Last updated: 12 August 2026 — this page is kept current.
1. Jurisdiction of the ICT infrastructure deployed (Art. 28(1)(a))
Zimun Labs UG (haftungsbeschränkt) is a company under German law established in Germany. The service runs on the Google Cloud Platform, region europe-west3 (Frankfurt am Main, Germany); the contracting party is Google Cloud EMEA Limited (Ireland). The infrastructure deployed is therefore subject to European Union law and to German and Irish law.
Stated openly rather than worded away: Google Cloud EMEA Limited belongs to a group with a US parent company (Google LLC), which is subject to US law including the CLOUD Act. A US disclosure order directed at the group therefore cannot be excluded as a matter of law. The measures below reduce that risk; they do not eliminate it.
2. Measures against international governmental access to non-personal data held in the Union (Art. 28(1)(b))
- Region pinning: storage and processing are fixed to the EU region Frankfurt; there is no replication to third-country regions.
- Encryption: transport exclusively over TLS; storage encrypted at rest.
- Access control: role-based, least-privilege permissions, service-account identities, logging of administrative access.
- Contractual safeguards: Google's Cloud Data Processing Addendum, including its commitments on handling governmental disclosure requests (review, redirecting the requesting authority to the customer, challenging unlawful requests, notification where legally permitted).
- Our own notification commitment: if Zimun itself receives a data access request from a third-country authority, Zimun informs the affected organisation before complying, unless the request serves law-enforcement purposes and informing would jeopardise their effectiveness (Art. 32(5) of Regulation (EU) 2023/2854; Section 12 (8) of the Terms).
- Legal framework: under Art. 32(1) of the Regulation, third-country governmental access to non-personal data held in the Union is permissible only on the basis of international agreements (such as mutual legal assistance treaties) or under the narrow conditions of Art. 32(3).
For personal data, the GDPR rules on third-country transfers apply in addition; they are described in the privacy policy (third-country transfers section). This page concerns the Data Act's separate subject matter: non-personal data.
3. Changes
If the infrastructure deployed, its region or its operator changes, this page is updated before the change takes effect; for sub-processors of personal data, the notification procedure of Section 6 (2) of the data processing agreement applies in addition.