Privacy Notice
Information pursuant to Articles 13, 14 GDPR and complementing the German Telecommunications Digital Services Data Protection Act (TDDDG).
1. Controller
The controller responsible for processing personal data in the context of the zimrly platform is:
Zimrly UG (haftungsbeschränkt)
Managing director: Philip-Daniel Kleudgen
Aubachstrasse 107, 56567 Neuwied, Germany
Amtsgericht Montabaur, HRB 31381
Email: info@deern-jung.com
There is currently no statutory obligation to appoint a data protection officer (§ 38 BDSG). Data protection enquiries can be directed to the email address above.
2. Role: Processor / Controller
zimrly is a SaaS platform for commercial accommodation businesses (hotels, holiday rentals). Personal data of guests of zimrly customers are processed exclusively on behalf of the respective customer (Article 28 GDPR). The accommodation business is therefore the data controller for guest data under data protection law. A data processing agreement is in place with every customer and can be viewed and accepted in the customer portal.
This privacy notice additionally describes the processing of personal data of visitors to the website and user accounts of the zimrly platform — for these purposes, Zimrly UG (haftungsbeschränkt) acts as independent controller.
3. Visiting the Website
When the website is accessed, technically necessary connection data are processed: IP address, date/time, requested URL, referrer, user-agent. Legal basis is Article 6 (1) lit. f GDPR (legitimate interest in providing and securing the website). These data are processed only for a short time by our hosting provider Vercel Inc. (function and edge request logs typically within a few hours to a maximum of one day, depending on the Vercel plan and log type). We do not operate a log drain that would copy these logs to an external system with longer retention, and we do not run our own webserver logs beyond this. Security-relevant application events (e.g. login, module activation, GDPR processes) are recorded separately in the audit log of our application and automatically deleted after 12 months (see section 8).
4. Account and Contract Handling
When registering an account and concluding a usage agreement, we process the following data:
- Name, email address, password hash (authentication)
- Company name, address, VAT ID, authorised representative (contract and invoicing)
- Payment data (Stripe — we do not store card data ourselves, only a Stripe customer ID)
- Activated modules, module configuration parameters, run receipts
Legal basis: Article 6 (1) lit. b GDPR (performance of contract) and Article 6 (1) lit. c GDPR (legal obligation — accounting and retention obligations under § 147 AO).
5. Processing on Behalf of the Customer
As part of the platform operation, guest master and reservation data (name, email, phone number, stay data, reservation notes, optionally conversation histories via WhatsApp) are processed exclusively on behalf of the respective hotel customer. Processing takes place on the basis of the DPA pursuant to Article 28 GDPR and the customer's instructions. Processing beyond the contractual purposes does not take place.
6. Recipients / Sub-Processors
We use the following sub-processors:
| Provider | Purpose | Location |
|---|---|---|
| Supabase Inc. | Database, authentication, file storage | EU (Ireland, eu-west-1) |
| Stripe Payments Europe Ltd. | Payment processing | Ireland (EU) |
| Vercel Inc. | Hosting, edge network | USA with EU edge (DPA, EU SCC) |
| easybill GmbH | Creation of DACH-compliant invoice documents | Germany |
| Brevo SAS (formerly Sendinblue) | Sending transactional emails (invoices, invitations, reset links) | France (servers in DE + FR) |
| Mistral AI SAS (optional, module-dependent) | AI-powered classification of reservation and communication content | France (models hosted in the EU) |
| Apify Technologies s.r.o. (optional, module-dependent) | Automated retrieval of publicly available guest reviews from review platforms (Booking.com, Google Maps, Airbnb). Only content that the platforms display publicly is retrieved. Only when the “Reviews” module is enabled. | Czech Republic (Prague), EU |
| Channex.io Ltd (optional, module-dependent) | Channel manager connection to online travel agencies (Booking.com, Expedia, Airbnb and others): distribution of availability, rates and restrictions, and receipt of the bookings, cancellations, guest messages and reviews originating there. Only when the “Channels” module is enabled. | United Kingdom (Channex.io Ltd), processing and hosting in the EU: Amsterdam, Netherlands (EU standard contractual clauses, module 2) |
| Sentry GmbH | Error monitoring and performance tracing of the zimrly platform. Captures server and browser errors including stack traces in order to ensure stability. Personal data are deliberately not transmitted by default (sendDefaultPii: false); session replay is disabled. | Germany (Sentry GmbH, Vienna/Berlin), processing in the EU data centre Frankfurt (*.de.sentry.io); parent organisation Functional Software, Inc. (USA) as corporate background (SCC + DPF) |
zimrly pursues an EU-only strategy for personal data: email dispatch (Brevo), AI processing (Mistral) and the primary data layer (Supabase eu-west-1) run via EU regions. Transfers to third countries are avoided wherever possible. Insofar as data are nevertheless transferred to third countries (outside the EEA), this takes place on the basis of EU standard contractual clauses (Article 46 (2) lit. c GDPR) or a valid adequacy decision (Article 45 GDPR, EU-US Data Privacy Framework).
Customer-direct integrations (not zimrly sub-processors): For certain optional modules our customer (the hotelier) connects a third-party provider to their own account. These include, among others:
- WhatsApp Business API via 360dialog GmbH (Germany)
- SMS sending/receiving via ClickSend Pty Ltd (Australia; EU processing available)
- PMS integration via 3rpms GmbH or apaleo GmbH (Germany)
- Revenue management / repricer via PriceLabs (USA, SCC) or RoomPriceGenie AG (Switzerland, adequacy decision)
- Time tracking via Crewmeister GmbH (Germany)
- Accounting / invoicing provider chosen by the customer (alternatively to easybill): Haufe-Lexware Services GmbH (lexoffice) (Germany), sevdesk GmbH (Germany) or Intuit Inc. (QuickBooks Online) (USA, DPF + SCC)
- Google LLC (Google Business Profile) for reviews sync in the Reviews module (USA, DPF + SCC)
zimrly is not a contractual party here but merely uses the API access provided by the customer. The customer enters into a separate data processing agreement with each of these providers (or is the bank's contractual party). Data flowing through zimrly are stored exclusively in the sub-processors listed above.
7. Cookies
We use exclusively technically necessary cookies (e.g. session cookie for authentication, cookie to store the consent decision). These are strictly necessary for the provision of the platform (§ 25 (2) no. 2 TDDDG); no consent is required.
On zimrly's own pages (marketing pages, blog, tools) and in the customer portal we do not use any tracking, profiling or advertising cookies. Nor do we embed any third-party tracking pixels there (no Google Analytics, no Meta pixel, no Hotjar). The cookieless, data-minimising analytics on these pages are described in section 12 a) to c).
To be distinguished from this are the direct-booking pages of our customers (zimr.ly/buchen/…). There, the respective accommodation business may enable statistics (Google Tag Manager / Google Analytics 4) and, separately from that, Google Ads conversion measurement. Both procedures use cookies or comparable technologies and run exclusively after your prior consent, which is requested separately for each purpose; without consent, no Google script is loaded and no cookie is set. Your decision is stored not in a cookie but in your browser's local storage, separately for each accommodation business; this storage is necessary to give effect to your decision (§ 25 (2) no. 2 TDDDG). Details in section 12 e) to g).
8. Retention Periods and Deletion Concept
Personal data are only stored for as long as is necessary for the respective purposes or as required by statutory retention obligations.
- Account data (profile, logins, module configuration): until deletion of the account, plus a 30-day technical buffer
- Invoice documents and accounting records: 10 years after the end of the calendar year in which the transaction took place (§ 147 AO, § 14b UStG)
- DPA acceptance records: 10 years after the end of the contract (proof obligation GDPR/BDSG)
- Server logs (Vercel): short-term (hours up to a maximum of one day, depending on the Vercel plan); no log drain with longer retention is active
- Audit log (security-relevant actions): 12 months
A detailed overview is set out in the internal deletion and retention concept (available on request).
9. Your Rights
You have the right at any time to:
- Access to the data stored about you (Article 15 GDPR)
- Rectification of incorrect data (Article 16 GDPR)
- Erasure of your data (Article 17 GDPR), insofar as no retention obligations conflict
- Restriction of processing (Article 18 GDPR)
- Data portability in a structured, commonly used format (Article 20 GDPR)
- Object to processing (Article 21 GDPR)
- Complaint to a supervisory authority (Article 77 GDPR) — the competent authority is the State Commissioner for Data Protection and Freedom of Information of Rhineland-Palatinate
Logged-in users can request access and deletion directly in the portal under "Settings → Legal → Privacy & Data Export". Alternatively by email to info@deern-jung.com.
10. Security
Data transmissions are exclusively encrypted (TLS 1.2 or higher). Provider tokens and access credentials for external systems are stored in the database encrypted with AES-256-GCM. Access to production infrastructure is restricted on a role-based basis; security-relevant actions are recorded in the audit log.
11. Use of Artificial Intelligence (AI)
For certain modules (in particular the AI chatbot in the unified inbox and the auto-reply function in the Reviews hub), zimrly uses AI-powered language models. This section fulfils the transparency obligation under Article 13 GDPR and under Article 50 of EU Regulation 2024/1689 ("AI Act").
- Provider used: Mistral AI SAS, 5 rue de Madrid, 75008 Paris, France. Models hosted in the EU.
- Data processed: Incoming email and platform messages from guests as well as minimal reservation metadata (reservation ID, arrival/departure date, room category). Special categories under Article 9 GDPR are not actively processed.
- Purpose: Classification of the guest inquiry (intent, language, urgency) as well as suggestion or automatic sending of a reply. Depending on configuration, the AI output is either handed over to the hotel staff as a draft for release or — with auto-send mode active and sufficient confidence — sent directly to the guest. Auto-send replies are marked with a clearly visible AI notice in the email body and a subject tag
[Automated Reply]. - Legal basis: Article 6 (1) lit. b GDPR (performance of contract for booking inquiries) and Article 6 (1) lit. f GDPR (legitimate interest in efficient, timely guest communication).
- Retention at the AI provider: Mistral AI SAS applies a zero-retention policy to API inputs — the transmitted texts are not used for model training and are not permanently stored. zimrly-internal telemetry (token consumption, model ID, timestamp, org reference — without message content) is stored in the table
ai_usage_eventsfor a maximum of 6 months. - Right to object / opt-out: Guests may stop AI communication at any time. An incoming message containing one of the trigger words "STOP", "MENSCH", "kein Bot", "no bot", "human" or "agent" permanently pauses the bot for the respective thread; a hotel staff member then replies personally. Alternatively, the objection can be addressed directly by email to the respective hotelier (controller).
- Risk classification under the AI Act: The AI systems used fall under the limited-risk area of the AI Act (subject to transparency requirements under Article 50, no biometric identification, no automated decision-making producing legal effects on the data subject).
More detailed documentation on AI literacy, risk analysis and accountability structure is maintained internally at docs/legal/AI_LITERACY.md and is provided on request.
12. Web Analytics and Reach Measurement
On our publicly accessible pages (marketing pages, blog, tools) we use cookieless, data-minimising analytics. The procedures described under a) to d) do not access your device, set no cookies and require no consent. In the logged-in customer portal (dashboard) and the admin area, no analytics take place.
On the direct-booking pages of our customers, the respective accommodation business may additionally enable statistics (e) and Google Ads conversion measurement (f). These two procedures use cookies or comparable technologies and run exclusively after your prior consent, given separately for each purpose.
a) Plausible Analytics (cookieless)
- Provider: Plausible Insights OÜ, Tallinn, Estonia (EU). Data are processed on servers in the EU (Germany).
- Purpose: Aggregated reach and usage statistics (page views, referrers, approximate region at country/city level, device type) to improve our offering.
- Method: Plausible uses no cookies and creates no cross-device identifiers. No personal profiles are formed; IP addresses are not stored but only used to generate a daily, non-reversible hash value in order to count returning visits.
- Legal basis: Article 6 (1) lit. f GDPR (legitimate interest in data-minimising analytics). As no cookies or comparable technologies for accessing your device are used, no consent is required under § 25 (2) TDDDG.
- Recipient: Page-view data are transmitted to Plausible Insights OÜ (plausible.io) as a processor. DPA: plausible.io/dpa.
- Objection: As no personal reference is created, an individual objection is technically not meaningful. You can nevertheless prevent collection by enabling "Do Not Track" (DNT) in your browser or using a script/ad blocker.
b) Google Search Console (aggregated search analysis)
- Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (parent: Google LLC, USA).
- Purpose: Analysis of which Google search queries lead to our website (aggregated search terms, impressions, clicks, positions), for search engine optimisation.
- Important: No tracking script is embedded on the website for this, and no visitors are tracked. We merely retrieve aggregated reports — which Google holds anyway as part of its search engine — via our own Google Cloud project (OAuth, scope
webmasters.readonly). The reports are aggregated and contain no data identifying individual visitors. - Legal basis: Article 6 (1) lit. f GDPR (legitimate interest in the discoverability and optimisation of our offering).
- Recipient: Google Ireland Limited / Google LLC. The Google Cloud data processing agreement applies; insofar as a transfer to the USA takes place, this is based on the EU standard contractual clauses or the EU-US Data Privacy Framework.
c) Search engine notification (IndexNow)
For faster indexing, we automatically notify search engines (including Microsoft Bing, Yandex) of newly published or changed page URLs via the IndexNow protocol. Only URLs of our own website are transmitted — no personal data and no visitor data.
d) Analysis of searches on our customers' booking pages
- Purpose: On our customers' direct-booking pages we measure how many enquiries led to a bookable offer and how many did not. From this we derive, for the individual accommodation business, the dates on which demand exceeds supply — the basis for pricing and occupancy recommendations.
- Method: We store only the requested period, the number of travellers and the search result. We do not store IP address, browser identifier, referrer or any session identifier — not even a hashed or salted one. No identifier is created that links individual visits; repeated identical searches are consolidated solely on the basis of the search attributes.
- No personal reference: No natural person can be identified from this information; it constitutes anonymous data within the meaning of Recital 26 GDPR, whose processing falls outside the scope of the GDPR. Neither access to nor storage of information on your device takes place, so section 25 TDDDG does not apply either and no consent is required.
- Recipients: None. The analysis takes place exclusively within our EU infrastructure and is not transmitted to third parties.
- Retention: 2 years; the records are deleted thereafter.
e) Statistics on our customers' booking pages (only with consent)
- Precondition: This measurement only takes place if the respective accommodation business has configured a Google Tag Manager container and/or a Google Analytics 4 property for its direct-booking page. If nothing is configured, you are neither asked nor is anything loaded.
- Controller and recipient: The measurement runs in the Google account of the respective accommodation business, which is the controller for it (see section 2); zimrly provides the technical integration. The recipient of the data is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (parent: Google LLC, USA). Insofar as a transfer to the USA takes place, this is based on the EU standard contractual clauses or the EU-US Data Privacy Framework.
- Purpose: Analysis of how the booking page is used and through which channel a booking came about (reach and channel statistics of the accommodation business).
- Consent: Before your decision, no Google script is loaded — no request, no cookie, no transmission of your IP address to Google. Only after your consent are the Tag Manager container and/or the Google Analytics script loaded, and in Google Consent Mode v2
analytics_storageis set to “granted”; all advertising purposes remain “denied”. If you choose “Decline” or tick nothing, nothing is loaded and nothing is measured. - Data transmitted: Page views of the booking flow with IP anonymisation enabled and, upon completion of a booking, a “purchase” event containing the booking code (as transaction ID), the gross amount and the currency. Deliberately not transmitted are any item or room list and any guest data (name, email address, phone number, postal address). The booking code serves solely to prevent Google from counting a booking twice.
- Legal basis: Article 6 (1) lit. a GDPR (consent) and § 25 (1) TDDDG for storing and accessing information on your device.
- Storage of your decision and withdrawal: Your decision is stored exclusively locally in your browser (local storage), separately for each accommodation business; it is not transmitted to us or to Google. You may withdraw your consent at any time with effect for the future: via the „Change privacy settings“ link at the bottom of the booking page, or by deleting the site data for zimr.ly in your browser; in both cases you will be asked again on your next visit. The lawfulness of processing carried out before the withdrawal remains unaffected.
f) Google Ads conversion measurement on our customers' booking pages (only with consent)
- Precondition: This measurement only takes place if the respective accommodation business has configured a Google Ads conversion action for its direct-booking page. Only then does the corresponding question appear; on all other booking pages it is not asked.
- Controller and recipient: The measurement runs in the Google Ads account of the respective accommodation business, which is the controller for it (see section 2); zimrly provides the technical integration. The recipient of the data is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (parent: Google LLC, USA). Insofar as a transfer to the USA takes place, this is based on the EU standard contractual clauses or the EU-US Data Privacy Framework.
- Purpose: Attribution of a completed booking to a Google ad of the accommodation business through which you reached the booking page (conversion measurement).
- Separate consent: Consent to advertising measurement is requested separately from consent to statistics (e) — two separate checkboxes, no bundled “accept all” button, and an equally visible option to decline. Consent previously given for statistics alone does not extend to advertising measurement; in that case you are asked again.
- Without consent: No Google Ads script is loaded, no request is sent to Google, no cookie is set and no IP address is transmitted to Google. If you have consented to statistics (e) only,
ad_storage,ad_user_dataandad_personalizationremain “denied” in Google Consent Mode v2 and advertising data redaction (ads_data_redaction) is active. - After consent: The Google Ads script is loaded and
ad_storage,ad_user_dataandad_personalizationare set to “granted”. Upon completion of a booking, a conversion event is transmitted containing the booking code as transaction ID, the gross amount and the currency (EUR). Not transmitted are guest data, in particular no email address, and no room category. The “Enhanced Conversions” feature (transmission of hashed contact data to Google) is expressly disabled (allow_enhanced_conversions: false). - Legal basis: Article 6 (1) lit. a GDPR (consent) and § 25 (1) TDDDG for storing and accessing information on your device.
- Storage of your decision and withdrawal: Your decision is stored exclusively locally in your browser (local storage), separately for each accommodation business; it is not transmitted to us or to Google. You may withdraw your consent at any time with effect for the future: via the „Change privacy settings“ link at the bottom of the booking page, or by deleting the site data for zimr.ly in your browser; in both cases you will be asked again on your next visit. The lawfulness of processing carried out before the withdrawal remains unaffected.
g) Measuring the success of ChatGPT (OpenAI) adverts on our customers' booking pages (consent only)
- When this applies at all: Only if you reached an accommodation business's website via an advert in ChatGPT, consented to the „Marketing“ category there, and the business has stored OpenAI credentials with us. Otherwise we receive no identifiers and transmit nothing.
- Where the identifiers come from: When you click „Book“, the business's website passes two identifiers to the booking page: a click reference (
oppref) and a random identifier by which OpenAI recognises your browser (obref). Both originate from cookies OpenAI set on the business's website; the booking page sets no cookies of its own for this. Zimrly UG (haftungsbeschränkt) operates the booking page on behalf of the business and stores the identifiers unchanged with the reservation. - Data transmitted: After a booking is completed, we transmit once, on behalf of the business and within seven days, to OpenAI Ireland Limited (Dublin): the booking code, the gross amount of the booking, the time of the reservation, the address of the booking page without parameters, and the two identifiers. Not transmitted are name, email address, phone number, travel dates or room category. Cancellations are not reported to OpenAI; cancelled bookings that have not yet been reported are not reported at all.
- Purpose: To determine whether adverts in ChatGPT lead to bookings and to steer the adverts accordingly. OpenAI may attribute the booking to the ChatGPT account through which the advert was seen.
- Controller and legal basis: The controller is the respective accommodation business; we act as its processor (Art. 28 GDPR). The legal basis is your consent given on the business's website (Art. 6(1)(a) GDPR).
- Recipient and third country: OpenAI Ireland Limited processes the data under its own responsibility, including in the USA, where no EU-level data protection is guaranteed; OpenAI is not certified under the EU-US Data Privacy Framework. Information on processing by OpenAI: openai.com/policies/eu-privacy-policy
- Consent carried over: If you have already decided on the business's website, that decision may be passed to the booking pages, and you will not be asked again here. Only a decision you made explicitly there is carried over, and only where the notice shown to you names zimrly UG as a recipient. You can change or withdraw it at any time via the privacy settings at the foot of the booking pages; a withdrawal made here stands and is not overwritten by a further visit from the business's website.
- Deletion and withdrawal: We delete the identifiers 90 days after your departure or, in the event of a cancellation, 90 days after the cancellation; the reservation itself remains subject to statutory retention periods. You may withdraw your consent at any time via the privacy settings of the business's website or of the booking pages; the lawfulness of processing carried out until then remains unaffected.
13. Changes to this Notice
We adapt this privacy notice when processing activities or the legal situation change. The version published here is authoritative at any given time.
As of 3 September 2026. The German version remains the authoritative legal document.