Privacy Policy
With the following information we would like to give you, as a "data subject", an overview of how we process your personal data and of your rights under data protection law. All processing is carried out in accordance with the EU General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG) and the German Telecommunications Digital Services Data Protection Act (TDDDG).
1. Controller
The controller within the meaning of the GDPR is:
Dennis Köhler
c/o Impressumservice Dein-Impressum
Stettiner Str. 41
35410 Hungen
Germany
E-mail: denniskoehler92@gmail.com
We have not appointed a data protection officer, as the legal requirements for doing so (in particular Section 38 BDSG) do not apply in our case.
2. General Information on Data Processing
Scope of processing
As a matter of principle, we only process personal data to the extent necessary to provide a functioning platform and our content and services, or where you have given your consent.
Legal bases
Depending on the case, processing is based on:
- your consent (Art. 6(1)(a) GDPR),
- the performance of a contract or pre-contractual measures (Art. 6(1)(b) GDPR),
- compliance with a legal obligation (Art. 6(1)(c) GDPR),
- our legitimate interests (Art. 6(1)(f) GDPR).
The legal basis applicable in each individual case is stated with the respective processing activities below.
Data erasure and storage period
We store personal data only for as long as required for the respective purpose or as prescribed by statutory retention periods. Once the purpose no longer applies or a retention period expires, the data is blocked or erased.
3. Scope of Application
This privacy policy applies to our services available under the following domains:
- tryvinculum.com including its subdomains, in particular
www.,app.(platform),store.(plugin marketplace) andapi.(programming interface) - tryvinculum.de (redirect to tryvinculum.com)
4. Technology
SSL/TLS encryption
We use SSL/TLS encryption to protect data in transit. You can recognize an
encrypted connection by the https:// in your browser's address bar.
Server log files
Each time you access our platform, your browser automatically transmits data to our server for technical reasons, which is processed briefly in log files. This includes in particular:
- IP address,
- browser type and version,
- operating system used,
- referrer URL,
- pages accessed,
- date and time of access.
The purpose is the correct delivery of content, ensuring system security and stability (including protection against abuse and overload) and technical error analysis. The legal basis is our legitimate interest (Art. 6(1)(f) GDPR) in a secure and functioning operation. The log data is not combined with other data sources and is deleted regularly.
Security logging
To protect user accounts, we log security-relevant events (in particular sign-ins, sign-outs and failed sign-in attempts) together with the time, IP address and browser identifier (user agent). You can view your active sessions and your sign-in history at any time in your profile settings and terminate sessions there. The legal basis is our legitimate interest in account and system security (Art. 6(1)(f) GDPR).
5. Cookies and Similar Technologies
We use only technically necessary cookies and similar technologies:
- short-lived cookies during the sign-in process (e.g. to secure the login flow),
- your browser's local storage to hold your session token so that you remain signed in.
This storage is strictly necessary to provide the functions you have expressly requested; it therefore does not require consent pursuant to Section 25(2) No. 2 TDDDG. The legal basis for the subsequent processing is Art. 6(1)(f) GDPR.
We do not use any tracking, analytics or marketing cookies.
6. Registration and User Account
To use the platform, you can create a user account (a separate account exists
for the plugin marketplace at store.). In doing so, we process the data you
provide, in particular:
- master data (e.g. username, name if provided, and other voluntary profile details),
- contact data (e.g. e-mail address),
- credentials (we store your password exclusively as a cryptographic hash, never in plain text),
- if set up by you: two-factor authentication data (encrypted TOTP secrets or passkey key material).
The purpose is the provision, administration and protection of your account. The legal basis is the performance of a contract or pre-contractual measures (Art. 6(1)(b) GDPR). We store this data for as long as your account exists; after its deletion, the data is removed or anonymized unless statutory retention obligations require otherwise.
7. Use of the Platform
Vinculum is a project management and developer platform. When you use it, we process the data that you enter into the platform yourself or that arises through its use, in particular in connection with:
- managing projects, tasks and boards,
- time tracking on projects and tasks,
- managing documentation and wiki content,
- uploading and managing files and attachments,
- using the integrated version control (Git) and CI/CD features,
- notifications within the platform and — depending on your settings — by e-mail (e.g. for mentions or task assignments).
The purpose is the provision of the features you use. The legal basis is the performance of a contract (Art. 6(1)(b) GDPR). Content you enter is stored for the duration of use and removed at your request or after account deletion. Please note: content you add to shared projects (e.g. tasks, comments, time entries) is visible to the other members of the respective project.
8. Sign-in via Third-Party Providers (Single Sign-On)
Where we offer sign-in via external identity providers and you choose to use it, you can sign in with an existing account at a third-party provider instead of a local password, currently in particular:
- Google (Google Ireland Ltd., Ireland / Google LLC, USA),
- Microsoft Entra ID (Microsoft Ireland Operations Ltd., Ireland / Microsoft Corporation, USA).
When you sign in, the respective provider transmits to us the data required to create your account and sign you in (in particular a user identifier, your e-mail address and your name). We do not transmit any platform content to the provider; only the sign-in process itself takes place via their systems.
Where data is processed in the USA in this context, the transfer is based on the provider's certification under the EU-US Data Privacy Framework or on standard contractual clauses. The legal basis is the performance of a contract with regard to the sign-in method you have chosen (Art. 6(1)(b) GDPR). Using third-party sign-in is voluntary; signing in with a local account remains available as an alternative. Further information can be found in the providers' privacy policies: https://policies.google.com/privacy · https://privacy.microsoft.com
9. Contacting Us
If you contact us via our contact form or by e-mail, we process the data you provide, in particular:
- contact data (e-mail address, optionally your name),
- content data (subject and message).
When you use the contact form, your IP address is used solely for short-term abuse prevention (rate limiting); it is not stored together with your message. You will receive an automatic confirmation of receipt by e-mail.
The purpose is the handling and answering of your enquiry. Depending on the matter, the legal basis is the performance of a contract or pre-contractual measures (Art. 6(1)(b) GDPR) or our legitimate interest in answering enquiries (Art. 6(1)(f) GDPR). Enquiries submitted via the contact form are automatically deleted no later than 12 months after receipt; they are deleted earlier once your enquiry has been conclusively dealt with and no retention obligations apply.
10. Hosting
Our platform is hosted by:
Hetzner Online GmbH
Industriestr. 25
91710 Gunzenhausen
Germany
The provider processes on our behalf the data arising from the use of the platform. This is based on a data processing agreement pursuant to Art. 28 GDPR. Processing takes place in a data center within the European Union; no transfer to a third country takes place in this respect. The legal basis for using this provider is our legitimate interest in secure and efficient operation (Art. 6(1)(f) GDPR).
11. Rights of the Data Subject
You have the following rights vis-à-vis us with regard to your personal data:
- access (Art. 15 GDPR) to the data stored about you,
- rectification of inaccurate data (Art. 16 GDPR),
- erasure (Art. 17 GDPR), unless statutory obligations prevent this,
- restriction of processing (Art. 18 GDPR),
- data portability (Art. 20 GDPR),
- objection to processing based on Art. 6(1)(e) or (f) GDPR (Art. 21 GDPR).
You can initiate an export of your data and the deletion of your account directly in your profile settings (self-service); in addition, you can contact us at any time via the e-mail address stated above.
Where processing is based on your consent, you may withdraw it at any time with effect for the future. The lawfulness of processing carried out before the withdrawal remains unaffected.
Irrespective of this, you have the right to lodge a complaint with a data protection supervisory authority, in particular in the member state of your habitual residence or of the place of the alleged infringement.
12. Storage Period
We process and store personal data only for as long as required for the respective purpose or as prescribed by statutory retention periods. Once the purpose no longer applies or a retention period expires, the data is routinely blocked or erased.
13. Currency and Amendments
This privacy policy is dated July 2026. Ongoing development of our platform or changes to legal or regulatory requirements may make it necessary to amend this privacy policy. The current version can always be found on this page.