Compliance & Security
CalPair synchronises calendar data between Google, Microsoft 365 and CalDAV providers. The service is operated entirely within the EU and follows the principle of data minimisation. This page summarises where data is processed, which certifications the underlying infrastructure holds, and which permissions CalPair requests.
Hosting in the EU
The application and all retrieved calendar data are processed on infrastructure of Hetzner Online GmbH in the Falkenstein (Germany) data centre. Transactional emails and encrypted off-site backups run via Scaleway SAS in Paris (France). Both locations are within the EU; no transfer to a third country takes place. Data processing agreements (DPAs) are in place with both providers.
Access tokens are stored encrypted with AES-256-GCM; transport is secured with TLS 1.3.
Infrastructure certifications
- ISO/IEC 27001:2022 — information security management system; scope: infrastructure, operations and support of the Nuremberg, Falkenstein and Helsinki data centre parks. Certified by SOCOTEC Certification Deutschland GmbH.
- BSI C5 Type 2 — Cloud Computing Compliance Criteria Catalogue of the German Federal Office for Information Security; confirms the effective implementation of the security criteria over an audit period.
Hetzner — ISO/IEC 27001:2022 certificate (PDF)
Hetzner provides the BSI C5 Type 2 attestation on request. Overview and current evidence: docs.hetzner.com/general/others/certificates.
These certifications apply to the infrastructure provider, not to CalPair itself.
Sub-processors
The following list is the current version of Annex 3 to the data processing agreement. It contains only service providers that process personal data on behalf of the customer. Both process exclusively within the EU.
| Sub-processor | Purpose / data processed | Location |
|---|---|---|
| Hetzner Online GmbH | Hosting, servers, database — all application and account data processed on behalf of the customer | Falkenstein, Germany (EU) |
| Scaleway SAS | Sending transactional emails to users, encrypted off-site database backups (object storage) | fr-par, France (EU) |
Not part of the processing on behalf of the customer: service providers CalPair uses for its own purposes, which never touch data processed on behalf of customers — payment processing (Stripe), the CDN of the public landing page (Bunny.net, visitor and HTTP metadata only), and accounting and invoice archiving (Lexware Office, pCloud). These are listed in the privacy policy.
Not sub-processors are the source and target calendars connected by the user (Google, Microsoft 365, CalDAV providers): access happens only on instruction, and the contractual relationship exists between the user and that provider.
Changes to this list are communicated to business customers in advance in accordance with the data processing agreement.
Permission model — delegated access only
For Microsoft 365 and Google Workspace, CalPair requests delegated permissions exclusively — access in the name of, and with the rights of, the signed-in user. No application-level or tenant-wide permissions are used.
- Microsoft Graph:
Calendars.ReadWrite,User.Read,offline_access(delegated). - Access only to calendars of users who have signed in and consented themselves.
- No access to other users' calendars; access ends on disconnection or revocation.
Agreements and data protection
- Privacy policy
- Legal notice
- Data processing agreement (DPA under Art. 28 GDPR): on request via the legal notice — CalPair acts as a processor towards business customers.
The linked Hetzner certificate is a mirrored copy of the original published by Hetzner; the current version held by Hetzner prevails.