Privacy Notice
Information pursuant to Articles 13, 14 GDPR and complementing the German Telecommunications Digital Services Data Protection Act (TDDDG).
1. Controller
The controller responsible for processing personal data in the context of the zimrly platform is:
Deern & Jung Investment GmbH
Managing director: Philip-Daniel Kleudgen
Aubachstrasse 107, 56567 Neuwied, Germany
Email: info@deern-jung.com
There is currently no statutory obligation to appoint a data protection officer (§ 38 BDSG). Data protection enquiries can be directed to the email address above.
2. Role: Processor / Controller
zimrly is a SaaS platform for commercial accommodation businesses (hotels, holiday rentals). Personal data of guests of zimrly customers are processed exclusively on behalf of the respective customer (Article 28 GDPR). The accommodation business is therefore the data controller for guest data under data protection law. A data processing agreement is in place with every customer and can be viewed and accepted in the customer portal.
This privacy notice additionally describes the processing of personal data of visitors to the website and user accountsof the zimrly platform — for these purposes, Deern & Jung Investment GmbH acts as independent controller.
3. Visiting the Website
When the website is accessed, technically necessary connection data are processed: IP address, date/time, requested URL, referrer, user-agent. Legal basis is Article 6 (1) lit. f GDPR (legitimate interest in providing and securing the website). These data are processed only for a short time by our hosting provider Vercel Inc. (function and edge request logs typically within a few hours to a maximum of one day, depending on the Vercel plan and log type). We do not operate a log drain that would copy these logs to an external system with longer retention, and we do not run our own webserver logs beyond this. Security-relevant application events (e.g. login, module activation, GDPR processes) are recorded separately in the audit log of our application and automatically deleted after 12 months (see section 8).
4. Account and Contract Handling
When registering an account and concluding a usage agreement, we process the following data:
- Name, email address, password hash (authentication)
- Company name, address, VAT ID, authorised representative (contract and invoicing)
- Payment data (Stripe — we do not store card data ourselves, only a Stripe customer ID)
- Activated modules, module configuration parameters, run receipts
Legal basis: Article 6 (1) lit. b GDPR (performance of contract) and Article 6 (1) lit. c GDPR (legal obligation — accounting and retention obligations under § 147 AO).
5. Processing on Behalf of the Customer
As part of the platform operation, guest master and reservation data (name, email, phone number, stay data, reservation notes, optionally conversation histories via WhatsApp) are processed exclusively on behalf of the respective hotel customer. Processing takes place on the basis of the DPA pursuant to Article 28 GDPR and the customer's instructions. Processing beyond the contractual purposes does not take place.
6. Recipients / Sub-Processors
We use the following sub-processors:
| Provider | Purpose | Location |
|---|---|---|
| Supabase Inc. | Database, authentication, file storage | EU (Ireland, eu-west-1) |
| Stripe Payments Europe Ltd. | Payment processing | Ireland (EU) |
| Vercel Inc. | Hosting, edge network | USA with EU edge (DPA, EU SCC) |
| easybill GmbH | Creation of DACH-compliant invoice documents | Germany |
| Brevo SAS (formerly Sendinblue) | Sending transactional emails (invoices, invitations, reset links) | France (servers in DE + FR) |
| Mistral AI SAS (optional, module-dependent) | AI-powered classification of reservation and communication content | France (models hosted in the EU) |
| Sentry GmbH | Error monitoring and performance tracing of the zimrly platform. Captures server and browser errors including stack traces in order to ensure stability. Personal data are deliberately not transmitted by default (sendDefaultPii: false); session replay is disabled. | Germany (Sentry GmbH, Vienna/Berlin), processing in the EU data centre Frankfurt (*.de.sentry.io); parent organisation Functional Software, Inc. (USA) as corporate background (SCC + DPF) |
zimrly pursues an EU-only strategy for personal data: email dispatch (Brevo), AI processing (Mistral) and the primary data layer (Supabase eu-west-1) run via EU regions. Transfers to third countries are avoided wherever possible. Insofar as data are nevertheless transferred to third countries (outside the EEA), this takes place on the basis of EU standard contractual clauses (Article 46 (2) lit. c GDPR) or a valid adequacy decision (Article 45 GDPR, EU-US Data Privacy Framework).
Customer-direct integrations (not zimrly sub-processors): For certain optional modules our customer (the hotelier) connects a third-party provider to their own account. These include, among others:
- WhatsApp Business API via 360dialog GmbH (Germany)
- SMS sending/receiving via ClickSend Pty Ltd (Australia; EU processing available)
- PMS integration via 3rpms GmbH or apaleo GmbH (Germany)
- Revenue management / repricer via Smartness Group / Smartpricing (Italy, EU)
- Time tracking via Crewmeister GmbH (Germany)
- Booking engine via Viato GmbH (Germany)
- Accounting / invoicing provider chosen by the customer (alternatively to easybill): Haufe-Lexware Services GmbH (lexoffice) (Germany), sevdesk GmbH (Germany) or Intuit Inc. (QuickBooks Online) (USA, DPF + SCC)
- Google LLC (Google Business Profile) for reviews sync in the Reviews module (USA, DPF + SCC)
zimrly is not a contractual partyhere but merely uses the API access provided by the customer. The customer enters into a separate data processing agreement with each of these providers (or is the bank's contractual party). Data flowing through zimrly are stored exclusively in the sub-processors listed above.
7. Cookies
We use exclusively technically necessary cookies (e.g. session cookie for authentication, cookie to store the consent decision). These are strictly necessary for the provision of the platform (§ 25 (2) no. 2 TDDDG); no consent is required.
We do not use any tracking, profiling or advertising cookies. No third-party tracking pixels either (no Google Analytics, no Meta pixel, no Hotjar). For cookieless, data-minimising analytics on our public pages, see section 12.
8. Retention Periods and Deletion Concept
Personal data are only stored for as long as is necessary for the respective purposes or as required by statutory retention obligations.
- Account data (profile, logins, module configuration): until deletion of the account, plus a 30-day technical buffer
- Invoice documents and accounting records: 10 years after the end of the calendar year in which the transaction took place (§ 147 AO, § 14b UStG)
- DPA acceptance records: 10 years after the end of the contract (proof obligation GDPR/BDSG)
- Server logs (Vercel): short-term (hours up to a maximum of one day, depending on the Vercel plan); no log drain with longer retention is active
- Audit log (security-relevant actions): 12 months
A detailed overview is set out in the internal deletion and retention concept (available on request).
9. Your Rights
You have the right at any time to:
- Access to the data stored about you (Article 15 GDPR)
- Rectification of incorrect data (Article 16 GDPR)
- Erasure of your data (Article 17 GDPR), insofar as no retention obligations conflict
- Restriction of processing (Article 18 GDPR)
- Data portability in a structured, commonly used format (Article 20 GDPR)
- Object to processing (Article 21 GDPR)
- Complaint to a supervisory authority (Article 77 GDPR) — the competent authority is the State Commissioner for Data Protection and Freedom of Information of Rhineland-Palatinate
Logged-in users can request access and deletion directly in the portal under "Settings → Legal → Privacy & Data Export". Alternatively by email to info@deern-jung.com.
10. Security
Data transmissions are exclusively encrypted (TLS 1.2 or higher). Provider tokens and access credentials for external systems are stored in the database encrypted with AES-256-GCM. Access to production infrastructure is restricted on a role-based basis; security-relevant actions are recorded in the audit log.
11. Use of Artificial Intelligence (AI)
For certain modules (in particular the AI chatbot in the unified inbox and the auto-reply functionin the Reviews hub), zimrly uses AI-powered language models. This section fulfils the transparency obligation under Article 13 GDPR and under Article 50 of EU Regulation 2024/1689 ("AI Act").
- Provider used: Mistral AI SAS, 5 rue de Madrid, 75008 Paris, France. Models hosted in the EU.
- Data processed: Incoming email and platform messages from guests as well as minimal reservation metadata (reservation ID, arrival/departure date, room category). Special categories under Article 9 GDPR are not actively processed.
- Purpose: Classification of the guest inquiry (intent, language, urgency) as well as suggestion or automatic sending of a reply. Depending on configuration, the AI output is either handed over to the hotel staff as a draft for release or — with auto-send mode active and sufficient confidence — sent directly to the guest. Auto-send replies are marked with a clearly visible AI notice in the email body and a subject tag
[Automated Reply]. - Legal basis: Article 6 (1) lit. b GDPR (performance of contract for booking inquiries) and Article 6 (1) lit. f GDPR (legitimate interest in efficient, timely guest communication).
- Retention at the AI provider: Mistral AI SAS applies a zero-retention policy to API inputs — the transmitted texts are not used for model training and are not permanently stored. zimrly-internal telemetry (token consumption, model ID, timestamp, org reference — without message content) is stored in the table
ai_usage_eventsfor a maximum of 6 months. - Right to object / opt-out: Guests may stop AI communication at any time. An incoming message containing one of the trigger words "STOP", "MENSCH", "kein Bot", "no bot", "human" or "agent" permanently pauses the bot for the respective thread; a hotel staff member then replies personally. Alternatively, the objection can be addressed directly by email to the respective hotelier (controller).
- Risk classification under the AI Act: The AI systems used fall under the limited-risk area of the AI Act (subject to transparency requirements under Article 50, no biometric identification, no automated decision-making producing legal effects on the data subject).
More detailed documentation on AI literacy, risk analysis and accountability structure is maintained internally at docs/legal/AI_LITERACY.md and is provided on request.
12. Web Analytics and Reach Measurement
On our publicly accessible pages (marketing pages, blog, tools) we use cookieless, data-minimising analytics. In the logged-in customer portal (dashboard) and the admin area, no analytics take place.
a) Plausible Analytics (cookieless)
- Provider: Plausible Insights OÜ, Tallinn, Estonia (EU). Data are processed on servers in the EU (Germany).
- Purpose: Aggregated reach and usage statistics (page views, referrers, approximate region at country/city level, device type) to improve our offering.
- Method: Plausible uses no cookies and creates no cross-device identifiers. No personal profiles are formed; IP addresses are not stored but only used to generate a daily, non-reversible hash value in order to count returning visits.
- Legal basis: Article 6 (1) lit. f GDPR (legitimate interest in data-minimising analytics). As no cookies or comparable technologies for accessing your device are used, no consent is required under § 25 (2) TDDDG.
- Recipient: Page-view data are transmitted to Plausible Insights OÜ (plausible.io) as a processor. DPA: plausible.io/dpa.
- Objection:As no personal reference is created, an individual objection is technically not meaningful. You can nevertheless prevent collection by enabling "Do Not Track" (DNT) in your browser or using a script/ad blocker.
b) Google Search Console (aggregated search analysis)
- Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (parent: Google LLC, USA).
- Purpose: Analysis of which Google search queries lead to our website (aggregated search terms, impressions, clicks, positions), for search engine optimisation.
- Important: No tracking script is embedded on the website for this, and no visitors are tracked. We merely retrieve aggregated reports — which Google holds anyway as part of its search engine — via our own Google Cloud project (OAuth, scope
webmasters.readonly). The reports are aggregated and contain no data identifying individual visitors. - Legal basis: Article 6 (1) lit. f GDPR (legitimate interest in the discoverability and optimisation of our offering).
- Recipient: Google Ireland Limited / Google LLC. The Google Cloud data processing agreement applies; insofar as a transfer to the USA takes place, this is based on the EU standard contractual clauses or the EU-US Data Privacy Framework.
c) Search engine notification (IndexNow)
For faster indexing, we automatically notify search engines (including Microsoft Bing, Yandex) of newly published or changed page URLs via the IndexNow protocol. Only URLs of our own website are transmitted — no personal data and no visitor data.
13. Changes to this Notice
We adapt this privacy notice when processing activities or the legal situation change. The version published here is authoritative at any given time.
As of 8 June 2026. The German version remains the authoritative legal document.