This Data Processing Agreement specifies the data-protection obligations between the ZekaBooking business customer as controller and zekahub IT-Dienstleistungen as processor.
1. Parties
Controller: the business identified in the ZekaBooking business account.
Processor:Kadir Kavak
trading as zekahub IT-Dienstleistungen
Aufenangerstraße 5
44229 Dortmund
Germany
Email: info@zekabooking.com
2. Subject matter and duration
The subject matter is the technical provision and operation of ZekaBooking for the business customer.
Processing on behalf begins with activation of the business account and ends with termination of the main agreement and completion of the agreed return or deletion measures.
3. Nature and purpose of processing
Processing includes in particular:
- providing a public booking page,
- recording and storing appointments,
- assigning services and employees,
- displaying and managing available times,
- sending confirmations, changes and reminders,
- providing the business portal,
- backup, restoration, maintenance and support.
4. Categories of data subjects
- end customers and prospective customers of the business customer,
- employees and authorised portal users of the business customer,
- contact persons of the business customer,
- where applicable, other persons lawfully included by the business customer in appointment data.
5. Types of personal data
- master and contact data, in particular name, email and telephone number,
- appointment, service, employee and time information,
- appointment notes entered by the end customer or business customer,
- status, cancellation and administration data,
- portal roles and business permissions,
- technical log, security and backup data.
6. Controller's right to issue instructions
- Processing is carried out exclusively on documented instructions from the business customer.
- Use of the configurable platform functions constitutes documented instructions.
- Further instructions may be submitted to support in text form.
- If the processor considers an instruction to violate data-protection law, it will inform the business customer without delay and may suspend execution until the matter has been clarified.
7. Obligations of the business customer
The business customer is responsible in particular for:
- the lawfulness of data collection and processing,
- fulfilling information obligations towards end customers and employees,
- the accuracy and currency of its instructions,
- granting and withdrawing business access rights,
- handling data-subject requests,
- setting appropriate deletion and retention periods.
8. Confidentiality
Persons with access to data processed on behalf are bound to confidentiality or are subject to an appropriate statutory duty of secrecy.
Access is restricted to persons who require it for operation, maintenance or support.
9. Technical and organisational measures
The processor uses in particular the following measures:
- encrypted transmission via HTTPS,
- secure password storage,
- role- and tenant-based access controls,
- protection against cross-site request forgery and unauthorised requests,
- logging of security-relevant operations,
- regular backups and restoration procedures,
- system, security and dependency updates,
- restriction of administrative access,
- procedures for handling security incidents.
The measures may be adapted to technical developments provided that the agreed level of protection is not reduced.
10. Sub-processors
The business customer grants general authorisation to engage necessary sub-processors.
At the date of this DPA, STRATO GmbH, Otto-Ostrowski-Straße 7, 10249 Berlin, is used in particular for hosting and technical infrastructure.
Intended material changes concerning sub-processors will be communicated to the business customer in advance in an appropriate form.
The business customer may object for an important data-protection reason.
The required data-protection obligations are contractually agreed with sub-processors.
11. Assistance obligations
The processor provides reasonable assistance to the business customer with:
- access, rectification, erasure and data portability,
- restriction and objection,
- assessment and notification of personal data breaches,
- data-protection impact assessments where required,
- evidence of the measures agreed in this DPA.
Requests from data subjects that recognisably concern the business customer's responsibility will be forwarded to the business customer unless a statutory obligation requires different handling.
12. Personal data breaches
The processor informs the business customer without undue delay of any breach of the protection of data processed on behalf that becomes known to it.
It provides the available information required by the business customer for assessment and statutory notifications.
13. Audits and evidence
Upon request, the processor provides appropriate information demonstrating compliance with this DPA.
Audits must be carried out with reasonable advance notice and while safeguarding security, confidentiality and the rights of other customers.
Disproportionate or repeated audits may be chargeable following prior coordination.
14. Return and deletion
After the end of the main agreement, data processed on behalf will be returned or deleted at the business customer's choice and instruction unless statutory retention obligations prevent this.
Data in backup copies will be kept protected until routine overwriting and will not be processed for other purposes.
15. Processing outside the EU/EEA
Data processed on behalf is generally processed within the European Union or European Economic Area.
Processing in a third country takes place only subject to the statutory requirements and after informing the business customer.
16. Liability and precedence
Liability is governed by statutory provisions and, additionally, by the main agreement.
In the event of conflicts between this DPA and other data-protection provisions of the main agreement, this DPA takes precedence for processing on behalf.
17. Conclusion of the agreement
This DPA is concluded electronically and forms part of the ZekaBooking agreement.
The information stored in the business account identifies the controller.
The current version is available at /avv.