Last updated: 2026-07-29
1. Controller (Art. 4(7), Art. 13(1)(a) GDPR)
Zimun Labs UG (haftungsbeschränkt)
Buchenteich 3
73773 Aichwald
Germany
Phone: +49 176 63030716
Email: info@zimun.online
Commercial register: Handelsregister B of the Local Court of Stuttgart, HRB 806662
Managing Director: Svetlana Ponomarenko
No Data Protection Officer has been appointed, as the statutory thresholds of Section 38 BDSG (generally at least 20 persons constantly engaged in automated processing of personal data) are not met. Contact for privacy enquiries: Svetlana Ponomarenko, reachable at info@zimun.online or via the contact details above.
2. Roles: Zimun and the organisations
Zimun is an appointment-scheduling platform. Independent businesses and service providers ("organisations" or "Service Customers") use the platform to manage appointments with their end-customers. Under data-protection law, the roles are as follows:
- Zimun Labs UG (haftungsbeschränkt) as controller: for operating the platform, providing the website, user accounts, the technical booking process, and the related transactional communications.
- Each organisation as an independent controller: for delivering the booked service, its customer relationship, and processing it initiates (e.g. the optional AI chat, see Section 13).
- Zimun as the organisation's processor (Art. 28 GDPR): to the extent Zimun stores and manages customer, appointment, and staff data on the organisation's behalf. The data processing agreement required for this is concluded as part of the organisation's usage contract; the organisation may request it from Zimun in text form at any time.
There is no joint controllership within the meaning of Art. 26 GDPR.
3. Hosting and server logs
The platform is hosted on Google Cloud Platform (Google App Engine, Google Cloud Firestore database) in the EU region europe-west3 (Frankfurt am Main, Germany). When you access the Service, technical access data is processed automatically:
- IP address
- Date and time of access
- Browser type and version, operating system
- Referrer URL
- Transferred data volume and HTTP status codes
Purpose: technical provision, stability, abuse prevention, and IT security. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the secure operation of the platform). Technical logs are retained for 30 days.
4. Cookies and local storage (Section 25 TDDDG)
Access to information on your end device is governed by Section 25 of the German TDDDG (formerly TTDSG). Strictly necessary cookies fall under Section 25(2) no. 2 TDDDG (no consent required); the related data processing is based on Art. 6(1)(f) GDPR. All non-essential services (currently only web analytics, Section 5) are managed via our consent banner (Klaro) and used only with your consent (Section 25(1) TDDDG, Art. 6(1)(a) GDPR).
Strictly necessary cookies and storage used:
- user_session — login session of signed-in users (HttpOnly); lifetime: 7 days (sliding).
- manage_session — management session for appointment-management links; lifetime: 2 hours.
- csrf_token — protection against cross-site request forgery; lifetime: 7 days.
- ms_login_state and ms_login_next — securing the Microsoft sign-in process (protection against login tampering and return to the page you came from); set only during the Microsoft login (HttpOnly); lifetime: 10 minutes.
- lang — stores your language preference; lifetime: 1 year.
- klaro (local storage/cookie) — stores your consent choices from the consent banner.
You can change or withdraw your consent choices at any time via the "Manage consent" link in the website footer.
5. Web analytics: Google Analytics 4 (only with consent)
We use Google Analytics 4 (provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland) only if you have consented via the consent banner. Without consent, no analytics script is loaded and no analytics cookies (_ga, _gid, _gat) are set. IP anonymisation is enabled.
Legal basis: Art. 6(1)(a) GDPR and Section 25(1) TDDDG (consent). You may withdraw your consent at any time with effect for the future via the cookie settings. Within Google Analytics, data may be transferred to Google LLC in the USA; Google LLC is certified under the EU-U.S. Data Privacy Framework (adequacy decision pursuant to Art. 45 GDPR), supplemented by EU Standard Contractual Clauses (Art. 46(2)(c) GDPR). Analytics data is processed only while your consent is active.
6. Typefaces (locally hosted)
For a consistent display, this website uses typefaces (Geist, Geist Mono, Source Serif 4) that are hosted locally on our own servers. When a page is opened, the font files are delivered from our hosting (Google Cloud, Frankfurt region — see Section 3); no connection to Google Fonts servers (fonts.googleapis.com / fonts.gstatic.com) or any other third party takes place, and your IP address is not transmitted to any third party in this respect.
Legal basis for the associated processing (delivery of the files via our hosting): Art. 6(1)(f) GDPR (legitimate interest in a uniform and technically reliable presentation of the website).
7. Appointment booking
When you book an appointment with an organisation, we process:
- Name
- Email address
- Phone number — on the public booking page only where the organisation offers SMS reminders and you have consented to receiving them (Section 8); without that consent, a phone number entered there is not stored. Where the organisation enters an appointment for you (see below), it may record your phone number for queries and appointment-related contact.
- Selected service/resource and appointment time
- Optional additional information entered in the booking form
Purpose: conclusion, management, and handling of the appointment, including transmission of the booking data to the selected organisation. Legal basis: Art. 6(1)(b) GDPR (carrying out the booking you requested and pre-contractual steps vis-à-vis the organisation); otherwise Art. 6(1)(f) GDPR (legitimate interest in operating the booking platform). Please do not enter special categories of personal data (Art. 9 GDPR, e.g. health data) in free-text fields unless necessary for the appointment.
Data not obtained from you (Art. 14 GDPR): Appointments may also be entered for you by the organisation (e.g. when arranged by phone or in person). In that case, we receive the data categories listed above from the organisation rather than from you; the information in this Privacy Policy applies accordingly. The same applies to waiting-list entries (name, contact details, requested time frame) as to appointment data.
Contact data is stored separately from the remaining appointment data: the general appointment record (time, service, resource, status) contains no contact data; name, email address, and phone number are held solely in a separate, specially protected record. That separate record is deleted by an automated daily deletion run one (1) month after the appointment; the remaining appointment data then no longer relates to you personally. Retention details: Section 17.
8. Transactional notifications: emails (Mailgun) and SMS reminders (Bird)
By email, the Service sends only transactional, appointment-related messages (confirmations, reminders, changes, cancellations, required follow-ups) and account-related notices. No marketing emails are sent without explicit consent. Legal basis: Art. 6(1)(b) GDPR.
Email delivery is handled by the processor Mailgun (Mailgun Technologies, Inc., part of the Sinch group, USA) under a data processing agreement. Open and click tracking is disabled on every message sent; outgoing emails contain no tracking pixels. Where personal data is transferred to the USA in this context, this is based on the EU Standard Contractual Clauses (Art. 46(2)(c) GDPR) and/or the EU-U.S. Data Privacy Framework.
SMS reminders (only with your consent): Where the respective organisation has enabled SMS reminders, you may consent during booking to receiving an appointment reminder by SMS and provide your phone number for this purpose. In that case, the Service sends a reminder SMS approximately 24 hours before the appointment; the data transmitted is your phone number and the message text (name of the organisation, booked service, appointment time). Without your consent, no reminder SMS is sent and a phone number entered on the booking page is not stored. Legal basis: your consent (Art. 6(1)(a) GDPR); you may withdraw it at any time with effect for the future, e.g. by notifying the organisation or info@zimun.online. The phone number and the consent record are deleted together with the other contact data one (1) month after the appointment (Section 17).
SMS delivery is handled by the provider Bird (Bird B.V., Amsterdam, Netherlands — formerly MessageBird) as a processor. SMS reminders are not currently activated; before activation, the processing locations and any third-country element will be added to this Privacy Policy.
9. User accounts and OAuth login (Google, Microsoft)
Members of organisations sign in via Google OAuth or Microsoft OAuth. From the respective provider we receive: email address, name/display name, provider-specific user ID, and, where applicable, a profile picture. We do not store passwords. For authentication, Google (Google Ireland Limited) and Microsoft (Microsoft Ireland Operations Limited) act as independent controllers; their privacy policies apply. Legal basis: Art. 6(1)(b) GDPR (provision of the account).
10. Calendar synchronisation (Google Calendar)
Members of an organisation can connect their Google Calendar via OAuth so that appointments are synchronised and availability is taken into account. Calendar and appointment metadata of the connected account is processed to the extent necessary for synchronisation. The connection is initiated by the member or organisation; legal basis vis-à-vis Zimun: Art. 6(1)(b) GDPR. The connection can be revoked at any time in the settings or in the Google account.
11. Video appointments (Google Meet)
Where an organisation has enabled video appointments, Google Meet links are created via the connected Google account of the respective member ("member-owned"). The video meeting itself takes place at Google; Google's privacy policies apply. Zimun merely stores the meeting link as part of the appointment.
12. Payment processing (planned: Stripe)
Currently, no online payment processing takes place via the platform. Integration of the payment provider Stripe (Stripe Payments Europe, Ltd., Ireland) is planned. Before payments go live, we will update this Privacy Policy with the applicable information (data categories, roles, legal bases, third-country transfers).
13. Organisations' AI chat (OpenAI via the organisation's own API key)
Organisations may optionally enable an AI-assisted booking chat. Important to know:
- The chat uses OpenAI's services exclusively via the respective organisation's own OpenAI API key. Zimun does not provide its own OpenAI keys.
- Under data-protection law, the organisation is therefore the controller for the chat processing; OpenAI is the organisation's (sub-)processor — not Zimun's. The organisation concludes the required data processing agreement with OpenAI itself and is responsible for the legal basis and any third-country transfer (typically EU Standard Contractual Clauses or the Data Privacy Framework with OpenAI).
- In this respect, Zimun forwards the chat content technically as the organisation's processor.
- Data that may reach OpenAI includes the free text you enter in the chat and booking-related context data (e.g. name, requested service, appointment times). Please do not enter sensitive data in the chat that is not required for booking the appointment.
14. Sharing with the organisation
To handle the appointment, we transmit to the organisation you selected: name, email address, phone number (if provided), selected service/resource, appointment time, and your optional additional information. The organisation processes this data as an independent controller for the delivery of the service.
15. Recipients and processors (Art. 13(1)(e) GDPR)
We use the following service providers:
- Google Cloud (hosting/database): Google Cloud EMEA Limited, Dublin, Ireland — processor; data processing in EU region europe-west3 (Frankfurt); data processing agreement (Google Cloud Data Processing Addendum); for any transfers to Google LLC (USA): EU Standard Contractual Clauses / EU-U.S. Data Privacy Framework.
- Mailgun (transactional email delivery): Mailgun Technologies, Inc. (Sinch group), USA — processor; see Section 8.
- Bird (SMS appointment reminders): Bird B.V., Amsterdam, Netherlands (formerly MessageBird) — processor; sending only with your consent; see Section 8.
- Google Ireland Limited: OAuth login, Google Calendar, Google Meet, Google Analytics — depending on the service, independent controller (login) or processor (analytics); see Sections 5, 9–11.
- Microsoft Ireland Operations Limited: OAuth login — independent controller; see Section 9.
- OpenAI: exclusively as the respective organisation's processor via the organisation's own API key — not a processor of Zimun; see Section 13.
- Authorities and other third parties: only where legally required (Art. 6(1)(c) GDPR).
Data is not sold or shared for advertising purposes.
16. Third-country transfers (Art. 44 et seq. GDPR)
Platform data is stored in the EU (Frankfurt am Main). Where, in individual cases, data is transferred to providers based in the USA (Google LLC, Mailgun/Sinch, and — within the organisation's area of responsibility — OpenAI), this is based on an adequacy decision (EU-U.S. Data Privacy Framework, Art. 45 GDPR) and/or the EU Standard Contractual Clauses (Art. 46(2)(c) GDPR). For SMS delivery via Bird (Section 8) — a provider based in the Netherlands (EU) — the question of any third-country transfers has not yet been conclusively verified.
17. Retention periods (Art. 13(2)(a) GDPR)
- Technical logs: 30 days.
- Appointment contact data (name, email, phone, consent records): 1 month after the appointment, then automatic deletion of the separate record.
- Remaining appointment data (time, service, resource, status — no contact data): until the organisation is deleted.
- Recurring appointments: the contact data stored in the series configuration (name, email, phone) is removed by the automated deletion run one (1) month after the series is cancelled; the contact data of the individual appointments of the series is subject to the above period of one (1) month after the respective appointment.
- User account data: until the account is deleted; after the contract ends, final deletion takes place after 30 days (the deletion may be revoked within this period).
- Analytics data: only while your consent is active.
- Billing and invoice data: Once paid plans are used, we retain invoices and accounting records in accordance with German commercial and tax retention obligations (Section 147 AO, Section 257 HGB: currently 8 years for accounting records, 10 years for commercial books/annual accounts). Legal basis: Art. 6(1)(c) GDPR.
18. Your rights (Art. 15–21, Art. 7(3), Art. 77 GDPR)
Vis-à-vis the respective controller, you have the right to:
- Access (Art. 15 GDPR),
- Rectification (Art. 16 GDPR),
- Erasure (Art. 17 GDPR),
- Restriction of processing (Art. 18 GDPR),
- Data portability (Art. 20 GDPR),
- Withdrawal of consent with effect for the future (Art. 7(3) GDPR).
Right to object (Art. 21 GDPR): Where we process data on the basis of Art. 6(1)(f) GDPR, you have the right to object to the processing at any time on grounds relating to your particular situation.
For processing for which the organisation is the controller (service delivery, AI chat), please address your request to the respective organisation; as its processor, we support the organisation in responding.
Right to lodge a complaint (Art. 77 GDPR): You have the right to complain to a data-protection supervisory authority. The authority competent for us is the State Commissioner for Data Protection and Freedom of Information of Baden-Württemberg (LfDI Baden-Württemberg), Stuttgart, www.baden-wuerttemberg.datenschutz.de. You may also contact the supervisory authority of your habitual residence.
19. Obligation to provide data (Art. 13(2)(e) GDPR)
You are neither legally nor contractually obliged to provide your data. However, without the information required for booking (name, email address, appointment time), an appointment cannot be booked or managed.
20. No automated decision-making (Art. 22 GDPR)
No automated decision-making, including profiling, within the meaning of Art. 22 GDPR takes place. The organisations' optional AI chat serves solely as a booking assistant and makes no decisions with legal or similarly significant effect.
21. Security (Art. 32 GDPR)
We implement technical and organisational measures pursuant to Art. 32 GDPR, including: TLS encryption (HTTPS), encryption at rest (Google Cloud), access controls, role-based permissions, monitoring and audit logs, and automated deletion policies.
22. Changes to this Privacy Policy
We update this Privacy Policy when the processing operations, the services used, or the legal situation change. The version published on this page applies; the effective date is stated above.
The German version of this Privacy Policy is authoritative; versions in other languages are non-binding convenience translations.