GDPR Compliant

GDPR-compliant appointment booking

Every online booking is the processing of personal data. That means your booking system must comply with the GDPR, or you are liable as the operator. Terminz is built from the ground up for German data protection law.

Who is responsible for what

The GDPR splits the roles clearly. Confusing them means signing the wrong contract.

ControllerArt. 4 (7) GDPR

That is you. You decide which customer data you collect and why. Access requests, deletion and informing your customers sit with you.

ProcessorArt. 28 GDPR

That is us. Terminz processes the data solely on your instructions and never for its own purposes.

That is why a data processing agreement is needed between you and us. It is part of the terms and takes effect with the contract; you do not have to request it separately.

Data processing agreement

What a processor owes you

Bound by instructions
We process data only as you specify, never for our own purposes.
Confidentiality
Everyone with access is bound to confidentiality.
Technical and organisational measures
Encrypted transfer, servers in Germany, role-based permissions and logged access.
Sub-processors
Who we use is listed openly in the contract. If someone is added, you hear about it beforehand and can object.
Support with data subject rights
When a customer asks for access or deletion, we give you the data and the tools for it.
Reporting data breaches
We report an incident to you without delay so you can meet your 72-hour deadline.
Deletion after the contract ends
When the contract ends the data is deleted or returned, apart from statutory retention obligations.
Evidence and audits
You may check that we hold to this, and you get the evidence for it.

Not every email rests on the same basis

Terminz sends four kinds of message to your customers. Each has its own legal basis and its own off switch.

Confirmations
Booking confirmation, change, cancellation, receipt. The basis is performance of the contract under Art. 6 (1)(b) GDPR.
Reminders
The reminder before an appointment is part of the service and runs on the same basis.
Marketing
Campaigns and promotions only go out with explicit consent, confirmed by double opt-in and revocable at any time.
Review requests
Asking for a review counts as marketing. It needs the same consent and the same way to opt out.

Frequently asked GDPR questions

What is the GDPR and why does it apply to me?

The GDPR regulates the handling of personal data in the EU. As soon as you store customer data for appointments, even just name and phone number, you are legally responsible. This applies regardless of business size.

Is booking data considered sensitive?

Yes. Name, contact details and appointment history are personal data. If you also record health data (e.g., for beauty or wellness treatments), this counts as a special category under Art. 9 GDPR and is subject to stricter rules.

Do I need a Data Processing Agreement (DPA)?

Yes. As soon as you use booking software that processes your customer data, you must sign a DPA with the provider under Art. 28 GDPR. Terminz provides a DPA by default. Without a DPA, use is not legally permitted.

Can my provider use US servers?

Since the CJEU's Schrems II ruling, a transfer to the USA is only permitted on a sound legal basis. With Terminz the application, the database and the object storage run in Germany. Payment processing, email delivery and maps rely on providers that also process in the USA; this is based on the EU-US Data Privacy Framework or the Standard Contractual Clauses and is disclosed per provider in the DPA.

What rights do my customers have?

Your customers have, among others, the right to access (Art. 15), rectification (Art. 16), deletion (Art. 17) and data portability (Art. 20). Terminz enables full data export and secure deletion as part of the platform.

Do I have to delete old customer data?

Yes. Under the storage limitation principle (Art. 5(1)(e) GDPR), data may only be stored as long as needed. For hairdressing services that's usually a few years, though tax retention obligations may require longer. Terminz offers deletion routines that help.

This page explains the legal position and is not legal advice. For your specific case, please ask your lawyer or data protection officer.

Start GDPR-compliant with Terminz

You don't need to be a data protection expert. Terminz handles the technical requirements, and you focus on your salon.