Compliance
As of 4 September 2026
This page is written for the people who have to sign an approval: security, data protection, procurement. It answers the usual questions up front — including the ones whose answers are not flattering.
Where it runs
| Component | Provider | Location |
|---|---|---|
| Application, database, backups | Convex, Inc. | EU region Ireland |
| Website delivery | Cloudflare, Inc. | Global network |
| System email | Lettermint B.V. | Netherlands |
The claim is EU hosted: stored data, backups and failover systems remain within the European Union.
Access from outside the EU
There is such access, and we name it. Our platform provider's technical support is based in the United States and may access the operating environment when handling reported incidents. In addition, technical metadata is transferred to the United States for operational monitoring. The provider does not currently offer a variant without this access.
Both are covered by the European Commission's Standard Contractual Clauses, supplemented by the UK Addendum for the United Kingdom. If your requirements rule out access from third countries, please tell us before an assessment — then we can establish first whether this fits at all.
Contracts
| Subject | Status |
|---|---|
| Data processing agreement with you (Art. 28 GDPR) | Template available on request |
| Data processing agreement with Convex | Concluded, including Standard Contractual Clauses |
| Data processing agreement with Cloudflare | Concluded, including SCCs and UK Addendum |
| Data processing agreement with Lettermint | Concluded |
We announce new sub-processors to contract customers 30 days in advance; objection on substantiated data protection grounds is possible.
Our platform provider maintains a SOC 2 Type II report. It is released only under a non-disclosure agreement — we may not pass it on, but we are happy to make the introduction.
Technical measures
- Credentials are stored encrypted (AES-256-GCM, versioned key).
- Transport encryption on all connections.
- Roles and permissions per organisation; administrative areas are not accessible to members.
- Security log covering sign-ins, role changes and invitations.
- Tenant binding: a Microsoft tenant can be bound to an organisation. A work account from that tenant can then only be connected within your organisation and under your policy — a private sign-up attempting to connect the same account is refused.
What we store
For events in a source calendar — a calendar you have set up as the source of a synchronisation — we store a reconciliation state so that changes can be detected. Calendars not used as a source are never read. What gets written into a target calendar is determined solely by the policy you set; actual attendee entries are never copied across.
Calendar content is not evaluated, not used for statistics about user groups and not used to train models. Details in theprivacy policy.
Retention
| Data | Duration |
|---|---|
| Reconciliation state, mappings, credentials | Until the connection or the account is deleted |
| Run logs (without event content) | 90 days |
| Technical rate counters | 24 hours |
| Security log | Anonymised on account deletion |
Deletion
Deletion can be triggered from within the application. It first removes the copies in target calendars — while the credentials for them are still valid — and then the stored data. Where this fails for individual calendars, we name them rather than claiming a complete deletion.
Open items
Ridian is under active development. The following points are not settled, and we consider it more honest to write that here than to be asked about it:
- The terms of use are a draft and have not yet been reviewed by counsel.
- An external security audit of the service is outstanding.
- General access is not open; use is currently arranged individually.
Contact
Questions about data protection, security or contract documents:[email protected]. We provide a data processing agreement template, the list of sub-processors and details of the technical measures on request.