated in aggregate (how many new accounts reached a step). Guest sessions of the demo are not recorded. The entries are deleted with your account.
Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest is improving the way into the application. You can object to this processing at any time, informally by email to the address in section 1; we then delete the entries.
Invitations
You can invite others through a personal link. If someone follows that link, the code it contains is kept in the browser's local storage until they register and is then assigned to their account. We store which account invited which, and whether the invitation was rewarded (30 days of Pro for both once the invited account has connected a calendar or created five tasks of its own). The inviter learns only the number, not who registered. Legal basis: Art. 6(1)(b) GDPR.
6. Content inside the application
We store the content you enter: tasks, notes, projects, workspaces, links, comments, appointments, attachments, and settings. This data serves solely to provide the application's features and is restricted to your account by database-level access rules (row level security).
Legal basis: Art. 6(1)(b) GDPR.
7. Contact and updates form
If you sign up for product updates on aevo.so, we process your first name, last name, e-mail address, and the time of sign-up in order to send you information about Aevo. You can unsubscribe at any time with an informal e-mail to support@abacado.com; we then delete your data. Legal basis: Art. 6(1)(a) GDPR (consent), revocable at any time with effect for the future.
If you contact us by e-mail, we process the information contained in your message in order to handle your request. Legal basis: Art. 6(1)(b) or (f) GDPR.
8. Paid subscriptions and payment processing
8.1 The "Pro" plan is sold through Paddle.com Market Ltd, Judd House, 18–29 Mora Street, London EC1V 8BT, United Kingdom, as Merchant of Record. For payment processing, invoicing, fraud prevention, and tax remittance, Paddle acts as an independent controller.
8.2 You enter payment details such as card numbers directly with Paddle. We neither receive nor store complete payment details. What we transmit to Paddle is an internal identifier of your user account so the order can be assigned to the correct account.
8.3 From Paddle we receive back: subscription status, plan, billing period, start and end of the term, payment status, and transaction and customer identifiers. We need this data to unlock the features you purchased. Legal basis: Art. 6(1)(b) GDPR.
8.4 Paddle processes data in the United Kingdom and the United States, among other places. An adequacy decision of the European Commission exists for the United Kingdom; transfers to the United States are based on standard contractual clauses or the EU-US Data Privacy Framework. Paddle's privacy policy is available at paddle.com/legal/privacy.
8.5 Invoicing and tax records are subject to statutory retention periods of up to ten years under German law and remain stored even after an account is deleted.
9. Email integration (IMAP)
Aevo optionally offers an IMAP integration that turns e-mails into tasks. It is voluntary and must be actively set up.
Data processed
- IMAP credentials (server, port, username, password) – stored encrypted (AES-256 via pgcrypto)
- Metadata and content of the retrieved messages
Retrieval happens only on your request and is limited to the last 50 messages. You can disconnect the integration at any time in the settings; the credentials are deleted in the process. Legal basis: Art. 6(1)(b) GDPR (providing the feature you set up).
10. Calendar integration (CalDAV)
Aevo optionally offers a CalDAV integration (for example iCloud Calendar or Nextcloud). It is voluntary.
Data processed
- CalDAV credentials (server URL, username, app-specific password) – stored encrypted (AES-256)
- Calendar events (title, date, time, description) from the connected calendar
Synchronisation runs at short intervals. You can disconnect the integration at any time; credentials and retrieved events are deleted in the process. Legal basis: Art. 6(1)(b) GDPR (providing the feature you set up).
11. Microsoft 365 integration
If you voluntarily connect a Microsoft 365 account, you authorise Aevo through Microsoft's sign-in process (OAuth 2.0). We receive access and refresh tokens and the identifier of the connected account; we never receive a password. Calendar and, where applicable, mailbox data are processed to the extent you grant during authorisation. You can revoke the connection at any time in the Aevo settings and additionally in your Microsoft account; the stored tokens are deleted in the process. Microsoft Corporation is the controller for processing inside your Microsoft account. Legal basis: Art. 6(1)(b) GDPR (providing the feature you set up).
11.1 Microsoft Teams
If your organisation makes the Aevo app available in Microsoft Teams, you can turn a Teams message into a task via “…” → “More actions” → “Create task in Aevo”. This requires that the Microsoft 365 account connected in Aevo is the same one you use in Teams (section 11).
When data is transmitted: Only when you trigger the action on a message yourself. Aevo does not read chats or channels and has no access to other messages.
What data: Microsoft sends the following to our server via the Microsoft Bot Framework:
- the text of the selected message, the sender's display name and a link to the message,
- your Microsoft Entra object ID and your organisation's ID (tenant ID), to match you to your Aevo account,
- technical details such as your Teams language setting.
We store the object ID together with your Microsoft 365 connection when you set that up in Aevo.
What is stored: When you open the action, we pre-fill the form with a title and notes but store nothing yet. Only when you click “Create” do we create a task containing the title, the notes (message text, sender name, link to the message), and the workspace and due date you chose. You can edit the content first. If you cancel, the message is not stored. Like all content in Aevo, the task is kept in our Supabase instance in the EU (Ireland), see section 3.
Logs: For operation, our server logs technical details for each request, without message content: time, type of request, status code and the IP address of the calling Microsoft server. In case of an error, it also logs your Aevo user ID and the error message. These logs are deleted automatically after 7 days at most (section 15). Legal basis: Art. 6(1)(f) GDPR, our legitimate interest in operational security and troubleshooting.
Third-party data: The message may contain names and content of other people, such as the sender. It only reaches your Aevo account if you create the task, and is visible only to you and the members of the chosen workspace.
Legal basis: Art. 6(1)(b) GDPR for the feature you trigger. For personal data of third parties in the message: Art. 6(1)(f) GDPR, our and your legitimate interest in organising your work.
Ending use: You can remove the app in Teams at any time, and your organisation's administrators can block it. If you disconnect Microsoft 365 in Aevo, we also delete the stored object ID. Tasks created from Teams remain until you delete them in Aevo.
12. Google Calendar integration
You can choose to connect one or more Google calendars to Aevo. Aevo requests read-only access from Google (scope calendar.readonly) plus your e-mail address and Google account identifier (openid, email). Aevo cannot create, change, or delete anything in your Google Calendar.
Data processed
From the calendars you select in Aevo, for the period from 7 days in the past to 90 days in the future, we read for each event: title, start, end, whether it is all-day, location, the organiser's e-mail address, link to the event in Google Calendar, cancellation status, and your own response ("maybe", "declined"). We also read the list of your calendar names to let you choose which ones to sync, and we store the e-mail address, account identifier, and, if any, Workspace domain of the connected Google account.
Purpose
Solely to show your events in Aevo, to calculate your free time for planning your day, and, when you trigger it, to create a task from an event. We do not import events you have declined, working-location entries, or birthdays.
Storage and security
The data is stored in our database at Supabase in the EU (Ireland region). The access token issued by Google is stored encrypted in a separate secrets vault that the app itself cannot read. Synchronisation runs on our servers about every 15 minutes. Events outside that period and events deleted in Google are removed at the next sync.
No sharing
We do not sell this data, use it for advertising, share it with third parties, or use it to train AI or machine-learning models. No person at Aevo reads your calendar data unless you explicitly ask us for support with it, it is necessary for security purposes (for example investigating abuse), or we are required to by law.
Deletion and revocation
You can disconnect at any time in Aevo under Settings → Calendars → Disconnect. We then revoke the access at Google and delete the token and all imported events. Tasks you created from an event yourself remain until you delete them. You can also revoke access at myaccount.google.com/permissions. Deleting your Aevo account deletes all of this data.
Legal basis: Art. 6(1)(b) GDPR (performance of the user agreement at your request).
Aevo's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
13. Recipients and processors
Beyond the service providers listed below, we do not share personal data:
| Provider | Purpose | Place of processing | Role |
|---|---|---|---|
| Supabase, Inc. | Database, authentication, file storage, server functions | EU (Ireland), support possibly third country | Processor (Art. 28 GDPR) |
| Hetzner Online GmbH | Data centre for our server (website aevo.so, server log files) | Germany | Processor (Art. 28 GDPR) |
| Paddle.com Market Ltd | Sale, payment, invoicing, sales tax | UK, USA | Independent controller |
| Microsoft Ireland Operations Ltd. / Microsoft Corporation | Provision of Microsoft 365 and Microsoft Teams, including transmission via the Microsoft Bot Framework, where you use these integrations | EU / USA | Independent controller |
| Google LLC | Only if the Google Calendar integration is enabled | EU / USA | Independent controller |
| PeerPush | Badge on the home page; loading the image transmits your IP address to PeerPush | Third country | Independent controller |
Transfers to third countries take place only on the basis of an adequacy decision, standard contractual clauses, or your explicit consent.
14. Cookies and local storage
Aevo uses only technically necessary cookies and local browser storage to keep you signed in and to save settings such as language and theme. We use no tracking or analytics cookies, which is why no cookie banner is required. On aevo.so we only store your language choice in the browser's local storage.
Reach measurement on the website. To see which pages are being opened we use Matomo at stats.abacado.com. The software runs on a server we operate ourselves; no data is passed to third parties. Matomo is configured to set no cookies, and your IP address is shortened before it is stored. What is recorded: the page opened, the referrer, an approximate location at country level, and the browser and operating system. It is never combined with your user account. The application at aevo.so/app is excluded from the measurement – no counter runs there.
Because no cookie is set and nothing is stored on or read from your device, no consent under sec. 25 TDDDG is required. The legal basis for the processing is our legitimate interest in a website that fits its audience, Art. 6(1)(f) GDPR. You can object at any time by enabling Do Not Track in your browser; Matomo is configured to respect that setting.
Legal basis: sec. 25(2)(2) TDDDG in conjunction with Art. 6(1)(b) GDPR.
15. Retention period
- Account and content data: for as long as your account exists; deleted when the account is deleted.
- Integration credentials: until the respective integration is disconnected.
- Website server log files and technical application logs: 7 days at most.
- Raw reach-measurement data: 90 days at most; after that only aggregates without personal reference remain.
- Data from the updates form: until you unsubscribe.
- Invoicing and tax data: up to 10 years due to statutory retention obligations.
You are responsible for exporting your content before deleting your account.
16. Your rights
As a data subject, you have the following rights:
- Access (Art. 15 GDPR)
- Rectification (Art. 16 GDPR)
- Erasure (Art. 17 GDPR) – also directly via the account deletion function
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Objection (Art. 21 GDPR)
- Withdrawal of consent (Art. 7(3) GDPR) at any time with effect for the future
Send requests to support@abacado.com. You also have the right to lodge a complaint with a supervisory authority. The authority responsible for us is the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen, Kavalleriestr. 2–4, 40213 Düsseldorf, Germany.
17. Changes to this Privacy Policy
We update this policy when legal requirements or features change. The current version is always available at aevo.so/datenschutz.html. We notify registered users by e-mail about material changes.