This Data Processing Agreement governs the processing of personal data by Terminz on behalf of your business under Art. 28 GDPR.
When you use Terminz as booking software, Terminz processes personal data of your customers on your behalf. In this case, you are the controller under Art. 4(7) GDPR, and Terminz acts as the processor under Art. 4(8) GDPR.
Under Art. 28 GDPR, a written Data Processing Agreement between you and Terminz is required before customer data is processed. Terminz provides this DPA by default for all customers.
Data Processor
Bornwerk UG (haftungsbeschränkt)
Märkische Straße 193, 44141 Dortmund, Deutschland
Data Controller
The legal entity that is the contracting party of the respective Terminz contract and uses Terminz to process customer data for appointment booking. Each legal entity holds its own contract and its own DPA.
Terminz processes personal data solely for the purpose of providing the appointment booking and salon management platform. The processing covers the following categories:
Data categories
Name, contact details, appointment history, payment data, optionally health-related notes
Nature of processing
Storage, retrieval, modification, internal transmission, deletion
Contact
Terminz uses the following vetted sub-processors. All providers are covered by a DPA under Art. 28 GDPR or appropriate safeguards under Chapter V GDPR.
| Provider | Purpose | Location | Safeguard |
|---|---|---|---|
| Hetzner Online GmbH | Server hosting and database operation (application server, PostgreSQL) | Germany (Falkenstein) | Processing in Germany; Art. 28 GDPR DPA |
| Amazon Web Services (AWS) | Object storage (file uploads, S3) and secrets management | Germany (eu-central-1, Frankfurt) | Processing in the EU; Art. 28 GDPR DPA |
| Cloudflare, Inc. | Content delivery network (CDN) and reverse proxy; processes inbound requests including IP address | EU edge / USA | EU-US Data Privacy Framework, otherwise Standard Contractual Clauses (SCC) |
| Stripe Payments Europe, Ltd. / Stripe, Inc. | Payment processing (registration, subscription) | Ireland / USA | EU-US Data Privacy Framework, otherwise Standard Contractual Clauses (SCC) |
| fiskaly GmbH | TSE signing for cash-register transactions (KassenSichV / cloud TSE) | EU | Processing in the EU; Art. 28 GDPR DPA |
| Resend (Plus Five Five, Inc.) | Transactional emails (booking confirmations, notifications) | USA | EU-US Data Privacy Framework, otherwise Standard Contractual Clauses (SCC) |
| Sentry (Functional Software, Inc.) | Error tracking and application monitoring | USA | EU-US Data Privacy Framework, otherwise Standard Contractual Clauses (SCC) |
| Google Ireland Ltd. / Google LLC | Analytics (incl. Google Tag Manager), maps/address lookup, sign-in | Ireland / USA | EU-US Data Privacy Framework, otherwise Standard Contractual Clauses (SCC) |
As data processor, Terminz commits to the following obligations under Art. 28(3) GDPR:
For questions about the DPA, data protection matters, or to exercise data subject rights, contact:
[email protected]This document is for informational purposes. The binding Data Processing Agreement is provided and signed upon entering a contract with Terminz. For legal inquiries, contact [email protected].