Does Zimun conclude an AVV (data processing agreement) with the practice?
Yes. The data processing agreement under Art. 28 GDPR is part of the usage contract and is concluded together with it — there is no separate signature round. You can request it in text form at any time, and the current version is published at zimun.online/avv.
Where is patient booking data stored?
In the EU. The platform runs on Google Cloud Platform in the region europe-west3, Frankfurt am Main. Transactional emails are sent through Mailgun's EU region, with open and click tracking disabled.
Who is the controller of patient data — the clinic or Zimun?
For your patients' booking data, the clinic is the controller and Zimun is the processor under Art. 28 GDPR, acting on the clinic's documented instructions. Zimun acts as a controller of its own only for running the platform itself — accounts, security, billing. Annex 4 of the data processing agreement allocates every processing operation to one of those two roles, bindingly.
How is health-related data treated?
The platform has no dedicated fields for health data and does not need any to operate. Where appointment data — the selected service and provider, or a voluntary free-text note — reveals health information in an individual case, Zimun processes it strictly under the data processing agreement, and the clinic remains responsible for a matching exception under Art. 9(2) GDPR. The agreement states this openly rather than leaving it unaddressed.
What data does a patient booking require, and how long is it kept?
A booking takes a name, an email address, and optionally a phone number — patients never create an account. Contact data is stored separately from the rest of the appointment record, and it is deleted automatically as a rule one month after the appointment; technical logs are kept for 30 days.