Last updated: 2026-08-23
Agreement on the processing of personal data on behalf of a controller (Article 28 GDPR)
between
the organisation (party to the platform usage agreement for the Zimun platform) — hereinafter the “controller” —
and
Zimun Labs UG (haftungsbeschränkt), Buchenteich 3, 73773 Aichwald, Germany, commercial register B of the local court (Amtsgericht) of Stuttgart, HRB 806662, represented by its managing director Svetlana Ponomarenko — hereinafter the “processor” or “Zimun” —
Section 1 Subject matter and duration of the processing
(1) Zimun provides the controller with the Zimun scheduling platform (zimun.online) as software as a service (the “main agreement”, i.e. Zimun's Terms and Conditions together with the selected plan). Within the scope of the main agreement, Zimun processes personal data on behalf of the controller.
(2) The subject matter of this DPA is the processing of personal data entered into the platform by the controller or its end customers (Annex 1).
(3) The duration of this DPA corresponds to the term of the main agreement. Termination of the main agreement is at the same time termination of this DPA with effect from the same date. For data that is still stored after termination of the main agreement until its final deletion or return under Section 8, the obligations of this DPA continue to apply.
Section 2 Nature and purpose of the processing, categories of data, data subjects
The nature, purpose, categories of data and categories of data subjects are set out in Annex 1 (Description of the processing).
Section 3 Responsibility and instructions
(1) The controller is solely responsible for the lawfulness of the processing and for safeguarding the rights of data subjects (Article 4(7) GDPR).
(2) Zimun processes the data exclusively on documented instructions from the controller (Article 28(3)(a) GDPR). The controller's use and configuration of the platform features constitutes a documented instruction; supplementary individual instructions require text form.
(3) If Zimun is of the opinion that an instruction infringes the GDPR or other data protection provisions, Zimun informs the controller without undue delay (Article 28(3), second subparagraph, GDPR) and may suspend execution until the matter is clarified.
(4) Processing for Zimun's own purposes does not take place within the scope of this DPA. Which processing is carried out on behalf of the controller and for which Zimun is itself the controller follows bindingly from Annex 4 (Allocation of roles). The operations listed in section B there — in particular accounts, operation and security of the platform, abuse prevention, billing and Zimun's own statutory obligations — are not the subject of this DPA and are described in Zimun's privacy policy. Receiving and handling bookings, including the related appointment notifications, does not fall within that scope but constitutes processing on behalf of the controller (Annex 4, section A).
Section 4 Confidentiality
Zimun only engages persons who have committed themselves to confidentiality or who are under an appropriate statutory obligation of confidentiality (Article 28(3)(b) GDPR).
Section 5 Security of processing (Article 32 GDPR)
(1) Zimun implements the measures described in Annex 2 (Technical and organisational measures) and keeps them at the state of the art.
(2) Zimun may further develop the measures provided that the level of protection is not reduced.
Section 6 Sub-processors
(1) The controller grants general authorisation (Article 28(2) GDPR) for the use of the sub-processors listed in Annex 3.
(2) Zimun informs the controller of intended changes (addition or replacement) at least 30 days before they take effect, in text form (for example by email or in-app notification). The controller may object on important data protection grounds; in the event of an objection, both parties have a right of extraordinary termination of the main agreement with effect from the date on which the change takes effect.
(3) Zimun imposes on each sub-processor, by contract, essentially the same data protection obligations as those set out in this DPA, before that sub-processor begins processing personal data (Article 28(4) GDPR). Those contracts are in place for the active sub-processors listed in Annex 3. Where a sub-processor listed there is not yet active, this is expressly noted in Annex 3; the contract is concluded before activation, and activation is notified in accordance with paragraph 2.
(4) Clarification — AI chat / OpenAI: The optional AI booking chat is operated exclusively with the controller's own OpenAI API key. OpenAI is therefore not a sub-processor of Zimun, but a direct processor of the controller. The controller concludes the required data processing agreement with OpenAI itself and is responsible for the legal basis, the third-country transfer and informing its end customers. In this respect, Zimun transmits chat content exclusively on instruction to the OpenAI endpoint designated by the controller.
(5) Clarification — online payment feature / Stripe: Where the controller activates the optional online payment feature, end-customer payments are processed via the controller's own Stripe account (Stripe Payments Europe, Ltd., Ireland); the basis is the controller's own agreement with Stripe. Stripe is not a sub-processor of Zimun in this respect: for executing the payments and for its own statutory verification and safeguarding duties (e.g. fraud and money-laundering prevention), Stripe acts as an independent controller; otherwise Stripe belongs to the controller's own service-provider chain. In this respect, Zimun transmits payment and booking-reference data on instruction to the controller's Stripe account and processes on behalf of the controller only the payment data listed in Annex 1; the end customer's email address is not transmitted to Stripe. Zimun does not collect or store payment-instrument data (e.g. card data); the end customer enters it directly with Stripe. Where Stripe acts for the billing of the fee Zimun charges the controller for the payment feature, this is processing within Zimun's own area of responsibility outside this DPA (Section 3(4)); no end-customer data is involved in that.
Section 7 Assistance to the controller
(1) Zimun assists the controller by appropriate technical and organisational measures in fulfilling data subject rights (Articles 12–23 GDPR; Article 28(3)(e) GDPR), in particular through the platform's rectification and deletion functions and — where export functions are available — through those; otherwise Zimun makes the data in question available on request in a common, machine-readable format (see the data access provision of the Terms and Conditions).
(2) Zimun assists the controller with the obligations under Articles 32–36 GDPR (security, notification of breaches, data protection impact assessment, consultation), taking into account the nature of the processing and the information available to Zimun (Article 28(3)(f) GDPR).
(3) Zimun notifies the controller of personal data breaches affecting the controller's processed data without undue delay after becoming aware of them (Article 33(2) GDPR).
Section 8 Deletion and return
(1) After termination of the main agreement, Zimun deletes the data processed on behalf of the controller or returns it at the controller's choice, unless a statutory retention obligation prevents this (Article 28(3)(g) GDPR). Final deletion takes place — subject to an earlier deletion request by the controller — 30 days after termination of the main agreement; within that period the controller may retrieve its data or revoke the termination (see the Terms and Conditions, provision on deletion after the end of the contract).
(2) Irrespective of this, the platform's automated deletion routines apply during the term of the contract (in particular deletion of the contact data relating to appointments one month after the appointment, or, for appointments paid online via the payment feature, 180 days after the appointment, because payments may still be subject to chargebacks or payment disputes within that period (Section 6(5)) — the remaining appointment data (time, service, resource) is then contact-data-reduced; in individual cases, in particular for small organisations or distinctive services, it may still relate to the end customer and therefore continues to be treated as personal data within the meaning of this DPA — and deletion of technical logs after 30 days).
Section 9 Evidence and audits
(1) Zimun makes available to the controller all information necessary to demonstrate compliance with the obligations under Article 28 GDPR (Article 28(3)(h) GDPR), as a rule by means of suitable documentation (for example a description of the technical and organisational measures, certifications/audit reports of the infrastructure providers, in particular Google Cloud).
(2) On-site inspections are permitted following prior notice with reasonable notice periods during usual business hours, insofar as the documentation is not sufficient in the individual case; trade secrets and other customers' data remain protected.
(3) The controller bears the costs of its own audits. For support services that go beyond providing existing documentation and the cooperation legally owed under Article 28(3)(h) GDPR, Zimun may charge reasonable remuneration based on time and effort; the controller's audit right is not thereby restricted or made conditional on advance payment.
Section 10 Third-country transfers
(1) Processing takes place in principle in the EU (Google Cloud region europe-west3, Frankfurt am Main).
(2) Insofar as sub-processors transfer data to third countries (Annex 3), this only takes place where an adequacy decision exists (Article 45 GDPR, for example the EU-U.S. Data Privacy Framework) or appropriate safeguards are in place (Article 46 GDPR, in particular the EU standard contractual clauses).
Section 11 Liability; final provisions
(1) Article 82 GDPR and the liability provisions of the main agreement apply to liability.
(2) Amendments and supplements to this DPA require text form. In the event of contradictions between this DPA and the main agreement, this DPA prevails in matters of data protection law.
(3) German law applies; the place of jurisdiction is determined by the main agreement.
Annex 1 — Description of the processing
- Subject matter: Provision and operation of the Zimun scheduling platform for the controller
- Nature of the processing: Collection via booking and administration interfaces, storage, display, transmission (notifications, calendar synchronisation, optional AI chat transport), automated deletion
- Purpose: Management of the controller's appointments, services, resources, team members and end-customer communication
- Categories of data: End customers: name, email address, telephone number, appointment data (service, resource, time), voluntary free-text entries, records of consent (for example acceptance of the Terms and Conditions, consent to SMS reminders including the time of consent); where applicable chat content (where the AI chat is enabled); waitlist entries; where the online payment feature is activated: payment data of the booking (payment status, amount, currency, time, refund status, assignment to booking and organisation) — no payment-instrument data such as card numbers; that is collected exclusively by Stripe (Section 6(5)). attendance details for the appointment (execution timestamps, attended or no-show mark, internal free-text note entered by the controller). Team members: name, email address, account/profile data, working/availability hours, calendar metadata (where synchronisation is enabled), actor identifiers for appointment operations (which member started, ended or recorded attendance for an appointment, each with a timestamp)
- Special categories (Article 9): The platform provides no dedicated data fields for special categories of personal data and does not require such data for its operation. However, where the controller offers health-related services, the appointment data (in particular the selected service and provider) and free-text entries may in individual cases reveal health data within the meaning of Article 9 GDPR; Zimun processes such data exclusively under this DPA as part of the data categories listed above. The controller is responsible for ensuring that an exception under Article 9(2) GDPR (where applicable in conjunction with Section 22 BDSG) applies to such processing, and instructs its end-customers, as part of data minimisation, not to enter health information in free-text fields unless required.
- Data subjects: The controller's end customers; the controller's team members/employees
- Duration: Term of the main agreement; automated deletion periods pursuant to Section 8(2)
Annex 2 — Technical and organisational measures (Article 32 GDPR)
The following measures describe the current state of the platform. Zimun develops them further in accordance with Section 5(2) without reducing the level of protection.
- 1. Infrastructure and physical access control: Operation exclusively in Google Cloud Platform data centres (App Engine, Firestore), EU region europe-west3 (Frankfurt am Main); no self-operated servers. Physical access control, environmental security, redundancy and certifications (inter alia ISO/IEC 27001, 27017, 27018, SOC 1/2/3) rest with the infrastructure provider and are evidenced through its audit reports (Section 9(1)).
- 2. Access control for production systems: Access to the production environment and the database is restricted via Google Cloud IAM to the managing director and secured by multi-factor authentication; the application runs under dedicated service accounts with the minimum necessary privileges.
- 3. Secret management: Application secrets (signing and encryption keys, API keys, service credentials, the private key of the database service account) are held exclusively in Google Secret Manager and fetched at runtime; they are not kept in source code, not in configuration files, and not in the deployed application package. Rotation is performed by adding a new version of the respective secret, with no code change. Clarification: identifiers that are public by design are not secrets within the meaning of this undertaking and are not covered by it — this concerns the browser key for map display, which is delivered in the HTML, and the search-engine indexing verification key, which the respective protocol requires us to publish at a public address. Such identifiers are protected by origin and usage restrictions rather than by secrecy.
- 4. User authentication: Sign-in exclusively via OAuth (Google, Microsoft); Zimun stores no passwords.
- 5. Authorisation and separation requirement: Role- and organisation-scoped permission checks in the application; logical tenant separation per organisation at the data level; no organisation has access to another organisation's data.
- 6. Transmission and storage control: TLS encryption (HTTPS) for all connections; encryption at rest by the infrastructure provider (Google Cloud standard).
- 7. Application security: Protection against cross-site request forgery (CSRF) and rate limiting on security-relevant endpoints.
- 8. Data minimisation through data separation: End-customer contact data is stored in a separate, specially protected record apart from the remaining appointment record; the general appointment record contains no contact data.
- 9. Deletion concept: An automated daily deletion run removes the contact data relating to appointments one (1) month after the appointment (for appointments paid online via the payment feature: 180 days after the appointment, Section 8(2)); technical server logs are retained for 30 days; deletion at the controller's request; final deletion after the end of the contract in accordance with Section 8.
- 10. Input control: Audit logging of administrative operations; technical server logs (30 days).
- 11. Availability and resilience: Redundancy, backups and recovery mechanisms of the managed infrastructure (App Engine/Firestore); monitoring of the service.
- 12. Instruction control: Selection of sub-processors in accordance with Article 28 GDPR; data processing agreements with all active sub-processors listed in Annex 3 (Section 6(3)).
- 13. Limits of the current measures: Regular external penetration tests and formalised, documented recovery exercises (restore tests) are not currently carried out; recoverability relies on the mechanisms of the managed infrastructure.
Annex 3 — Approved sub-processors
-
Google Cloud EMEA Limited (Google Cloud Platform: App Engine, Firestore, Cloud Logging, Secret Manager)
- Service: Hosting, database, operation
- Place of processing: EU — region europe-west3 (Frankfurt am Main); support/incidental access by Google LLC (USA) possible
- Transfer mechanism: Google Cloud Data Processing Addendum; EU standard contractual clauses / EU-U.S. Data Privacy Framework
-
Mailgun Technologies, Inc. (Sinch group)
- Service: Transactional email delivery (open and click tracking disabled)
- Place of processing: Mailgun's EU region (messages processed and stored within the European Union); provider is US-incorporated, so support access from a third country cannot be entirely excluded
- Transfer mechanism: Mailgun/Sinch DPA; EU standard contractual clauses or EU-U.S. Data Privacy Framework
-
Bird B.V. (formerly MessageBird), Amsterdam, Netherlands
- Service: Sending of SMS appointment reminders (only where the organisation has enabled the feature and with the end customer's consent; the telephone number and the message text are transmitted)
- Place of processing: Netherlands (EU)
- Status: Not yet active. SMS sending is not currently enabled platform-wide. Before it is enabled, Zimun will conclude the data processing agreement with Bird and verify the processing locations and any third-country transfers (Articles 45/46 GDPR); this Annex will be updated beforehand and changes will be communicated in accordance with Section 6(2).
-
Google Ireland Limited (Google Maps Platform: Maps JavaScript API, Geocoding, Time Zone)
- Service: Map display and address search on the settings pages for the organisation and its locations, and server-side determination of the coordinates and time zone of an address
- Categories of data concerned: in the browser, the member's IP address and browser details plus the address entered into the address search; server-side, the address entered by the controller. No end-customer data — Google Maps is not embedded on the public booking pages.
- Place of processing: EU/Ireland; transfer to Google LLC (USA) possible
- Transfer mechanism: Google Maps Platform Data Processing Terms; EU Standard Contractual Clauses / EU-U.S. Data Privacy Framework
- Particularity: the browser-side embedding occurs only after an explicit click by the member ("Load map"), preceded by a notice that the IP address will be transmitted. Before that click no connection to Google takes place.
Addition regarding the calendar and video features (not sub-processing, but a transfer requiring disclosure): where a video meeting is provided for an appointment, the end customer's email address is added as a guest to the meeting created via the member's Google account; Google then sends a calendar invitation. The calendar entry Zimun writes into the member's calendar, by contrast, contains no end-customer data (only the service name and the time slot), and out of the member's calendar only busy time slots are taken, not the subject lines of their private appointments.
Not in Zimun's sub-processor chain: OpenAI (AI chat) — engaged directly by the controller with the controller's own API key (Section 6(4)). Stripe (online payment feature) — the controller's payment service provider via the controller's own Stripe account, and an independent controller for executing payments and for its own statutory duties (Section 6(5)). Google Ireland Limited and Microsoft Ireland Operations Limited act as independent controllers for the OAuth sign-in; Google Calendar/Google Meet are connected at the initiative of the respective member via that member's own Google account.
Annex 4 — Allocation of roles (binding)
This annex allocates every processing operation to a role. It governs this contract, the Terms and Zimun's privacy policy; descriptions elsewhere that deviate are to be construed in accordance with this annex.
A. Processing on behalf of the organisation (Zimun = processor, Art. 28 GDPR)
The organisation determines the legal basis; Zimun requires no legal basis of its own in this respect.
- A1 — End-customer data (name, email address, phone number), appointment and booking data, waitlist entries, optional free-text information. Data subjects: end customers.
- A2 — Receiving, changing and cancelling bookings via the organisation's booking pages and management interfaces, including bookings submitted via API and MCP access. Data subjects: end customers.
- A3 — Appointment-related transactional messages to end customers (confirmation, reminder, change, cancellation, necessary follow-ups) including SMS reminders; delivery logs for those messages. Data subjects: end customers.
- A4 — Calendar synchronisation and creation of video-appointment invitations via the respective member's account. Data subjects: end customers, members.
- A5 — Forwarding of chat content to the OpenAI endpoint designated by the organisation (Section 6(4)). Data subjects: end customers.
- A6 — Where the online payment feature is activated: payment data of the booking (status, amount, currency, time, refund status, assignment to booking and organisation). Data subjects: end customers.
- A7 — Master and availability data of team members, insofar as the organisation enters it for scheduling. Data subjects: members.
B. Processing for which Zimun is itself the controller
Not the subject of this DPA; described in Zimun's privacy policy.
- B1 — Creation and administration of user accounts, sign-in via OAuth, role and permission management. Legal basis: Art. 6(1)(b) GDPR where the data subject is themselves the contracting party (in particular sole traders); otherwise Art. 6(1)(f) GDPR (interest in performing the contract with the organisation).
- B2 — Records of acceptance of the legal documents (version, checksum, time, acting person). Legal basis: Art. 6(1)(f) GDPR (evidence of incorporation under Section 305(2) BGB, defence against claims) and (b) where the acting person is themselves the contracting party.
- B3 — Operation, availability and security of the platform, technical server logs, backups. Legal basis: Art. 6(1)(f) GDPR, in conjunction with Art. 32 GDPR.
- B4 — Abuse and fraud prevention, rate limiting, pseudonymous session identifiers of the AI chat. Legal basis: Art. 6(1)(f) GDPR.
- B5 — Billing of Zimun's charges to the organisation, invoicing, payment reconciliation. Legal basis: Art. 6(1)(b) and (c) GDPR.
- B6 — Zimun's own communication with the organisation and its members (account-service notices, support, notices under Sections 9(4) and 17 of the Terms). Legal basis: Art. 6(1)(b) or (f) GDPR.
- B7 — Compliance with Zimun's own statutory obligations (commercial and tax retention, due-diligence, reporting and cooperation duties under the PStTG, information to authorities, the notice procedure under Art. 16 DSA). Legal basis: Art. 6(1)(c) GDPR.
- B8 — Use of the website and the public booking pages outside a booking (language selection, session and CSRF cookies). Legal basis: Art. 6(1)(f) GDPR, Section 25(2) no. 2 TDDDG.
- B9 — Web analytics. Legal basis: Art. 6(1)(a) GDPR, Section 25(1) TDDDG.
C. Delimitation
Where Zimun accesses content from section A to prevent abuse (B4) or to comply with a statutory obligation (B7), Zimun acts in that respect as processor and requires the organisation's instruction, unless Union or Member State law obliges Zimun directly (Art. 28(3)(a) GDPR); in that case Zimun informs the organisation, unless that law prohibits it. There is no joint controllership (Art. 26 GDPR).