This is an English translation provided for convenience. The legally binding version is the German one; in case of any discrepancy, the German version prevails.
This Data Processing Agreement (DPA) specifies the data protection obligations between you as the controller (the business) and Develogix Agency e.U. as the data processor (zeitl) pursuant to Art. 28 GDPR. It applies to all personal data that zeitl processes on your behalf in the course of using the software.
1. Subject Matter and Duration
The subject matter is the processing of personal data by zeitl for the purpose of providing the appointment booking software. The duration corresponds to the term of the principal contract (use of zeitl). The controller has the right to issue instructions.
2. Nature, Purpose and Data Subjects
- Nature of processing: Collection, storage, organisation, display, sending of notifications, deletion and export within the scope of the software functions.
- Purpose: Appointment management, operation of the booking page, customer database, notifications, anonymous reach measurement of the booking page (no cookies, no storage of the IP address — can be switched off by the business) and — depending on the plan — payment initiation and statistics.
- Data subjects: End customers of the business and its employees.
- Categories of data: Contact data of end customers (name, e-mail, phone), appointment and booking data, internal notes, payment status (no full card data — these are processed directly by the payment service provider), technical usage data.
Special categories of personal data: To the extent that you as the controller record special categories of personal data within the meaning of Art. 9 GDPR (e.g. health information in consent forms/waivers or in internal notes), zeitl processes these exclusively on your documented instructions within the scope of the software functions. Ensuring that a valid legal basis exists under Art. 9(2) GDPR — as a rule the explicit consent of the data subject — is the sole responsibility of you as the controller. zeitl does not request such data on its own initiative.
Demarcation from the zeitl customer account: End customers book via a cross-business zeitl customer account (the identifier is the phone number confirmed by SMS, plus name and e-mail for login/sending). For this account zeitl itself is the controller (see Privacy Policy, Section 3.5) — it is not the subject of this DPA. The sole subject of this DPA is the business-specific data in the controller's customer database (their appointments, notes, counters, online block).
3. Obligations of zeitl as Data Processor
- Processing exclusively on documented instructions of the controller, unless required by law to do otherwise.
- Obligating all persons involved in processing to confidentiality.
- Implementing appropriate technical and organisational measures pursuant to Art. 32 GDPR (see Section 4).
- Supporting the controller in responding to data subject requests and in data protection impact assessments and reporting obligations, where necessary and possible.
- Promptly informing the controller upon becoming aware of any personal data breach.
- No use of data for own purposes. zeitl does not operate a marketplace and does not pass on the business's customer data to third parties for advertising purposes.
4. Technical and Organisational Measures (TOMs)
- Transport encryption (TLS) for all connections; passwords stored exclusively as a cryptographic hash.
- Access control via roles and permissions; two-factor authentication available.
- Hosting, database and backups exclusively in the EU (Hetzner, data centres in Germany/Finland). Regular, encrypted backups.
- Tenant separation: the data of each business is logically strictly separated.
- Logging of security-relevant processes, including administrative support access (impersonation).
5. Sub-processors
You consent to the use of the following sub-processors. All of them meet the requirements of the GDPR; transfers to third countries are made only with appropriate safeguards.
- Hetzner Online GmbH (Gunzenhausen, Germany; data centres in Germany and Finland): Hosting of the application, database and uploaded documents as well as encrypted backups — exclusively in the EU. ISO/IEC 27001 certified.
- Stripe Payments Europe, Ltd. (Ireland): Processing of the business's subscription payments to zeitl.
- Mollie B.V. (Netherlands): Processing of online deposits from end customers to the business (Basic/Pro).
- Lettermint B.V. (Zwolle, Netherlands): Sending of transactional e-mails (booking confirmations, reminders, login links) and feedback on their delivery. Processing and delivery take place exclusively in European data centres; no transfer to third countries occurs.
- seven communications GmbH & Co. KG (Kiel, Germany): Sending of the SMS with the one-time code to confirm the phone number and — depending on the plan — SMS reminders. EU hosting, ISO/IEC 27001 certified.
- WhatsApp Ireland Ltd. (Dublin, Ireland) / Meta Platforms: Delivery of appointment reminders and messages via WhatsApp, if the business has activated this channel and the end customer selects it. The phone number and message text are transmitted; a transfer to the USA (Meta Platforms, Inc.) takes place on the basis of the EU-US Data Privacy Framework, supplemented by EU Standard Contractual Clauses.
We will inform you in advance of any intended changes to this list; you may raise a justified objection.
6. Data Subject Rights and Deletion
zeitl supports you in responding to the rights of your end customers (access, rectification, erasure, restriction, data portability, objection). Customer data can be exported as CSV/JSON at any time. After termination of the contract, personal data will be deleted or returned at the controller's choice, unless statutory retention obligations apply.
7. Evidence and Audits
We will provide you with the information necessary to demonstrate compliance with Art. 28 GDPR and will enable reasonable audits — primarily by providing appropriate evidence, so as not to disproportionately disrupt ongoing operations.
8. Final Provisions
Austrian law applies. In the event of any conflict between this DPA and the principal contract, the provisions of this DPA shall prevail in matters of data protection law. Please direct data protection enquiries to office@develogix.at.
Version 2026-08-20 · As of: 20.08.2026.