Skip to content
Ridian
Request accessde

Privacy policy

As of 4 September 2026

This is a machine translation. Ridian is operated by a German company, and this document was written in German under German law. Only theGerman version is legally binding; this translation is provided for convenience. Where the two differ, the German text applies.

This policy describes what is processed when using Ridian. It also states the points that cannot be presented as an advantage — for instance that technical support based in the United States can access the operating environment.

1. Controller

PPJ Venture Labs UG (haftungsbeschränkt), Hohenzollernstraße 30, 80801 Munich, Germany, represented by Paul Koch.[email protected] ·full details (German)

If you use Ridian as a member of an organisation that has a contract with us, that organisation is the controller for the calendar data; we then process it on their behalf under Art. 28 GDPR.

2. If you only visit this website

When these pages are requested, our delivery provider processes technically necessary connection data: IP address, time, requested address, volume transferred, browser and operating system identifiers. A page cannot be delivered without them.

Legal basis is Art. 6(1)(f) GDPR (legitimate interest in secure operation).

No analytics, no cookies, no external fonts. This website sets no cookies, embeds no tracking pixels and loads no fonts from third-party servers. There is therefore no consent banner — there would be nothing to consent to.

3. If you send an access request

The access form collects your name, work email address, company, optional role and the information you provide about your intended use. We use these details only to assess and answer your request. Lettermint B.V. in the Netherlands delivers the request to us by email.

The legal basis is Art. 6(1)(b) GDPR for steps requested before entering into a contract and, for general business enquiries, Art. 6(1)(f) GDPR (our legitimate interest in responding). We retain an enquiry until it has been resolved and thereafter only as long as necessary for contract preparation or statutory record-keeping duties.

4. If you create an account

DataPurposeLegal basis
Email address, name, password hash or sign-in via Google or MicrosoftMaintaining the account, authentication, address verificationArt. 6(1)(b)
Organisation, role, invitationsTeam collaboration, permissionsArt. 6(1)(b)
Security log: sign-ins, role changes, invitations — with IP address and browser identifierTraceability of security-relevant eventsArt. 6(1)(f)

5. If you connect calendars

You grant us access to the calendars you select via Google, Microsoft or CalDAV. We store those credentials encrypted (AES-256-GCM with a versioned key).

What we store, and why

For every event in a source calendar — a calendar you have set up as the source of a synchronisation — we store a reconciliation state. It contains the event data in normalised form: title, description, location, times, status, recurrence rules, reminders and, where the provider supplies them, the attendees.

This state is required to detect changes. Without it, the entire calendar would have to be rewritten on every run. Calendars you do not use as a source are never read.

What is written into a target calendar is determined solely by the policy you set. It ranges from “show as busy only” to full details. Actual attendee entries are never copied into target calendars — that would trigger invitation emails to those people.

Purposes of processing

We process the event data of your source calendars in order to

  1. carry out the synchronisation you have set up, and
  2. give you and applications you have expressly authorised access to your calendar data — for example through our interface or an AI assistant you have connected.

There is no processing for our own purposes: calendar content is not evaluated, not used for statistics about user groups and not used to train models. Operational figures such as the number of runs or error rates contain no event content.

Events may contain special categories of personal data under Art. 9 GDPR, for instance indications of health or beliefs. We do not evaluate them; which details a target calendar receives is determined by your policy.

6. Retention

DataDuration
Account and organisation dataUntil the account is deleted
Reconciliation state, mappings, credentialsUntil the connection or account is deleted
Synchronisation run logs (without event content)90 days
Technical counters for provider rate limits24 hours
Security logAnonymised on account deletion, not erased
Access and business enquiriesUntil resolved, then where required for contract preparation or statutory record-keeping

The security log is retained in anonymised form: the link to your person is removed, while the record that an event occurred remains.

7. Recipients

Processors

ProviderTaskLocation
Convex, Inc.Application and databaseEU region Ireland
Cloudflare, Inc.Website deliveryGlobal network
Lettermint B.V.Sending system and contact emailsNetherlands

Recipients you initiate

When you connect a calendar, we communicate with its provider on your behalf — Google Ireland Limited, Microsoft Ireland Operations Limited or the CalDAV service you specify. These providers are not our processors; you established the connection yourself.

8. Transfers to third countries

We state this point explicitly because it can be decisive for organisations with strict requirements.

The application is operated by Convex in the EU region Ireland.Stored data, backups and failover systems remain within the European Union.

For operational monitoring, technical metadata is transferred to service providers in the United States. Convex's technical support is based in the United States and may access the operating environment when handling reported incidents. Convex does not currently offer a variant without this access.

This website is delivered via Cloudflare. Calendar content is not transmitted in the process — the application communicates directly with the EU region.

Both transfers are covered by the European Commission's Standard Contractual Clauses, which form part of the data processing agreements; for customers in the United Kingdom, supplemented by the UK Addendum.

9. Your rights

You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection to processing based on legitimate interests (Art. 21).

Deleting your account is possible within the application itself. It also removes the copies we created in your target calendars — provided the credentials for them are still valid. Where this fails for individual calendars, we tell you which ones are affected.

You may lodge a complaint with a supervisory authority. The authority responsible for us is the Bavarian Data Protection Authority (Bayerisches Landesamt für Datenschutzaufsicht), Promenade 18, 91522 Ansbach, Germany.

9. Changes

We update this policy when the processing changes. Existing contract customers are informed separately and in advance about new sub-processors.