Data protection at calovo
This is an English translation of our German privacy policy, provided for your convenience. In the event of any discrepancy between the two language versions, the German version shall prevail.
You can find our terms and conditions here: https://fr.calovo.com/agb
You currently allow cookies.
This setting applies exclusively to your visit to our own website. Where a calovo calendar is embedded in a customer's website (widget, calendar view or subscribe button), we do not use any analytics tools and no analytics cookies there at all – see section VIII. When you subscribe to a calendar we merely use a random, technically necessary identifier (section VII).
We measure the reach of our pages predominantly without cookies on our own server, without storing IP addresses and without passing data on to third parties – the details are set out in section VI.
I. Name and address of the controller
The controller within the meaning of the General Data Protection Regulation and other national data protection laws of the member states as well as other data protection provisions is:
Termine.de AG
Leopoldstraße 2-8
32051 Herford
Germany
Support centre: Send a support ticket
Website: www.calovo.de
II. Data protection contact
Data protection is anchored directly at executive-board level. The Board is the central contact for all data protection matters:
Termine.de AG
Board: Carlos Knoke Flores
Leopoldstraße 2-8
32051 Herford
Germany
Email: datenschutz@calovo.com
Website: www.calovo.de
III. General information on data processing
1. Scope of the processing of personal data
We process personal data only to the extent necessary for a functioning website, our content and services, performance of contracts, compliance with legal obligations, or legitimate interests. Where processing requires consent, we obtain it before processing and it may be withdrawn with effect for the future.
2. Legal basis for the processing of personal data
Where we obtain the data subject's consent for processing operations involving personal data, Art. 6(1)(a) of the EU General Data Protection Regulation (GDPR) serves as the legal basis.
Where personal data is processed that is necessary for the performance of a contract to which the data subject is party, Art. 6(1)(b) GDPR serves as the legal basis. This also applies to processing operations that are necessary in order to take steps prior to entering into a contract.
Where processing of personal data is necessary for compliance with a legal obligation to which our company is subject, Art. 6(1)(c) GDPR serves as the legal basis.
In the event that vital interests of the data subject or another natural person make the processing of personal data necessary, Art. 6(1)(d) GDPR serves as the legal basis.
Where processing is necessary to safeguard a legitimate interest of our company or of a third party, and the interests, fundamental rights and fundamental freedoms of the data subject do not override the first-mentioned interest, Art. 6(1)(f) GDPR serves as the legal basis for the processing.
3. Erasure of data and storage period
The data subject's personal data is erased or blocked as soon as the purpose of storage ceases to apply. Data may also be stored beyond that point where this has been provided for by the European or national legislator in Union regulations, laws or other provisions to which the controller is subject. Data is also blocked or erased when a storage period prescribed by the standards referred to expires, unless there is a need for further storage of the data for the conclusion or performance of a contract.
IV. Provision of the website and creation of log files
1. Description and scope of the data processing
Each time our website is accessed, our system automatically collects data and information from the computer system of the accessing device. The following data is collected in the process:
- Information about the browser type and the version used
- The user's operating system
- The user's internet service provider
- The user's IP address
- Date and time of access
- Websites from which the user's system reaches our website
- Websites that are accessed by the user's system via our website
This data is stored in our system's log files, including the IP address. These log files are not merged with other personal data – such as your customer account – and no user profiles are created from them. The log files serve exclusively for technical operation and for defending against attacks.
2. Legal basis for the data processing
The legal basis for the temporary storage of the data and the log files is Art. 6(1)(f) GDPR.
3. Purpose of the data processing
The temporary storage of the IP address by the system is necessary in order to enable the website to be delivered to the user's device. For this purpose, the user's IP address must remain stored for the duration of the session.
These purposes also constitute our legitimate interest in the data processing pursuant to Art. 6(1)(f) GDPR.
4. Duration of storage
The data is erased as soon as it is no longer necessary to achieve the purpose for which it was collected. Where data is collected for the provision of the website, this is the case when the respective session has ended.
Where data is stored in log files, this is the case after seven days at the latest. Storage beyond that period is possible. In that case the users' IP addresses are erased or altered so that it is no longer possible to identify the accessing client.
5. Right to object and to request removal
The collection of data for the provision of the website and the storage of data in log files is strictly necessary for the operation of the website. Consequently, the user has no right to object.
V. Use of cookies
1. Description and scope of the data processing
Our website uses cookies. Cookies are text files that are stored in, or by, the internet browser on the user's computer system. When a user accesses a website, a cookie may be stored on the user's operating system. This cookie contains a characteristic string that allows the browser to be identified uniquely when the website is accessed again.
We use cookies to make our website more user-friendly. Some elements of our website require the accessing browser to be identifiable even after a change of page.
The following data is stored and transmitted in these cookies:
| Cookie | Purpose | Storage period | Consent |
|---|---|---|---|
cal_sess |
Maintains your session for as long as you are logged in or filling in a form. | 120 minutes from the last activity | technically necessary |
XSRF-TOKEN |
Protects forms against misuse by third-party websites. | until the browser is closed | technically necessary |
calfeed_subscriber |
Random subscriber identifier that technically provides and manages your calendar subscriptions (see section VII). It contains no information about your person. | 10 years, so that a subscription can still be recognised and terminated after a long period of time | technically necessary for the function you requested |
ga_allowed |
Stores your decision about analytics cookies so that we do not have to ask you again and can respect your refusal. | 1 year | technically necessary (consent management) |
calovo_public_locale |
Remembers the language you have chosen. | 1 year | technically necessary (your selection) |
calovo_last_feed, calovo_subscribe_fid |
Remember the calendar you last opened so that the transition between the website and the calovo app arrives at the right destination. | until the browser is closed | technically necessary |
feed_challenge_participant |
Keeps you signed in to a prediction game so that you can submit predictions without signing in again each time (see section XII). | 30 days | technically necessary for participation |
_ga, _ga_… |
Google Analytics 4 – distinguishing returning visits (see point 2). | up to 2 years | only with your consent |
In addition, your browser stores the search terms you last entered (a maximum of five) locally on your device so that the search can offer them to you again. This list is not transmitted to us and can be removed at any time in the search via “Clear history”.
The first time you access our website, a notice banner informs you about analytics cookies and refers you to this privacy policy. Until you consent there, only the cookies marked above as technically necessary are set. You can change your decision at any time:
You currently allow cookies.
2. Google Analytics 4 – only with your consent
On our general web pages we additionally use Google Analytics 4, an analytics service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (“Google”). Without your consent nothing is loaded from Google – the analytics program is only requested at all once you have consented.
According to the provider, Google Analytics 4 does not store any IP addresses. The IP address is used only briefly to determine the country approximately and is then discarded. What is processed is essentially the pages accessed, time spent, approximate location (country/region), the device and browser used as well as the source through which you reached us. In addition, we report individual events such as selecting and being handed off to a calendar app; we cannot tell whether the subscription is completed successfully there.
Processing on servers of Google LLC in the USA is possible. This is based on the EU-US Data Privacy Framework, to which Google has submitted, and additionally on the EU standard contractual clauses (Art. 46(2)(c) GDPR). The user-related data stored by Google Analytics is deleted automatically after 14 months at the latest.
Google Analytics is not used on our embedded surfaces – that is, in widgets, calendar embeds and subscribe buttons that run on our customers' websites (see section VIII).
You can withdraw your consent at any time with effect for the future using the button above. Independently of this, you can prevent collection by Google using the browser add-on provided by Google: https://tools.google.com/dlpage/gaoptout. Further information on data processing by Google: https://policies.google.com/privacy.
3. Legal basis for the data processing
Technically necessary cookies and comparable storage access are permissible under § 25(2) no. 2 TDDDG; subsequent processing of personal data is based on Art. 6(1)(b) or (f) GDPR. Analytics cookies are set and evaluated only with consent pursuant to § 25(1) TDDDG and Art. 6(1)(a) GDPR.
4. Purpose of the data processing
The purpose of using technically necessary cookies is to make the use of websites easier for users. Some functions of our website cannot be offered without the use of cookies. For these it is necessary that the browser is recognised even after a change of page.
The user data collected through technically necessary cookies is not used to create user profiles. We use analytics cookies only after consent, for the purpose of improving the quality of our website and its content. Analytics cookies allow us to learn how the website is used and thus to optimise our service continuously.
5. Duration of storage, right to object and to request removal
Cookies are stored on the user's device and transmitted from it to our site. As a user you therefore also have full control over the use of cookies. By changing the settings in your internet browser you can deactivate or restrict the transmission of cookies. Cookies that have already been stored can be deleted at any time. This can also be done automatically. If cookies are deactivated for our website, it may no longer be possible to use all functions of the website to their full extent.
VI. Reach measurement without cookies
1. Description and scope of the data processing
In order to understand which content on calovo is being used, we count page views on our own server – without a cookie, without recognition beyond the day in question and without passing data on to third parties. No information is stored on or read from your device in the process.
When a page is accessed, we briefly process:
- the page accessed (internal name of the page template, e. g. “home page”, not the full address),
- the date of access (to the day, without a time),
- the internet address of the page from which you reached us – solely its host name (e. g. “google.com”), not the full address,
- your IP address and browser identifier – solely in order to form an irreversible check value from them immediately.
This check value is derived from a secret key that changes daily, together with your IP address and browser identifier. All that is stored of it is a counter from which the number of distinct visitors on a given day can be estimated – the check value itself can neither be reversed nor formed again on the following day. IP address and browser identifier are never stored at any point. Recognition across several days, a cross-device profile or a merger with your account is therefore technically impossible.
What is stored permanently is exclusively aggregated figures, such as “home page, 12 August 2026, 1,428 views”. We count automated accesses (search engine crawlers) separately so that they do not distort the analysis.
2. Legal basis for the data processing
The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in being able to understand and improve the use and technical delivery of our service. Consent is not required because for this purpose we neither store information on your device nor access information stored there (§ 25 TDDDG).
3. Purpose of the data processing
We identify which content is in demand, through which sources visitors find us and whether technical changes impair usage. The analysis is carried out exclusively in aggregated form; individual persons are not identifiable in it.
4. Duration of storage
The intermediate values used to form the check value are deleted automatically after two days at the latest. The aggregated counter values no longer have any personal reference and are retained permanently for time-series comparison.
5. Right to object and to request removal
Since no individual personal data is stored, subsequent attribution or erasure is technically impossible. However, we can comply with your objection under Art. 21 GDPR for the future – please contact our data protection contact for this purpose (section II).
VII. Calendar subscriptions (calfeeds)
1. Description and scope of the data processing
The core of our service is subscribing to calendars: you add a calendar address (what is known as an ICS address) to your calendar app, which then retrieves this address independently at regular intervals in order to load new events.
For this to work, that address contains two randomly generated identifiers: a subscriber identifier and an identifier for the respective subscription. They contain no information about your person and are created without registration. We need them in order to recognise the same subscription each time it is retrieved – for instance to deliver the correct events to you and to be able to terminate a subscription on request.
Each time your calendar app retrieves the data, we process:
- the two identifiers referred to above,
- the date and time of the retrieval,
- the identifier of your calendar software (e. g. “iOS Calendar”, “Google Calendar”, “Outlook”),
- the number of previous retrievals of this subscription.
From this we determine aggregated key figures which we make available to the respective calendar provider: how many subscribers its calendar has, how many have been newly added and which calendar programs are used. The calendar provider receives exclusively these aggregated figures, no identifiers and no information about individual subscribers.
Exception – calendars with access approval: Individual calendars release their content only after approval by the provider. If you submit an access request for such a calendar, you additionally provide your name, your email address and, optionally, a message. This information is stored together with the subscriber identifier referred to above and displayed to the calendar's provider so that the provider can decide on your request. From that point on, the previously purely random identifier is attributed to your person. You can withdraw your access request together with your name and email address at any time and have it erased; please contact our data protection contact for this purpose (section II).
Exception – voluntary newsletter sign-up: On topic pages and on the subscribe page of individual providers' calendars, which those providers link from their own websites, you may voluntarily leave an email address for that provider's newsletter after choosing your calendar app. This step is optional and can be skipped; the calendar subscription works exactly the same without it. The address you provide is not linked to the random subscriber identifier described above. Details are set out in section IX.
2. Legal basis for the data processing
The legal basis for providing the subscription is Art. 6(1)(b) GDPR, since the processing is necessary in order to provide the service you have requested. For the aggregated analysis the legal basis is Art. 6(1)(f) GDPR; our legitimate interest and that of the calendar providers lies in being able to demonstrate the reach of a calendar.
3. Purpose of the data processing
The identifiers serve the technical provision and management of the subscription. We additionally need the identifier of the calendar software in order to prepare calendar files correctly for the respective software – the common calendar programs behave differently.
4. Duration of storage
The data relating to a subscription is stored for as long as the subscription exists. If your calendar app permanently stops retrieving the address, the subscription is deemed to have ended. The aggregated figures then no longer have any personal reference.
5. Right to object and to request removal
You end a subscription by removing the calendar in your calendar app; no further retrievals then take place. The subscriber identifier is stored in your browser (see section V) and can be deleted there at any time.
VIII. Widgets and embedded content on partner websites
1. Description and scope of the data processing
Our customers can embed calovo calendars in their own website – as a calendar view, an event list or a subscribe button. If you access such a page, this component is loaded from our servers; in doing so, your IP address and browser identifier are transmitted to us as a technical necessity.
On these embedded surfaces we deliberately do not use any analytics tools whatsoever: no Google Analytics and no analytics cookies. We count exclusively on the server side and in aggregated form how often an embed has been accessed and on which website it is embedded (only its host name). We set a cookie here only if you actively start the subscription process – the subscriber identifier described in section VII is then required.
2. Legal basis for the data processing
The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest and that of the embedding customer lies in ensuring the delivery of the embed and in being able to demonstrate its use.
3. Purpose of the data processing
The aggregated count shows us and our customer whether and to what extent an embed is used and whether it is delivered without technical faults.
4. Duration of storage, right to object and to request removal
The information provided under section VI applies. The operator of the embedding website is responsible for the data processing on that website itself; please refer to that operator's privacy policy for the details.
IX. Email notifications and newsletters
The calovo product newsletter is voluntary and separate from the account and operational email. It may be requested during signup or in the cockpit email settings using a separate, unticked declaration. Opening an account alone is not marketing consent. The subscription becomes active only after a factual confirmation email and a subsequent confirmation step deliberately completed by the recipient (double opt-in). The legal basis is Art. 6(1)(a) and Art. 7 GDPR in conjunction with Section 7 UWG.
For proof, we store the email address, user reference and language, the full consent wording with version and checksum, source and times of request, confirmation and withdrawal, pseudonymised technical evidence and delivery status. Unconfirmed requests expire after 24 hours. Following withdrawal, the necessary evidence is generally retained until the end of the third calendar year following withdrawal. Only after confirmed double opt-in and activation of the delivery integration is the required data transferred to a new audience reserved exclusively for proven consent at The Rocket Science Group LLC d/b/a Mailchimp (Intuit group, USA). Individual open and click tracking is not used for this programme. Details, withdrawal and third-country safeguards are set out in the cockpit privacy policy.
Required system email, configured import failure reports and separately selectable optional product email are distinct from this newsletter. Consent can be withdrawn at any time with effect for the future in the email settings or through the unsubscribe link in every newsletter email.
Newsletters of our customers (provider newsletters): On our topic pages and – where the respective provider has enabled it – on the subscribe page of that provider's calendars, which the provider links from its own website, you may voluntarily leave an email address for that provider's newsletter after choosing your calendar app. The step is optional and can be skipped; the calendar subscription works exactly the same without it.
The controller for such a newsletter is exclusively the respective provider, who also sends it. calovo (Termine.de AG) collects, confirms and documents the sign-up on the provider's behalf as a processor pursuant to Art. 28 GDPR. The legal basis is Art. 6(1)(a) and Art. 7 GDPR in conjunction with Section 7 UWG.
The sign-up only becomes effective after a factual confirmation email and the confirmation step deliberately completed in it (double opt-in). For proof, we store the email address, the full consent wording with version and checksum, the language, the source page or the calfeed concerned, the times of request, confirmation and withdrawal, as well as pseudonymised hash values of the IP address. Unconfirmed requests expire after 24 hours and are deleted. Following a withdrawal, minimal evidence is retained until the end of the third calendar year after the withdrawal.
The email address is passed on exclusively to the respective provider and is not used for calovo's own marketing. You can withdraw your consent at any time with effect for the future – via the withdrawal link in the confirmation email, via the unsubscribe link in every newsletter email, or directly with the provider. The address is not linked to the random subscriber identifier described in section VII, and existing calovo account data are not used for this purpose either.
X. Registration
1. Description and scope of the data processing
On our website users may register by providing personal data. The data is transmitted to us, stored and disclosed only to the processors named in this notice where necessary for operation, email delivery and performance of the contract. Registration data is not used for advertising merely because an account is opened. Only where the separate newsletter declaration is selected voluntarily and subsequently confirmed by double opt-in do we additionally process the data described in section IX for that purpose. In particular, we process:
- Form of address (Mr/Ms)
- First name
- Last name
- Name of the organisation
- Street & house number
- Postcode
- City
- Country
We also store the time of registration and the accepted contract-document versions and evidence needed to demonstrate the account agreement. We do not record the registration as marketing consent.
2. Legal basis for the data processing
The legal basis is Art. 6(1)(b) GDPR for the performance of the contract and steps prior to entering into it. Art. 6(1)(f) GDPR additionally applies to security, abuse prevention and evidence of the agreement.
3. Purpose of the data processing
Registration of the user is necessary for the performance of a contract with the user or in order to take steps prior to entering into a contract. The purpose of the data processing is the proper provision of an account as well as the provision of a legal notice for the (potential) subscribers of the provider's calfeeds.
4. Duration of storage
The data is erased as soon as it is no longer necessary to achieve the purpose for which it was collected. For data collected during the registration process for the performance of a contract or in order to take steps prior to entering into a contract, this is the case when the data is no longer necessary for the performance of the contract. Even after the contract has been concluded, there may still be a need to store the contracting party's personal data in order to comply with contractual or statutory obligations.
5. Right to object and to request removal
As a user, you have the option of cancelling your registration at any time. You can have the data stored about you changed at any time. In order to delete or change data, the user must log in to their account at calpit.calovo.com. Under the menu item “My account” the data can be changed, or the entire account can be deleted by clicking “Delete account”. Where the data is necessary for the performance of a contract or in order to take steps prior to entering into a contract, early erasure of the data is only possible insofar as no contractual or statutory obligations preclude erasure.
XI. Contact form and contact by email
1. Description and scope of the data processing
Our website contains a contact form which can be used to make contact electronically. If a user makes use of this option, the data entered into the input form is transmitted to us and stored.
The contact enquiry is processed via the support system operated by calovo. In connection with handling the enquiry, the following data is processed in the support system:
- First name and last name
- Email address
- Subject and content of your message
- where applicable, the calendar to which your enquiry relates
- Date and time of the enquiry
So that we can classify your enquiry, the page from which you opened the form is automatically added to the message. Access credentials such as tokens or passwords are removed technically in the process. When you submit the form you are forwarded to our support system; your details are passed on in the address bar and may therefore appear in your browser history.
Your consent to the processing of the data is obtained as part of the submission process, with a reference to this privacy policy.
Alternatively, contact can be made using the email address provided in the legal notice. In that case, the user's personal data transmitted with the email is stored. The data is used exclusively for processing the conversation.
The support system can be reached at https://support.calovo.com.
2. Legal basis for the data processing
The legal basis for the processing of the data, where the user has given consent, is Art. 6(1)(a) GDPR. The legal basis for the processing of data transmitted in the course of sending an email is Art. 6(1)(f) GDPR. Where the email contact is aimed at concluding a contract, the additional legal basis for the processing is Art. 6(1)(b) GDPR.
3. Purpose of the data processing
The processing of the personal data from the input form serves us solely to handle the contact made. In the case of contact by email, this also constitutes the necessary legitimate interest in processing the data.
The other personal data processed during the submission process serves to prevent misuse of the contact form and to ensure the security of our information technology systems.
4. Duration of storage
The data is erased as soon as it is no longer necessary to achieve the purpose for which it was collected. For the personal data from the input form of the contact form and for data sent by email, this is the case when the respective conversation with the user has ended. The conversation has ended when it can be inferred from the circumstances that the matter concerned has been conclusively clarified.
The personal data collected additionally during the submission process is erased after a period of seven days at the latest.
5. Right to object and to request removal
The user has the option of withdrawing their consent to the processing of personal data at any time. If the user contacts us by email, they may object to the storage of their personal data at any time. In such a case the conversation cannot be continued. All personal data stored in the course of making contact is erased in that case.
6. Notices of allegedly illegal content
Through our notice mechanism under Article 16 of the Digital Services Act, we process the exact location, explanation and any supporting evidence, and generally the reporting person's name and email address. The statutory exception for certain offences against children allows a notice without a name and email address. We also document review status, the decision and reasons, and notifications to the parties involved.
Processing is necessary to comply with our statutory review, reasoning and information duties (Art. 6(1)(c) GDPR in conjunction with the Digital Services Act) and for abuse prevention and the establishment, exercise or defence of legal claims (Art. 6(1)(f) GDPR). Concluded records are automatically erased three years after the final decision; an open review is not erased merely because time has elapsed.
XII. Prize draws and prediction games
1. Description and scope of the data processing
On individual pages we offer prize draws and prediction games. Participation is always voluntary; without participating you can continue to use the rest of our service unchanged.
In a prize draw we process the data you provide – as a rule first name, last name, email address and, if the prize draw includes a question, your answer. To confirm your email address we send an activation link. If you win, we additionally store the fact that you have won and the contact details with which you did so, in order to be able to attribute and hand over the prize. To defend against automated entries we use Google reCAPTCHA on these pages (see section XIV).
In a prediction game we process your email address, a display name chosen by you, the predictions you submit and the time of your last sign-in. Signing in takes place without a password via a sign-in link that we send you by email. In addition, we record which version of the terms of participation and of the privacy notices you have accepted, in order to be able to demonstrate this later. The display name is visible to other participants; your email address is not.
2. Legal basis for the data processing
The legal basis is Art. 6(1)(b) GDPR: the processing is necessary for carrying out the participation relationship that comes into existence with your sign-up. Insofar as you have additionally consented to being notified, the legal basis is Art. 6(1)(a) GDPR.
3. Purpose of the data processing
The data serves to carry out the respective game: attributing participation, determining and notifying the winners as well as demonstrating that the game was conducted properly.
4. Duration of storage
The data is erased as soon as it is no longer necessary for carrying out and completing the respective game and no statutory retention periods preclude erasure.
5. Right to object and to request removal
You may withdraw your participation at any time and request the erasure of your participation data; please contact our data protection contact for this purpose (section II). Withdrawal removes the possibility of continuing to take part in the respective game or of receiving a prize.
XIII. Data processing in the calovo Android app
1. Description and scope of the data processing
When you use our Android app “calovo”, we process data that is necessary to provide the app's functions, in particular the calendars you have subscribed to and device-related identifiers for synchronisation. In addition, the app uses the following services provided by Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland; hereinafter “Google”):
- Firebase Crashlytics (crash reports)
- Firebase Cloud Messaging (push notifications)
- Google Analytics for Firebase (usage statistics – only with your consent)
2. Crash reports (Firebase Crashlytics)
In order to ensure the stability of the app, technical information (device type, operating system version, app version, crash log) is transmitted to Google in the event of a crash. Your device's advertising ID is not used for this purpose. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest lies in fixing errors and ensuring a functioning app.
3. Usage statistics (Google Analytics for Firebase)
Only if you have expressly consented in the app does the app collect anonymous usage statistics via Google Analytics for Firebase, e. g. which functions are used and whether subscribing to a calendar is successful. Device-related identifiers are processed in this context, including your device's advertising ID. The advertising ID is used exclusively for analytics and attribution purposes; it is not used for personalised advertising.
The legal basis is your consent, Art. 6(1)(a) GDPR. The data may be processed on servers of Google LLC in the USA; the transfer takes place on the basis of the EU-US Data Privacy Framework and additionally the EU standard contractual clauses (Art. 46(2)(c) GDPR). The user-related data stored by Google Analytics is deleted automatically after 14 months at the latest.
You can withdraw or give your consent at any time with effect for the future: in the app via the menu under “Privacy & analytics”. If you withdraw consent, the data collected on the device for Analytics is reset.
4. Push notifications (Firebase Cloud Messaging)
So that the calendars you have subscribed to are updated promptly, the app registers a device token with Firebase Cloud Messaging, via which we send update notices to your device. The legal basis is Art. 6(1)(b) GDPR (provision of the calendar subscriptions you use) or Art. 6(1)(f) GDPR.
5. Duration of storage, right to object and to request removal
Processing by Crashlytics and Cloud Messaging ends when the app is uninstalled. You can withdraw your Analytics consent in the app at any time as described under point 3. Further information on data processing by Google can be found at https://policies.google.com/privacy and at https://firebase.google.com/support/privacy.
XIV. Hosting and service providers used
1. Hosting and operation
Our website and the associated services are operated at DigitalOcean LLC in its data centre in Frankfurt am Main. For storing images and files we additionally use the Amazon S3 storage service provided by Amazon Web Services, likewise in the Frankfurt am Main region.
Both providers process the data arising in this context (in particular the log files referred to in section IV) on our instructions on the basis of a data processing agreement pursuant to Art. 28 GDPR. Primary resources are configured in EU regions. Where access from a third country cannot be excluded, it is safeguarded by appropriate transfer mechanisms, in particular the EU standard contractual clauses and supplementary measures and, where applicable, an adequacy decision. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest lies in secure and reliable operation.
2. Sending emails
For sending system and information emails (such as activation links, password resets or notices about your calendars) we use Mailgun Technologies, Inc., part of the Sinch group. Your email address and the content of the respective message are transmitted. A data processing agreement pursuant to Art. 28 GDPR is in place; the legal basis is Art. 6(1)(b) or (f) GDPR.
3. Error diagnostics
To identify and remedy faults and monitor platform performance, we use SmartBear Software Inc. (Bugsnag) for error diagnostics and New Relic, Inc. for infrastructure and performance monitoring. A technical report may contain the address accessed, error trace, timestamp and browser/system information; input and content data is filtered where technically possible and access is restricted. The legal basis is Art. 6(1)(f) GDPR – our legitimate interest lies in secure, stable and efficient operation.
4. Google reCAPTCHA
On our prize draw pages we use reCAPTCHA provided by Google Ireland Limited in order to detect automated entries (“bots”). In doing so, your IP address as well as information about your browser and your usage behaviour on the page are transmitted to Google and evaluated there. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest lies in protecting our prize draws against abusive automated participation. Further information: https://policies.google.com/privacy.
5. Feedback forms
On individual partner pages we embed a form provided by Typeform (Typeform S.L., Barcelona, Spain), through which you can give us feedback voluntarily. When such a page is accessed, the form is loaded from the provider's servers; your IP address is transmitted to that provider in the process. We process your answers exclusively in order to evaluate your feedback. The legal basis is Art. 6(1)(f) GDPR.
6. Support system
We handle contact enquiries in a support system operated by ourselves at support.calovo.com. Details on this can be found in section XI.
7. AI translations of public descriptions
calovo automatically translates published calendar and provider descriptions to make content internationally accessible. We send only the description text intended for publication to Hetzner Online GmbH. Private, offline, unlisted or access-protected calfeeds and visitor, sign-in or internal account data are not transmitted. Automatic translations are labelled and the original remains unchanged.
Hetzner processes the text for us as a processor. According to the current Inference documentation, Hetzner does not store request or response content unless legally required to do so. calovo stores the finished translation and labels it as automatically translated on the web.
For text submitted by a customer for publication, the customer determines the purpose and legal basis of publication; calovo processes the text, including translation, as a processor under Art. 28 GDPR and on documented instructions through the enabled feature. For calovo's own editorial public content, Termine.de AG is the controller; the legal basis is Art. 6(1)(f) GDPR and our legitimate interest is international discoverability and clear presentation of public event offerings.
The translation feature is enabled by default and can be disabled at any time in the account settings with effect for the future. No new text is then transmitted and existing automatic translations are no longer displayed. Customers must not place confidential information, special categories of personal data or data for which they lack a lawful basis for publication and translation in public description fields. Data subjects may contact our data protection contact under section II with an objection or erasure request.
XV. Rights of the data subject
If personal data relating to you is processed, you are a data subject within the meaning of the GDPR and you have the following rights vis-à-vis the controller:
1. Right of access
You may request confirmation from the controller as to whether personal data relating to you is processed by us. If such processing is taking place, you may request the following information from the controller:
- (1) the purposes for which the personal data is processed;
- (2) the categories of personal data which are processed;
- (3) the recipients or categories of recipients to whom the personal data relating to you has been or will be disclosed;
- (4) the envisaged period for which the personal data relating to you will be stored or, if specific information on this is not possible, the criteria used to determine that period;
- (5) the existence of a right to rectification or erasure of the personal data relating to you, a right to restriction of processing by the controller or a right to object to such processing;
- (6) the existence of a right to lodge a complaint with a supervisory authority;
- (7) all available information as to the origin of the data where the personal data is not collected from the data subject;
- (8) the existence of automated decision-making including profiling pursuant to Art. 22(1) and (4) GDPR and – at least in those cases – meaningful information about the logic involved as well as the significance and the envisaged consequences of such processing for the data subject.
You have the right to request information as to whether the personal data relating to you is transferred to a third country or to an international organisation. In this context you may request to be informed about the appropriate safeguards pursuant to Art. 46 GDPR in connection with the transfer.
2. Right to rectification
You have a right to rectification and/or completion vis-à-vis the controller where the processed personal data relating to you is inaccurate or incomplete. The controller must carry out the rectification without undue delay.
3. Right to restriction of processing
Under the following conditions you may request the restriction of the processing of the personal data relating to you:
- (1) if you contest the accuracy of the personal data relating to you for a period enabling the controller to verify the accuracy of the personal data;
- (2) the processing is unlawful and you oppose the erasure of the personal data and request the restriction of the use of the personal data instead;
- (3) the controller no longer needs the personal data for the purposes of the processing, but you require it for the establishment, exercise or defence of legal claims, or
- (4) if you have objected to processing pursuant to Art. 21(1) GDPR and it has not yet been established whether the legitimate grounds of the controller override your grounds.
Where the processing of the personal data relating to you has been restricted, such data may – apart from being stored – only be processed with your consent or for the establishment, exercise or defence of legal claims or for the protection of the rights of another natural or legal person or for reasons of important public interest of the Union or of a member state.
Where the processing has been restricted in accordance with the above conditions, you will be informed by the controller before the restriction is lifted.
4. Right to erasure
a) Obligation to erase
You may request the controller to erase the personal data relating to you without undue delay, and the controller is obliged to erase such data without undue delay where one of the following grounds applies:
- (1) The personal data relating to you is no longer necessary for the purposes for which it was collected or otherwise processed.
- (2) You withdraw your consent on which the processing was based pursuant to Art. 6(1)(a) or Art. 9(2)(a) GDPR, and there is no other legal basis for the processing.
- (3) You object to the processing pursuant to Art. 21(1) GDPR and there are no overriding legitimate grounds for the processing, or you object to the processing pursuant to Art. 21(2) GDPR.
- (4) The personal data relating to you has been processed unlawfully.
- (5) The erasure of the personal data relating to you is necessary for compliance with a legal obligation under Union law or the law of the member states to which the controller is subject.
- (6) The personal data relating to you was collected in relation to the offer of information society services pursuant to Art. 8(1) GDPR.
b) Information to third parties
Where the controller has made the personal data relating to you public and is obliged pursuant to Art. 17(1) GDPR to erase it, the controller shall, taking account of available technology and the cost of implementation, take reasonable steps, including of a technical nature, to inform controllers which are processing the personal data that you as the data subject have requested from them the erasure of any links to, or copies or replications of, that personal data.
c) Exceptions
The right to erasure does not exist insofar as the processing is necessary
- (1) for exercising the right of freedom of expression and information;
- (2) for compliance with a legal obligation which requires processing by Union or member state law to which the controller is subject, or for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;
- (3) for reasons of public interest in the area of public health pursuant to Art. 9(2)(h) and (i) as well as Art. 9(3) GDPR;
- (4) for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes pursuant to Art. 89(1) GDPR, insofar as the right referred to in section a) is likely to render impossible or seriously impair the achievement of the objectives of that processing, or
- (5) for the establishment, exercise or defence of legal claims.
5. Right to be informed
If you have asserted the right to rectification, erasure or restriction of processing vis-à-vis the controller, the controller is obliged to communicate this rectification or erasure of the data or restriction of processing to all recipients to whom the personal data relating to you has been disclosed, unless this proves impossible or involves disproportionate effort.
You have the right vis-à-vis the controller to be informed about those recipients.
6. Right to data portability
You have the right to receive the personal data relating to you which you have provided to the controller in a structured, commonly used and machine-readable format. You also have the right to transmit that data to another controller without hindrance from the controller to which the personal data was provided, where
- (1) the processing is based on consent pursuant to Art. 6(1)(a) GDPR or Art. 9(2)(a) GDPR or on a contract pursuant to Art. 6(1)(b) GDPR and
- (2) the processing is carried out by automated means.
In exercising this right you further have the right to have the personal data relating to you transmitted directly from one controller to another controller, where technically feasible. The freedoms and rights of other persons must not be adversely affected as a result.
The right to data portability does not apply to processing of personal data necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller.
7. Right to object
You have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data relating to you which is carried out on the basis of Art. 6(1)(e) or (f) GDPR; this also applies to profiling based on those provisions.
The controller will no longer process the personal data relating to you unless it can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims.
Where the personal data relating to you is processed for direct marketing purposes, you have the right to object at any time to the processing of the personal data relating to you for the purposes of such marketing; this also applies to profiling to the extent that it is related to such direct marketing.
If you object to processing for direct marketing purposes, the personal data relating to you will no longer be processed for those purposes.
In the context of the use of information society services, and notwithstanding Directive 2002/58/EC, you may exercise your right to object by automated means using technical specifications.
8. Right to withdraw the declaration of consent under data protection law
You have the right to withdraw your declaration of consent under data protection law at any time. The withdrawal of consent does not affect the lawfulness of the processing carried out on the basis of the consent up to the point of withdrawal.
9. Automated individual decision-making, including profiling
You have the right not to be subject to a decision based solely on automated processing – including profiling – which produces legal effects concerning you or similarly significantly affects you. This does not apply if the decision
- (1) is necessary for entering into, or performance of, a contract between you and the controller,
- (2) is authorised by Union or member state law to which the controller is subject and which also lays down suitable measures to safeguard your rights and freedoms and legitimate interests, or
- (3) is based on your explicit consent.
However, such decisions must not be based on special categories of personal data pursuant to Art. 9(1) GDPR, unless Art. 9(2)(a) or (g) GDPR applies and suitable measures to safeguard your rights and freedoms and legitimate interests have been taken.
With regard to the cases referred to in (1) and (3), the controller shall implement suitable measures to safeguard your rights and freedoms and legitimate interests, which shall include at least the right to obtain human intervention on the part of the controller, to express your point of view and to contest the decision.
10. Right to lodge a complaint with a supervisory authority
Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, in particular in the member state of your habitual residence, place of work or place of the alleged infringement, if you consider that the processing of the personal data relating to you infringes the GDPR.
The supervisory authority with which the complaint has been lodged shall inform the complainant of the progress and the outcome of the complaint, including the possibility of a judicial remedy pursuant to Art. 78 GDPR.
Last updated: 21 August 2026