iCal Feed Credential Management Policy

1. Purpose

This document describes the handling, storage, and security of third-party credentials used to generate iCal calendar feeds via the service. The system allows users to provide credentials for external services (e.g., Bakaláři) and receive a static, read-only iCal URL that can be used across devices.

The design balances usability (static device-independent links) with security and GDPR compliance.

2. Overview of the System

3. Data Minimization and Retention

4. Security Measures

5. GDPR & EU Compliance

6. Responsibilities

7. Limitations

8. Summary

Credentials are encrypted at rest using a mandatory AES key derived from a user secret. iCal URLs are static, read-only, and device-independent. Users retain control over revocation, and GDPR principles are followed: data minimization, encryption, and user rights enforcement.