Privacy Policy Version dated: 29 August 2026 1. Controller The controller within the meaning of the General Data Protection Regulation (GDPR) and other national data protection laws of the Member States, as well as other data protection provisions, is: JDu Apps Sole proprietor: Julian Dubbert Eilenau 11 22087 Hamburg Germany Email: privacy@copy-for-trello.com Website: copy-for-trello.com 2. General information on data processing We process our users’ personal data only to the extent necessary to provide a functional website and our content and services. As a rule, we process our users’ personal data only with the user’s consent. An exception applies in cases where obtaining consent in advance is impossible for factual reasons and processing is permitted by law. 3. Data processing in connection with our migration service 3.1 Scope of data processing We provide a service for the automated migration of data from project management and collaboration platforms (in particular Trello®). In the course of this service, the following categories of data are processed: • Boards/projects and their structural data • Lists and comparable structural elements • Cards/tasks with titles and descriptions • Labels and tags • Checklists • Comments and activities • Due dates and status information • Attachments, files and images • User assignments and mentions • Links and references • Other data supported by the respective platform The actual scope of data processed depends on the technical capabilities of the respective platform, its API interface, the permissions granted and the specific configuration chosen by the customer. 3.2 Legal bases for processing Data transferred in the course of a migration is processed on the following legal bases: Art. 6(1)(b) GDPR (pre-contractual measures and performance of a contract): Processing is necessary for the performance of the migration contract concluded between the customer and us. Art. 6(1)(f) GDPR (legitimate interests): Where necessary, we process data to safeguard our legitimate interests in the technical provision of the service, troubleshooting, ensuring IT security and improving our services. 3.3 Data sources Data is retrieved directly from the respective third-party platforms (e.g. Trello®) via the API interfaces provided there. The customer grants the necessary permissions for this purpose (e.g. via OAuth or API tokens). We do not obtain knowledge of customers’ passwords on third-party platforms. 3.4 Retention period Data processed in the course of a migration is stored only for as long as is necessary to perform the migration. Temporary storage: To perform a migration, customer data may be stored temporarily on our systems (e.g. for processing, interim storage of attachments, error handling or logging). Deletion: After a migration is completed or cancelled, temporarily stored data is generally deleted within 14 days, unless statutory retention obligations or other legitimate grounds prevent this. Backups: Data may remain in technical backup copies for a limited period. Deletion from backup copies takes place as part of regular technical deletion cycles. Contract data: Contract and invoice data is stored beyond the end of the contract on the basis of statutory provisions (e.g. tax and commercial law retention periods). 4. Recipients and transfer of data 4.1 Recipients of data In the course of our business activities, we work with various service providers whom we engage as processors to deliver our services. Recipients of data may in particular include: • Hosting and cloud providers: To provide the technical infrastructure and store data • Payment service providers: To process payments (e.g. Stripe) • Email service providers: To send emails • Database providers: To store and manage data • Monitoring and security service providers: To monitor and secure the service • Third-party platforms: The respective platform providers (e.g. Trello®) whose APIs we use to perform migrations A complete list of current processors can be requested from us. 4.2 Transfers to third countries Personal data is transferred to third countries (outside the European Union / European Economic Area) only where this is necessary to perform the migration (e.g. where third-party platforms have servers in the USA) and appropriate data protection safeguards exist. Where third-party platforms are established in a third country, data is transferred only if the European Commission has determined an adequate level of protection for that country or appropriate safeguards exist (e.g. the European Commission’s standard contractual clauses). 4.3 Processing on behalf of the controller We have concluded data processing agreements pursuant to Art. 28 GDPR with all our processors, ensuring that data is processed only on our behalf and in accordance with our instructions and that data protection requirements are observed. 5. Data processing when initiating and performing contracts 5.1 Contact When you contact us by email or contact form, we store the data you provide (e.g. name, email address, telephone number where applicable) in order to handle your enquiry. The legal bases for this are Art. 6(1)(b) GDPR (pre-contractual measures) and Art. 6(1)(f) GDPR (legitimate interest in handling enquiries). 5.2 Ordering process and payment processing In the ordering process, the following data is processed: • Contact details (name, email address) • Order and contract data (selected services, configurations) • Payment data (via the payment service provider Stripe) Payment processing is handled via the payment service provider Stripe. Stripe’s privacy policy applies to payment processing. We do not obtain knowledge of complete credit card information. The legal basis is Art. 6(1)(b) GDPR (performance of a contract). 6. Cookies and tracking 6.1 Use of cookies We use technically necessary cookies on our website to enable use of the website and to provide certain functions. These cookies are required for the website to operate (e.g. session cookies for authentication). Technically necessary cookies are set on the basis of Art. 6(1)(f) GDPR (legitimate interest in the technical provision of the website). Users can prevent the storage of cookies through appropriate browser settings; however, we point out that in this case not all functions of our website may be fully available. 6.2 Server log files Our web host automatically collects and stores information in so-called server log files that your browser transmits to us. These are: • Browser type and version • Operating system used • Referrer URL • Host name of the accessing computer • Time of the server request This data is processed for statistical purposes and to ensure the technical operation of the website. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in technical security and statistical analysis). 7. Your rights as a data subject As a data subject, you have the following rights under the GDPR: 7.1 Right of access (Art. 15 GDPR) You may request confirmation from us as to whether personal data concerning you is being processed by us. If this is the case, you have the right to access such data and to further information specified in Art. 15 GDPR. 7.2 Right to rectification (Art. 16 GDPR) You have the right to obtain without undue delay the rectification of inaccurate personal data concerning you. You also have the right to have incomplete personal data completed, taking into account the purposes of processing. 7.3 Right to erasure (Art. 17 GDPR) You may request that personal data concerning you be erased without undue delay where one of the grounds listed in Art. 17(1) GDPR applies (e.g. the data is no longer necessary for the purposes for which it was collected). 7.4 Right to restriction of processing (Art. 18 GDPR) You have the right to obtain restriction of processing of personal data concerning you where one of the conditions set out in Art. 18(1) GDPR is met. 7.5 Right to data portability (Art. 20 GDPR) You have the right to receive the personal data concerning you that you have provided to us in a structured, commonly used and machine-readable format. You also have the right to transmit those data to another controller without hindrance from us. 7.6 Right to withdraw consent (Art. 7(3) GDPR) You have the right to withdraw your consent to data processing at any time with effect for the future. Withdrawal may be sent to the contact address given above. 7.7 Right to lodge a complaint with a supervisory authority (Art. 77 GDPR) Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work or place of the alleged infringement, if you consider that the processing of personal data concerning you infringes the GDPR. 8. SSL/TLS encryption For security reasons and to protect the transmission of confidential content, this site uses SSL/TLS encryption. You can recognise an encrypted connection by the fact that the browser address bar changes from “http://” to “https://” and by the lock symbol in your browser bar. When SSL/TLS encryption is active, data you transmit to us cannot be read by third parties. 9. Data protection officer We have not appointed a data protection officer. For questions about data protection, please contact us directly. Alternatively, you may contact the competent supervisory authority directly: The Hamburg Commissioner for Data Protection and Freedom of Information Ludwig-Erhard-Str. 22, 7th floor 20459 Hamburg Germany Phone: +49 40 428 54 4040 Email: mailbox@datenschutz.hamburg.de Website: www.datenschutz-hamburg.de 10. Updates and changes to this Privacy Policy We reserve the right to adapt this Privacy Policy from time to time in order to reflect changed legal requirements or changes to our service and data processing. The current version published on our website applies to you. By continuing to use our website, you agree to the updated Privacy Policy. We recommend reviewing this Privacy Policy regularly. 11. Note on joint responsibility with third-party platforms Where we use APIs of third-party platforms (e.g. Trello®), joint responsibility within the meaning of Art. 26 GDPR may exist between us and the respective platform provider. Details of joint responsibility and the allocation of obligations can be found in the privacy policies of the respective third-party platforms. We process data exclusively on our behalf and in accordance with our customers’ instructions.