Last updated: 2026-08-20
1. Controller (Art. 4(7), Art. 13(1)(a) GDPR)
Zimun Labs UG (haftungsbeschränkt)
Buchenteich 3
73773 Aichwald
Germany
Phone: +49 176 63030716
Email: info@zimun.online
Commercial register: Handelsregister B of the Local Court of Stuttgart, HRB 806662
Managing Director: Svetlana Ponomarenko
We have assessed the designation of a data protection officer against Art. 37 GDPR and Section 38 BDSG. On that assessment, no designation is required: Zimun is not a public authority or body (Art. 37(1)(a) GDPR). Our core activity is providing appointment-scheduling software; it does not consist of processing operations which require regular and systematic monitoring of data subjects on a large scale (Art. 37(1)(b) GDPR) — we do not monitor end-customer behaviour, and we use web analytics only with your consent (Section 5). Nor does our core activity consist of large-scale processing of special categories of personal data or of data relating to criminal convictions and offences (Art. 37(1)(c) GDPR); the platform provides no dedicated fields for special categories. Where an organisation offers health-related services, the appointment data and free-text entries of its end-customers may in individual cases reveal health data within the meaning of Art. 9 GDPR (see Section 7 and Annex 1 to the data processing agreement); we process such data as a processor on the instructions of the relevant organisation; the organisation is the controller. A processor's own core activities can also trigger the designation duty — what matters is therefore not the role but the scale. Large-scale processing within the meaning of Art. 37(1)(c) GDPR does not currently exist: the platform presently has no health-related organisations and no end-customers whose appointment data could reveal health data. We repeat this scale assessment as soon as health-related organisations use the platform, documenting the number of affected organisations and end-customers, data volume, duration and reach of the processing. The thresholds of Section 38 BDSG are not met: we do not as a rule constantly employ at least 20 persons in the automated processing of personal data (Section 38(1) sentence 1 BDSG); we do not currently carry out processing that we ourselves would have to submit to a data protection impact assessment under Art. 35 GDPR, and we do not process personal data commercially for the purpose of transfer or for market or opinion research (Section 38(1) sentence 2 BDSG). We keep this assessment under review and will designate a data protection officer as soon as any of these conditions is met; the details will then be published here. Until then, the contact for data protection enquiries is Svetlana Ponomarenko, reachable at info@zimun.online or via the contact details above.
2. Roles: Zimun and the organisations
Zimun is an appointment-scheduling platform. Independent businesses and service providers ("organisations" or "Service Customers") use the platform to manage appointments with their end-customers. Under data-protection law, the roles are as follows:
- Zimun Labs UG (haftungsbeschränkt) as controller: for operating, securing and maintaining the platform, providing the website, user accounts and sign-in, abuse and fraud prevention, billing Zimun's own charges, and meeting Zimun's own statutory obligations. Receiving and handling bookings, and appointment-related notifications, are not covered by this — for those, Zimun acts as the organisation's processor (third bullet). The binding allocation of each processing operation to a role is set out in Annex 4 to the data processing agreement; where Zimun acts as processor, the organisation is the controller within the meaning of Art. 4(7) GDPR, it determines the legal basis, and it owes you the information under Art. 13, 14 GDPR. We provide the information in this policy in addition, so that you can see what happens on the platform.
- Each organisation as an independent controller: for delivering the booked service, its customer relationship, and processing it initiates (e.g. the optional AI chat, see Section 13).
- Zimun as the organisation's processor (Art. 28 GDPR): to the extent Zimun stores and manages customer, appointment, and staff data on the organisation's behalf. The data processing agreement required for this is concluded as part of the organisation's usage contract; the organisation may request it from Zimun in text form at any time.
There is no joint controllership within the meaning of Art. 26 GDPR.
3. Hosting and server logs
The platform is hosted on Google Cloud Platform (Google App Engine, Google Cloud Firestore database) in the EU region europe-west3 (Frankfurt am Main, Germany). When you access the Service, technical access data is processed automatically:
- IP address
- Date and time of access
- Browser type and version, operating system
- Referrer URL
- Transferred data volume and HTTP status codes
Purpose: technical provision, stability, abuse prevention, and IT security. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the secure operation of the platform). Technical logs are retained for 30 days.
4. Cookies and local storage (Section 25 TDDDG)
Access to information on your end device is governed by Section 25 of the German TDDDG (formerly TTDSG). Strictly necessary cookies fall under Section 25(2) no. 2 TDDDG (no consent required); the related data processing is based on Art. 6(1)(f) GDPR. All non-essential services (currently only web analytics, Section 5) are managed via our consent banner (Klaro) and used only with your consent (Section 25(1) TDDDG, Art. 6(1)(a) GDPR).
Strictly necessary cookies and storage used:
- user_session — login session of signed-in users (HttpOnly); lifetime: 7 days (sliding).
- manage_session — management session for appointment-management links; lifetime: 2 hours.
- csrf_token — protection against cross-site request forgery; lifetime: 7 days.
- ms_oauth_state and ms_login_next — securing the Microsoft sign-in process (protection against login tampering and return to the page you came from); set only during the Microsoft login (HttpOnly); lifetime: 10 minutes.
- g_state — set by Google's sign-in service when the login page is opened (state of the Google sign-in dialog, see Section 9); lifetime: 6 months.
- lang — stores your language preference; lifetime: 1 year.
- klaro (cookie) — stores your consent choices from the consent banner; lifetime: 120 days.
- zimun.mapsConsent (session storage, only on the settings pages for the organisation and its locations) — stores your decision to load the Google map, so that configuring several locations does not require clicking again on every page; lifetime: until the end of the browser session.
You can change or withdraw your consent choices at any time via the "Manage consent" link in the website footer.
5. Web analytics: Google Analytics 4 (only with consent)
We use Google Analytics 4 (provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland) only if you have consented via the consent banner. Without consent, no analytics script is loaded and no analytics cookies (_ga, _ga_*) are set. IP anonymisation is enabled.
Legal basis: Art. 6(1)(a) GDPR and Section 25(1) TDDDG (consent). You may withdraw your consent at any time with effect for the future via the cookie settings. Within Google Analytics, data may be transferred to Google LLC in the USA; Google LLC is certified under the EU-U.S. Data Privacy Framework (adequacy decision pursuant to Art. 45 GDPR), supplemented by EU Standard Contractual Clauses (Art. 46(2)(c) GDPR). After a withdrawal, no further analytics data is collected; event data already collected is deleted by Google at the end of the configured retention period, and in any event no later than 14 months after collection.
6. Typefaces and other embedded content (locally hosted)
For a consistent display, this website uses typefaces (Geist, Geist Mono, Source Serif 4) that are hosted locally on our own servers. When a page is opened, the font files are delivered from our hosting (Google Cloud, Frankfurt region — see Section 3); no connection to Google Fonts servers (fonts.googleapis.com / fonts.gstatic.com) takes place.
The same applies to the other files your browser needs in order to display our pages — scripts, stylesheets and images. They are delivered exclusively from our hosting; we embed no third-party content delivery networks (CDNs). Simply opening our pages, and in particular the public booking pages, therefore transmits your IP address to no third party. The sole exception is the sign-in page, which loads the respective provider's sign-in script — see below and Section 9.
There are two exceptions, both of which require an action on your part and therefore do not occur when a page is merely opened:
- Maps (Google Maps): maps and the address search on the settings pages for organisations and locations are loaded only after an explicit click. Until then nothing is transmitted to Google; the button states that loading will transmit the IP address to Google. See Section 15 for details.
- Web analytics (Google Analytics 4): loaded only after your consent — see Section 5.
For the sign-in process itself, the sign-in script of the respective provider (Google or Microsoft) is additionally loaded when you open our sign-in page; this is a technical precondition of the sign-in method you chose (Section 9).
Legal basis for the associated processing (delivery of the files via our hosting): Art. 6(1)(f) GDPR (legitimate interest in a uniform and technically reliable presentation of the website).
7. Appointment booking
When you book an appointment with an organisation, we process:
- Name
- Email address
- Phone number — on the public booking page only where the organisation offers SMS reminders and you have consented to receiving them (Section 8); without that consent, a phone number entered there is not stored. Where the organisation enters an appointment for you (see below), it may record your phone number for queries and appointment-related contact.
- Selected service/resource and appointment time
- Optional additional information entered in the booking form
Purpose: conclusion, management, and handling of the appointment, including transmission of the booking data to the selected organisation. Role and legal basis: Zimun processes this data as the processor of the organisation you selected (Section 2). The controller is the organisation; it determines the legal basis — typically Art. 6(1)(b) GDPR for the contract for the booked service, or pre-contractual steps, between you and the organisation. Zimun requires no legal basis of its own for this processing and does not rely on Art. 6(1)(b) GDPR vis-à-vis you; no contract for the booked service is concluded with Zimun (Terms, Section 13 (2)). Where Zimun technically provides the booking function you called up and defends it against abuse, Zimun is the controller; the legal basis there is Art. 6(1)(f) GDPR. Please do not enter health information or any other special categories of personal data (Art. 9 GDPR) in free-text fields; where the organisation needs such information, it collects it from you directly.
Data not obtained from you (Art. 14 GDPR): Appointments may also be entered for you by the organisation (e.g. when arranged by phone or in person). In that case, we receive the data categories listed above from the organisation rather than from you; the information in this Privacy Policy applies accordingly. Waiting-list entries (name, contact details, requested time frame) are deleted 30 days after the entry is settled, and in any case no later than 12 months after receipt.
Minors: The platform is not directed at children. Appointments for minors may be booked by their parents or guardians; under the Terms and Conditions, organisation and member accounts require the holder to be of legal age.
Contact data is stored separately from the remaining appointment data: the general appointment record (time, service, resource, status) contains no contact data; name, email address, and phone number are held solely in a separate, specially protected record. That separate record is deleted by an automated daily deletion run one (1) month after the appointment; the remaining appointment data (time, service, resource) then contains no contact data. We continue to treat it as personal data: in individual cases — a small practice, a rarely booked service, a low-volume calendar — the time, service and resource may still allow a link to you, in particular by the organisation itself. Where the appointment was paid online via the payment feature (Section 12), the separate contact record is instead deleted 180 days after the appointment: within that period, payments may still be subject to chargebacks or payment disputes whose attribution and resolution would not be possible without this record (Art. 6(1)(f), Art. 17(3)(e) GDPR). Retention details: Section 17.
8. Transactional notifications: emails (Mailgun) and SMS reminders (Bird)
By email, the Service sends only transactional, appointment-related messages (confirmations, reminders, changes, cancellations, waitlist notifications, required follow-ups) and account-related notices. No marketing emails are sent without explicit consent. Roles and legal bases: appointment-related messages to end-customers are sent by Zimun as the organisation's processor; the controller is the organisation and it determines the legal basis (typically Art. 6(1)(b) GDPR for the contract between you and the organisation). Account-related messages to organisations and their members are sent by Zimun in its own capacity as controller; the legal basis is Art. 6(1)(b) GDPR where the recipient is themselves the contracting party, and otherwise Art. 6(1)(f) GDPR (interest in performing the contract with the organisation).
Email delivery is handled by the processor Mailgun (Mailgun Technologies, Inc., part of the Sinch group) under a data processing agreement. We use Mailgun's EU region exclusively, so messages are processed and stored within the European Union. As the provider is US-incorporated, access from a third country (for example during support) cannot be entirely excluded; the safeguards named in Section 16 apply to it. Open and click tracking is disabled on every message sent; outgoing emails contain no tracking pixels. Where personal data is transferred to the USA in this context, this is based on the EU Standard Contractual Clauses (Art. 46(2)(c) GDPR) and/or the EU-U.S. Data Privacy Framework.
SMS reminders (only with your consent): Where the respective organisation has enabled SMS reminders, you may consent during booking to receiving an appointment reminder by SMS and provide your phone number for this purpose. In that case, the Service sends a reminder SMS approximately 24 hours before the appointment; the data transmitted is your phone number and the message text (name of the organisation, booked service, appointment time). Without your consent, no reminder SMS is sent and a phone number entered on the booking page is not stored. Legal basis: your consent (Art. 6(1)(a) GDPR); you may withdraw it at any time with effect for the future, e.g. by notifying the organisation or info@zimun.online. The phone number and the consent record are deleted together with the other contact data in accordance with the periods in Section 17 (as a rule one (1) month after the appointment; 180 days for appointments paid online).
Delivery records: Mailgun reports to us when a message could not be delivered permanently or temporarily, was marked as spam, or was unsubscribed. For each of these events we store only what the organisation needs in order to spot a delivery problem: the affected email address, the reason for non-delivery, and the time. Subject lines and message contents are not stored. These records are deleted after 90 days. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the deliverability of appointment-related messages).
Replies to our emails: if you reply to an appointment confirmation, the reply is evaluated in order to detect an acceptance or decline of the appointment. The content of your reply is not stored — neither the text nor the subject nor your sender address. What is stored is only technical information (message id, time, sender domain, number of attachments, and whether an accept/decline could be detected), and even that only for 30 days.
SMS delivery is handled by the provider Bird (Bird B.V., Amsterdam, Netherlands — formerly MessageBird) as a processor. Sending of reminder SMS is not yet enabled platform-wide; a consent given during booking is already recorded, but an SMS will only be sent once the feature is enabled. Before it is enabled, the processing locations and any third-country element will be verified and added to this Privacy Policy.
9. User accounts and OAuth login (Google, Microsoft)
Members of organisations sign in via Google OAuth or Microsoft OAuth. From the respective provider we receive: email address, name/display name, provider-specific user ID, and, where applicable, a profile picture. We do not store passwords. For authentication, Google (Google Ireland Limited) and Microsoft (Microsoft Ireland Operations Limited) act as independent controllers; their privacy policies apply. Zimun is the controller for account administration. Legal basis: Art. 6(1)(b) GDPR where the member is themselves Zimun's contracting party (in particular sole traders and freelancers); where the organisation is a legal person and the member is its employee or representative, Art. 6(1)(f) GDPR — legitimate interest in performing the contract concluded with the organisation and in secure access.
Record of acceptance of our legal documents: when an organisation creates an account, we record which version of the Terms and of the Privacy Policy applied at the time. What is stored: the version number and a checksum (hash) of the accepted text, the time, the language in which the text was displayed, the acting person (id, email address, role), and the way in which acceptance took place — via the notice next to the sign-in button, via an explicit tick, or via a confirmation in the settings. No IP address and no browser details are stored; the items listed above are sufficient for the purpose. Purpose: evidence that our contract terms were validly incorporated (Section 305(2) BGB) and accountability (Art. 5(2) GDPR). Legal basis: Art. 6(1)(f) GDPR — legitimate interest in evidencing the valid incorporation of the contract terms (Section 305 (2) BGB) and in defending against claims — and Art. 6(1)(b) GDPR where the acting person is themselves the contracting party.
To render the Google sign-in button, the login page loads a script of Google's sign-in service from accounts.google.com; in doing so, your IP address is transmitted to Google, and Google sets the g_state cookie (Section 4). This happens only on the login page and is necessary for the Google sign-in offered there (Section 25(2) no. 2 TDDDG; Art. 6(1)(b) or (f) GDPR — provision of the sign-in feature you requested).
10. Calendar synchronisation (Google Calendar)
Members of an organisation can connect their Google Calendar via OAuth so that appointments are synchronised and availability is taken into account. The connection is initiated by the member or organisation; legal basis vis-à-vis Zimun: Art. 6(1)(b) GDPR. The connection can be revoked at any time in the settings or in the Google account, and the access is then removed in full.
Synchronisation runs in both directions, and in both directions it is limited to what is necessary:
- Out of the member's calendar we take only the busy time slots, so that no booking falls into a period that is already taken. The subject lines and contents of a member's private appointments are not stored — availability requires knowing that a period is taken, not what with.
- Into the member's calendar we write an entry for each appointment containing the name of the booked service and the time slot. No end-customer data is transmitted: the entry contains neither the name nor the email address nor the phone number of the person who booked. Who booked the appointment remains visible in the service itself, where access requires signing in and the retention periods in this policy apply.
11. Video appointments (Google Meet)
Where an organisation has enabled video appointments, Google Meet links are created via the connected Google account of the respective member ("member-owned"). The video meeting itself takes place at Google; Google's privacy policies apply. Of the meeting itself, Zimun stores only the link as part of the appointment.
Invitation as a guest: for a video appointment, the email address you provided is added to the meeting as a guest. Google then sends you a calendar invitation from the member's account, and the appointment appears with its join link in your own calendar; you can also join the meeting without waiting in a lobby. Your email address is transmitted to Google for this purpose. That transmission is made on the organisation's instruction; Zimun acts as its processor in this respect, and the organisation is the controller. It determines the legal basis — typically Art. 6(1)(b) GDPR for the contract for the video appointment concluded between you and the organisation. If you would rather this did not happen, please book an on-site or telephone appointment, or contact the organisation.
12. Payment processing (Stripe)
This section describes the online payment feature through which end-customers can pay the organisation for the booked service online; it becomes available once Zimun offers it and the organisation has activated it. Payment processing is handled by the payment service provider Stripe (Stripe Payments Europe, Ltd., Dublin, Ireland — "Stripe"). As long as an organisation has not activated the feature, no online payment processing takes place via the platform for its bookings.
- Payment to the organisation: The payee is always the organisation; the payment is processed via the organisation's own Stripe account. Zimun never receives end-customer funds at any point. You enter your payment details (e.g. card data) directly into Stripe's payment form; they are transmitted directly to Stripe and are neither stored nor accessed by Zimun. For a payment, Zimun processes only its status, amount, currency, time, refund status, and its assignment to the booking and the organisation.
- Roles (per processing purpose): For executing the payment and for its own statutory verification and safeguarding duties (e.g. fraud and money-laundering prevention), Stripe processes personal data as an independent controller. Insofar as end-customer payment data is processed under the organisation's own Stripe agreement, Stripe belongs to the organisation's service-provider chain, not to Zimun's; in this respect Zimun acts as the organisation's processor (Section 2). Only for billing the fee Zimun charges the organisation for the payment feature is Stripe a recipient or processor of Zimun; no end-customer data is involved in that.
- Payment receipt: Zimun does not pass your email address to Stripe; no automatic payment receipt is therefore sent via the platform. You can obtain a receipt for the payment on request from the organisation as the recipient of the payment.
- Roles and legal bases: the payment data for your booking is processed by Zimun as the organisation's processor; the controller is the organisation and it determines the legal basis (typically Art. 6(1)(b) GDPR for the contract concluded between you and the organisation). For executing the payment and for its own statutory duties, Stripe is an independent controller. Only for billing the fee Zimun charges the organisation is Zimun the controller; legal basis: Art. 6(1)(b) and (c) GDPR. No end-customer data is involved in that.
- Tax reporting obligations (DAC7/PStTG) — organisations only: As the operator of a digital platform, Zimun is legally required (German Platform Tax Transparency Act — PStTG) to collect, verify and annually report to the Federal Central Tax Office (Bundeszentralamt für Steuern) certain information about organisations that are providers within the meaning of the PStTG and carry out a relevant activity for a consideration the amount of which is known to us or ought to be known to us (Section 5 (1) and (2) PStTG). By what route or by whom payment is made is irrelevant for this (Section 5 (2) sentence 3 PStTG). Considerations whose amount is neither known to us nor ought to be known to us are not reported. Details (the information collected, the verification procedure, the time of reporting) follow from Sections 14, 17 and 18 PStTG.
13. Organisations' AI chat (OpenAI via the organisation's own API key)
Organisations may optionally enable an AI-assisted booking chat. Important to know:
- The chat uses OpenAI's services exclusively via the respective organisation's own OpenAI API key. Zimun does not provide its own OpenAI keys.
- Under data-protection law, the organisation is therefore the controller for the chat processing; OpenAI is the organisation's (sub-)processor — not Zimun's. The organisation concludes the required data processing agreement with OpenAI itself and is responsible for the legal basis and any third-country transfer (typically EU Standard Contractual Clauses or the Data Privacy Framework with OpenAI).
- In this respect, Zimun forwards the chat content technically as the organisation's processor.
- Data that may reach OpenAI includes the free text you enter in the chat and booking-related context data (e.g. name, requested service, appointment times). Please do not enter sensitive data in the chat that is not required for booking the appointment.
What Zimun itself stores: we do not store the conversation — it exists only in your browser and is gone once you close the window. For the duration of a chat session (15 minutes) we hold technical details: the session id, the organisation, the language, the time zone, and a pseudonym of your IP address. The address itself is not stored; the pseudonym is formed with a secret key and cannot be reversed. Its only purpose is to detect abusive use — the chat can be used without signing in and consumes the organisation's own credit. The session data is deleted once it expires. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in preventing abusive use).
Where the chat runs as an embedded window on an organisation's website, we do not learn which page you came from: the referring address is not stored.
14. Sharing with the organisation
The booking data (name, email address, phone number where provided, selected service/resource, appointment time and any optional additional information) is made available to the organisation you selected in its account; that organisation is the controller for this data from the outset, and Zimun stores it on its behalf (Section 2). This is therefore not a disclosure between two controllers. The organisation uses the data to deliver the service you booked.
15. Recipients and processors (Art. 13(1)(e) GDPR)
We use the following service providers:
- Google Cloud (hosting/database): Google Cloud EMEA Limited, Dublin, Ireland — processor; data processing in EU region europe-west3 (Frankfurt); data processing agreement (Google Cloud Data Processing Addendum); for any transfers to Google LLC (USA): EU Standard Contractual Clauses / EU-U.S. Data Privacy Framework.
- Mailgun (transactional email delivery): Mailgun Technologies, Inc. (Sinch group) — processor; processing in the EU region; see Section 8.
- Bird (SMS appointment reminders): Bird B.V., Amsterdam, Netherlands (formerly MessageBird) — processor; sending only with your consent; see Section 8.
- Google Ireland Limited: OAuth login, Google Calendar, Google Meet, Google Analytics — depending on the service, independent controller (login) or processor (analytics); see Sections 5, 9–11.
- Google Maps (maps, address search, time-zone lookup): Google Ireland Limited or Google LLC. Two distinct operations are involved. In the browser: the map and the address search on the settings pages for the organisation and its locations load only after an explicit click; the member's IP address and browser details are then transmitted to Google, and for the address search also the address entered. Those pages are accessible only to signed-in members; Google Maps is not embedded on the public booking pages. On our servers: to determine the coordinates and time zone of an address we call Google's Geocoding and Time Zone APIs; what is transmitted is the address entered by the organisation, with no reference to an end customer. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in location management and in correct time-zone determination); where the member is themselves Zimun's contracting party, additionally Art. 6(1)(b) GDPR. No end-customer data is involved. For any transfers to the USA, the safeguards named in Section 16 apply.
- Stripe (online payments): Stripe Payments Europe, Ltd., Dublin, Ireland — payment service provider; independent controller for executing payments and for its own statutory duties, otherwise — depending on the processing purpose — a service provider of the organisation (its own Stripe account) or a recipient/processor of Zimun for fee billing; see Section 12.
- German Federal Central Tax Office (Bundeszentralamt für Steuern, BZSt): recipient of the legally required reports under the PStTG — only information about organisations that are reportable providers within the meaning of the PStTG, no end-customer data; see Section 12.
- Microsoft Ireland Operations Limited: OAuth login — independent controller; see Section 9.
- OpenAI: exclusively as the respective organisation's processor via the organisation's own API key — not a processor of Zimun; see Section 13.
- Authorities and other third parties: only where legally required (Art. 6(1)(c) GDPR).
Data is not sold or shared for advertising purposes.
16. Third-country transfers (Art. 44 et seq. GDPR)
Platform data is stored in the EU (Frankfurt am Main). Where, in individual cases, data is transferred to providers based in the USA (Google LLC, Mailgun/Sinch, in the context of payment processing also Stripe, Inc., and — within the organisation's area of responsibility — OpenAI), this is based on an adequacy decision (EU-U.S. Data Privacy Framework, Art. 45 GDPR) and/or the EU Standard Contractual Clauses (Art. 46(2)(c) GDPR). For SMS delivery via Bird (Section 8) — a provider based in the Netherlands (EU) — any third-country transfers will be verified and added here before sending is enabled.
17. Retention periods (Art. 13(2)(a) GDPR)
- Technical logs: 30 days.
- Appointment contact data (name, email, phone, consent records): 1 month after the appointment, then automatic deletion of the separate record. For appointments paid online via the payment feature (Section 12): 180 days after the appointment, because payments may still be subject to chargebacks or payment disputes within that period (Art. 6(1)(f), Art. 17(3)(e) GDPR).
- Remaining appointment data (time, service, resource, status — no contact data): until the organisation is deleted.
- Recurring appointments: the contact data stored in the series configuration (name, email, phone) is removed by the automated deletion run one (1) month after the series is cancelled; the contact data of the individual appointments of the series is subject to the above periods (one (1) month after the respective appointment; 180 days for appointments paid online).
- User account data: until the account is deleted; after the contract ends, final deletion takes place after 30 days (the deletion may be revoked within this period).
- Analytics data: no further collection after withdrawal; event data already collected is deleted by Google no later than 14 months after collection (Section 5).
- Email delivery records (affected address, reason for non-delivery, time): 90 days. Technical details of reply emails (no content, no sender address): 30 days. See Section 8.
- Chat sessions: the session itself expires after 15 minutes; the associated technical record is deleted the following day. Conversation transcripts are not stored (Section 13).
- Appointment change history: who changed what on an appointment and when is retained as evidence that our processing was lawful (Art. 5(2) GDPR) and deleted four years after the entry — the regular limitation period is three years from the end of the year in which a claim arose (Sections 195, 199 BGB). Where you as an end customer are the acting person, your email address is removed from those entries together with the rest of your contact data; what remains is a pseudonym that cannot be reversed and that keeps the history traceable without naming you.
- Technical counters for abuse prevention (for example limiting sign-in attempts): two time windows, then automatic deletion. What is stored is a pseudonym of the IP address, not the address itself. Caches for repeated API calls: 24 hours.
- Billing and invoice data: Once paid tiers are used, we retain billing-related records under the commercial and tax retention duties: commercial books, inventories, annual accounts and records within the meaning of Section 147 (1) no. 1 AO: 10 years (Section 147 AO, Section 257 HGB); booking documents and invoices: 8 years (Section 14b UStG, Section 147 AO); other documents subject to retention: per the applicable statutory period, generally 6 years. Legal basis: Art. 6(1)(c) GDPR.
- Records under the German Platform Tax Transparency Act (collection, verification, and reporting of the information of organisations that are reportable providers within the meaning of the PStTG, Section 12): ten years, then deletion (Section 24 PStTG). Legal basis: Art. 6(1)(c) GDPR.
- Withdrawal declarations via the withdrawal function (Section 22b): four years from the declaration; retained on behalf of the organisation concerned.
- Record of acceptance of our legal documents: four years after acceptance. It documents which version of the Terms, the privacy policy and the data processing agreement an organisation accepted, and concerns its authorised representative, not end customers.
Enquiries submitted through the contact form on our website are deleted 30 days after handling is complete, and in any event no later than twelve months after receipt — see Section 22.
Backups: to enable recovery after a technical fault or an erroneous deletion, we keep a 7-day point-in-time recovery window and additionally create weekly backups of the database in the same EU region (Frankfurt am Main). Backups are deleted automatically after 30 days — the same period that applies to the contact data of an appointment, so that a backup does not meaningfully outlive a deletion. Data deleted from the live system remains present in backups already taken until those backups expire; if a backup is exceptionally restored, the deletion routines described above are applied again immediately. Legal basis: Art. 6(1)(f) GDPR in conjunction with Art. 32(1)(c) GDPR (ability to restore availability in a timely manner).
18. Your rights (Art. 15–21, Art. 7(3), Art. 77 GDPR)
Vis-à-vis the respective controller, you have the right to:
- Access (Art. 15 GDPR),
- Rectification (Art. 16 GDPR),
- Erasure (Art. 17 GDPR),
- Restriction of processing (Art. 18 GDPR),
- Data portability (Art. 20 GDPR),
- Withdrawal of consent with effect for the future (Art. 7(3) GDPR).
Right to object (Art. 21 GDPR): Where we process data on the basis of Art. 6(1)(f) GDPR, you have the right to object to the processing at any time on grounds relating to your particular situation.
For processing for which the organisation is the controller — that is your booking, appointment and contact data, the appointment-related messages, the calendar and video features, the AI chat and the service delivery itself (Annex 4, section A of the data processing agreement) — please direct your request to the relevant organisation; we support it as processor in answering and forward any request received by us to it without undue delay. For the processing listed in Annex 4, section B, Zimun is your contact.
Right to lodge a complaint (Art. 77 GDPR): You have the right to complain to a data-protection supervisory authority. The authority competent for us is the State Commissioner for Data Protection and Freedom of Information of Baden-Württemberg (LfDI Baden-Württemberg), Stuttgart, www.baden-wuerttemberg.datenschutz.de. You may also contact the supervisory authority of your habitual residence.
19. Obligation to provide data (Art. 13(2)(e) GDPR)
You are not legally obliged to provide your data. However, the mandatory booking details (name, email address, appointment time) are required to conclude and handle the booking; without them, an appointment cannot be booked or managed. All other information is voluntary.
20. No automated decision-making (Art. 22 GDPR)
No automated decision-making, including profiling, within the meaning of Art. 22 GDPR takes place. The organisations' optional AI chat serves solely as a booking assistant and makes no decisions with legal or similarly significant effect.
21. Security (Art. 32 GDPR)
We implement technical and organisational measures pursuant to Art. 32 GDPR, including: TLS encryption (HTTPS), encryption at rest (Google Cloud), access controls, role-based permissions, monitoring and audit logs, and automated deletion runs.
22. Contact form and enquiries
When you contact us via the website's contact form or by email, we process the data you provide (name, email address, content of the message) and — for abuse prevention (spam protection, rate limiting) — technical data of the submission (IP address, browser identifier). Purpose: handling and answering your enquiry. Legal basis: Art. 6(1)(b) GDPR where your enquiry relates to a contract or its initiation, otherwise Art. 6(1)(f) GDPR (legitimate interest in answering enquiries and preventing abuse). The message is stored on our platform and additionally delivered to our mailbox (sent via Mailgun, Section 8). We delete contact enquiries: 30 days after handling is complete, and in any case no later than 12 months after receipt; statutory retention obligations remain unaffected.
22a. Reports of illegal content (Art. 16 DSA)
Illegal content can be reported to us via our reporting form or by email (Terms, Section 15a). Controller for processing the notice: Zimun. Data processed: the content of the notice (explanation, location concerned), the submitter's name and email address — except for notices concerning offences under Articles 3 to 7 of Directive 2011/93/EU, which may be submitted without them —, the reference number, the times of receipt and decision, and our decision with reasons. Purposes and legal bases: receiving, assessing and deciding the notice, acknowledging receipt and communicating the decision — Art. 6(1)(c) GDPR in conjunction with Art. 16 of Regulation (EU) 2022/2065; the subsequent retention — Art. 6(1)(f) GDPR (legitimate interest in evidencing our decisions and in defending against claims). Recipients: internally, the person handling the notice; authorities only where legally required. Retention: four years from the entry — not because Regulation (EU) 2022/2065 requires it, but in view of the standard limitation period of three years from the end of the year in which a claim arose (Sections 195, 199 BGB). The rights under Section 18 apply; for anonymous notices under the exception above we can confirm neither receipt nor our decision, as there is no means of contact.
22b. Withdrawal declarations via the withdrawal function (Section 356a BGB)
For contracts concluded online that carry a right of withdrawal, the platform provides the statutory withdrawal function. If you submit a withdrawal declaration there, we process the details you enter: your name, the reference to the affected booking and your email address, together with the time of the declaration. These details are stored with the declaration, receipt is confirmed to you by email (Section 356a(4) BGB), and the organisation concerned is notified so it can settle the withdrawal.
Roles: the withdrawal concerns the contract between you and the organisation. The controller for this processing is the organisation; it determines the legal basis (typically Art. 6(1)(c) GDPR in conjunction with its duties under Sections 355, 356a BGB). Zimun processes the declaration as the organisation's processor (Annex 4 section A of the data processing agreement). Retention: four years from the declaration — in view of the standard limitation period (Sections 195, 199 BGB), so that the declaration and its receipt remain provable for both sides. You may address access and erasure requests to the organisation or to us; we forward them as described in Section 18.
23. Changes to this Privacy Policy
We update this Privacy Policy when the processing operations, the services used, or the legal situation change. The version published on this page applies; the effective date is stated above.
The German version of this Privacy Policy is authoritative; versions in other languages are non-binding convenience translations.