ZB ZekaBooking Booking system for businesses
Home Pricing Business login Try for free
Legal information

Data Processing Agreement (DPA)

Transparent information about ZekaBooking, privacy, contracts and the use of our platform.

Last updated: 22 July 2026 · Version 1.0

This Data Processing Agreement specifies the data-protection obligations between the ZekaBooking business customer as controller and zekahub IT-Dienstleistungen as processor.

This DPA applies only to processing carried out by ZekaBooking on the business customer's instructions. ZekaBooking's own platform processing, such as contract administration, security or platform account management, is not covered by this DPA.

1. Parties

Controller: the business identified in the ZekaBooking business account.

Processor:
Kadir Kavak
trading as zekahub IT-Dienstleistungen
Aufenangerstraße 5
44229 Dortmund
Germany
Email: info@zekabooking.com

2. Subject matter and duration

The subject matter is the technical provision and operation of ZekaBooking for the business customer.

Processing on behalf begins with activation of the business account and ends with termination of the main agreement and completion of the agreed return or deletion measures.

3. Nature and purpose of processing

Processing includes in particular:

  • providing a public booking page,
  • recording and storing appointments,
  • assigning services and employees,
  • displaying and managing available times,
  • sending confirmations, changes and reminders,
  • providing the business portal,
  • backup, restoration, maintenance and support.

4. Categories of data subjects

  • end customers and prospective customers of the business customer,
  • employees and authorised portal users of the business customer,
  • contact persons of the business customer,
  • where applicable, other persons lawfully included by the business customer in appointment data.

5. Types of personal data

  • master and contact data, in particular name, email and telephone number,
  • appointment, service, employee and time information,
  • appointment notes entered by the end customer or business customer,
  • status, cancellation and administration data,
  • portal roles and business permissions,
  • technical log, security and backup data.
Special categories of personal data: ZekaBooking is not designed for freely recording health data or other data under Article 9 GDPR in appointment notes. If the business customer requires such processing, it must be separately agreed in advance and assessed technically and legally.

6. Controller's right to issue instructions

  1. Processing is carried out exclusively on documented instructions from the business customer.
  2. Use of the configurable platform functions constitutes documented instructions.
  3. Further instructions may be submitted to support in text form.
  4. If the processor considers an instruction to violate data-protection law, it will inform the business customer without delay and may suspend execution until the matter has been clarified.

7. Obligations of the business customer

The business customer is responsible in particular for:

  • the lawfulness of data collection and processing,
  • fulfilling information obligations towards end customers and employees,
  • the accuracy and currency of its instructions,
  • granting and withdrawing business access rights,
  • handling data-subject requests,
  • setting appropriate deletion and retention periods.

8. Confidentiality

Persons with access to data processed on behalf are bound to confidentiality or are subject to an appropriate statutory duty of secrecy.

Access is restricted to persons who require it for operation, maintenance or support.

9. Technical and organisational measures

The processor uses in particular the following measures:

  • encrypted transmission via HTTPS,
  • secure password storage,
  • role- and tenant-based access controls,
  • protection against cross-site request forgery and unauthorised requests,
  • logging of security-relevant operations,
  • regular backups and restoration procedures,
  • system, security and dependency updates,
  • restriction of administrative access,
  • procedures for handling security incidents.

The measures may be adapted to technical developments provided that the agreed level of protection is not reduced.

10. Sub-processors

The business customer grants general authorisation to engage necessary sub-processors.

At the date of this DPA, STRATO GmbH, Otto-Ostrowski-Straße 7, 10249 Berlin, is used in particular for hosting and technical infrastructure.

Intended material changes concerning sub-processors will be communicated to the business customer in advance in an appropriate form.

The business customer may object for an important data-protection reason.

The required data-protection obligations are contractually agreed with sub-processors.

11. Assistance obligations

The processor provides reasonable assistance to the business customer with:

  • access, rectification, erasure and data portability,
  • restriction and objection,
  • assessment and notification of personal data breaches,
  • data-protection impact assessments where required,
  • evidence of the measures agreed in this DPA.

Requests from data subjects that recognisably concern the business customer's responsibility will be forwarded to the business customer unless a statutory obligation requires different handling.

12. Personal data breaches

The processor informs the business customer without undue delay of any breach of the protection of data processed on behalf that becomes known to it.

It provides the available information required by the business customer for assessment and statutory notifications.

13. Audits and evidence

Upon request, the processor provides appropriate information demonstrating compliance with this DPA.

Audits must be carried out with reasonable advance notice and while safeguarding security, confidentiality and the rights of other customers.

Disproportionate or repeated audits may be chargeable following prior coordination.

14. Return and deletion

After the end of the main agreement, data processed on behalf will be returned or deleted at the business customer's choice and instruction unless statutory retention obligations prevent this.

Data in backup copies will be kept protected until routine overwriting and will not be processed for other purposes.

15. Processing outside the EU/EEA

Data processed on behalf is generally processed within the European Union or European Economic Area.

Processing in a third country takes place only subject to the statutory requirements and after informing the business customer.

16. Liability and precedence

Liability is governed by statutory provisions and, additionally, by the main agreement.

In the event of conflicts between this DPA and other data-protection provisions of the main agreement, this DPA takes precedence for processing on behalf.

17. Conclusion of the agreement

This DPA is concluded electronically and forms part of the ZekaBooking agreement.

The information stored in the business account identifies the controller.

The current version is available at /avv.

ZB

ZekaBooking

Online appointment booking for businesses and their customers.

Home Pricing

For businesses

Business portal How ZekaBooking works Terms for business customers Data processing Plan & cancellation

For appointment customers

My appointments Booking privacy

Platform & legal

Imprint Privacy Cookie information Cookie settings
The respective business is the provider and contractual partner for the booked service. ZekaBooking provides the technical booking platform. © 2026 ZekaBooking · developed by zekahub IT-Dienstleistungen.

Privacy Terms Cookie information Legal notice