This agreement governs the processing of personal data by Bornwerk on behalf of the business customer under Art. 28 GDPR. It becomes part of the contract when the contract is concluded.
Last updated: 16 August 2026
When you use Terminz for your business, Bornwerk processes personal data of your customers and staff on your behalf. You remain the controller and Bornwerk acts as processor. Art. 28 GDPR requires a contract setting out the processor's obligations.
This page is that contract. You do not need to request it or sign it separately: it is an annex to Part B of the General Terms and Conditions and is concluded in electronic form together with the contract under Art. 28(9) GDPR. For processing where Bornwerk is itself the controller, the privacy policy applies instead.
Data Processor
Bornwerk UG (haftungsbeschränkt)
Märkische Straße 193, 44141 Dortmund, Deutschland
Data Controller
The legal entity that is the contracting party of the respective Terminz contract and uses Terminz to process customer data. Each legal entity holds its own contract and its own DPA; several locations of the same legal entity are covered by the same agreement.
This agreement sets out the data protection obligations of the parties arising from the use of the software under Part B of the General Terms and Conditions. It applies to all processing of personal data that Bornwerk carries out for the business customer.
In the event of a conflict between this agreement and the remaining provisions of the contract, this agreement prevails insofar as the processing of personal data is concerned.
The business customer is the controller under Art. 4(7) GDPR for the personal data of its end customers and staff processed through the software. It alone must ensure that a legal basis exists for that processing and that data subjects are informed under Art. 13 and 14 GDPR.
Bornwerk acts as processor under Art. 4(8) GDPR in that respect. For Bornwerk's own processing — in particular the business customer's contract, billing and account data as well as visitor data on terminz.com — Bornwerk is the controller; the privacy policy applies there, not this agreement.
Each legal entity holds its own contract and therefore its own data processing agreement. Where the business customer operates several locations under the same legal entity, they are covered by the same agreement.
Where an end user creates their own user account with Bornwerk, Bornwerk is the controller for the account and login details that end user provides and for their cross-business appointment overview; the legal basis is the usage contract under Part A of the General Terms and Conditions (Art. 6(1)(b) GDPR). Bornwerk is likewise the controller for the platform-wide profile of a person's contact details, through which the business customer can find an existing person and attach a customer relationship with its own business; it prevents duplicate records and keeps the person's own appointment overview together. Neither processing is covered by this agreement. The information a business customer collects or adds about an end user remains processing on its behalf under this agreement and is not made accessible to other business customers.
This agreement is concluded together with the contract under B.3 of the General Terms and Conditions and runs for its duration. It ends when the contract ends, without separate notice being required.
This agreement cannot be terminated without terminating the contract. The obligations under § 12 survive the end of this agreement.
Bornwerk processes personal data solely for the purpose of providing and operating the contractually agreed software: appointment booking and management, customer and staff administration, time tracking, payment and point-of-sale functions, notifications, and the business customer's public profile page.
Processing comprises collection, recording, organisation, storage, adaptation, retrieval, consultation, use, transmission, restriction, erasure and destruction of personal data. It takes place in member states of the European Union unless § 14 provides otherwise.
The data subjects are the business customer's end customers, its staff and contributors, and the contact persons of its business partners. The following categories of data are processed:
The business customer alone is responsible for processing special categories of personal data. It must ensure that a condition under Art. 9(2) GDPR applies — as a rule the data subject's explicit consent under Art. 9(2)(a) GDPR — and that such details are not entered in fields not intended for them.
Bornwerk processes personal data only on documented instructions from the business customer, including with regard to transfers to third countries (Art. 28(3)(a) GDPR). The contract including this agreement, together with the settings the business customer makes in the software, constitute the initial instruction.
Individual instructions are issued in text form to [email protected]. The owner of the legal entity and the persons it designates are authorised to issue instructions.
If Bornwerk considers that an instruction infringes the GDPR or other data protection provisions, it informs the business customer without delay (Art. 28(3), second subparagraph, second sentence GDPR) and may suspend execution until the instruction is confirmed or amended.
Bornwerk engages only persons who have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality (Art. 28(3)(b) GDPR). The obligation continues after the activity ends.
The persons engaged are familiarised with the data protection provisions relevant to them before taking up their activity.
Bornwerk implements the technical and organisational measures required under Art. 32 GDPR to ensure a level of security appropriate to the risk (Art. 28(3)(c) GDPR). The measures in place are described in Annex 2.
Bornwerk may adapt the measures to the state of the art as long as the agreed level of protection is not reduced. Material changes are reflected in Annex 2.
Bornwerk maintains administrative access to the data processed on the business customer's behalf for support and troubleshooting. It is limited to a small number of named persons bound to confidentiality under § 7 and is used only to perform the contract or on the business customer's instruction.
The business customer gives general authorisation for the engagement of other processors (Art. 28(2), second sentence GDPR). The sub-processors engaged at the time the contract is concluded are listed in Annex 1 and are thereby authorised.
Bornwerk informs the business customer at least 30 days before engaging a new sub-processor or replacing an existing one, in text form to the email address held in the account. The business customer may object to the change on data protection grounds within 14 days of receipt.
If the business customer objects, the parties seek an amicable solution. If Bornwerk cannot reasonably provide the service without the sub-processor concerned, the business customer may terminate the contract for cause with effect from the date the change takes effect.
Bornwerk imposes on every sub-processor, by contract, the same data protection obligations as are set out in this agreement (Art. 28(4) GDPR) and remains liable for its conduct as for its own.
Purely ancillary services such as telecommunications, cleaning or maintenance services do not constitute sub-processing within the meaning of this agreement.
Bornwerk assists the business customer by appropriate technical and organisational measures in responding to requests from data subjects under Art. 12 to 23 GDPR (Art. 28(3)(e) GDPR). Access, rectification, erasure, restriction, export and objection can be carried out by the business customer directly in the software.
If a data subject approaches Bornwerk directly, Bornwerk forwards the request to the business customer without delay and does not answer it itself, insofar as it concerns processing carried out on the business customer's behalf.
Bornwerk further assists the business customer in complying with the obligations under Art. 32 to 36 GDPR, in particular with a data protection impact assessment and any prior consultation of the supervisory authority, taking into account the nature of processing and the information available to Bornwerk (Art. 28(3)(f) GDPR).
Bornwerk notifies the business customer of any personal data breach affecting the data processed on its behalf without undue delay after becoming aware of it, in text form to the email address held in the account (Art. 33(2) GDPR).
The notification describes, where available, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken and proposed. Information not yet available is provided as it emerges.
Notification to the supervisory authority under Art. 33(1) GDPR and communication to the data subjects under Art. 34 GDPR are the responsibility of the business customer; Bornwerk assists.
After the contract ends, Bornwerk deletes all personal data processed on the business customer's behalf or returns it, at the business customer's choice (Art. 28(3)(g) GDPR). The business customer states its choice by the end of the contract; if it does not, the data is deleted.
During the term of the contract the business customer can download its data at any time through the software's export functions in a structured, commonly used and machine-readable format. After the contract ends the data remains retrievable for 90 days under B.18 of the General Terms and Conditions; Bornwerk sends an email reminder before deletion.
Data subject to a statutory retention obligation is excluded from erasure, in particular till, receipt and invoice data under § 147 AO, § 257 HGB and the German Cash Register Ordinance. Such data is restricted from further processing until the respective period expires and is then deleted.
Billing documents retain the recipient details recorded when they were issued. An erasure request under Art. 17 GDPR does not cover them for as long as the retention obligation lasts (Art. 17(3)(b) GDPR).
Backups are overwritten as part of normal rotation; individual records are not selectively deleted from existing backups.
Bornwerk makes available to the business customer all information necessary to demonstrate compliance with the obligations under Art. 28 GDPR (Art. 28(3)(h) GDPR). Evidence may be provided through current self-assessments, the documentation under Annex 2, or audit reports and certificates from independent bodies.
Where this evidence is not sufficient in an individual case, Bornwerk allows the business customer, or an auditor mandated by it who is bound to secrecy and is not a competitor of Bornwerk, to conduct an audit. It takes place after 30 days' notice, during normal business hours, without disrupting operations, and at most once per calendar year; more frequently where there is specific cause, in particular after a personal data breach or upon order of a supervisory authority.
The business customer bears the cost of an audit it initiates. Bornwerk may charge a reasonable fee for its own effort unless the audit reveals a breach for which Bornwerk is responsible.
Processing takes place in Germany as a rule. Where individual sub-processors process data outside the European Union, this is stated in Annex 1.
A transfer takes place only where the conditions of Chapter V GDPR are met: on the basis of an adequacy decision under Art. 45 GDPR, in particular the EU-US Data Privacy Framework, or on the basis of the European Commission's Standard Contractual Clauses under Art. 46(2)(c) GDPR together with supplementary measures.
B.17 of the General Terms and Conditions governs liability. Art. 82 GDPR remains unaffected.
Bornwerk is not required to appoint a data protection officer; the conditions of Art. 37 GDPR and § 38 BDSG are not met. The contact address stated below is the point of contact for data protection matters.
Bornwerk may amend this agreement where a change in the law, a requirement of a supervisory authority, or case law makes it necessary. The amendment is communicated in text form at least 30 days before it takes effect; if the business customer does not object within that period, it is deemed accepted. The communication points out the right to object and the consequences of silence.
All other amendments require text form. If a provision is invalid, the validity of the remaining provisions is unaffected. German law applies.
The following sub-processors are authorised under § 9 of this agreement. All are bound by a contract under Art. 28 GDPR; where processing takes place outside the EU, the safeguards under Chapter V GDPR are stated.
| Provider | Purpose | Location | Safeguard |
|---|---|---|---|
| Hetzner Online GmbH | Operation of the application servers and the database | Germany (Falkenstein) | Processing exclusively in Germany |
| Amazon Web Services EMEA SARL | Object storage for uploaded files, secrets management and encrypted database backups | Germany (eu-central-1 region, Frankfurt) | Storage exclusively in Germany; Standard Contractual Clauses for parent-group support access |
| Cloudflare Germany GmbH / Cloudflare, Inc. | Content delivery network, reverse proxy and media delivery; processes every inbound request including the IP address | EU edge / worldwide | EU-US Data Privacy Framework, supplemented by Standard Contractual Clauses |
| Stripe Payments Europe, Ltd. / Stripe, Inc. | Payment processing including card payments at the card reader | Ireland / USA | EU-US Data Privacy Framework, supplemented by Standard Contractual Clauses |
| fiskaly GmbH | Signing of till transactions by the certified technical security device under the German Cash Register Ordinance | Austria (Vienna) | Processing exclusively within the EU |
| Resend (Plus Five Five, Inc.) | Delivery of transactional emails to end customers and staff, such as booking confirmations, reminders and receipts | USA | EU-US Data Privacy Framework, supplemented by Standard Contractual Clauses |
| Functional Software, Inc. (Sentry) | Detection of technical application errors; the operation name, error code and page are transmitted, not the contents of the application | EU region (Frankfurt) | Stored in the EU; US support access based on the EU-US Data Privacy Framework or the Standard Contractual Clauses |
| Google Ireland Ltd. / Google LLC | Google Maps Platform: address autocompletion when an address is entered, and the map shown on the public profile page | Ireland / USA | EU-US Data Privacy Framework, supplemented by Standard Contractual Clauses |
| Google Ireland Ltd. / Google LLC | Google Identity Services: signing in with a Google account during booking and in the customer account | Ireland / USA | EU-US Data Privacy Framework, supplemented by Standard Contractual Clauses |
Audience measurement and analytics on terminz.com are not covered by this agreement: Bornwerk is the controller there. Those services do not run on your business's booking and profile pages.
Measures under Art. 32 GDPR as at the date of this agreement.
Instructions under § 6, requests from data subjects and any other question about this agreement should be addressed to:
[email protected]The competent supervisory authority for Bornwerk is the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia. The German version of this agreement prevails.