Privacy Policy

With the following information we would like to give you, as a "data subject", an overview of how we process your personal data and of your rights under data protection law. All processing is carried out in accordance with the EU General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG) and the German Telecommunications Digital Services Data Protection Act (TDDDG).

1. Controller

The controller within the meaning of the GDPR is:

Dennis Köhler
c/o Impressumservice Dein-Impressum
Stettiner Str. 41
35410 Hungen
Germany
E-mail: denniskoehler92@gmail.com

We have not appointed a data protection officer, as the legal requirements for doing so (in particular Section 38 BDSG) do not apply in our case.

2. General Information on Data Processing

Scope of processing

As a matter of principle, we only process personal data to the extent necessary to provide a functioning platform and our content and services, or where you have given your consent.

Legal bases

Depending on the case, processing is based on:

The legal basis applicable in each individual case is stated with the respective processing activities below.

Data erasure and storage period

We store personal data only for as long as required for the respective purpose or as prescribed by statutory retention periods. Once the purpose no longer applies or a retention period expires, the data is blocked or erased.

3. Scope of Application

This privacy policy applies to our services available under the following domains:

4. Technology

SSL/TLS encryption

We use SSL/TLS encryption to protect data in transit. You can recognize an encrypted connection by the https:// in your browser's address bar.

Server log files

Each time you access our platform, your browser automatically transmits data to our server for technical reasons, which is processed briefly in log files. This includes in particular:

The purpose is the correct delivery of content, ensuring system security and stability (including protection against abuse and overload) and technical error analysis. The legal basis is our legitimate interest (Art. 6(1)(f) GDPR) in a secure and functioning operation. The log data is not combined with other data sources and is deleted regularly.

Security logging

To protect user accounts, we log security-relevant events (in particular sign-ins, sign-outs and failed sign-in attempts) together with the time, IP address and browser identifier (user agent). You can view your active sessions and your sign-in history at any time in your profile settings and terminate sessions there. The legal basis is our legitimate interest in account and system security (Art. 6(1)(f) GDPR).

5. Cookies and Similar Technologies

We use only technically necessary cookies and similar technologies:

This storage is strictly necessary to provide the functions you have expressly requested; it therefore does not require consent pursuant to Section 25(2) No. 2 TDDDG. The legal basis for the subsequent processing is Art. 6(1)(f) GDPR.

We do not use any tracking, analytics or marketing cookies.

6. Registration and User Account

To use the platform, you can create a user account (a separate account exists for the plugin marketplace at store.). In doing so, we process the data you provide, in particular:

The purpose is the provision, administration and protection of your account. The legal basis is the performance of a contract or pre-contractual measures (Art. 6(1)(b) GDPR). We store this data for as long as your account exists; after its deletion, the data is removed or anonymized unless statutory retention obligations require otherwise.

7. Use of the Platform

Vinculum is a project management and developer platform. When you use it, we process the data that you enter into the platform yourself or that arises through its use, in particular in connection with:

The purpose is the provision of the features you use. The legal basis is the performance of a contract (Art. 6(1)(b) GDPR). Content you enter is stored for the duration of use and removed at your request or after account deletion. Please note: content you add to shared projects (e.g. tasks, comments, time entries) is visible to the other members of the respective project.

8. Sign-in via Third-Party Providers (Single Sign-On)

Where we offer sign-in via external identity providers and you choose to use it, you can sign in with an existing account at a third-party provider instead of a local password, currently in particular:

When you sign in, the respective provider transmits to us the data required to create your account and sign you in (in particular a user identifier, your e-mail address and your name). We do not transmit any platform content to the provider; only the sign-in process itself takes place via their systems.

Where data is processed in the USA in this context, the transfer is based on the provider's certification under the EU-US Data Privacy Framework or on standard contractual clauses. The legal basis is the performance of a contract with regard to the sign-in method you have chosen (Art. 6(1)(b) GDPR). Using third-party sign-in is voluntary; signing in with a local account remains available as an alternative. Further information can be found in the providers' privacy policies: https://policies.google.com/privacy · https://privacy.microsoft.com

9. Contacting Us

If you contact us via our contact form or by e-mail, we process the data you provide, in particular:

When you use the contact form, your IP address is used solely for short-term abuse prevention (rate limiting); it is not stored together with your message. You will receive an automatic confirmation of receipt by e-mail.

The purpose is the handling and answering of your enquiry. Depending on the matter, the legal basis is the performance of a contract or pre-contractual measures (Art. 6(1)(b) GDPR) or our legitimate interest in answering enquiries (Art. 6(1)(f) GDPR). Enquiries submitted via the contact form are automatically deleted no later than 12 months after receipt; they are deleted earlier once your enquiry has been conclusively dealt with and no retention obligations apply.

10. Hosting

Our platform is hosted by:

Hetzner Online GmbH
Industriestr. 25
91710 Gunzenhausen
Germany

The provider processes on our behalf the data arising from the use of the platform. This is based on a data processing agreement pursuant to Art. 28 GDPR. Processing takes place in a data center within the European Union; no transfer to a third country takes place in this respect. The legal basis for using this provider is our legitimate interest in secure and efficient operation (Art. 6(1)(f) GDPR).

11. Rights of the Data Subject

You have the following rights vis-à-vis us with regard to your personal data:

You can initiate an export of your data and the deletion of your account directly in your profile settings (self-service); in addition, you can contact us at any time via the e-mail address stated above.

Where processing is based on your consent, you may withdraw it at any time with effect for the future. The lawfulness of processing carried out before the withdrawal remains unaffected.

Irrespective of this, you have the right to lodge a complaint with a data protection supervisory authority, in particular in the member state of your habitual residence or of the place of the alleged infringement.

12. Storage Period

We process and store personal data only for as long as required for the respective purpose or as prescribed by statutory retention periods. Once the purpose no longer applies or a retention period expires, the data is routinely blocked or erased.

13. Currency and Amendments

This privacy policy is dated July 2026. Ongoing development of our platform or changes to legal or regulatory requirements may make it necessary to amend this privacy policy. The current version can always be found on this page.