Security and data protection

Your data sits in Germany. And stays there.

Application, database and files run on servers in Germany. What we do to protect them is written out here in full, without the seal bingo.

What we don't do

We don't sell data, don't pass it to ad networks and don't mine it for anyone else's purposes. Your customer list is yours, not ours.

Terminz earns from the software subscription, not from booking commission and not from data.

Privacy page with the data processing agreement and error monitoring
The DPA, the subprocessors and exactly what error monitoring sends — listed openly.

Nine points, in plain words

Where the data sits
Application, database and file uploads run exclusively in German data centres. No transfer to third countries without a legal basis.
Encryption
TLS throughout for transfer, passwords stored as hashes, sensitive fields encrypted on top in the database.
Who can see what
Permissions follow the role and the location. A staff member sees the calendar, not the revenue.
Tenant separation
Each location sees only its own data. Every query checks the tenant, not just the role.
Logging
Sign-ins, permission changes and access to customer data are logged and visible in the dashboard.
Your customers' rights
Access, export and deletion are features in the system, not a support ticket.
Monitoring and backups
Automatic backups with tested restores, plus error and uptime monitoring around the clock.
Sub-processors
Who we use is listed openly in the DPA. If someone is added, you hear about it beforehand.
If you leave
A full export of your data at any time. After the contract ends it is deleted, apart from statutory retention periods.

More questions about data protection?

Write to us with whatever your data protection officer wants to know. We answer in writing so you can pass it on.