Last updated: 2026-07-29
Agreement on the processing of personal data on behalf of a controller (Article 28 GDPR)
between
the organisation (party to the platform usage agreement for the Zimun platform) — hereinafter the “controller” —
and
Zimun Labs UG (haftungsbeschränkt), Buchenteich 3, 73773 Aichwald, Germany, commercial register B of the local court (Amtsgericht) of Stuttgart, HRB 806662, represented by its managing director Svetlana Ponomarenko — hereinafter the “processor” or “Zimun” —
Section 1 Subject matter and duration of the processing
(1) Zimun provides the controller with the Zimun scheduling platform (zimun.online) as software as a service (the “main agreement”, i.e. Zimun's Terms and Conditions together with the selected plan). Within the scope of the main agreement, Zimun processes personal data on behalf of the controller.
(2) The subject matter of this DPA is the processing of personal data entered into the platform by the controller or its end customers (Annex 1).
(3) The duration of this DPA corresponds to the term of the main agreement. Termination of the main agreement is at the same time termination of this DPA with effect from the same date. For data that is still stored after termination of the main agreement until its final deletion or return under Section 8, the obligations of this DPA continue to apply.
Section 2 Nature and purpose of the processing, categories of data, data subjects
The nature, purpose, categories of data and categories of data subjects are set out in Annex 1 (Description of the processing).
Section 3 Responsibility and instructions
(1) The controller is solely responsible for the lawfulness of the processing and for safeguarding the rights of data subjects (Article 4(7) GDPR).
(2) Zimun processes the data exclusively on documented instructions from the controller (Article 28(3)(a) GDPR). The controller's use and configuration of the platform features constitutes a documented instruction; supplementary individual instructions require text form.
(3) If Zimun is of the opinion that an instruction infringes the GDPR or other data protection provisions, Zimun informs the controller without undue delay (Article 28(3), second subparagraph, GDPR) and may suspend execution until the matter is clarified.
(4) Processing for Zimun's own purposes does not take place within the scope of this DPA. (Processing operations for which Zimun is itself the controller — platform operation, accounts, billing — are described in Zimun's privacy policy and are not the subject of this DPA.)
Section 4 Confidentiality
Zimun only engages persons who have committed themselves to confidentiality or who are under an appropriate statutory obligation of confidentiality (Article 28(3)(b) GDPR).
Section 5 Security of processing (Article 32 GDPR)
(1) Zimun implements the measures described in Annex 2 (Technical and organisational measures) and keeps them at the state of the art.
(2) Zimun may further develop the measures provided that the level of protection is not reduced.
Section 6 Sub-processors
(1) The controller grants general authorisation (Article 28(2) GDPR) for the use of the sub-processors listed in Annex 3.
(2) Zimun informs the controller of intended changes (addition or replacement) at least 30 days before they take effect, in text form (for example by email or in-app notification). The controller may object on important data protection grounds; in the event of an objection, both parties have a right of extraordinary termination of the main agreement with effect from the date on which the change takes effect.
(3) Zimun imposes on sub-processors, by contract, essentially the same data protection obligations as those set out in this DPA (Article 28(4) GDPR).
(4) Clarification — AI chat / OpenAI: The optional AI booking chat is operated exclusively with the controller's own OpenAI API key. OpenAI is therefore not a sub-processor of Zimun, but a direct processor of the controller. The controller concludes the required data processing agreement with OpenAI itself and is responsible for the legal basis, the third-country transfer and informing its end customers. In this respect, Zimun transmits chat content exclusively on instruction to the OpenAI endpoint designated by the controller.
Section 7 Assistance to the controller
(1) Zimun assists the controller by appropriate technical and organisational measures in fulfilling data subject rights (Articles 12–23 GDPR; Article 28(3)(e) GDPR), in particular through the platform's rectification and deletion functions and — where export functions are available — through those; otherwise Zimun makes the data in question available on request in a common, machine-readable format (see the data access provision of the Terms and Conditions).
(2) Zimun assists the controller with the obligations under Articles 32–36 GDPR (security, notification of breaches, data protection impact assessment, consultation), taking into account the nature of the processing and the information available to Zimun (Article 28(3)(f) GDPR).
(3) Zimun notifies the controller of personal data breaches affecting the controller's processed data without undue delay after becoming aware of them (Article 33(2) GDPR).
Section 8 Deletion and return
(1) After termination of the main agreement, Zimun deletes the data processed on behalf of the controller or returns it at the controller's choice, unless a statutory retention obligation prevents this (Article 28(3)(g) GDPR). Final deletion takes place — subject to an earlier deletion request by the controller — 30 days after termination of the main agreement; within that period the controller may retrieve its data or revoke the termination (see the Terms and Conditions, provision on deletion after the end of the contract).
(2) Irrespective of this, the platform's automated deletion routines apply during the term of the contract (in particular deletion/anonymisation of appointment data one month after the appointment, deletion of technical logs after 30 days).
Section 9 Evidence and audits
(1) Zimun makes available to the controller all information necessary to demonstrate compliance with the obligations under Article 28 GDPR (Article 28(3)(h) GDPR), as a rule by means of suitable documentation (for example a description of the technical and organisational measures, certifications/audit reports of the infrastructure providers, in particular Google Cloud).
(2) On-site inspections are permitted following prior notice with reasonable notice periods during usual business hours, insofar as the documentation is not sufficient in the individual case; trade secrets and other customers' data remain protected.
(3) The controller bears the costs of its own audits. For support services that go beyond providing existing documentation and the cooperation legally owed under Article 28(3)(h) GDPR, Zimun may charge reasonable remuneration based on time and effort; the controller's audit right is not thereby restricted or made conditional on advance payment.
Section 10 Third-country transfers
(1) Processing takes place in principle in the EU (Google Cloud region europe-west3, Frankfurt am Main).
(2) Insofar as sub-processors transfer data to third countries (Annex 3), this only takes place where an adequacy decision exists (Article 45 GDPR, for example the EU-U.S. Data Privacy Framework) or appropriate safeguards are in place (Article 46 GDPR, in particular the EU standard contractual clauses).
Section 11 Liability; final provisions
(1) Article 82 GDPR and the liability provisions of the main agreement apply to liability.
(2) Amendments and supplements to this DPA require text form. In the event of contradictions between this DPA and the main agreement, this DPA prevails in matters of data protection law.
(3) German law applies; the place of jurisdiction is determined by the main agreement.
Annex 1 — Description of the processing
- Subject matter: Provision and operation of the Zimun scheduling platform for the controller
- Nature of the processing: Collection via booking and administration interfaces, storage, display, transmission (notifications, calendar synchronisation, optional AI chat transport), automated deletion
- Purpose: Management of the controller's appointments, services, resources, team members and end-customer communication
- Categories of data: End customers: name, email address, telephone number, appointment data (service, resource, time), voluntary free-text entries, records of consent (for example acceptance of the Terms and Conditions, consent to SMS reminders including the time of consent); where applicable chat content (where the AI chat is enabled); waitlist entries. Team members: name, email address, account/profile data, working/availability hours, calendar metadata (where synchronisation is enabled)
- Special categories (Article 9): Not envisaged; the controller ensures that free-text fields are not systematically used for Article 9 data
- Data subjects: The controller's end customers; the controller's team members/employees
- Duration: Term of the main agreement; automated deletion periods pursuant to Section 8(2)
Annex 2 — Technical and organisational measures (outline)
To be completed with the specific, current measures before conclusion; the basis is the current state of the platform:
- 1. Physical access control: Operation in Google Cloud data centres (certified inter alia to ISO 27001); no self-operated servers; access to production systems only for authorised persons with multi-factor authentication.
- 2. System and data access control: Role-based and tenant-based permissions (organisation isolation), OAuth-based sign-in without password storage, dedicated service accounts with minimal privileges, secret management via Google Secret Manager.
- 3. Transmission control: TLS encryption (HTTPS) for all connections; encryption at rest (Google Cloud standard).
- 4. Input control: Logging of security-relevant operations (audit logs).
- 5. Instruction control: Selection of sub-processors in accordance with Article 28; data processing agreements with all sub-processors.
- 6. Availability control: Managed infrastructure (App Engine/Firestore), backups/redundancy of the infrastructure provider, monitoring.
- 7. Separation requirement: Logical tenant separation per organisation.
- 8. Deletion concept: Automated daily deletion run (contact data relating to appointments approximately 1 month after the appointment; technical logs 30 days), deletion on request.
Annex 3 — Approved sub-processors
-
Google Cloud EMEA Limited (Google Cloud Platform: App Engine, Firestore, Cloud Logging, Secret Manager)
- Service: Hosting, database, operation
- Place of processing: EU — region europe-west3 (Frankfurt am Main); support/incidental access by Google LLC (USA) possible
- Transfer mechanism: Google Cloud Data Processing Addendum; EU standard contractual clauses / EU-U.S. Data Privacy Framework
-
Mailgun Technologies, Inc. (Sinch group)
- Service: Transactional email delivery (tracking disabled)
- Place of processing: USA / EU sending region (for the configuration see the compliance checklist, open item)
- Transfer mechanism: Mailgun/Sinch DPA; EU standard contractual clauses or EU-U.S. Data Privacy Framework
-
Bird B.V. (formerly MessageBird), Amsterdam, Netherlands
- Service: Sending of SMS appointment reminders (only where the organisation has enabled the feature and with the end customer's consent; the telephone number and the message text are transmitted)
- Place of processing: Netherlands (EU); further processing locations
- Transfer mechanism: Conclusion of the Bird DPA and transfer mechanism for any third-country transfers
Not in Zimun's sub-processor chain: OpenAI (AI chat) — engaged directly by the controller with the controller's own API key (Section 6(4)). Google Ireland Limited and Microsoft Ireland Operations Limited act as independent controllers for the OAuth sign-in; Google Calendar/Google Meet are connected at the initiative of the respective member via that member's own Google account.