Privacy Policy

This is an English translation provided for convenience. The legally binding version is the German one; in case of any discrepancy, the German version prevails.

Protecting your data matters to us — and, frankly, it is also a selling point. This policy informs you pursuant to the General Data Protection Regulation (GDPR) and the Austrian Data Protection Act (DSG) about which personal data we process, for what purpose, and what rights you have.

1. Controller

Develogix Agency e.U. (zeitl is a product of Develogix Agency e.U.)
Owner: Raphael Planer
Johannes-Filzer-Straße 46, 5020 Salzburg, Austria
E-mail: office@develogix.at

2. What matters most: where tracking occurs — and where it does not

No marketing tracking takes place on the booking pages of our businesses or in your customer account. When you book an appointment with a business, only a technically necessary session cookie is set — it keeps the booking process together and protects against abuse (CSRF). If you choose to stay signed in when booking, a login cookie with a lifetime of one year is added; it serves solely the sign-in you requested and can be ended at any time by signing out (Section 3.6). Such cookies do not require consent. No Meta Pixel, no analytics tools, no cross-site profiles. This is a deliberate decision: this data belongs to the business, not to us.

On our own website (zeitl.at) and in the backend for businesses we additionally use the Meta Pixel to measure which of our ads on Facebook and Instagram lead to a registration. It is loaded exclusively with your consent — which is why you see a cookie banner there. If you decline, no pixel is loaded and no marketing cookie is set; zeitl works in full without it. Details in Section 3.8. Via the same banner you may also consent to a functional referral cookie if you come to us via a “Refer a friend” link (Section 3.10).

For reach measurement we use Pirsch Analytics. The analysis runs purely server-side on our own infrastructure, entirely without cookies and without building personal profiles, and therefore does not require consent (Art. 6(1)(f) GDPR).

3. What data we process

3.1 Server logs

When you visit the website, our hosting provider (Hetzner Online GmbH, Germany) technically processes connection data (IP address, date and time, page accessed, browser type). The legal basis is our legitimate interest in secure and stable operation (Art. 6(1)(f) GDPR). Hosting takes place exclusively in the EU; logs are automatically deleted after a short time.

3.2 Contact

If you contact us by e-mail, we process your details to handle the request (Art. 6(1)(b) and (f) GDPR). The data are deleted as soon as they are no longer needed for processing and no statutory retention obligations apply.

3.3 Registration and operation of your zeitl account

Upon registration we process name, e-mail address and password (stored only as a cryptographic hash) as well as the data of your business (name, address, opening hours, services). The legal basis is the performance of a contract (Art. 6(1)(b) GDPR). Payment data for subscription billing are processed by our payment service provider Stripe (see Section 5).

3.4 Booking data in a business's customer database — zeitl as data processor

Once you book an appointment with a business, that business creates an entry about you in its customer database (your appointments with it, internal notes, no-show/cancellation counters, an optional online block). For these business-specific data the respective business is the data controller — zeitl processes them as a data processor pursuant to Art. 28 GDPR on the basis of a Data Processing Agreement (DPA) concluded in the app. Each business can see only its own appointments with you; the online block and the counters apply exclusively per business. This data belongs to the business: it can be exported at any time and is never used by us for our own purposes or passed on.

If a business records an appointment as a no-show, it may have you notified about this by email. The business writes the text of that message; zeitl sends it on the business's behalf and appends a note about a possible block from online booking. The legal basis is the business's legitimate interest in the utilisation of its appointments (Art. 6(1)(f) GDPR). The message may be sent automatically if a past appointment was not ticked off in the business's calendar and the business has configured such appointments to count as no-shows.

3.5 Your zeitl customer account — zeitl as controller

To book online, you need a zeitl customer account. It is cross-business: with one account you book with all zeitl businesses and see your appointments bundled under "My Appointments". For this account we process name, e-mail address and phone number. The phone number is the unique identifier of your account and is confirmed by a one-time code; the e-mail address is used for sending and for password-free login via a sign-in link. For these identity and login data, zeitl (Develogix e.U.) is the data controller; the legal basis is the performance of a contract (Art. 6(1)(b) GDPR). The business you are booking with receives from your account only the contact data necessary for the appointment. You can have your customer account deleted at any time (see Section 7).

Because the account applies across businesses, you are recognised on every zeitl booking page while you are signed in — your name and contact details are then already filled in. This display happens in your browser only: your data reach the respective business only once you actually book an appointment there.

3.6 Signing in with a one-time code and the login cookie

If you are not signed in, you identify yourself when booking with your phone number and a 6-digit one-time code. By default we send the code via WhatsApp from our central zeitl number; at your request — or if delivery fails — also by e-mail to the address on file in your account, or by SMS. We process your phone number or e-mail address, the code and the time; the code is stored only in encrypted (hashed) form and expires after a few minutes. The purpose is to prove that the appointment and the account really are yours. The legal basis is the performance of a contract as well as our legitimate interest in secure accounts and protection against fraudulent bookings (Art. 6(1)(b) and (f) GDPR). If the code goes via WhatsApp, what is described in Section 3.9 about transfers to WhatsApp/Meta applies in addition.

When booking you can choose whether you want to stay signed in on this device. If you leave the box ticked, we store a login cookie with a lifetime of one year so that you can book without a code in future. If you untick it, the sign-in applies only to the current session and ends when you close the browser. The cookie serves solely the sign-in you requested, not advertising or analytics; you can sign out at any time — directly on the booking page via "Not you?" or in the customer portal.

3.7 Protection against spam and bots (Cloudflare Turnstile)

On the registration form and on the public booking pages we use Cloudflare Turnstile — a cookie-free alternative to captchas that detects and blocks automated requests (bots). Turnstile processes technical signals from your browser (including IP address, browser and device information, and interaction patterns) and generates a unique, short-lived verification token, which we verify server-side against Cloudflare. No cookies are set and no cross-site profiles are created. The legal basis is our legitimate interest in protection against abuse, spam and automated bookings (Art. 6(1)(f) GDPR). The provider is Cloudflare acting as a data processor (see Section 4).

3.8 Meta Pixel (Facebook and Instagram) — only with your consent

On our website and in the backend for businesses we use the Meta Pixel of Meta Platforms Ireland Ltd. (Merrion Road, Dublin 4, D04 X2K5, Ireland). It shows us which of our ads on Facebook and Instagram actually lead to a registration or subscription — without this measurement we could not use our advertising budget sensibly. The Pixel does not run on the businesses' booking pages or in the customer account (see Section 2).

Data processed: IP address, browser and device information, page accessed, referrer, time, and triggered events (page view, completed registration, completed onboarding, completed subscription including plan and price). If you are simultaneously logged into Facebook or Instagram, Meta may link these events to your account there. For this purpose, the cookies _fbp and _fbc are set with a retention period of three months each.

The legal basis is exclusively your consent (Art. 6(1)(a) GDPR and § 165(3) TKG 2021), which you grant via the cookie banner. Without consent, Meta's script is not loaded at all. You can withdraw your consent at any time with future effect — via the Cookie settings. Upon withdrawal we delete the cookies _fbp and _fbc set on our domain and no longer load the Pixel. Cookies that Meta has set on its own domains cannot be deleted by us technically — you manage those in your Facebook or Instagram settings.

Joint controllership: For the collection and transmission of data to Meta, we and Meta Platforms Ireland Ltd. are joint controllers pursuant to Art. 26 GDPR; the allocation is governed by Meta's Controller Addendum. Meta alone is responsible for subsequent further processing. You can exercise your data subject rights both against us and directly against Meta. Details on how Meta uses the data can be found in Meta's Privacy Policy; you can adjust your advertising settings at facebook.com/settings?tab=ads.

Third-country transfer: Data are also transferred to Meta Platforms, Inc. in the USA. Meta Platforms, Inc. is certified under the EU-US Data Privacy Framework; an adequacy decision of the European Commission of 10 July 2023 therefore exists for the USA. EU Standard Contractual Clauses apply additionally. Despite these safeguards, access by US authorities cannot be entirely excluded.

3.9 Appointment reminders and messages by SMS or WhatsApp

Before your appointment, the business automatically reminds you — depending on its settings by e-mail, SMS or WhatsApp. Such reminders form part of the appointment transaction; the legal basis is the performance of a contract or our legitimate interest in avoiding missed appointments (Art. 6(1)(b) and (f) GDPR). You can choose at the time of booking whether you receive reminders by SMS or WhatsApp.

If the WhatsApp channel is used, we transmit your phone number and the message text to WhatsApp Ireland Ltd. / Meta (see Section 4). This may result in a transfer to the USA (Meta Platforms, Inc.), safeguarded via the EU-US Data Privacy Framework and supplementary EU Standard Contractual Clauses; access by US authorities cannot be entirely excluded. How WhatsApp/Meta processes the data beyond this is governed by the WhatsApp terms.

In addition, at the time of booking you may voluntarily consent to receive news and offers from the business (by e-mail, SMS or WhatsApp). This consent is optional and not required for the booking (Art. 6(1)(a) GDPR) and can be withdrawn at any time with future effect — for example via an unsubscribe link or by a brief notice to the business. Without this consent you will only receive appointment-related messages.

3.10 Referral programme — “Refer a friend” cookie

If you come to us via another business's referral link (address containing ?ref=…), we store the referral code with your consent in a functional first-party cookie called zeitl_ref. Its sole purpose is to attribute your later registration to the referral so that the referring business receives its credit. Lifetime: 60 days.

The legal basis is your consent (Art. 6(1)(a) GDPR and § 165(3) TKG 2021), given via the cookie banner. Without consent the cookie is not set and no attribution takes place. You can withdraw your consent at any time with effect for the future via the cookie settings; the cookie is then deleted. No cross-site profiles are created and no data is transferred to third parties.

3.11 Visitor counting on booking pages — on behalf of the business

So that a business can tell how well its booking page works, we count visits there — without cookies, without names and without recognising you beyond the same day. The measurement runs purely on our server; no script is loaded and nothing is stored on your device. No third party is involved.

What is processed: the time of the visit, how far the booking got (page viewed, treatment chosen, time chosen, details filled in, booked), the treatment chosen first, the address of the referring site without path or parameters (e.g. “instagram.com”) including any campaign tags from the link (utm_*), the rough device type (phone, tablet, computer) and the country.

What happens to your IP address: it is not stored. It is used solely to derive the country; after that it feeds — together with your browser identifier and a daily rotating random value — into an irreversible hash that merely groups several visits on the same day. From the next day on, not even that hash can be linked to anyone. No profile is built across businesses: the same person produces a different value at every business.

Not counted: search engines and other bots, visits by the business's own team, and browsers sending “Do Not Track” or Global Privacy Control. The respective business is the controller for this analysis; zeitl acts as processor (section 3.4). The legal basis is the business's legitimate interest in shaping its booking offer to demand (Art. 6(1)(f) GDPR); as no access to your device takes place, no consent under § 165(3) TKG 2021 is required. Retention: at most 400 days, after which the rows are deleted automatically. The business can switch the counting off in its settings at any time.

3.12 E-mail sending and delivery log

All e-mails from zeitl — booking confirmations, reminders, cancellations, login links — are sent via the European sending service Lettermint (Lettermint B.V., Netherlands; see point 4). This transmits your e-mail address and the content of the message. Operations and delivery take place exclusively in European data centres; no transfer to third countries occurs.

For every e-mail sent we record whether it could be delivered — that is, the time, recipient address, type of message and the response of the receiving server (such as "delivered" or "address does not exist"). The business sees this status in its customer record. The sole purpose is to notice a booking confirmation that never arrived before you end up standing in front of a closed door. The legal basis is performance of the contract and the legitimate interest in demonstrably functioning appointment communication (Art. 6(1)(b) and (f) GDPR).

No read tracking: We do not use tracking pixels and do not record whether you opened an e-mail or clicked a link in it. Only technical delivery is recorded.

4. Recipients and data processors

We only use service providers that meet the requirements of the GDPR:

Transfers to third countries only take place where an adequacy decision or appropriate safeguards (e.g. Standard Contractual Clauses) exist.

5. Payment data

Credit and bank data are collected and processed directly by our payment service providers — subscription billing by Stripe, online deposits by Mollie — they do not reach our servers. Details: Stripe Privacy Policy, Mollie Privacy Policy.

6. Retention periods

We store personal data only for as long as necessary for the stated purposes or as required by statutory retention obligations (e.g. §132 of the Federal Fiscal Code (BAO): 7 years for accounting records). Upon deletion of your account, all business and customer data are permanently deleted — after a prior export option.

Automatic deletion of inactive free/trial accounts: If a business’s free or trial account remains inactive for more than 60 days (no login, no bookings), it is deactivated and, after a 30-day grace period, permanently deleted together with all business and customer data. We warn the business beforehand by email (7 days and 1 day in advance); logging in resets the period.

7. Your rights

You have the right at any time to access, rectification, erasure, restriction of processing, data portability and to object to the processing of your personal data. Please contact office@develogix.at. You may also lodge a complaint with the Austrian Data Protection Authority: dsb.gv.at.

You can delete your zeitl customer account yourself at any time: in the customer portal under "My Appointments" → "My Account" → "Delete account". Your identity data (name, e-mail, phone number) will be anonymised; appointments that have already taken place will remain with the respective business for accounting purposes (statutory retention obligation, §132 BAO).

8. Data security

We take appropriate technical and organisational measures to protect your data against loss, misuse and unauthorised access — including TLS encryption, hashed passwords, two-factor authentication and regular backups within the EU. We also prevent double bookings — but that is on the homepage.

9. Questions?

Data protection queries are answered by a human, in English or German: office@develogix.at

Version 2026-08-20 · As of: 20.08.2026