Last updated: 2026-08-04
1. Controller (Art. 4(7), Art. 13(1)(a) GDPR)
Zimun Labs UG (haftungsbeschränkt)
Buchenteich 3
73773 Aichwald
Germany
Phone: +49 176 63030716
Email: info@zimun.online
Commercial register: Handelsregister B of the Local Court of Stuttgart, HRB 806662
Managing Director: Svetlana Ponomarenko
No Data Protection Officer has been appointed, as the statutory thresholds of Section 38 BDSG (generally at least 20 persons constantly engaged in automated processing of personal data) are not met. Contact for privacy enquiries: Svetlana Ponomarenko, reachable at info@zimun.online or via the contact details above.
2. Roles: Zimun and the organisations
Zimun is an appointment-scheduling platform. Independent businesses and service providers ("organisations" or "Service Customers") use the platform to manage appointments with their end-customers. Under data-protection law, the roles are as follows:
- Zimun Labs UG (haftungsbeschränkt) as controller: for operating the platform, providing the website, user accounts, the technical booking process, and the related transactional communications.
- Each organisation as an independent controller: for delivering the booked service, its customer relationship, and processing it initiates (e.g. the optional AI chat, see Section 13).
- Zimun as the organisation's processor (Art. 28 GDPR): to the extent Zimun stores and manages customer, appointment, and staff data on the organisation's behalf. The data processing agreement required for this is concluded as part of the organisation's usage contract; the organisation may request it from Zimun in text form at any time.
There is no joint controllership within the meaning of Art. 26 GDPR.
3. Hosting and server logs
The platform is hosted on Google Cloud Platform (Google App Engine, Google Cloud Firestore database) in the EU region europe-west3 (Frankfurt am Main, Germany). When you access the Service, technical access data is processed automatically:
- IP address
- Date and time of access
- Browser type and version, operating system
- Referrer URL
- Transferred data volume and HTTP status codes
Purpose: technical provision, stability, abuse prevention, and IT security. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the secure operation of the platform). Technical logs are retained for 30 days.
4. Cookies and local storage (Section 25 TDDDG)
Access to information on your end device is governed by Section 25 of the German TDDDG (formerly TTDSG). Strictly necessary cookies fall under Section 25(2) no. 2 TDDDG (no consent required); the related data processing is based on Art. 6(1)(f) GDPR. All non-essential services (currently only web analytics, Section 5) are managed via our consent banner (Klaro) and used only with your consent (Section 25(1) TDDDG, Art. 6(1)(a) GDPR).
Strictly necessary cookies and storage used:
- user_session — login session of signed-in users (HttpOnly); lifetime: 7 days (sliding).
- manage_session — management session for appointment-management links; lifetime: 2 hours.
- csrf_token — protection against cross-site request forgery; lifetime: 7 days.
- ms_oauth_state and ms_login_next — securing the Microsoft sign-in process (protection against login tampering and return to the page you came from); set only during the Microsoft login (HttpOnly); lifetime: 10 minutes.
- g_state — set by Google's sign-in service when the login page is opened (state of the Google sign-in dialog, see Section 9); lifetime: 6 months.
- lang — stores your language preference; lifetime: 1 year.
- klaro (cookie) — stores your consent choices from the consent banner; lifetime: 120 days.
- zimun.mapsConsent (session storage, only on the settings pages for the organisation and its locations) — stores your decision to load the Google map, so that configuring several locations does not require clicking again on every page; lifetime: until the end of the browser session.
You can change or withdraw your consent choices at any time via the "Manage consent" link in the website footer.
5. Web analytics: Google Analytics 4 (only with consent)
We use Google Analytics 4 (provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland) only if you have consented via the consent banner. Without consent, no analytics script is loaded and no analytics cookies (_ga, _ga_*) are set. IP anonymisation is enabled.
Legal basis: Art. 6(1)(a) GDPR and Section 25(1) TDDDG (consent). You may withdraw your consent at any time with effect for the future via the cookie settings. Within Google Analytics, data may be transferred to Google LLC in the USA; Google LLC is certified under the EU-U.S. Data Privacy Framework (adequacy decision pursuant to Art. 45 GDPR), supplemented by EU Standard Contractual Clauses (Art. 46(2)(c) GDPR). After a withdrawal, no further analytics data is collected; event data already collected is deleted by Google at the end of the configured retention period, and in any event no later than 14 months after collection.
6. Typefaces and other embedded content (locally hosted)
For a consistent display, this website uses typefaces (Geist, Geist Mono, Source Serif 4) that are hosted locally on our own servers. When a page is opened, the font files are delivered from our hosting (Google Cloud, Frankfurt region — see Section 3); no connection to Google Fonts servers (fonts.googleapis.com / fonts.gstatic.com) takes place.
The same applies to the other files your browser needs in order to display our pages — scripts, stylesheets and images. They are delivered exclusively from our hosting; we embed no third-party content delivery networks (CDNs). Simply opening our pages, and in particular the public booking pages, therefore transmits your IP address to no third party. The sole exception is the sign-in page, which loads the respective provider's sign-in script — see below and Section 9.
There are two exceptions, both of which require an action on your part and therefore do not occur when a page is merely opened:
- Maps (Google Maps): maps and the address search on the settings pages for organisations and locations are loaded only after an explicit click. Until then nothing is transmitted to Google; the button states that loading will transmit the IP address to Google. See Section 15 for details.
- Web analytics (Google Analytics 4): loaded only after your consent — see Section 5.
For the sign-in process itself, the sign-in script of the respective provider (Google or Microsoft) is additionally loaded when you open our sign-in page; this is a technical precondition of the sign-in method you chose (Section 9).
Legal basis for the associated processing (delivery of the files via our hosting): Art. 6(1)(f) GDPR (legitimate interest in a uniform and technically reliable presentation of the website).
7. Appointment booking
When you book an appointment with an organisation, we process:
- Name
- Email address
- Phone number — on the public booking page only where the organisation offers SMS reminders and you have consented to receiving them (Section 8); without that consent, a phone number entered there is not stored. Where the organisation enters an appointment for you (see below), it may record your phone number for queries and appointment-related contact.
- Selected service/resource and appointment time
- Optional additional information entered in the booking form
Purpose: conclusion, management, and handling of the appointment, including transmission of the booking data to the selected organisation. Legal basis: Art. 6(1)(b) GDPR (carrying out the booking you requested and pre-contractual steps vis-à-vis the organisation); otherwise Art. 6(1)(f) GDPR (legitimate interest in operating the booking platform). Please do not enter special categories of personal data (Art. 9 GDPR, e.g. health data) in free-text fields unless necessary for the appointment.
Data not obtained from you (Art. 14 GDPR): Appointments may also be entered for you by the organisation (e.g. when arranged by phone or in person). In that case, we receive the data categories listed above from the organisation rather than from you; the information in this Privacy Policy applies accordingly. Waiting-list entries (name, contact details, requested time frame) are deleted 30 days after the entry is settled, and in any case no later than 12 months after receipt.
Minors: The platform is not directed at children. Appointments for minors may be booked by their parents or guardians; under the Terms and Conditions, organisation and member accounts require the holder to be of legal age.
Contact data is stored separately from the remaining appointment data: the general appointment record (time, service, resource, status) contains no contact data; name, email address, and phone number are held solely in a separate, specially protected record. That separate record is deleted by an automated daily deletion run one (1) month after the appointment; the remaining appointment data then no longer relates to you personally. Retention details: Section 17.
8. Transactional notifications: emails (Mailgun) and SMS reminders (Bird)
By email, the Service sends only transactional, appointment-related messages (confirmations, reminders, changes, cancellations, required follow-ups) and account-related notices. No marketing emails are sent without explicit consent. Legal basis: Art. 6(1)(b) GDPR.
Email delivery is handled by the processor Mailgun (Mailgun Technologies, Inc., part of the Sinch group) under a data processing agreement. We use Mailgun's EU region exclusively, so messages are processed and stored within the European Union. As the provider is US-incorporated, access from a third country (for example during support) cannot be entirely excluded; the safeguards named in Section 16 apply to it. Open and click tracking is disabled on every message sent; outgoing emails contain no tracking pixels. Where personal data is transferred to the USA in this context, this is based on the EU Standard Contractual Clauses (Art. 46(2)(c) GDPR) and/or the EU-U.S. Data Privacy Framework.
SMS reminders (only with your consent): Where the respective organisation has enabled SMS reminders, you may consent during booking to receiving an appointment reminder by SMS and provide your phone number for this purpose. In that case, the Service sends a reminder SMS approximately 24 hours before the appointment; the data transmitted is your phone number and the message text (name of the organisation, booked service, appointment time). Without your consent, no reminder SMS is sent and a phone number entered on the booking page is not stored. Legal basis: your consent (Art. 6(1)(a) GDPR); you may withdraw it at any time with effect for the future, e.g. by notifying the organisation or info@zimun.online. The phone number and the consent record are deleted together with the other contact data one (1) month after the appointment (Section 17).
Delivery records: Mailgun reports to us when a message could not be delivered permanently or temporarily, was marked as spam, or was unsubscribed. For each of these events we store only what the organisation needs in order to spot a delivery problem: the affected email address, the reason for non-delivery, and the time. Subject lines and message contents are not stored. These records are deleted after 90 days. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the deliverability of appointment-related messages).
Replies to our emails: if you reply to an appointment confirmation, the reply is evaluated in order to detect an acceptance or decline of the appointment. The content of your reply is not stored — neither the text nor the subject nor your sender address. What is stored is only technical information (message id, time, sender domain, number of attachments, and whether an accept/decline could be detected), and even that only for 30 days.
SMS delivery is handled by the provider Bird (Bird B.V., Amsterdam, Netherlands — formerly MessageBird) as a processor. Sending of reminder SMS is not yet enabled platform-wide; a consent given during booking is already recorded, but an SMS will only be sent once the feature is enabled. Before it is enabled, the processing locations and any third-country element will be verified and added to this Privacy Policy.
9. User accounts and OAuth login (Google, Microsoft)
Members of organisations sign in via Google OAuth or Microsoft OAuth. From the respective provider we receive: email address, name/display name, provider-specific user ID, and, where applicable, a profile picture. We do not store passwords. For authentication, Google (Google Ireland Limited) and Microsoft (Microsoft Ireland Operations Limited) act as independent controllers; their privacy policies apply. Legal basis: Art. 6(1)(b) GDPR (provision of the account).
Record of acceptance of our legal documents: when an organisation creates an account, we record which version of the Terms and of the Privacy Policy applied at the time. What is stored: the version number and a checksum (hash) of the accepted text, the time, the language in which the text was displayed, the acting person (id, email address, role), and the way in which acceptance took place — via the notice next to the sign-in button, via an explicit tick, or via a confirmation in the settings. No IP address and no browser details are stored; the items listed above are sufficient for the purpose. Purpose: evidence that our contract terms were validly incorporated (Section 305(2) BGB) and accountability (Art. 5(2) GDPR). Legal basis: Art. 6(1)(b) and (f) GDPR. These records concern the organisation's authorised representative, not end customers; for the retention period see Section 17.
To render the Google sign-in button, the login page loads a script of Google's sign-in service from accounts.google.com; in doing so, your IP address is transmitted to Google, and Google sets the g_state cookie (Section 4). This happens only on the login page and is necessary for the Google sign-in offered there (Section 25(2) no. 2 TDDDG; Art. 6(1)(b) or (f) GDPR — provision of the sign-in feature you requested).
10. Calendar synchronisation (Google Calendar)
Members of an organisation can connect their Google Calendar via OAuth so that appointments are synchronised and availability is taken into account. The connection is initiated by the member or organisation; legal basis vis-à-vis Zimun: Art. 6(1)(b) GDPR. The connection can be revoked at any time in the settings or in the Google account, and the access is then removed in full.
Synchronisation runs in both directions, and in both directions it is limited to what is necessary:
- Out of the member's calendar we take only the busy time slots, so that no booking falls into a period that is already taken. The subject lines and contents of a member's private appointments are not stored — availability requires knowing that a period is taken, not what with.
- Into the member's calendar we write an entry for each appointment containing the name of the booked service and the time slot. No end-customer data is transmitted: the entry contains neither the name nor the email address nor the phone number of the person who booked. Who booked the appointment remains visible in the service itself, where access requires signing in and the retention periods in this policy apply.
11. Video appointments (Google Meet)
Where an organisation has enabled video appointments, Google Meet links are created via the connected Google account of the respective member ("member-owned"). The video meeting itself takes place at Google; Google's privacy policies apply. Of the meeting itself, Zimun stores only the link as part of the appointment.
Invitation as a guest: for a video appointment, the email address you provided is added to the meeting as a guest. Google then sends you a calendar invitation from the member's account, and the appointment appears with its join link in your own calendar; you can also join the meeting without waiting in a lobby. Your email address is transmitted to Google for this purpose. Legal basis: Art. 6(1)(b) GDPR (performance of the video appointment you booked). If you would rather this did not happen, please book an on-site or telephone appointment, or contact the organisation.
12. Payment processing (planned: Stripe)
Currently, no online payment processing takes place via the platform. Integration of the payment provider Stripe (Stripe Payments Europe, Ltd., Ireland) is planned. Before payments go live, we will update this Privacy Policy with the applicable information (data categories, roles, legal bases, third-country transfers).
13. Organisations' AI chat (OpenAI via the organisation's own API key)
Organisations may optionally enable an AI-assisted booking chat. Important to know:
- The chat uses OpenAI's services exclusively via the respective organisation's own OpenAI API key. Zimun does not provide its own OpenAI keys.
- Under data-protection law, the organisation is therefore the controller for the chat processing; OpenAI is the organisation's (sub-)processor — not Zimun's. The organisation concludes the required data processing agreement with OpenAI itself and is responsible for the legal basis and any third-country transfer (typically EU Standard Contractual Clauses or the Data Privacy Framework with OpenAI).
- In this respect, Zimun forwards the chat content technically as the organisation's processor.
- Data that may reach OpenAI includes the free text you enter in the chat and booking-related context data (e.g. name, requested service, appointment times). Please do not enter sensitive data in the chat that is not required for booking the appointment.
What Zimun itself stores: we do not store the conversation — it exists only in your browser and is gone once you close the window. For the duration of a chat session (15 minutes) we hold technical details: the session id, the organisation, the language, the time zone, and a pseudonym of your IP address. The address itself is not stored; the pseudonym is formed with a secret key and cannot be reversed. Its only purpose is to detect abusive use — the chat can be used without signing in and consumes the organisation's own credit. The session data is deleted once it expires. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in preventing abusive use).
Where the chat runs as an embedded window on an organisation's website, we do not learn which page you came from: the referring address is not stored.
14. Sharing with the organisation
To handle the appointment, we transmit to the organisation you selected: name, email address, phone number (if provided), selected service/resource, appointment time, and your optional additional information. The organisation processes this data as an independent controller for the delivery of the service.
15. Recipients and processors (Art. 13(1)(e) GDPR)
We use the following service providers:
- Google Cloud (hosting/database): Google Cloud EMEA Limited, Dublin, Ireland — processor; data processing in EU region europe-west3 (Frankfurt); data processing agreement (Google Cloud Data Processing Addendum); for any transfers to Google LLC (USA): EU Standard Contractual Clauses / EU-U.S. Data Privacy Framework.
- Mailgun (transactional email delivery): Mailgun Technologies, Inc. (Sinch group) — processor; processing in the EU region; see Section 8.
- Bird (SMS appointment reminders): Bird B.V., Amsterdam, Netherlands (formerly MessageBird) — processor; sending only with your consent; see Section 8.
- Google Ireland Limited: OAuth login, Google Calendar, Google Meet, Google Analytics — depending on the service, independent controller (login) or processor (analytics); see Sections 5, 9–11.
- Google Maps (maps, address search, time-zone lookup): Google Ireland Limited or Google LLC. Two distinct operations are involved. In the browser: the map and the address search on the settings pages for the organisation and its locations load only after an explicit click; the member's IP address and browser details are then transmitted to Google, and for the address search also the address entered. Those pages are accessible only to signed-in members; Google Maps is not embedded on the public booking pages. On our servers: to determine the coordinates and time zone of an address we call Google's Geocoding and Time Zone APIs; what is transmitted is the address entered by the organisation, with no reference to an end customer. Legal basis: Art. 6(1)(b) and (f) GDPR (providing location management and correct time-zone calculation). For any transfers to the USA, the safeguards named in Section 16 apply.
- Microsoft Ireland Operations Limited: OAuth login — independent controller; see Section 9.
- OpenAI: exclusively as the respective organisation's processor via the organisation's own API key — not a processor of Zimun; see Section 13.
- Authorities and other third parties: only where legally required (Art. 6(1)(c) GDPR).
Data is not sold or shared for advertising purposes.
16. Third-country transfers (Art. 44 et seq. GDPR)
Platform data is stored in the EU (Frankfurt am Main). Where, in individual cases, data is transferred to providers based in the USA (Google LLC, Mailgun/Sinch, and — within the organisation's area of responsibility — OpenAI), this is based on an adequacy decision (EU-U.S. Data Privacy Framework, Art. 45 GDPR) and/or the EU Standard Contractual Clauses (Art. 46(2)(c) GDPR). For SMS delivery via Bird (Section 8) — a provider based in the Netherlands (EU) — any third-country transfers will be verified and added here before sending is enabled.
17. Retention periods (Art. 13(2)(a) GDPR)
- Technical logs: 30 days.
- Appointment contact data (name, email, phone, consent records): 1 month after the appointment, then automatic deletion of the separate record.
- Remaining appointment data (time, service, resource, status — no contact data): until the organisation is deleted.
- Recurring appointments: the contact data stored in the series configuration (name, email, phone) is removed by the automated deletion run one (1) month after the series is cancelled; the contact data of the individual appointments of the series is subject to the above period of one (1) month after the respective appointment.
- User account data: until the account is deleted; after the contract ends, final deletion takes place after 30 days (the deletion may be revoked within this period).
- Analytics data: no further collection after withdrawal; event data already collected is deleted by Google no later than 14 months after collection (Section 5).
- Email delivery records (affected address, reason for non-delivery, time): 90 days. Technical details of reply emails (no content, no sender address): 30 days. See Section 8.
- Chat sessions: the session itself expires after 15 minutes; the associated technical record is deleted the following day. Conversation transcripts are not stored (Section 13).
- Appointment change history: who changed what on an appointment and when is retained as evidence that our processing was lawful (Art. 5(2) GDPR) and deleted four years after the entry — the regular limitation period is three years from the end of the year in which a claim arose (Sections 195, 199 BGB). Where you as an end customer are the acting person, your email address is removed from those entries together with the rest of your contact data; what remains is a pseudonym that cannot be reversed and that keeps the history traceable without naming you.
- Technical counters for abuse prevention (for example limiting sign-in attempts): two time windows, then automatic deletion. What is stored is a pseudonym of the IP address, not the address itself. Caches for repeated API calls: 24 hours.
- Billing and invoice data: Once paid plans are used, we retain billing-related records in accordance with German commercial and tax retention obligations: invoices and accounting vouchers for 8 years (Section 14b UStG, Section 147 AO), commercial books, annual accounts, and other required records for 10 years (Section 147 AO, Section 257 HGB). Legal basis: Art. 6(1)(c) GDPR.
- Record of acceptance of our legal documents: four years after acceptance. It documents which version of the Terms, the privacy policy and the data processing agreement an organisation accepted, and concerns its authorised representative, not end customers.
Enquiries submitted through the contact form on our website are deleted 30 days after handling is complete, and in any event no later than twelve months after receipt — see Section 22.
Backups: to enable recovery after a technical fault or an erroneous deletion, we keep a 7-day point-in-time recovery window and additionally create weekly backups of the database in the same EU region (Frankfurt am Main). Backups are deleted automatically after 30 days — the same period that applies to the contact data of an appointment, so that a backup does not meaningfully outlive a deletion. Data deleted from the live system remains present in backups already taken until those backups expire; if a backup is exceptionally restored, the deletion routines described above are applied again immediately. Legal basis: Art. 6(1)(f) GDPR in conjunction with Art. 32(1)(c) GDPR (ability to restore availability in a timely manner).
18. Your rights (Art. 15–21, Art. 7(3), Art. 77 GDPR)
Vis-à-vis the respective controller, you have the right to:
- Access (Art. 15 GDPR),
- Rectification (Art. 16 GDPR),
- Erasure (Art. 17 GDPR),
- Restriction of processing (Art. 18 GDPR),
- Data portability (Art. 20 GDPR),
- Withdrawal of consent with effect for the future (Art. 7(3) GDPR).
Right to object (Art. 21 GDPR): Where we process data on the basis of Art. 6(1)(f) GDPR, you have the right to object to the processing at any time on grounds relating to your particular situation.
For processing for which the organisation is the controller (service delivery, AI chat), please address your request to the respective organisation; as its processor, we support the organisation in responding.
Right to lodge a complaint (Art. 77 GDPR): You have the right to complain to a data-protection supervisory authority. The authority competent for us is the State Commissioner for Data Protection and Freedom of Information of Baden-Württemberg (LfDI Baden-Württemberg), Stuttgart, www.baden-wuerttemberg.datenschutz.de. You may also contact the supervisory authority of your habitual residence.
19. Obligation to provide data (Art. 13(2)(e) GDPR)
You are not legally obliged to provide your data. However, the mandatory booking details (name, email address, appointment time) are required to conclude and handle the booking; without them, an appointment cannot be booked or managed. All other information is voluntary.
20. No automated decision-making (Art. 22 GDPR)
No automated decision-making, including profiling, within the meaning of Art. 22 GDPR takes place. The organisations' optional AI chat serves solely as a booking assistant and makes no decisions with legal or similarly significant effect.
21. Security (Art. 32 GDPR)
We implement technical and organisational measures pursuant to Art. 32 GDPR, including: TLS encryption (HTTPS), encryption at rest (Google Cloud), access controls, role-based permissions, monitoring and audit logs, and automated deletion runs.
22. Contact form and enquiries
When you contact us via the website's contact form or by email, we process the data you provide (name, email address, content of the message) and — for abuse prevention (spam protection, rate limiting) — technical data of the submission (IP address, browser identifier). Purpose: handling and answering your enquiry. Legal basis: Art. 6(1)(b) GDPR where your enquiry relates to a contract or its initiation, otherwise Art. 6(1)(f) GDPR (legitimate interest in answering enquiries and preventing abuse). The message is stored on our platform and additionally delivered to our mailbox (sent via Mailgun, Section 8). We delete contact enquiries: 30 days after handling is complete, and in any case no later than 12 months after receipt; statutory retention obligations remain unaffected.
23. Changes to this Privacy Policy
We update this Privacy Policy when the processing operations, the services used, or the legal situation change. The version published on this page applies; the effective date is stated above.
The German version of this Privacy Policy is authoritative; versions in other languages are non-binding convenience translations.