ZepDesk accounting software
ZepDesk
Sign in Try it free
Home / Privacy Policy

Privacy Policy

Binding version, adopted unchanged from our body of legal texts. Questions about it are answered at datenschutz@zepdesk.de.

Version 1.1.0 Valid from 2026-07-14 Provider: ZeptronIT UG (haftungsbeschränkt), Harmsdorf

As of: 2026-07-14

This English text is a convenience translation. The legally binding version is the German original.

1. Controller

The controller responsible for data processing on this website and the ZepDesk platform is:
ZeptronIT UG (haftungsbeschränkt)
Leon Marzoll
Möhlbarg 12, 23911 Harmsdorf
Email: datenschutz@zepdesk.de

2. Collection and Processing of Personal Data

2.1 When Visiting the Website

When this website is accessed, information is automatically sent by the browser of your device to the server of our website and temporarily stored in a log file: IP address (anonymized after 7 days), date and time of access, time-zone difference from GMT, content of the request (the specific page), access status/HTTP status code, amount of data transferred, referrer URL, browser, operating system and its interface, language and version of the browser software.

Legal basis: Art. 6 Abs. 1 lit. f DSGVO (GDPR) (legitimate interest in secure, stable operation).
Storage period: 7 days, after which the IP is automatically anonymized.

2.2 When Registering and Using ZepDesk

We process the following personal data:

  • Contact data: first and last name, email address, company, billing address
  • Login data: hashed password hash (never in plain text), session cookies
  • Payment data: processed exclusively by our payment provider Mollie (see section 5) and never reach us in plain text
  • Usage data: login times, API access logs, subdomain usage for troubleshooting and abuse detection
  • Support data: the contents of your support requests

Legal basis: Art. 6 Abs. 1 lit. b DSGVO (performance of a contract); for billing purposes also Art. 6 Abs. 1 lit. c DSGVO (statutory retention obligation, §§ 147 AO (German Fiscal Code), 257 HGB (German Commercial Code)).

3. Cookies

Our website uses only technically necessary cookies (a session cookie to maintain your login, CSRF protection). No marketing, analytics, or tracking cookies without your explicit consent.

Legal basis: § 25 Abs. 2 TDDDG (German Telecommunications Digital Services Data Protection Act) (technically necessary).

4. Hosting and Infrastructure

The ZepDesk platform is operated within the EU. We use the following infrastructure provider:
Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen
Data centers exclusively within the EU/EEA. A data processing agreement pursuant to Art. 28 DSGVO exists with Hetzner.

5. Payment Processing (Mollie)

For payment processing (SEPA direct debit, credit card, PayPal) we use the EU payment provider:
Mollie B.V., Keizersgracht 126, 1015 CW Amsterdam, Niederlande

During payment, the following data is transmitted to Mollie: name, email address, invoice amount, IBAN or card details. The payment data is entered encrypted directly with Mollie and does not reach us in plain text (PCI-DSS compliant). Mollie's privacy policy: mollie.com/privacy.

Legal basis: Art. 6 Abs. 1 lit. b DSGVO (performance of a contract).
AVV (data processing agreement): A data processing agreement pursuant to Art. 28 DSGVO exists with Mollie.

6. Email Delivery

We send transactional emails (password reset, invoices, system notifications) via our own SMTP server or via Postmark Deutschland. The contents of your emails are not analyzed for advertising purposes.

7. Data Processing (AVV)

Insofar as you, as the customer, process personal data of your end customers or employees in ZepDesk, you are the controller within the meaning of the DSGVO and we are your processor pursuant to Art. 28 DSGVO. The data processing agreement (AVV) required for this is part of our AGB (general terms and conditions) and is concluded online upon conclusion of the contract. You can find the text at /avv.

7a. Platform-as-a-Service: Technical Access to Your Instance

ZepDesk is not only a standard SaaS solution but also a Platform-as-a-Service (PaaS): your instance runs on a dedicated virtual machine that we operate, maintain, and, on request, can also customize individually for you. This entails certain technical access options, which we transparently disclose here:

7a.1 Passive Monitoring (automatic, without Ops interaction)

To ensure operation, we continuously collect and store technical metrics:

  • VM telemetry (every minute): CPU, RAM, disk utilization, number of sites, load average
  • Site metrics (daily): database size in MB, file size in MB, number of users, number of companies, number of invoices, as numeric values, not contents
  • HTTP availability checks: every 5 minutes, response status code and response time
  • Agent heartbeats from the customer VM (status, version, uptime)
  • Server log files: Apache/Nginx access and error logs for 7 days, then IP anonymization

Contents from your database (customer, invoice, and article data) are not read during passive monitoring. Legal basis: Art. 6 Abs. 1 lit. b DSGVO (performance of a contract) and lit. f (legitimate interest in stable operation).

7a.2 Active Ops Access (only in case of a malfunction or upon your instruction)

For maintenance and customization purposes, our technicians have the technical ability to connect to your instance. Specifically, we can:

  • SSH login as root or as a technical service account on your VM (via a management SSH key)
  • Database access: database administrator access for troubleshooting, backup restoration, data repair
  • Execute platform maintenance commands: Migration, module install commands)
  • Impersonation: switch into your customer platform as a logged-in user in order to reproduce a specific support issue
  • Deploy custom code: install our own extension modules or scripts, provided that you have commissioned customization services

7a.3 When do we actively access?

Exclusively in one of the following cases:

  1. Upon your express instruction / your support ticket request (e.g. "please install Addon X", "my import got stuck"). Legal basis: Art. 6 Abs. 1 lit. b DSGVO (performance of a contract) and, if you have concluded a Platform Service Agreement (see /platform-service), also this contractual basis.
  2. In the event of a serious malfunction that endangers the operation of your instance (e.g. disk full, DB corruption). Legal basis: Art. 6 Abs. 1 lit. f DSGVO (legitimate interest in service availability).
  3. In the event of security incidents (e.g. suspected malware, brute-force attacks). Legal basis: Art. 6 Abs. 1 lit. f DSGVO.
  4. In the event of a legal obligation (e.g. official requests for information). Legal basis: Art. 6 Abs. 1 lit. c DSGVO.

7a.4 Audit-Log

Every active Ops access is logged in the customer portal under My Account → Audit-Log: timestamp, affected site, type of action, the Ops person performing it, and, where applicable, the ticket number. You can view this log at any time and request an export.

7a.5 Independence from the Standard SaaS Usage Agreement

Active Ops customization services (point 7a.2, item 5 above) require a separate Platform Service Agreement (PSV). Without such a PSV, our active interventions are limited to maintenance and emergency measures (7a.3 nos. 2 to 4). Details on the PSV can be found at /platform-service.

7b. AI Assistant (optional feature)

ZepDesk includes an optional AI assistant that supports you in operating it (answering questions, creating drafts and booking suggestions, performing operating steps). The feature is opt-in and not required for the operation of the core functions.

Which data is transmitted: only if you actively use the AI assistant are your input and a portion of the currently visible page content (limited, not your entire database) transmitted to the configured language model in order to generate the response. Without active use, no transmission takes place.

Provider (Bring Your Own Key): the language model is provided by a provider that you configure yourself and for which you store your own access key (BYOK). The key is stored encrypted and is not logged. For this third-party service chosen by you, you are the contracting party of the respective provider; its terms and privacy notices apply additionally in this respect.

Transfer to a third country: if you choose a provider outside the EU (e.g. Anthropic, based in the USA), a transfer to a third country takes place in this respect. Alternatively, you can integrate an EU provider via a compatible endpoint. Our platform's own AI functions (receipt text recognition/OCR and speech-to-text), by contrast, run on servers in the EU.

No advice: outputs of the AI assistant are non-binding recommendations and information, not tax or legal advice; details are governed by the AGB.
Legal basis: Art. 6 Abs. 1 lit. b DSGVO (use of the feature you have activated); with respect to the provider relationship you have chosen, your own legal basis as the controller.

8. Storage Period

  • Account data: for the duration of the contract plus a 30-day grace period. Thereafter, complete deletion or anonymization, insofar as no statutory retention obligations preclude this.
  • Invoice data: 10 years pursuant to § 147 AO, § 257 HGB.
  • Server logs: 7 days, then IP anonymization.
  • Backups: 30 days rolling, then automatic deletion.

9. Your Rights

You have the right, in relation to us:

  • to information (Art. 15 DSGVO) about the data stored concerning you
  • to rectification (Art. 16 DSGVO) of inaccurate or incomplete data
  • to erasure (Art. 17 DSGVO / "right to be forgotten")
  • to restriction of processing (Art. 18 DSGVO)
  • to data portability (Art. 20 DSGVO) in a common machine-readable format
  • to object to the processing (Art. 21 DSGVO)
  • to withdraw your consent (Art. 7 Abs. 3 DSGVO)

You can lodge complaints with the competent supervisory authority: Unabhängiges Landeszentrum für Datenschutz Schleswig-Holstein (ULD), Holstenstraße 98, 24103 Kiel.

To exercise your rights, contact us at datenschutz@zepdesk.de. In addition, we provide self-service functions in the customer portal under My Account → Data Export / Data Deletion.

10. SSL/TLS Encryption

For security reasons, this page and the entire ZepDesk platform use end-to-end SSL/TLS encryption (Let's Encrypt, protocol TLS 1.2 / 1.3). You can recognize this by the "https://" and the padlock symbol in your browser bar.

11. Changes to This Privacy Policy

We reserve the right to adapt this statement so that it always complies with current legal requirements or in order to implement changes to our services in the privacy policy. The new privacy policy then applies to your renewed visit. The current version is always available online at /datenschutz.

The path of your data, documented.

Legal texts are not an end in themselves: every version is versioned, dated, and traceable. The process behind it in four steps.

STEP 1
Collection
STEP 2
Purpose limitation
STEP 3
Processing in the EU
STEP 4
Deletion after the retention period
PROCEDURE ................

The binding version is the one specified above with its effective date.