Privacy Policy
As of: August 2026 · Applies to aevo.so and the application at aevo.so/app
- Controller
- Data processing principles
- Hosting and infrastructure
- Website server log files
- Registration and user account
- Content inside the application
- Contact and updates form
- Paid subscriptions and payment processing
- Email integration (IMAP)
- Calendar integration (CalDAV)
- Microsoft 365 integration
- Recipients and processors
- Cookies and local storage
- Retention period
- Your rights
- Changes to this Privacy Policy
1. Controller
abacado IT Services – Christoph Geiser
c/o Postflex #7297, Emsdettener Str. 10, 48268 Greven
Germany
E-Mail: support@abacado.com
There is no statutory obligation to appoint a data protection officer. Please direct privacy enquiries to the address above.
2. Data processing principles
We process personal data only to the extent necessary to operate Aevo. We use no analytics tools, no tracking, no advertising networks, and no social media plugins. There is no profiling and no automated decision-making.
Aevo contains no AI features. Your content is not used to train AI models and is not passed to AI services.
We do not sell data and do not disclose it for advertising purposes. Data is shared only with the processors listed in section 12 and where required by law.
3. Hosting and infrastructure
3.1 Website aevo.so. The website runs on a server we operate ourselves in a data centre of Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The server location is Germany; a data processing agreement under Art. 28 GDPR is in place with Hetzner. No content is loaded from external content delivery networks; fonts and images are served from the same server. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in operating the website securely).
3.2 Application aevo.so/app. The application uses the Supabase platform (database, authentication, file storage, server functions) provided by Supabase, Inc., 970 Toa Payoh North, Singapore, as its backend. The instance is located in the EU region (Ireland), where user data is stored; in normal operation it does not leave the EU. Supabase, Inc. is based outside the EU, so access by support and maintenance staff from a third country cannot be ruled out; a data processing agreement under Art. 28 GDPR and standard contractual clauses under Art. 46 GDPR are in place for this. Legal basis: Art. 6(1)(b) GDPR.
3.3 Transmission between your browser and our servers is encrypted end to end using TLS.
4. Website server log files
When you visit aevo.so, the web server automatically records access data: the page requested, date and time, volume of data transferred, status code, referrer, browser type and version, operating system, and IP address. This data serves technical delivery and security purposes and is not merged with other sources. It is deleted or anonymised after 7 days at the latest. Legal basis: Art. 6(1)(f) GDPR.
5. Registration and user account
Using Aevo requires an account. We process:
- Email address – for identification and transactional e-mails (for example password resets)
- Password – stored only as a cryptographic hash, never in plain text
- Display name and, optionally, a profile picture
- Registration timestamp and time of last sign-in
Legal basis: Art. 6(1)(b) GDPR (performance of a contract).
6. Content inside the application
We store the content you enter: tasks, notes, projects, workspaces, links, comments, appointments, attachments, and settings. This data serves solely to provide the application's features and is restricted to your account by database-level access rules (row level security).
Legal basis: Art. 6(1)(b) GDPR.
7. Contact and updates form
If you sign up for product updates on aevo.so, we process your first name, last name, e-mail address, and the time of sign-up in order to send you information about Aevo. You can unsubscribe at any time with an informal e-mail to support@abacado.com; we then delete your data. Legal basis: Art. 6(1)(a) GDPR (consent), revocable at any time with effect for the future.
If you contact us by e-mail, we process the information contained in your message in order to handle your request. Legal basis: Art. 6(1)(b) or (f) GDPR.
8. Paid subscriptions and payment processing
8.1 The "Pro" plan is sold through Paddle.com Market Ltd, Judd House, 18–29 Mora Street, London EC1V 8BT, United Kingdom, as Merchant of Record. For payment processing, invoicing, fraud prevention, and tax remittance, Paddle acts as an independent controller.
8.2 You enter payment details such as card numbers directly with Paddle. We neither receive nor store complete payment details. What we transmit to Paddle is an internal identifier of your user account so the order can be assigned to the correct account.
8.3 From Paddle we receive back: subscription status, plan, billing period, start and end of the term, payment status, and transaction and customer identifiers. We need this data to unlock the features you purchased. Legal basis: Art. 6(1)(b) GDPR.
8.4 Paddle processes data in the United Kingdom and the United States, among other places. An adequacy decision of the European Commission exists for the United Kingdom; transfers to the United States are based on standard contractual clauses or the EU-US Data Privacy Framework. Paddle's privacy policy is available at paddle.com/legal/privacy.
8.5 Invoicing and tax records are subject to statutory retention periods of up to ten years under German law and remain stored even after an account is deleted.
9. Email integration (IMAP)
Aevo optionally offers an IMAP integration that turns e-mails into tasks. It is voluntary and must be actively set up.
Data processed
- IMAP credentials (server, port, username, password) – stored encrypted (AES-256 via pgcrypto)
- Metadata and content of the retrieved messages
Retrieval happens only on your request and is limited to the last 50 messages. You can disconnect the integration at any time in the settings; the credentials are deleted in the process. Legal basis: Art. 6(1)(a) GDPR (consent through active setup).
10. Calendar integration (CalDAV)
Aevo optionally offers a CalDAV integration (for example iCloud Calendar or Nextcloud). It is voluntary.
Data processed
- CalDAV credentials (server URL, username, app-specific password) – stored encrypted (AES-256)
- Calendar events (title, date, time, description) from the connected calendar
Synchronisation runs at short intervals. You can disconnect the integration at any time; credentials and retrieved events are deleted in the process. Legal basis: Art. 6(1)(a) GDPR.
11. Microsoft 365 integration
If you voluntarily connect a Microsoft 365 account, you authorise Aevo through Microsoft's sign-in process (OAuth 2.0). We receive access and refresh tokens and the identifier of the connected account; we never receive a password. Calendar and, where applicable, mailbox data are processed to the extent you grant during authorisation. You can revoke the connection at any time in the Aevo settings and additionally in your Microsoft account; the stored tokens are deleted in the process. Microsoft Corporation is the controller for processing inside your Microsoft account. Legal basis: Art. 6(1)(a) GDPR.
12. Recipients and processors
Beyond the service providers listed below, we do not share personal data:
| Provider | Purpose | Place of processing | Role |
|---|---|---|---|
| Supabase, Inc. | Database, authentication, file storage, server functions | EU (Ireland), support possibly third country | Processor (Art. 28 GDPR) |
| Hetzner Online GmbH | Data centre for our server (website aevo.so, server log files) | Germany | Processor (Art. 28 GDPR) |
| Paddle.com Market Ltd | Sale, payment, invoicing, sales tax | UK, USA | Independent controller |
| Microsoft Corporation | Only if the Microsoft 365 integration is enabled | EU / USA | Independent controller |
Transfers to third countries take place only on the basis of an adequacy decision, standard contractual clauses, or your explicit consent.
13. Cookies and local storage
Aevo uses only technically necessary cookies and local browser storage to keep you signed in and to save settings such as language and theme. We use no tracking or analytics cookies, which is why no cookie banner is required. On aevo.so we only store your language choice in the browser's local storage.
Legal basis: sec. 25(2)(2) TDDDG in conjunction with Art. 6(1)(b) GDPR.
14. Retention period
- Account and content data: for as long as your account exists; deleted when the account is deleted.
- Integration credentials: until the respective integration is disconnected.
- Server log files: 7 days at most.
- Data from the updates form: until you unsubscribe.
- Invoicing and tax data: up to 10 years due to statutory retention obligations.
You are responsible for exporting your content before deleting your account.
15. Your rights
As a data subject, you have the following rights:
- Access (Art. 15 GDPR)
- Rectification (Art. 16 GDPR)
- Erasure (Art. 17 GDPR) – also directly via the account deletion function
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Objection (Art. 21 GDPR)
- Withdrawal of consent (Art. 7(3) GDPR) at any time with effect for the future
Send requests to support@abacado.com. You also have the right to lodge a complaint with a supervisory authority. The authority responsible for us is the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen, Kavalleriestr. 2–4, 40213 Düsseldorf, Germany.
16. Changes to this Privacy Policy
We update this policy when legal requirements or features change. The current version is always available at aevo.so/datenschutz.html. We notify registered users by e-mail about material changes.