← Compliance Center

Legal

Data Processing Agreement

Version 1.0 — as of 26 September 2026

How this agreement is concluded. This agreement is part of the Ridian terms of service and is concluded with them, without a signature (section 13).

Use the print view to save or print the full text. You do not need to send anything back.

1. Scope, roles and term

This data processing agreement forms part of the Ridian terms of service between you (“Customer”) and PPJ Venture Labs UG (haftungsbeschränkt), Hohenzollernstraße 30, 80801 Munich, Germany, registered at Amtsgericht München under HRB 308771 (“PPJ”). Ridian is a brand of PPJ. It governs all processing of personal data that PPJ carries out on your behalf when you use Ridian, and takes effect when you accept the terms of service.

You act as controller, or as a processor authorised by your own controller to appoint PPJ. You document the roles and authorisations for each organisation you connect. Where you connect data for which another party is controller, you are responsible for having that authority.

For personal data processed on your behalf, this agreement takes precedence over conflicting provisions of the terms of service. It applies for as long as PPJ processes such data and until return or deletion is complete.

This agreement applies where you use Ridian for professional or business purposes or for an organisation. If you use Ridian purely privately, there is no processing on your behalf; PPJ then processes your data as controller, as described in the privacy policy.

2. Subject matter, data and data subjects

PPJ processes personal data to provide the calendar functions you enable: setting up connections, reading source calendars, reconciling and writing to target calendars, deleting, and the support necessary for those functions.

Data subjects are your users and staff, your contacts, participants of the appointments concerned and other people named in the provider data you release. Processed data comprises account and organisation identifiers, calendar identifiers, contact details, encrypted connection secrets, full source event states including title, description, location, times, recurrence and available attendees, target mappings and operational and permission records. Restricting output to busy information limits what is written, not what is read and stored from the source.

Where you expressly enable them, task, contact and directory, outgoing plaintext mail and room data are processed for the action you request. These non-calendar contents are not retained as an application content store; limited hashes, encrypted provider identifiers and provenance records support safe retries.

Where you activate the in-app assistant, your request, reviewed earlier messages and the calendar, task, contact and account information needed to answer it are sent to the language model provider named on the sub-processor page. This happens only for your request and not for training.

Special categories of personal data are not intended for this processing. Calendar entries can nonetheless contain them. If you foresee such use, agree suitable measures and a legal basis with us beforehand.

3. Instructions and purpose limitation

PPJ processes personal data only on your documented instructions. Those instructions consist of this agreement, the terms of service, the configuration you set in the product and instructions in text form from the contacts you authorise.

PPJ does not use data processed on your behalf for its own advertising, for profiling, or to train AI models. This applies equally in relation to the providers we engage.

Where law requires PPJ to process contrary to your instructions, PPJ informs you beforehand unless that law forbids it. If PPJ considers an instruction to infringe data protection law, PPJ informs you without delay and may suspend the affected operation until the matter is resolved.

Technical access to a function is not an instruction and does not extend the agreed scope.

4. Confidentiality and personnel

PPJ binds every person authorised to access personal data to confidentiality in writing before that access is granted, instructs them, and limits access to what their task requires.

Access is reviewed when tasks or roles change and withdrawn without delay once it is no longer needed.

5. Security of processing

PPJ implements appropriate technical and organisational measures under Article 32 GDPR and reviews their effectiveness regularly and following relevant events. They comprise: transport encryption on all connections; provider credentials stored encrypted with AES-256-GCM under versioned keys held separately from the records; encryption of stored data and backups by the platform provider; individual operator accounts with least necessary privilege and protected secret storage; roles and permissions bound to the organisation, so that knowing an identifier does not grant access to another organisation’s calendar; operator views that contain no raw calendar content; security and operational logs limited to approved metadata, with tokens, passwords and calendar content excluded from error reports; and versioned, automatically checked changes with targeted acceptance before new permission or data paths are released.

Measures may be developed further as long as the level of protection remains at least equivalent. Material changes to your detriment require prior agreement.

Customer data is processed only in approved production environments. Development and staging use synthetic or genuinely anonymised data with separate databases and secrets.

You protect your own credentials and grant only the access that is necessary.

6. Sub-processors

You give general written authorisation under Article 28(2) GDPR for the sub-processors listed on the sub-processor page, which forms part of this agreement. Each is authorised only for the purpose described there; naming a provider does not authorise any further processing.

Before a sub-processor processes personal data, PPJ binds it to data protection obligations equivalent to those in this agreement, checks its safeguards, and remains fully liable for its performance. On request, PPJ provides the relevant provisions of the sub-processing agreement; commercial terms may be redacted.

PPJ announces additions, replacements and material extensions at least 30 calendar days before use, by email to the address of your account or to a contract contact you have named, and by updating the sub-processor page. It is your responsibility to keep that address current.

You may object within those 30 days on substantiated data protection grounds. The affected processing then does not begin until the objection is resolved. If no reasonable alternative is available, either party may terminate the affected service at no cost to you.

Systems you connect yourself are not sub-processors of PPJ. This includes the calendar, directory and mail systems you link — such as Google, Microsoft, Apple, Exchange and CalDAV — and the assistant or MCP clients you choose to use. Their selection and contractual coverage rest with you.

7. International transfers

Stored data, backups and failover for the application remain in the European Union. Processing in third countries nonetheless occurs, in two forms. Technical operating metadata is transferred to the United States for performance monitoring. In addition, our platform provider’s technical support is based in the United States and may access the operating environment when handling reported incidents; the provider does not offer a variant without this access. Added to this are the global networks of the providers named on the sub-processor page, which states the processing location for each of them.

Such transfers take place on the Standard Contractual Clauses of the European Commission, supplemented where applicable by the UK Addendum, together with the measures set out in section 5.

8. Assistance with data subject rights

PPJ forwards requests from data subjects to you without undue delay and responds substantively only on your instructions or where law requires it.

Taking into account the nature of the processing and the information available, PPJ assists you with appropriate technical and organisational measures in responding to requests for access, rectification, erasure, restriction, portability and objection, and with your obligations under Articles 32 to 36 GDPR.

Ordinary assistance is included. Exceptional effort is chargeable only where agreed beforehand, and such an agreement must not delay a statutory deadline.

9. Personal data breaches

PPJ notifies you without undue delay after becoming aware of a personal data breach affecting data processed on your behalf, and does not wait for the investigation to be complete.

The first notice states what is known about the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, the measures taken, and a contact point. Missing details follow as soon as they are available.

PPJ limits the effects, preserves the necessary evidence and supports your notification duties under Articles 33 and 34 GDPR.

10. Evidence and audits

PPJ makes available the information necessary to demonstrate compliance with Article 28 GDPR and allows and contributes to audits, including inspections, conducted by you or by an auditor you mandate who is bound to confidentiality.

Compliance is demonstrated primarily through the information in this agreement, current documentation of the measures and written answers to your questions. Inspections are coordinated at reasonable notice, take place no more than once per calendar year and at your cost, unless they reveal a material breach by PPJ. These limits do not apply to a check following a concrete incident or a request from a supervisory authority. Data of other customers, trade secrets and system security are protected.

Provider reports are shared only as far as their confidentiality terms allow. Where necessary, PPJ supports alternative evidence or arranges direct contact with the provider.

11. Retention, return and deletion

Retention: reconciliation state, target mappings and connection credentials are held for as long as the connection or the account exists. Run logs, which contain no event content, are held for 90 days. Technical counters are held for 24 hours. Entries in the security log lose their personal reference when the account is deleted. Backups roll over automatically and are held for no longer than 30 days.

When processing on your behalf ends, you choose whether PPJ returns the data in a common structured format or deletes it. PPJ carries this out without undue delay, as a rule within 30 days. Where a provider connection is no longer available or a statutory duty applies, PPJ explains the reason and agrees the extension with you.

Copies created by Ridian in target calendars are removed before the credentials needed for that are deleted, so far as instructed and technically reachable. Copies that cannot be reached are named to you. Appointments created at a user’s explicit request remain in the provider calendar unless you instruct otherwise.

Backups remain locked until they expire as scheduled; if a backup is restored, deletion instructions are applied again. Purpose limitation, confidentiality and security continue to apply until deletion is complete.

Records PPJ must keep by law, and PPJ’s own contract administration, are processed separately under PPJ’s own responsibility and are not covered by this deletion duty.

12. Changes to this agreement

Each version of this agreement carries a version number and a date. Earlier versions are available on request.

PPJ may change this agreement where a legitimate reason applies, in particular a change in law or in supervisory guidance, an adjustment to the technical measures, or a clarification that does not reduce your rights. PPJ announces such a change at least 30 calendar days before it takes effect, by email to the address named in section 6. If you object within that period, PPJ may terminate the affected service at the end of the notice period; otherwise the new version applies from the date stated.

Changes that materially reduce your rights or PPJ’s obligations, or that extend the purposes of processing, require your renewed express acceptance. PPJ obtains it in the product before the new version applies to you.

Changes to the sub-processor list follow section 6 and not this section.

13. A signed copy

This agreement is concluded in electronic form and is valid without a signature, as Article 28(9) GDPR permits. You can save and print it at any time using the print view on this page.

If your organisation requires a countersigned copy naming both parties, write to [email protected]. We will complete the party details, sign, and send it to you for signature. The content is identical to this page in the version stated.

14. Final provisions

German law applies, excluding the UN Convention on Contracts for the International Sale of Goods and subject to mandatory provisions.

This agreement is published in German and English. In case of discrepancy, the German version prevails.

Should a provision be or become invalid, the remainder of this agreement stays in force and the statutory rules apply in its place.

Questions about this agreement, about data protection or about a countersigned copy: [email protected].

26 September 2026

Related documents

The sub-processor list forms part of this agreement. The terms of service govern the service itself, and the privacy policy describes the processing we carry out as controller. The German version is at Auftragsverarbeitung.