Legal Document

Data Processing Agreement (DPA)

This Data Processing Agreement governs the processing of personal data by Terminz on behalf of your business under Art. 28 GDPR.

Overview

When you use Terminz as booking software, Terminz processes personal data of your customers on your behalf. In this case, you are the controller under Art. 4(7) GDPR, and Terminz acts as the processor under Art. 4(8) GDPR.

Under Art. 28 GDPR, a written Data Processing Agreement between you and Terminz is required before customer data is processed. Terminz provides this DPA by default for all customers.

Parties

Data Processor

Bornwerk UG

Bornwerk UG (haftungsbeschränkt)

Märkische Straße 193, 44141 Dortmund, Deutschland

[email protected]

Data Controller

The legal entity that is the contracting party of the respective Terminz contract and uses Terminz to process customer data for appointment booking. Each legal entity holds its own contract and its own DPA.

Subject Matter

Terminz processes personal data solely for the purpose of providing the appointment booking and salon management platform. The processing covers the following categories:

Data categories

Name, contact details, appointment history, payment data, optionally health-related notes

Nature of processing

Storage, retrieval, modification, internal transmission, deletion

Sub-Processors

Terminz uses the following vetted sub-processors. All providers are covered by a DPA under Art. 28 GDPR or appropriate safeguards under Chapter V GDPR.

ProviderPurposeLocationSafeguard
Hetzner Online GmbHServer hosting and database operation (application server, PostgreSQL)Germany (Falkenstein)Processing in Germany; Art. 28 GDPR DPA
Amazon Web Services (AWS)Object storage (file uploads, S3) and secrets managementGermany (eu-central-1, Frankfurt)Processing in the EU; Art. 28 GDPR DPA
Cloudflare, Inc.Content delivery network (CDN) and reverse proxy; processes inbound requests including IP addressEU edge / USAEU-US Data Privacy Framework, otherwise Standard Contractual Clauses (SCC)
Stripe Payments Europe, Ltd. / Stripe, Inc.Payment processing (registration, subscription)Ireland / USAEU-US Data Privacy Framework, otherwise Standard Contractual Clauses (SCC)
fiskaly GmbHTSE signing for cash-register transactions (KassenSichV / cloud TSE)EUProcessing in the EU; Art. 28 GDPR DPA
Resend (Plus Five Five, Inc.)Transactional emails (booking confirmations, notifications)USAEU-US Data Privacy Framework, otherwise Standard Contractual Clauses (SCC)
Sentry (Functional Software, Inc.)Error tracking and application monitoringUSAEU-US Data Privacy Framework, otherwise Standard Contractual Clauses (SCC)
Google Ireland Ltd. / Google LLCAnalytics (incl. Google Tag Manager), maps/address lookup, sign-inIreland / USAEU-US Data Privacy Framework, otherwise Standard Contractual Clauses (SCC)

Terminz's Key Obligations

As data processor, Terminz commits to the following obligations under Art. 28(3) GDPR:

  • Process personal data only on documented instructions from the controller
  • Ensure confidentiality by binding all persons authorized to process the data
  • Implement appropriate technical and tenantal measures under Art. 32 GDPR
  • Inform the controller before adding or changing any sub-processor
  • Assist with fulfilling data subject rights (access, deletion, portability)
  • Delete or return all personal data upon termination of the contract

Data Protection Contact

For questions about the DPA, data protection matters, or to exercise data subject rights, contact:

[email protected]

This document is for informational purposes. The binding Data Processing Agreement is provided and signed upon entering a contract with Terminz. For legal inquiries, contact [email protected].