As of: 2026-10-01
This English text is a convenience translation. The legally binding version is the German original.
1. Controller
The controller responsible for data processing on this website and the ZepDesk platform is:
ZeptronIT UG (haftungsbeschränkt)
Leon Marzoll
Möhlbarg 12, 23911 Harmsdorf
Email: datenschutz@zepdesk.de
2. Collection and Processing of Personal Data
2.1 When Visiting the Website
When this website is accessed, information is automatically sent by the browser of your device to the server of our website and temporarily stored in a log file: IP address, date and time of access, time-zone difference from GMT, content of the request (the specific page), access status/HTTP status code, amount of data transferred, referrer URL, browser, operating system and its interface, language and version of the browser software. The server of this website is located in a data center of Hetzner Online GmbH in Helsinki, Finland (EU), and is separate from the ZepDesk platform (section 4).
Legal basis: Art. 6 Abs. 1 lit. f DSGVO (GDPR) (legitimate interest in secure, stable operation).
Storage period: The IP address is not anonymized. No fixed deletion period is currently set for these log files; once it is set, we will state it here.
2.2 When Registering and Using ZepDesk
We process the following personal data:
- Contact data: first and last name, email address, company, billing address
- Login data: hashed password hash (never in plain text), session cookies
- Payment data: processed exclusively by our payment provider Mollie (see section 5) and never reach us in plain text
- Usage data: login times, API access logs, subdomain usage for troubleshooting and abuse detection
- Support data: the contents of your support requests
Legal basis: Art. 6 Abs. 1 lit. b DSGVO (performance of a contract); for billing purposes also Art. 6 Abs. 1 lit. c DSGVO (statutory retention obligation, §§ 147 AO (German Fiscal Code), 257 HGB (German Commercial Code)).
2.3 Protection of the Login (Cloudflare Turnstile)
We protect the pages for login, registration and password reset on app.zepdesk.de against automated access with Cloudflare Turnstile. For this, your browser loads a program from Cloudflare and transmits technical information to Cloudflare such as IP address, browser and device characteristics and information about the interaction with the page. Cloudflare then confirms whether the request comes from a human; our platform checks this result. Your login credentials and content from ZepDesk are not sent to Cloudflare. If the protection is set up for your instance, the same applies to the emergency access through which administrators log in directly to your ZepDesk instance.
Recipient: Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA. Processing in the USA
takes place; it is based on the adequacy decision of the EU Commission on the EU-US Data Privacy Framework, under
which Cloudflare is certified.
Legal basis: Art. 6 Abs. 1 lit. f DSGVO (protecting your account and the platform against automated
login attempts). Access to information on your device is strictly necessary under § 25 Abs. 2 Nr. 2 TDDDG in order
to provide the secured login you requested.
2.4 Address Completion (OpenPLZ API and Photon)
So that addresses arrive complete and correctly spelled, ZepDesk and the registration on app.zepdesk.de suggest matching entries while you type. For this, our server queries two public directories, not your browser. The services therefore see the IP address of our server, not that of your device.
- Postal code and municipality (OpenPLZ API): In the setup wizard and for the assessment rate of trade tax and property tax, that is for your registered office, your business premises and your properties, we send the postal code and receive the associated localities and municipalities with the official municipality key. If a postal code covers several municipalities, we additionally send the longest word of the street name, without the house number. Recipient: STÜBER SYSTEMS GmbH, Grabbeallee 31, 13156 Berlin, Germany.
- Address (Photon): In address fields, for example for customers, suppliers, business partners, leads, shareholders, members and properties, in the company and billing details, in the setup wizard, during registration and in the partner application, we send the street name without the house number once it has three characters, and receive suggestions from OpenStreetMap data. Recipient: komoot GmbH, Kienberger Allee 4, 12529 Schönefeld, Germany.
Only the postal code and the street name are transmitted, no house number. Names, e-mail addresses, customer numbers and other content from ZepDesk do not go to the services. A postal code and a street name without a house number do not relate to an identifiable person. We cache the answers on our server so that the same question does not go out again: localities for a postal code for up to 30 days, address suggestions for one hour.
Legal basis: insofar as personal data is involved at all, Art. 6(1)(f) GDPR (legitimate interest in complete, correctly spelled addresses and in the correct municipality for the assessment rate).
2.5 Checking VAT Identification Numbers (VIES)
Whether a VAT identification number is valid is checked by our server with the VAT Information Exchange System VIES of the European Commission. Only the country code and the number are transmitted. VIES forwards the request to the tax administration of the state that issued the number and reports back whether it is valid, depending on the state also with the holder's name and address. We cache the answer for one day.
- Your own number: when you enter or change it in your account on app.zepdesk.de, and in the partner application. Whether we charge you VAT depends on it.
- In ZepDesk: the numbers of your business partners in the recapitulative statement and the number of a lead when you enter it, then once a month again.
Recipients: European Commission (VIES) and the tax administration of the member state that issued
the number.
Legal basis: for your own number Art. 6(1)(c) GDPR (VAT obligations when we invoice you) and
Art. 6(1)(f) GDPR; we check the numbers of your business partners and leads on your behalf (section 7).
2.6 Time Stamps for the Change Log
If anchoring is switched on for your instance, our server sends a hash value of the latest entry in your change log to a time-stamping service once a day, by default freeTSA.org, and receives a signed time stamp in return. This makes it possible to show later that the log has not been changed since. A hash value allows no conclusion about the content or about persons; no personal data leaves our server. By default, anchoring is switched off.
3. Cookies
Our website uses only technically necessary cookies (a session cookie to maintain your login, CSRF protection). No marketing, analytics, or tracking cookies without your explicit consent.
Legal basis: § 25 Abs. 2 TDDDG (German Telecommunications Digital Services Data Protection Act) (technically necessary).
3a. Web analytics (Umami)
For anonymous web analytics we use Umami, a self-hosted analytics tool on our own server (analytics.zeptronit.com) in a data center of Hetzner Online GmbH in Helsinki, Finland (EU). Umami works without cookies and without cross-device tracking. Only aggregated, anonymous usage data is collected, such as the page viewed, the referrer, the approximate country of origin, and the browser and device type. No full IP addresses are stored and no data is shared with third parties.
Legal basis: Art. 6 Abs. 1 lit. f DSGVO (legitimate interest in the needs-based design and statistical analysis of our website). As no cookies are set and no personal data is processed, no consent under § 25 TDDDG is required.
4. Hosting and Infrastructure
We operate the ZepDesk platform in data centers of
Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen,
at the Falkenstein (Vogtland) site in Germany. The application, the databases, files and receipts, the daily
backups, our management platform app.zepdesk.de with the central login and the knowledge service of the AI
assistant are located there. Hetzner acts for us as a processor pursuant to Art. 28 DSGVO.
Outside Germany, but within the EU, the following process data:
- Receipt recognition and dictation: Scaleway SAS in a data center in Paris, France (section 7b).
- Website and web analytics: servers of Hetzner Online GmbH in Helsinki, Finland (sections 2.1 and 3a). They contain no data from ZepDesk.
Further recipients are named in sections 2.3 (protection of the login), 2.4 (address completion), 2.5 (VAT ID), 5 (payments), 5a (bank connection), 5b (integrations), 6 (email delivery), 7b (AI assistant) and 7c (app).
5. Payment Processing (Mollie)
For payment processing (SEPA direct debit, credit card, PayPal) we use the EU payment provider:
Mollie B.V., Keizersgracht 126, 1015 CW Amsterdam, Niederlande
During payment, the following data is transmitted to Mollie: name, email address, invoice amount, IBAN or card details. The payment data is entered encrypted directly with Mollie and does not reach us in plain text (PCI-DSS compliant). Mollie's privacy policy: mollie.com/privacy.
Legal basis: Art. 6 Abs. 1 lit. b DSGVO (performance of a contract).
Role: Mollie processes this data as a payment service provider.
5a. Bank Connectivity (finAPI and Qonto)
When you link a bank account in ZepDesk to import your transactions automatically, we use the following
account information service under PSD2:
finAPI GmbH, Adams-Lehmann-Straße 44, 80797 München, Germany
The connection to your bank is authorized solely by you via your bank's secured procedure. The account and transaction data you release is transmitted (including IBAN, balance, booking texts, amounts, payment references). finAPI is a payment service provider licensed and supervised by BaFin. finAPI's privacy notice: finapi.io/datenschutz.
Legal basis: Art. 6 Abs. 1 lit. b DSGVO (performance of a contract) and your consent under Art. 6 Abs. 1 lit. a DSGVO for the account access.
Server location: Germany (EU).
Role: finAPI acts for us as an account information service.
Qonto: If your business account is with Qonto, you can connect it directly instead of via finAPI. For this, you store an API key from your Qonto account in ZepDesk, and ZepDesk uses it to fetch your transactions from Qonto (Qonto SA, 6 Impasse Bonne Nouvelle, 75010 Paris, France). Only the request and your key go to Qonto; ZepDesk stores the key encrypted. Qonto is your bank, not our service provider; we process the transactions on your behalf (section 7).
5b. Integrations You Switch On Yourself
ZepDesk can connect to services where you have your own account. Data only flows once your company's administration switches on an integration and stores your access to the provider for it. ZepDesk then uses this access to fetch data from your account with the provider, such as payments, payouts and fees, orders or booked appointments, and stores it in your instance. ZepDesk writes nothing into your account with the provider; only the request and your access go to the provider. ZepDesk stores the access encrypted. If you switch an integration off, ZepDesk fetches nothing more.
- Payment services: Mollie (your own Mollie account, independent of section 5), PayPal, Stripe, SumUp
- Online shops and marketplaces: Ecwid, Billbee, Shopify as soon as it is available in ZepDesk
- Industry software: Das Programm
- Appointments: meetergo
- Webhooks to Make, Zapier or your own system, as soon as you can create them in ZepDesk: exactly the events you select then go, with their fields, to the address you specify.
You are the controller for this data, and we process it on your behalf (section 7). You have your own contract with the provider; its terms and privacy notices apply, including on where it processes data. You connect your bank via section 5a, the AI assistant via section 7b.
6. Email Delivery
We send emails of the platform (such as confirmation codes, password resets, invoices, system notifications)
via the mail server of
ALL-INKL.COM, Neue Medien Münnich, owner René Münnich, Hauptstraße 68, 02742 Friedersdorf,
with data centers in Dresden, Germany. The emails you send from ZepDesk to your customers and business partners
also go through this mail server, as long as you have not set up your own mailbox for sending in ZepDesk. The
contents of your emails are not analyzed for advertising purposes.
7. Data Processing (AVV)
Insofar as you, as the customer, process personal data of your end customers or employees in ZepDesk, you are the controller within the meaning of the DSGVO and we are your processor pursuant to Art. 28 DSGVO. The data processing agreement (AVV) required for this is part of our AGB (general terms and conditions) and is concluded online upon conclusion of the contract. You can find the text at /avv.
7a. Platform-as-a-Service: Technical Access to Your Instance
ZepDesk is not only a standard SaaS solution but also a Platform-as-a-Service (PaaS): your instance runs in its own, separated area (namespace) of our Kubernetes cluster at Hetzner in Falkenstein, with its own database schema and its own area in the object storage. We operate and maintain it and customize it individually on request. This entails certain technical access options, which we transparently disclose here:
7a.1 Passive Monitoring (automatic, without Ops interaction)
To ensure operation, we continuously collect and store technical metrics:
- Telemetry of the cluster nodes and the containers of your instance: utilization of processor, memory and storage
- Site metrics (daily): database size in MB, file size in MB, number of users, number of companies, number of invoices, as numeric values, not contents
- HTTP availability checks: every 5 minutes, response status code and response time
- Status reports of the containers of your instance (status, version, uptime)
- Server log files: access and error logs of the web server of your instance, with IP address. They are kept in the container logs of the cluster, are not anonymized and disappear when the cluster rotates them by size or the container is replaced; no separate deletion period is set
Contents from your database (customer, invoice, and article data) are not read during passive monitoring. Legal basis: Art. 6 Abs. 1 lit. b DSGVO (performance of a contract) and lit. f (legitimate interest in stable operation).
7a.2 Active Ops Access (only in case of a malfunction or upon your instruction)
For maintenance and customization purposes, our technicians have the technical ability to connect to your instance. Specifically, we can:
- Administrative access to the cluster nodes and into the containers of your instance (running commands, reading logs)
- Database access: database administrator access for troubleshooting, backup restoration, data repair
- Execute platform maintenance commands:
Migration, module install commands) - Impersonation: switch into your customer platform as a logged-in user in order to reproduce a specific support issue
- Deploy custom code: install our own extension modules or scripts, provided that you have commissioned customization services
7a.3 When do we actively access?
Exclusively in one of the following cases:
- Upon your express instruction / your support ticket request (e.g. "please install Addon X", "my import got stuck"). Legal basis: Art. 6 Abs. 1 lit. b DSGVO (performance of a contract) and, if you have concluded a Platform Service Agreement (see /platform-service), also this contractual basis.
- In the event of a serious malfunction that endangers the operation of your instance (e.g. disk full, DB corruption). Legal basis: Art. 6 Abs. 1 lit. f DSGVO (legitimate interest in service availability).
- In the event of security incidents (e.g. suspected malware, brute-force attacks). Legal basis: Art. 6 Abs. 1 lit. f DSGVO.
- In the event of a legal obligation (e.g. official requests for information). Legal basis: Art. 6 Abs. 1 lit. c DSGVO.
7a.4 Information about Access
There is currently no log of this access that you can view yourself in the customer portal. We answer questions about individual access to your instance at datenschutz@zepdesk.de; your right of access under Art. 15 DSGVO (section 9) remains unaffected.
7a.5 Independence from the Standard SaaS Usage Agreement
Active Ops customization services (point 7a.2, item 5 above) require a separate Platform Service Agreement (PSV). Without such a PSV, our active interventions are limited to maintenance and emergency measures (7a.3 nos. 2 to 4). Details on the PSV can be found at /platform-service.
7b. AI Assistant (optional feature)
ZepDesk includes an optional AI assistant that supports you in operating it (answering questions, creating drafts and booking suggestions, performing operating steps). The feature is opt-in and not required for the operation of the core functions.
Which data is transmitted: only if you actively use the AI assistant are your input and a portion of the currently visible page content (limited, not your entire database) transmitted to the configured language model in order to generate the response. Without active use, no transmission takes place.
Provider (Bring Your Own Key): the language model is provided by a provider that you configure yourself and for which you store your own access key (BYOK). The key is stored encrypted and is not logged. For this third-party service chosen by you, you are the contracting party of the respective provider; its terms and privacy notices apply additionally in this respect. If you do not use your own access but an access to a provider that we provide, we transmit your input and the page excerpt to this provider on your behalf; for a provider based in the USA, the following paragraph then applies as well.
Transfer to a third country: if you choose a provider outside the EU (e.g. Anthropic, based in the USA), a transfer to a third country takes place in this respect. Alternatively, you can integrate an EU provider via a compatible endpoint. Our platform's own AI functions, by contrast, run exclusively on servers in the EU, and they are two distinct things:
- Receipt recognition: An uploaded receipt is transmitted to Scaleway SAS, 8 rue de la Ville-l’Évêque, 75008 Paris, France, so that a language model can read out supplier, date, amounts, tax rates and a suggested account assignment. What is transmitted is the receipt as an image or, if the file contains text, that text. Scaleway acts for us as a processor pursuant to Art. 28 GDPR; processing takes place in a data center in Paris, no transfer to a third country occurs. According to Scaleway, it does not store the content and does not use it for training; only if a request causes a technical error there may Scaleway keep it for up to two weeks for troubleshooting. The result is a suggestion and creates no booking; only your approval does.
- Speech-to-text (“dictation”): your recording goes via our management platform in Falkenstein to Scaleway (address as above), where a language model in a data center in Paris turns it into text; storage and troubleshooting are handled as for receipt recognition. We do not store the recording; the recognized text appears in your input field. If we switch off the outsourced recognition, a speech recognition on our management platform in Falkenstein produces the text, and the recording does not leave Germany.
No advice: outputs of the AI assistant are non-binding recommendations
and information, not tax or legal advice; details are governed by the AGB.
Legal basis: Art. 6 Abs. 1 lit. b DSGVO (use of the feature you have
activated); with respect to the provider relationship you have chosen, your own legal basis
as the controller.
7c. ZepDesk App for Android and iOS
The ZepDesk app gives you access to your ZepDesk instance from your phone. For the business data you view, enter and send in the app (such as receipts, invoices, customers and files in the document storage), sections 2.2, 4, 7 and 7b apply as in the web interface. This section describes what the app processes beyond that. The app shows no advertising, does not track you across other apps or websites, does not read an advertising ID, sets no cookies and receives no push notifications. It includes no third-party analytics or crash reporting services; which technical data Google receives from the document scanner on Android is described in 7c.3.
7c.1 Sign-in and connections
You sign in to our platform app.zepdesk.de with your email address and password, and where required with a confirmation code. The app then receives an access token and a refresh token and keeps both in the protected storage of the device (Keychain on iOS, Keystore on Android). They cannot be transferred to another device; on Android they are excluded from the device backup. For your company the app additionally obtains short-lived access credentials that are held in memory only.
The app connects exclusively to app.zepdesk.de and to the address of your ZepDesk instance. Where applicable it loads your company logo through a time-limited link from our storage at Hetzner (section 4). All connections are encrypted (HTTPS); the published app does not allow unencrypted connections.
Legal basis: Art. 6 Abs. 1 lit. b DSGVO (performance of the contract).
Storage period: the refresh token is valid for at most 30 days. When you sign out, the app
signs you out with us and deletes both tokens from the device. For sign-in records on our platform,
section 2.2 applies.
7c.2 Device check against abusive access
So that only the genuine app on an unmodified device obtains access, the app identifies itself when you sign in, when you reset your password and when it requests access credentials: on Android via Google's Play Integrity API, on iOS via Apple's App Attest. For this the app passes only a one-time random number from our platform to the service (on iOS its hash) and forwards the service's response to us. No content from ZepDesk is sent to Google or Apple. According to Google, Google additionally processes information about the app (package name, version, signing certificate), its licensing status and information about the device, such as an attestation by Google Play services. On Android we have Google decrypt the result and verify it ourselves; on iOS we store the public part of the App Attest key in order to verify later checks. We log the result of each check without any information about your person.
Legal basis: Art. 6 Abs. 1 lit. f DSGVO (protecting your account and the platform against
automated and abusive access). Access to your device is strictly necessary under § 25 Abs. 2 Nr. 2 TDDDG to
provide the secured access you have requested.
Recipients: on Android Google Ireland Limited, Gordon House, Barrow Street, Dublin 4,
Ireland; on iOS Apple Distribution International Ltd., Hollyhill Industrial Estate, Hollyhill, Cork,
Ireland. Processing in the USA cannot be ruled out; it is based on the European Commission's adequacy
decision for the EU-US Data Privacy Framework, insofar as the respective recipient is certified under it.
Storage period: the random number is valid for a single check and expires after five
minutes. The public App Attest key is not assigned to any person and remains stored as long as the
installation can use it. According to Google, Google deletes its data after a fixed retention period.
7c.3 Camera, scanner, photos and files
You capture receipts and documents with the operating system's document scanner: on iOS with Apple's VisionKit, on Android with the Google ML Kit document scanner from Google Play services. Edge detection and cropping take place on the device. If the scanner is not available, the app takes the photo directly. The app asks for camera permission before it uses the camera for the first time; it uses the camera only when you start a capture or the reading of a QR code. The app reads the QR code on a till receipt on the device and sends only the decoded text to your ZepDesk instance. You choose photos and files for the document storage in the system picker; the app receives only what you select there and does not ask for access to your photo library or your storage. Captures and files are sent to your ZepDesk instance only when you store them or send them as a receipt; sections 7 and 7b apply there.
Google ML Kit (Android only): the document scanner and the QR reader on Android are based on ML Kit. According to Google, the scanner processes the images on the device. ML Kit does, however, transmit technical usage data to Google, such as the device manufacturer, model and operating system, the app's package name and version, a per-installation identifier, performance metrics, and event and error codes. According to Google, it uses this data for diagnostics and usage analytics of ML Kit and does not pass it on to third parties. The recipient is Google (address as in 7c.2).
Legal basis: Art. 6 Abs. 1 lit. b DSGVO for capture, selection and transfer; access to the
device's camera and storage is strictly necessary under § 25 Abs. 2 Nr. 2 TDDDG to carry out the capture you
have started. For the use of ML Kit, Art. 6 Abs. 1 lit. f DSGVO (a reliable system scanner instead of the
app accessing the camera itself).
Storage period: captures remain in the app's outbox until they are sent or discarded by you
(7c.6). The app clears the caches of the scanner and of the picker as soon as it has taken over the capture
or stored the file.
7c.4 Error reports
If an unexpected error occurs in the app, it sends an error report to our platform (app.zepdesk.de). The same applies to crashes recorded by the operating system (on Android the list of terminated processes, on iOS MetricKit); the app reads these at a later start. A report contains: the first line of the error message (at most 300 characters), a shortened extract of the affected program locations, the type of error, the app version, the operating system and its version, and the address of the ZepDesk instance currently open. It contains neither your name nor your email address nor an identifier of your account. Before sending, the app replaces email addresses, IBANs, long character strings and numbers with six or more digits with placeholders; for crashes recorded by the operating system only email addresses and IBANs, because long character strings there are program addresses. The app sends at most 20 reports per start. Reports it could not send are kept until the next start, at most 30 reports.
Legal basis: Art. 6 Abs. 1 lit. f DSGVO (error-free and secure operation of the app).
Crashes recorded by the operating system are read under § 25 Abs. 2 Nr. 2 TDDDG, as this is strictly
necessary to keep the app you use working.
Recipients: only us; the platform runs at Hetzner (section 4).
Storage period: 14 days in our platform's error log, then automatic deletion. On the device
until the next successful transmission.
7c.5 Device key and biometrics
When you approve a tax return or tax filing to the tax office from the app, you confirm this with your device's biometrics, such as Face ID or your fingerprint. For this the app creates, once per company and user, a key in the security area of the device (Secure Enclave on iOS, Keystore on Android). The private part never leaves the device. The following are sent to your ZepDesk instance: the public key, on Android the Keystore attestation (certificate chain), the device name (on Android manufacturer and model, on iOS the device type such as "iPhone"), a random identifier of this installation and a signature for each approval. Your instance checks whether an Android key has been revoked using Google's public revocation list; no information about you is sent to Google in the process.
Your biometric characteristics are processed exclusively by the operating system. The app only receives the result, confirmed or not. The same applies to the app lock with Face ID or fingerprint, which you can switch on under "Mehr" (More).
Legal basis: Art. 6 Abs. 1 lit. b DSGVO (carrying out your approval) and Art. 6 Abs. 1
lit. f DSGVO (proof that the approval came from your device).
Storage period: device keys are not deleted but only revoked, so that approvals can be
verified later. The proof of an approval (signature, key identifier, time, IP address and client identifier)
is stored together with the transmission record and kept as long as that record.
7c.6 Data on the device, signing out and uninstalling
The protected storage of the device holds the tokens, your app lock choice, the identifiers of the device keys and the identifier of this installation. The app's directory holds: the outbox with receipts not yet sent (photos and details), unfinished invoices and quotes, the most recently loaded overview, your company's logo and colours, the areas you visited last, your settings (such as language and appearance) and error reports waiting to be sent. Other apps cannot access this data.
When you sign out, the app deletes the tokens, the cached overview, logo and colours, the areas visited last, unfinished invoices and quotes, and your app lock choice. Receipts in the outbox remain on the device until they are sent after your next sign-in or you discard them in the outbox; the device keys and your settings remain as well.
Device backup: if you have switched on the backup of your device (Google on Android, iCloud on iOS), it may contain content from the app's directory, such as receipts in the outbox. Your sign-in is excluded: on Android the backup does not include the protected storage, on iOS the tokens can only be used on this device.
Uninstalling: when you delete the app, the operating system removes the app's directory, and on Android also the keys in the Keystore. iOS may keep Keychain entries beyond an uninstallation. Please therefore sign out before deleting the app.
Legal basis: Art. 6 Abs. 1 lit. b DSGVO; storage on the device is strictly necessary under § 25 Abs. 2 Nr. 2 TDDDG to provide the functions you use.
7c.7 Sharing, links and obtaining the app
If you share a PDF or a file or choose "In anderer App öffnen" (open in another app), the app briefly places the file in a temporary directory, hands it to the system share sheet and then deletes it. You decide where the file goes. The app opens the legal texts, help and the account deletion page in your browser; sections 2.1 and 3a apply there.
You obtain the app through Google Play or the App Store. Google and Apple respectively process data under their own responsibility, such as your store account and the time of the download. Their privacy notices apply.
8. Storage Period
- Account data: for the duration of the contract plus a 30-day grace period. Thereafter, complete deletion or anonymization, insofar as no statutory retention obligations preclude this.
- Invoice data: 8 years pursuant to § 147 (3) AO, § 257 (4) HGB, § 14b UStG, from the end of the calendar year.
- Server logs: without anonymization and without a fixed deletion period, see sections 2.1 and 7a.1.
- Backups: daily, in the object storage in Falkenstein. They are kept until a deletion rule is set up; we will then state the period here.
- ZepDesk app: see section 7c.
9. Your Rights
You have the right, in relation to us:
- to information (Art. 15 DSGVO) about the data stored concerning you
- to rectification (Art. 16 DSGVO) of inaccurate or incomplete data
- to erasure (Art. 17 DSGVO / "right to be forgotten")
- to restriction of processing (Art. 18 DSGVO)
- to data portability (Art. 20 DSGVO) in a common machine-readable format
- to object to the processing (Art. 21 DSGVO)
- to withdraw your consent (Art. 7 Abs. 3 DSGVO)
You can lodge complaints with the competent supervisory authority: Unabhängiges Landeszentrum für Datenschutz Schleswig-Holstein (ULD), Holstenstraße 98, 24103 Kiel.
To exercise your rights, contact us at datenschutz@zepdesk.de. You can export your data yourself at any time with the complete export under Administration → Company → Complete export; if you cancel, we also provide you with an export.
10. SSL/TLS Encryption
For security reasons, this page and the entire ZepDesk platform use end-to-end SSL/TLS encryption (Let's Encrypt, protocol TLS 1.2 / 1.3). You can recognize this by the "https://" and the padlock symbol in your browser bar.
11. Changes to This Privacy Policy
We reserve the right to adapt this statement so that it always complies with current legal requirements or in order to implement changes to our services in the privacy policy. The new privacy policy then applies to your renewed visit. The current version is always available online at /datenschutz.
The path of your data, documented.
Legal texts are not an end in themselves: every version is versioned, dated, and traceable. The process behind it in four steps.
The binding version is the one specified above with its effective date.