Privacy Policy
This Privacy Policy explains how personal data is processed when you use Copy for Trello® by JDu Apps.
Privacy Policy
Version dated: 29 August 2026
1. Controller
The controller within the meaning of the General Data Protection Regulation
(GDPR) and other national data protection laws of the Member States, as well as
other data protection provisions, is:
JDu Apps
Sole proprietor: Julian Dubbert
Eilenau 11
22087 Hamburg
Germany
Email: privacy@copy-for-trello.com
Website: copy-for-trello.com
2. General information on data processing
We process our users’ personal data only to the extent necessary to provide a
functional website and our content and services. As a rule, we process our
users’ personal data only with the user’s consent. An exception applies in
cases where obtaining consent in advance is impossible for factual reasons and
processing is permitted by law.
3. Data processing in connection with our migration service
3.1 Scope of data processing
We provide a service for the automated migration of data from project management
and collaboration platforms (in particular Trello®). In the course of this
service, the following categories of data are processed:
• Boards/projects and their structural data
• Lists and comparable structural elements
• Cards/tasks with titles and descriptions
• Labels and tags
• Checklists
• Comments and activities
• Due dates and status information
• Attachments, files and images
• User assignments and mentions
• Links and references
• Other data supported by the respective platform
The actual scope of data processed depends on the technical capabilities of the
respective platform, its API interface, the permissions granted and the specific
configuration chosen by the customer.
3.2 Legal bases for processing
Data transferred in the course of a migration is processed on the following
legal bases:
Art. 6(1)(b) GDPR (pre-contractual measures and performance of a contract):
Processing is necessary for the performance of the migration contract concluded
between the customer and us.
Art. 6(1)(f) GDPR (legitimate interests): Where necessary, we process data to
safeguard our legitimate interests in the technical provision of the service,
troubleshooting, ensuring IT security and improving our services.
3.3 Data sources
Data is retrieved directly from the respective third-party platforms (e.g.
Trello®) via the API interfaces provided there. The customer grants the
necessary permissions for this purpose (e.g. via OAuth or API tokens). We do
not obtain knowledge of customers’ passwords on third-party platforms.
3.4 Retention period
Data processed in the course of a migration is stored only for as long as is
necessary to perform the migration.
Temporary storage: To perform a migration, customer data may be stored
temporarily on our systems (e.g. for processing, interim storage of
attachments, error handling or logging).
Deletion: After a migration is completed or cancelled, temporarily stored data
is generally deleted within 14 days, unless statutory retention obligations or
other legitimate grounds prevent this.
Backups: Data may remain in technical backup copies for a limited period.
Deletion from backup copies takes place as part of regular technical deletion
cycles.
Contract data: Contract and invoice data is stored beyond the end of the
contract on the basis of statutory provisions (e.g. tax and commercial law
retention periods).
4. Recipients and transfer of data
4.1 Recipients of data
In the course of our business activities, we work with various service
providers whom we engage as processors to deliver our services. Recipients of
data may in particular include:
• Hosting and cloud providers: To provide the technical infrastructure and
store data
• Payment service providers: To process payments (e.g. Stripe)
• Email service providers: To send emails
• Database providers: To store and manage data
• Monitoring and security service providers: To monitor and secure the service
• Third-party platforms: The respective platform providers (e.g. Trello®)
whose APIs we use to perform migrations
A complete list of current processors can be requested from us.
4.2 Transfers to third countries
Personal data is transferred to third countries (outside the European Union /
European Economic Area) only where this is necessary to perform the migration
(e.g. where third-party platforms have servers in the USA) and appropriate data
protection safeguards exist.
Where third-party platforms are established in a third country, data is
transferred only if the European Commission has determined an adequate level of
protection for that country or appropriate safeguards exist (e.g. the European
Commission’s standard contractual clauses).
4.3 Processing on behalf of the controller
We have concluded data processing agreements pursuant to Art. 28 GDPR with all
our processors, ensuring that data is processed only on our behalf and in
accordance with our instructions and that data protection requirements are
observed.
5. Data processing when initiating and performing contracts
5.1 Contact
When you contact us by email or contact form, we store the data you provide
(e.g. name, email address, telephone number where applicable) in order to handle
your enquiry. The legal bases for this are Art. 6(1)(b) GDPR (pre-contractual
measures) and Art. 6(1)(f) GDPR (legitimate interest in handling enquiries).
5.2 Ordering process and payment processing
In the ordering process, the following data is processed:
• Contact details (name, email address)
• Order and contract data (selected services, configurations)
• Payment data (via the payment service provider Stripe)
Payment processing is handled via the payment service provider Stripe. Stripe’s
privacy policy applies to payment processing. We do not obtain knowledge of
complete credit card information. The legal basis is Art. 6(1)(b) GDPR
(performance of a contract).
6. Cookies and tracking
6.1 Use of cookies
We use technically necessary cookies on our website to enable use of the website
and to provide certain functions. These cookies are required for the website to
operate (e.g. session cookies for authentication).
Technically necessary cookies are set on the basis of Art. 6(1)(f) GDPR
(legitimate interest in the technical provision of the website). Users can
prevent the storage of cookies through appropriate browser settings; however, we
point out that in this case not all functions of our website may be fully
available.
6.2 Server log files
Our web host automatically collects and stores information in so-called server
log files that your browser transmits to us. These are:
• Browser type and version
• Operating system used
• Referrer URL
• Host name of the accessing computer
• Time of the server request
This data is processed for statistical purposes and to ensure the technical
operation of the website. The legal basis is Art. 6(1)(f) GDPR (legitimate
interest in technical security and statistical analysis).
7. Your rights as a data subject
As a data subject, you have the following rights under the GDPR:
7.1 Right of access (Art. 15 GDPR)
You may request confirmation from us as to whether personal data concerning you
is being processed by us. If this is the case, you have the right to access
such data and to further information specified in Art. 15 GDPR.
7.2 Right to rectification (Art. 16 GDPR)
You have the right to obtain without undue delay the rectification of inaccurate
personal data concerning you. You also have the right to have incomplete
personal data completed, taking into account the purposes of processing.
7.3 Right to erasure (Art. 17 GDPR)
You may request that personal data concerning you be erased without undue delay
where one of the grounds listed in Art. 17(1) GDPR applies (e.g. the data is
no longer necessary for the purposes for which it was collected).
7.4 Right to restriction of processing (Art. 18 GDPR)
You have the right to obtain restriction of processing of personal data
concerning you where one of the conditions set out in Art. 18(1) GDPR is met.
7.5 Right to data portability (Art. 20 GDPR)
You have the right to receive the personal data concerning you that you have
provided to us in a structured, commonly used and machine-readable format. You
also have the right to transmit those data to another controller without
hindrance from us.
7.6 Right to withdraw consent (Art. 7(3) GDPR)
You have the right to withdraw your consent to data processing at any time with
effect for the future. Withdrawal may be sent to the contact address given
above.
7.7 Right to lodge a complaint with a supervisory authority (Art. 77 GDPR)
Without prejudice to any other administrative or judicial remedy, you have the
right to lodge a complaint with a supervisory authority, in particular in the
Member State of your habitual residence, place of work or place of the alleged
infringement, if you consider that the processing of personal data concerning
you infringes the GDPR.
8. SSL/TLS encryption
For security reasons and to protect the transmission of confidential content,
this site uses SSL/TLS encryption. You can recognise an encrypted connection
by the fact that the browser address bar changes from “http://” to “https://”
and by the lock symbol in your browser bar.
When SSL/TLS encryption is active, data you transmit to us cannot be read by
third parties.
9. Data protection officer
We have not appointed a data protection officer. For questions about data
protection, please contact us directly.
Alternatively, you may contact the competent supervisory authority directly:
The Hamburg Commissioner for Data Protection and Freedom of Information
Ludwig-Erhard-Str. 22, 7th floor
20459 Hamburg
Germany
Phone: +49 40 428 54 4040
Email: mailbox@datenschutz.hamburg.de
Website: www.datenschutz-hamburg.de
10. Updates and changes to this Privacy Policy
We reserve the right to adapt this Privacy Policy from time to time in order to
reflect changed legal requirements or changes to our service and data
processing. The current version published on our website applies to you.
By continuing to use our website, you agree to the updated Privacy Policy. We
recommend reviewing this Privacy Policy regularly.
11. Note on joint responsibility with third-party platforms
Where we use APIs of third-party platforms (e.g. Trello®), joint responsibility
within the meaning of Art. 26 GDPR may exist between us and the respective
platform provider. Details of joint responsibility and the allocation of
obligations can be found in the privacy policies of the respective third-party
platforms. We process data exclusively on our behalf and in accordance with our
customers’ instructions.
Download
You can download the Privacy Policy as a text file.