Internal notice: draft — legal review required

This page is a technical draft with placeholders. Before publishing, all placeholders must be replaced with verified company facts and the full text must pass a legal review (a lawyer or a German generator such as eRecht24 / activeMind). This notice disappears once legalReviewCompleted is set to true in lib/legal/legal-config.ts.

Privacy policy

Version: 2026-07-22 — draft, legal review pending.

1. Controller

The controller within the meaning of the GDPR for the processing of personal data on this website and in the Kalup application (unless stated otherwise below) is: [COMPANY_LEGAL_NAME] [COMPANY_STREET_AND_NUMBER], [COMPANY_POSTAL_CODE_AND_CITY], [COMPANY_COUNTRY] Email: [COMPANY_EMAIL] Phone: [COMPANY_PHONE]

2. Data protection officer

Contact: [DPO_CONTACT]

3. Roles: controller and processor

Kalup is a B2B application for HR, project and calendar administration. Two layers must be distinguished under data protection law: a) For data of website visitors and user accounts (e.g. sign-in data, log data), [COMPANY_LEGAL_NAME] is the controller. b) For personal data of our customers’ employees that customers process in the application (e.g. master data, absences, working hours), the respective customer (employer) is generally the controller; [COMPANY_LEGAL_NAME] acts in that respect as a processor on the basis of a data processing agreement (Art. 28 GDPR). To exercise their rights in that respect, data subjects should primarily contact their employer. [This delineation is a draft and must be reviewed by legal counsel.]

4. Hosting (OVH, EU)

The application is operated at OVH SAS in the Gravelines, France (EU) data center. Processing takes place exclusively within the EU; no transfers to third countries occur. A data processing agreement (Art. 28 GDPR) is in place with the hosting provider. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in secure, stable operation) and Art. 28 GDPR within the processing relationship.

5. Server log files

When the application is accessed, our web server (nginx) automatically processes access logs: IP address, timestamp, requested URL, HTTP status, user agent. Purpose: security, error analysis and stability. Legal basis: Art. 6(1)(f) GDPR. Logs are deleted after [LOG_RETENTION_DAYS] days.

6. Sign-in (Keycloak)

Sign-in is handled by our self-hosted identity service Keycloak (OpenID Connect with PKCE). Sign-in data (username/email), session data and session cookies of the identity service are processed; these are technically necessary for sign-in (§ 25(2) TDDDG). Access tokens are kept in the browser ONLY in memory and are not stored persistently; during the sign-in redirect a short-lived technical state is placed in sessionStorage. Legal basis: Art. 6(1)(b) GDPR.

7. Transactional emails

For functions such as password reset and email verification we send emails via the service provider [SMTP_PROVIDER] (processor; EU region and a data processing agreement are required — to be fixed before production). Email address and message content are processed. Legal basis: Art. 6(1)(b) GDPR.

8. Error monitoring (Sentry) — only with consent

To detect technical errors we use Sentry — exclusively after your consent (Art. 6(1)(a) GDPR, § 25(1) TDDDG). Without consent, Sentry is not loaded at all. Configuration: EU data residency, no transmission of credentials, tokens or input content, no session replay. A data processing agreement is in place with Sentry. You can withdraw your consent at any time with effect for the future via the cookie settings.

9. Cookies and local storage

We use no tracking or marketing cookies and embed no external CDNs, fonts or scripts (all assets are self-hosted). The following storage operations take place:

Overview of cookies and local storage entries
NamePurposeDurationCategory
NEXT_LOCALE (cookie)Stores the selected language.12 monthsNecessary
theme (localStorage)Stores the selected color scheme (light/dark).Unlimited (until deleted)Necessary
kalup-consent (localStorage)Stores your consent selection (with version and timestamp).12 months (then asked again)Necessary
oidc.* (sessionStorage)Short-lived technical state during the sign-in redirect (PKCE).Minutes (until sign-in completes)Necessary
Keycloak session cookiesSign-in session at the self-hosted identity service (own domain).SessionNecessary

10. Your rights

As a data subject you have the following rights. Where Kalup acts as a processor for your employer (see section 3), please direct your request primarily to your employer.

  • Access (Art. 15 GDPR)
  • Rectification (Art. 16 GDPR)
  • Erasure (Art. 17 GDPR)
  • Restriction of processing (Art. 18 GDPR)
  • Data portability (Art. 20 GDPR)
  • Objection to processing based on Art. 6(1)(f) GDPR (Art. 21 GDPR)
  • Withdrawal of given consent with effect for the future (Art. 7(3) GDPR), e.g. via the cookie settings
  • Complaint to a supervisory authority (Art. 77 GDPR). Competent authority: [SUPERVISORY_AUTHORITY]

11. Retention periods

We process personal data only for as long as required for the respective purposes: server logs [LOG_RETENTION_DAYS] days; consent selection 12 months; account and application data for the duration of the contractual relationship and thereafter according to statutory retention obligations. [Add concrete periods per category during legal review.]

12. Obligation to provide data

Providing sign-in data is required to use the application; without it, sign-in is not possible. Beyond that, there is no statutory or contractual obligation to provide personal data to us.

13. Automated decision-making

Automated decision-making, including profiling (Art. 22 GDPR), does not take place.

14. Changes to this policy

We update this privacy policy when processing or the legal situation changes. The version published here applies (version: 2026-07-22). In case of material changes to the cookie/storage practice we will ask for your consent again.