Vai al contenuto
Iscriviti alla lista d'attesa

Privacy policy (Datenschutzerklärung)

Versione del 2026-09-24

Indice

This is a courtesy translation. The German version of this privacy policy is the legally binding one; in case of any discrepancy between the German and the English version, the German version prevails.

1 · Controller

Oliver Wagener Ahnekamp 41, 31137 Hildesheim, Deutschland Represented by: Oliver Wagener Email: datenschutz@zirko.io

No data protection officer has been designated; the conditions of Art. 37 DSGVO (GDPR) / § 38 BDSG (German Federal Data Protection Act) are not currently met.

2 · Two roles: controller and processor

Zirko is software for trade businesses (Handwerksbetriebe — skilled-trades businesses). We therefore process personal data in two different roles; depending on who you are, one or the other applies to you:

You visit our website or you are our contracting party. Then we are the controller — for delivering the pages, for your user account (Zugangskonto), for the contract and for billing. What we do in that role is set out in § 4.

You are a customer, a supplier or an employee (Beschäftigter) of a business (Betrieb) that uses Zirko. Then your data is in Zirko because that business entered it there. It is the controller, not us; we are its processor and act only on its instruction (Art. 28 GDPR). You therefore request access, rectification and erasure from that business. If such a request reaches us directly, we forward it without undue delay and support the business in answering it — we are not permitted to answer it ourselves. What is processed in this role is set out in § 5.

  • Art. 6 (1) (b) — contract and pre-contractual measures (user account, provision of the service, billing).
  • Art. 6 (1) (c) — legal obligation (retention of our own bookkeeping, § 147 AO (Abgabenordnung — German Fiscal Code)).
  • Art. 6 (1) (f) — legitimate interest (secure and stable operation, prevention of abuse).
  • Art. 6 (1) (a) — consent; it is the basis solely for the entry in the launch list (§ 4.7).
  • Art. 28 — processing on behalf of the controller for our customers.

Beyond that, we obtain no consent: operating the website and the application involves no processing that requires one (§ 7).

4 · What we process as a controller

4.1 Accessing the website and the application

When you access them, the hosting provider processes server and access logs: IP address, time, the address requested, the referrer address and the browser identification. They are technically necessary for delivery and serve to fend off attacks.

  • Legal basis: Art. 6 (1) (f), and for signed-in users additionally (b).
  • Recipient: Vercel (§ 6).
  • Storage period: according to the hosting provider's retention time. We do not keep a permanent copy of our own and we do not evaluate these logs in a personally identifiable way.

4.2 User account, sign-in, invitations

For an account we process: email address, password hash value, first and last name, optionally a telephone number, a profile picture, your language setting as well as sign-in times and session attributes.

  • Legal basis: Art. 6 (1) (b) and (f).
  • Recipients: Supabase (accounts and sign-in), Resend (sending confirmation and password emails) — § 6.
  • Storage period: until the account is deleted. You can delete your account yourself in the application. In doing so, identity and affiliation are removed: account, profile, profile picture, memberships and invitations. Records with a statutory evidential function — in particular working times, absences and the business's accounting documents (Belege) — remain in place; in them, the remaining identifier can no longer be resolved to any name after deletion. Further details in § 5 and § 9.

4.3 Contract and billing

For the contract we process the name of the business, address, billing contact, VAT identification number (USt-IdNr.) or tax number, the license type and quantity booked as well as the subscription status.

Billing is carried out by Paddle as Merchant of Record — in legal terms Paddle is the seller, collects payment in its own name and issues the invoice to you itself. Payment data (card, SEPA) does not reach us; it is held exclusively by Paddle. We merely mirror the status.

When you book, Paddle's checkout window opens in your browser. Your browser then connects directly to Paddle. Paddle is a controller in its own right for the entire billing process and is not our processor — for your IP address and your payment details just as much as for the invoicing data we pass to it. What appears in that window — product, quantity, allocation to your business — we assemble beforehand on our server and not in your browser; otherwise these values could be altered before submission.

  • Legal basis: Art. 6 (1) (b); for the retention of our own bookkeeping (c) in conjunction with § 147 AO.
  • Storage period: end of the contract plus the statutory retention periods for our own bookkeeping.

4.4 Messages to you

We send system messages: confirmation of registration, password reset, invitations, contract and status notifications. The recipient is Resend; what is recorded is the address, the content and the delivery status.

Amendments to the AGB (General Terms and Conditions) are notified by email to all accounts of the business with administrative rights and are additionally displayed in the application (AGB § 15 (3)). As evidence we store when the notification went out and to how many addresses, the dispatch service provider's identifiers, until when an objection can be made, and whether, when and from which account consent was given or an objection was made. The evidence is kept for as long as the business exists (Art. 6 (1) (b) GDPR).

We send promotional messages only to the launch list — with your express consent and within the narrow scope described in § 4.7. There is no regular newsletter.

4.5 Your inquiries

If you contact us by email or via the contact form on our website, we process your details in order to answer you (Art. 6 (1) (b) or (f)). Inquiries that have the character of a commercial letter are subject to the retention periods under commercial and tax law.

The contact form collects name, email address and message — nothing more. Your details are not stored but transmitted as an email to our mailbox; Resend handles the sending (§ 6). When you submit, we also process your IP address in order to limit the number of messages per connection (Art. 6 (1) (f) — protection against mass abuse of the form). For that purpose it is held only as a shortened checksum bound to the day in working memory, for one hour at most, and is neither stored nor transmitted.

There is no chat window on our pages, and for the contact form we use no captcha from a third-party provider.

4.6 Error reports

If an error occurs in the application, we generate an error report in order to find and fix the fault. The recipient is Sentry (EU data residency, § 6).

Only this exhaustive list is transmitted: error identifier, error type, the area affected, the address of the page in patterned form (without identifiers), the identifier of your business, your role, the technical call stack lines — as well as technical framing details of the error itself: runtime environment (browser or server), name of the environment, version of the application and an internal error number with no personal reference. These framing details, too, contain no content and no personal reference beyond the identifier of the business mentioned.

Not transmitted are: the wording of the error message, names, addresses, amounts, document texts or other content. The detailed entry containing the wording stays in our own server log. Content from a business's data does not reach third parties by this route.

Which role we act in depends on where the report comes from. What our server reports carries no reference to a business: the report arises outside the session; the identifier of the business and the role are not in it. The same applies to everything called up without signing in. These reports concern our own application alone — for them we are the controller. If, on the other hand, the browser of a signed-in user reports an error, the identifier of their business and their role are attached to it; they come from the verified session and not from the report. To that extent we process details from the business's holdings and act as its processor (§ 2); Sentry is our sub-processor in this, as the data processing agreement sets out.

  • Legal basis, in so far as we are the controller (reports without any reference to a business): Art. 6 (1) (f). For the reports carrying the identifier of the business and the role, we act on its behalf (Art. 28 GDPR); which legal basis applies there is determined by the business.
  • Storage period: the service's retention time.

4.7 Launch list (Interessentenliste)

Until Zirko is generally available, you can sign up on our website for a launch list. Its purpose is narrowly limited: one notification as soon as Zirko is available — no newsletter, no ongoing advertising.

What is stored: your email address, the market on whose page you signed up (it determines the language of your emails), the times of sign-up, of the last confirmation email, of confirmation and of notification, as well as technical checksums of the confirmation and unsubscribe links. The time of the last email limits how often our form can write to the same address and so protects your mailbox from repeated sends. Your IP address is not stored — on submission the same volume protection applies as for the contact form (§ 4.5): a shortened checksum bound to the day, in working memory only, for one hour at most.

The legal basis is your consent (Art. 6 (1) (a) GDPR; for the promotional approach § 7 (2) no. 2 UWG). It is obtained by the double opt-in procedure: after signing up you receive an email with a confirmation link, and only your click on the confirmation page puts you on the list. That click is at the same time our proof of consent (Art. 7 (1)). An entry that is not confirmed is deleted after 30 days.

Withdrawal: every email sent to the list contains an unsubscribe link. Removing yourself deletes your entry completely — not even a "suppression list" remains. In addition, an informal email to datenschutz@zirko.io is sufficient at any time (Art. 7 (3); the lawfulness of the processing carried out up to the withdrawal remains unaffected).

Deletion also without any action on your part, by a daily automatic deletion run — in each case with the next run after the period expires: unconfirmed entries 30 days after sign-up; all entries 30 days after the notification; and one year after your confirmation, if by then there was nothing to notify you about.

Service providers involved (both § 6): the list is held at Supabase in Frankfurt; the emails are sent by Resend.

5 · What we process as a processor for businesses

The controller in each case is the business. What is processed — depending on what it uses:

AreaData subjectsData
Customers and invoice recipientsThe business's customers and their contact personsName, form of address, addresses, email, telephone, website, VAT identification number, payment term, free text
Projects, reports, files, project chatCustomers, employeesProject and address data, contact persons, site photos, messages, signatures on reports
Outgoing documentsThe business's customersRecipient address, line items, amounts, payment, dunning and dispatch notes; where a quote, cost estimate, order confirmation or delivery note is sent as a draft, the sent version as a PDF
Incoming documentsSuppliers and their employeesOriginal file, the fields extracted from it, allocations and checking notes. The sender may receive an automatic reply — either because their message contained no readable e-invoice or because nobody allocated it. A message that has not been allocated is returned to its sender 30 days after arrival and its content deleted. No more than one such email goes out per sender per day
Scheduling and time trackingThe business's employeesWorking and travel times, site addresses, corrections to the working-time account, absences including their type (e.g. leave, sickness, short-time work) and the approval status
Payroll and costing basesEmployeesAllocation to wage groups and hourly rates
App notificationsEmployeesDevice identifier for notifications
Automated messages — only if the business has switched them on (§ 5.1)The business's customers, employees, the business itselfName and email address of the recipient, the trigger (document, project, appointment, deadline), the text from the business's template, the time of dispatch and the delivery status; in the case of an upload link, the files provided there
Sending via the business's own mailbox — only if the business has connected it (§ 5.2)The mailbox holder; the recipients of the messagesAddress and provider of the mailbox, for the other providers server and user name; the credentials, encrypted; times of connection and of the last message sent; recipient address, text and attachments of the individual message
Automatic allocation of employees to a project — only if the business has switched it on (§ 9)The business's employeesThe persons the business has recorded by name for each project status, the project and the time of the allocation. No message goes out in the process
Feedback sent from within the application — only if a user sends one (§ 5.3)The business's employees; the business's customers, in so far as they are visible on a recordingFree text of the user, business, role, page visited in patterned form, version of the application and time; voluntarily a screenshot or screen recording that may show screen contents and thus data of the business's customers — names, addresses, amounts, possibly bank details

On the absence type "sickness": even without a diagnosis it may be data concerning health within the meaning of Art. 9 GDPR. We treat it as such; it is for the business as controller to create the legal basis for it (Art. 9 (2) (b) in conjunction with § 26 (3) BDSG). The data processing agreement expressly names this category.

On time tracking — no location tracking, no monitoring of conduct or performance. The mobile application collects no location data; it does not query the device's whereabouts, and the security headers on every response block the browser's geolocation function (§ 10). The "site address" on a time entry is the address of the site taken from the schedule, not the measured whereabouts of a person. Nor is there any evaluation of the conduct or performance of individual employees by us: no punctuality score, no ranking, no report to superiors about the conduct of individuals (see also § 5.1). What the business itself does with the recorded times is governed by the employment law applicable to it and by co-determination — it is the controller for that.

Three kinds of processing that expressly do not take place:

  1. No artificial intelligence is used. Zirko transmits nothing to a third party's language, text or speech recognition model — not for documents, not for reports, not for quotes, not for messages.
  2. The character recognition of incoming invoices runs entirely on your device. The invoice image does not leave the browser and reaches no third party. We also load the program components required for it from our own server instead of from a third-party network; no third party thereby learns the time or the IP address of an invoice upload.

The character recognition is a pattern recognizer on your device that recognizes letters in an image. It is not a language model within the meaning of point 1, and it transmits nothing to third parties.

  1. Address suggestions run via our server, not out of your browser. The provider learns neither your IP address nor who is searching. All that is stored with us is the finished address, no provider identifier and no raw response.

5.1 Automated messages

A business can allow Zirko to send a message of its own accord in certain situations: a reminder when a quote goes unanswered, a note before an appointment, a request to provide documents. We call these automations. This section is addressed to the recipients of such a message.

No automation is switched on by default. The business switches on each one itself, sets its deadlines and writes the text that reaches you. It can switch any of them off again at any time with immediate effect.

Who decides what you receive. The business decides: whether an automation runs at all, after how many days, with what text and to whom. We carry out what it has set. It is the controller (§ 2), we are its processor.

No assessment of you as a person. An automation checks a simple question — "has the quote gone unanswered for seven days?" — and then sends the text the business has stored. It assesses nothing about you, builds no profile, checks no creditworthiness and takes no decision: it does not issue an invoice, does not change one, approves nothing and triggers no payment. No language model is involved in this — neither in the question nor in the text.

Three groups of recipients:

  • The business itself — reminders to its own address. No third party learns of them.
  • An employee of the business, on the matter that concerns them personally (for instance: a time entry is missing). This message goes to them, not to their superiors. Zirko does not send any report to superiors about the conduct or performance of individual employees.
  • The business's customers — follow-up messages, appointment reminders, notices about an expiring link, requests for documents. Only in this case does a message leave the business.

The upload link. If a business asks you via such a message to provide documents, the message contains a time-limited link that belongs to that one matter only. What you upload through it then sits with the business like any other file it holds on your matter — it is responsible for it. We do not review it and we do not evaluate it.

What happens to this data. For dispatch, your email address and the text of the message go to our dispatch service provider (§ 6, the Resend row) — or, if the business has connected its own mailbox and the message is not addressed to an employee, to the provider of that mailbox (§ 5.2) — and to no one else; automation does not bring an additional service provider into being. A log entry remains with us: when which message went to whom. The business can view it for 30 days; it serves as its proof of what was sent in its name.

We evaluate none of this — no cross-business evaluation, no statistics about content, no product improvement derived from your messages.

If you do not want this: contact the business the message comes from. It is the controller and can switch the automation off or exclude you from it. If your objection reaches us, we forward it to the business without undue delay (§ 9).

5.2 Sending via the business's own mailbox

A business can connect its own email mailbox to Zirko. The messages Zirko sends on its behalf — documents, payment reminders and the automated messages to its customers and to itself (§ 5.1) — then go out from its address, and as a rule a copy is kept in its "Sent" folder (see below). Messages to the business's employees, by contrast, always go via our dispatch service provider (§ 6, the Resend row) — they do not belong in a mailbox read by the management. No mailbox is connected by default; only an admin of the business can connect or disconnect one. Here, too, the business is the controller (§ 2); we are its processor and send what it has arranged.

Sending only, no reading. Zirko reads no message from the mailbox — neither the inbox nor drafts, contacts or calendars. What the access looks like depends on the provider:

  • Google (Gmail, Google Workspace): the business signs in with Google and grants a permission there that allows sending only; in addition we learn the account's address. Google itself files the sent message under "Sent".
  • Microsoft (Outlook.com, Microsoft 365): likewise a permission for sending only, together with the account's address. Microsoft itself files the sent message under "Sent Items".
  • All other providers: the business enters the server, user name and password — or an app password it has created for this purpose with the provider. Zirko uses these to send via the provider's outgoing mail server. If the business has also entered its provider's IMAP server, Zirko then files the sent message in the "Sent" folder; to find that folder, Zirko reads the list of folder names — not any message in it. If filing fails, the message has still been sent, only without a copy in "Sent".

The permissions granted to Google and Microsoft remain valid until the business disconnects the mailbox; this lets scheduled messages go out without anyone having to sign in again.

What we store. The mailbox's address and provider; for the other providers, server, ports, user name and the name of the "Sent" folder; the times of connection and of the last message sent; after a failure, an error code without content. The credentials themselves — with Google and Microsoft an access token issued by the provider, otherwise the password — we store encrypted. The key is not kept in the database but only in our server's environment, and the credentials never reach a browser, not even the business's own (§ 10). We use them solely to send and file the business's messages.

Who receives the message. When a mailbox is connected, our server hands the message — recipient address, text and attachments — directly to the provider of that mailbox, not to our dispatch service provider from § 6. The mailbox provider is not our sub-processor and is therefore not in the list in § 6: the business chose it, has its own contract with it, and the provider processes the message like any other sent from that mailbox. Where and on what basis it processes the data — including in third countries — follows from the business's contract with it.

The copy in "Sent" is visible to whoever reads the mailbox. Who has access to it is decided by the business. Messages to its employees are not kept there (see above).

When the message still goes via our dispatch service provider. Apart from the messages to employees, in two cases (§ 6, the Resend row): if, with its attachments, it is larger than Zirko permits for this provider's mailbox — when documents are sent, Zirko shows this before sending — and if it is certain that nothing arrived at the provider, for instance because signing in there fails. If it is unclear whether the message has already gone out, we do not send it a second time.

No delivery report. Via the business's own mailbox we receive no feedback on delivery; all that is recorded is that and when the message was sent.

Disconnecting. When the business disconnects the mailbox, we delete the credentials immediately. With Google we additionally revoke the permission with the provider. With Microsoft, revoking from outside would only be possible by ending every sign-in of the person — we do not do that. Without the deleted credentials Zirko can no longer send anything there; the account holder can additionally remove Zirko from the list of connected apps in their Microsoft account. With the other providers there is nothing to revoke; anyone who wants to be sure changes the password there or deletes the app password. When the business is deleted, the credentials are deleted as well; § 8 applies to backup copies.

Information from Google. Zirko's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We use this information solely for sending from Zirko, not for advertising and not for training models, and we do not pass it on to third parties.

5.3 Feedback sent from within the application

Anyone signed in to Zirko can send us feedback from within the application — "something is stuck here", "this calculates wrongly", "the button does nothing". This section is addressed to the employees of a business who do so, and to its customers whose data may end up on an image in the process.

What always goes with it. The free text you write, and with it five details without which a report saying "it doesn't work" would be worthless: the business, your role, the page visited in patterned form (/kunden/:id instead of the address of a particular customer), the version of the application and the time. The content of the page does not go with it of its own accord.

Screenshot and screen recording are voluntary and off by default. You decide whether to attach a recording. The current browser tab is pre-selected, not the entire screen; you see the recording before sending and can discard it.

What such a recording shows. A screenshot of this application shows data of your business's customers: names, addresses, amounts, possibly bank details. A video shows them in motion. Anyone sending a recording transmits personal data of third parties — hence the look at it before it goes out.

Who is the controller. The business (§ 2). You trigger the transmission yourself in the individual case, and that is an instruction to us within the meaning of the data processing agreement (§ 8 there); here, too, we act as its processor. A business can have the feedback function switched off for itself.

Who can read it. Zirko's support — and you yourself: you see your own feedback and our reply to it in the application. Other businesses see nothing of it, and nobody else in your own business reads it either. Storage is with Supabase in Frankfurt (§ 6). That feedback has been received is reported to us by an email via Resend (§ 6) to a mailbox under our own domain; it carries the free text together with the business and the role, not your name, not your address and no attachments. Recordings are viewed exclusively in the application. There is no disclosure to third parties, no use for advertising either, and no language model is involved in it (§ 6).

What we use it for — and what not. Exclusively to investigate and remedy the reported error. Not for the general improvement of the software, not as product knowledge, not for advertising and not for an evaluation across businesses.

What happens to it afterwards. Once the investigation is complete, we delete the recording. Independently of that, an outer limit applies: attachments and feedback are deleted at the latest 90 days after receipt. If you delete your user account, the feedback is separated from your person.

6 · Recipients, service providers and third countries

Services used

ServiceProvider and registered officePurposePlace of processingThird country and basis
SupabaseSupabase Pte. Ltd., 65 Chulia Street #38-02/03, OCBC Centre, Singapore 049513Database, authentication, file storageProject region FrankfurtThe contracting party is the company in Singapore; for Singapore there is no adequacy decision. Administration and support may take place from Singapore and the USA → standard contractual clauses under the Supabase DPA (version 1 of 1 August 2026), which is concluded upon acceptance of the terms. The payload data itself remains in the EU
VercelVercel, Inc., USAHosting of the website and the application, server functions, scheduling of the daily runs (payment reminders, automation, exports, archive notices). Our own e-invoicing service also runs there: it generates and validates invoice files — for businesses in the application and for the free validation tool on the website. It is not a further provider, but the same processing by the same processorServer functions fixed to Frankfurt; the upstream middleware runs at the edge of the global networkEU-U.S. Data Privacy Framework — Vercel Inc. is certified for it itself (official list at dataprivacyframework.gov, OrganizationId 6847, active until 29 April 2027); in addition, the standard contractual clauses and the UK IDTA from the Vercel DPA, which does not itself mention the DPF
ResendPLUS FIVE FIVE (trading as Resend), USADispatch of system, document and payment reminder emails as well as of the automated messages — reminders to the business and its employees, follow-up messages, appointment reminders and upload requests to the business's customers; reporting back of the delivery status. The same service also receives mail: supplier invoices sent to a business's inbound address pass through Resend — with third parties' addresses, bank details and amountsUSAStandard contractual clauses; under the Data Privacy Framework the legal name PLUS FIVE FIVE is certified for the EU and the United Kingdom, not for Switzerland — for transfers from Switzerland the standard contractual clauses alone carry the transfer. The content and attachments of the email as well as the addresses of both sides go to the service. The provider uses sub-processors of its own, all of them in the USA; its list is available at resend.com/legal/subprocessors (as at 27 August 2026)
GeoapifyKEPTAGO LTD, Cyprus (EU)Address suggestionsThe provider's EU endpointEU. The provider uses Cloudflare (Germany and USA) as a sub-processor; for transfers to the USA the EU-U.S. Data Privacy Framework or standard contractual clauses apply
PaddlePaddle.com Market Limited or Paddle Payments Limited, London, United KingdomBilling of the Zirko subscription as Merchant of Record: checkout, payment processing, invoicing to the business, customer portalUK, with its own sub-processorsNot a processor, but a controller in its own right — and that for the entire billing process, not only for the payment (Paddle Master Services Agreement clause 14.2: "each party acts as an independent Controller"). The basis for the transfer is the adequacy decision for the United Kingdom (Art. 45 GDPR); beyond that, Paddle's Data Sharing Addendum applies — standard contractual clauses, Module 1 (controller to controller), not a data processing agreement. Payment data (card, SEPA) does not arise at Zirko
SentryFunctional Software, Inc. (Sentry), USA — EU data residency, German ingestion pointError reportsEU (German ingestion point)EU data residency; additionally the standard contractual clauses of the Sentry DPA, which is expressly accepted before the first transfer — it is not concluded together with the account. What is transmitted is an exhaustive list: error identifier, error type, area, patterned route, business identifier, role, call stack lines — no message wording, no names, no amounts, no document texts. The browser reports exclusively via our own server, never directly to Sentry
Google WorkspaceGoogle Ireland Ltd., DublinBusiness mailboxes for the eight addresses (info@, support@, datenschutz@ …): incoming inquiries, support and contract correspondenceEU (Ireland); US parent companyCloud Data Processing Addendum (part of the account's contract); for transfers, DPF or standard contractual clauses pursuant to the CDPA
umamiUmami Software, Inc., USA — cloud instanceAudience measurement without cookies on the website and in the application (details in the audience measurement section of the privacy policy): page accessed, referring page, browser and device type, country; the IP address is only transiently computed to distinguish visits and is not storedEU region of the accountStandard contractual clauses under the Umami DPA. US provider: administration and support may access from the USA
European Commission (VIES)EUVerification of VAT identification numbers (USt-IdNr.)EUnot a processor — a verification body provided for by law (§ 18e UStG (German VAT Act))
Squarespace (domain registrar)Squarespace Ireland Ltd.Registration of zirko.io / zirko.deEUNo access to users' personal data

Envisaged, not currently in use

No data flows to these services. Before any of them is put into operation, a data processing agreement will first be concluded in each case and this list will be supplemented.

ServiceEnvisaged purposeStatus
Firebase Cloud Messaging / Apple PushDispatch of notifications to the mobile appNot in operation; no data is transmitted to these services
SMS service provider (envisaged: Twilio)Dispatch of the one-time passwords when signing in by telephone numberNot in operation; no messages are sent and no data is transmitted

Expressly not

ServiceStatus
Artificial intelligence — any provider, any purposeNot integrated. Nothing goes to a third party's language, text or speech recognition model — not for extracting data from incoming documents, not for reports, not for quotes, not for messages. The character recognition (OCR) of incoming invoices is not affected by this: it runs in the user's browser, is a pattern recognizer on the device and not a language model, and its program components are loaded from our own server. Equally unaffected is the automation: it works according to fixed rules set by the business, not with a model
Content delivery networks for fonts or scriptsNot used. We deliver the fonts and program components of our pages from our own server

On processing on behalf of the controller. The service providers named above process personal data exclusively on our instruction and only for the purposes stated. Excepted are those bodies that are expressly listed above as not being processors.

Not in this list is the provider of an email mailbox that a business has itself connected to Zirko (§ 5.2). It is not our service provider but the business's.

On third countries. Where standard contractual clauses or the EU-U.S. Data Privacy Framework are named above, the transfer is based on Art. 46 (2) (c) or Art. 45 GDPR respectively. We provide a copy of the relevant basis on request (datenschutz@zirko.io).

The database and the file storage are located in Frankfurt, and the server functions that query them run there as well.

7 · Cookies, tracking and audience measurement

We measure our audience without cookies — with Umami (§ 6). What is counted is which pages are accessed, which page visitors come from, browser and device type and the country. In doing so nothing is stored on your device and nothing is read from it — no cookie, no identifier in storage. That is why there is also no consent banner: the consent requirement of § 25 (1) TDDDG (German Telecommunications and Telemedia Data Protection Act) attaches to storing on or reading from the terminal equipment, and that is precisely what does not happen.

The measurement is nevertheless personally identifiable for a moment: for technical reasons your browser transmits its IP address. It is not stored, but only used transiently, in computed form, to tell visits apart; the reports contain anonymous counters with no reference to you as a person. No profile is created across websites, and nothing goes to advertising networks. The legal basis is Art. 6 (1) (f) GDPR — our interest in knowing which content is read and which is not; you can object to the measurement at any time (Art. 21, § 9).

Beyond that: no Google Analytics, no pixel, no advertising network.

The same applies to the error reports under § 4.6: they contain no identifier with which your usage behavior could be tracked across pages.

The only cookies set are those strictly necessary for operation (§ 25 (2) no. 2 TDDDG): the session cookie for your sign-in, where access protection for non-public areas is active, its cookie, and, while an admin connects a mailbox with Google or Microsoft (§ 5.2), an encrypted cookie that assigns this sign-in process to its business; it is deleted when the sign-in is completed and is valid for ten minutes at most. In addition the application stores data locally in your browser so that it can carry on working without a connection; it is removed when you sign out or when the browser data is cleared. From there, the only thing that goes to our server is what you have submitted yourself and what is waiting for a connection in a dead spot — a recorded time entry or a project message, for instance. This local cache is not evaluated.

8 · How long we store data

What governs is § 5 of the record of processing activities; the points most important for you:

WhatFor how long
User account and profileuntil the account is deleted
Contract and billing dataend of the contract + statutory retention of our bookkeeping
Server and access logsthe hosting provider's retention time
Inquiries via the form or by emailuntil they have been finally dealt with; deleted thereafter, unless a retention period under commercial or tax law applies (commercial letters: Germany 6 years)
Launch list (§ 4.7)unconfirmed: 30 days; after the notification: 30 days; without a notification: 1 year from confirmation — in each case with the next daily deletion run; on unsubscribing: immediately
A business's content (customers, projects, documents, times)the business decides. After the end of the contract we delete it or hand it over, at its choice (Art. 28 (3) (g))
Issued documentsunchangeable; deletion only after the expiry of the business's statutory retention period. How long it lasts is determined by the law at the seat of the business — for bookkeeping records five to ten years, in each case from the end of the calendar year. Within one country the period may depend on the type of document: in Germany, invoices and accounting vouchers have had to be retained for eight years since 1 January 2025 (§ 147 (3) sentence 1 AO, § 14b (1) sentence 1 UStG), books and annual financial statements for ten years (§ 147 (1) no. 1 AO); Austria seven years (§ 132 (1) BAO) and Switzerland ten years (Art. 958f (1) OR) apply the same period to both. The period for your own country is shown by the application under Settings → Retention; the countries are listed in § 9 (1) of the AGB (General Terms and Conditions)
Sent version of a draft (quote, cost estimate, order confirmation, delivery note)filed unchangeably as soon as it goes out; the same applies as for issued documents (row above)
Working times and absencesaccording to the employment-law and tax-law periods of the respective country
Log of the automated messages (§ 5.1)The business sees the last 30 days. The entries are attached to the respective matter and are deleted with it; files provided via an upload link share the fate of the project they belong to
Credentials of a connected mailbox (§ 5.2)until the business disconnects the mailbox — then immediately — or until the business is deleted
Feedback sent from within the application (§ 5.3)The recording is deleted when the investigation is complete, at the latest 90 days after it was received; the feedback itself likewise at the latest after 90 days

Backup copies. Backup copies are made of the database and the files so that a technical failure does not cost any data. Individual records cannot be extracted from such a copy. Where deletion there would be possible only with disproportionate effort, we block the data against any further processing; it is finally deleted when the retention period of the respective backup copy expires, at the latest after 30 days. The same is stated in the contract (AGB (General Terms and Conditions) § 12 (4) (c), data processing agreement (Auftragsverarbeitungsvertrag, AVV) § 13 (3)).

Issued invoices. Tax law and the GoBD (the German principles for the proper keeping and retention of books, records and documents in electronic form and for data access — an administrative instruction of the Federal Ministry of Finance) require that an issued invoice remains unchangeable. A request for erasure under Art. 17 GDPR therefore does not lead to deletion here (Art. 17 (3) (b)), but to the restriction of processing (Art. 18 (1) (b)): the document is retained for the statutory purpose and is no longer used for anything else. An incorrect invoice is corrected by a Storno — a cancellation document (in accounting terms a reversal, issued as a credit note) posted alongside the original — never by changing the original.

9 · Your rights

You have the right of access (Art. 15), to rectification (Art. 16), to erasure (Art. 17), to restriction of processing (Art. 18), to data portability (Art. 20) and to object to processing based on legitimate interests (Art. 21). You can withdraw a consent you have given at any time with effect for the future (Art. 7 (3)).

Whom to contact:

  • If your matter concerns our website, your user account, the contract or billing: us, at datenschutz@zirko.io.
  • If your data is in Zirko because a trade business entered it there: that business. It is the controller and alone entitled to provide the information. We forward inquiries without undue delay and support it.

Irrespective of this, you have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), in particular in the Member State of your habitual residence, place of work or the place of the alleged infringement. The authority responsible for us is:

Der Landesbeauftragte für den Datenschutz Niedersachsen, Prinzenstraße 5, 30159 Hannover, Telefon 0511 120-4500, poststelle@lfd.niedersachsen.de, www.lfd.niedersachsen.de

We do not build profiles and we do not evaluate personal characteristics. There is no creditworthiness, conduct or reliability assessment in Zirko, no scoring and no evaluation across businesses.

On the automated messages (§ 5.1): they follow rules that the respective business has set and can switch off at any time. All they do is send a message: they do not issue a document, do not change one, approve nothing and trigger no payment. No one takes a decision about you that would be attributable to us; the decision whether and how you are written to was taken beforehand by the business.

One automation does not send a message but makes an allocation, and it concerns solely the business's employees: for each project status the business can record by name which of its employees are allocated to the project as soon as that status occurs. The automation enters precisely that list. It selects no one, assesses no one and removes no one — and, like all the others, it is switched off by default.

10 · Security

We take technical and organizational measures in accordance with Art. 32 GDPR. The most important are:

  • Separation of the businesses at database level. Every table is protected by row-level security rules (RLS) tied to the respective business. This is checked automatically with every change; a table without such a rule is not put into operation.
  • Permissions are decided on the server, not in the interface.
  • Encrypted transmission (TLS) and encrypted storage at our service providers.
  • File stores are not public, carry the business in the path and have their own access rules and limits on size and type. We do not accept image formats that can execute program code (SVG).
  • Issued documents are technically unchangeable and cannot be deleted — enforced in the database, not only in the application.
  • Credentials for mailboxes (§ 5.2) are encrypted with AES-256-GCM and bound to their record; the key is kept only in our server's environment. The table cannot be reached from the browser or by signed-in users. We connect to outgoing mail and IMAP servers only in encrypted form (at least TLS 1.2) and only at publicly reachable addresses.
  • Security headers on every response — in particular a Content Security Policy that determines which sources the browser may load anything from at all, as well as HSTS, Referrer Policy and Permissions Policy.
  • Separate environments for development and production.

11 · Country-specific provisions

This privacy policy is structured according to the GDPR. Where the law of one of the countries we operate in requires further statements, they appear here — and they apply only to data subjects in that country. For everyone else, this section changes nothing.

Japan

Japanese data protection law applies to us. Where this privacy policy refers to applicable law, for data subjects in Japan this includes the 個人情報の保護に関する法律 (Act on the Protection of Personal Information, "APPI"). The basis is Art. 171 APPI: the Act also applies to processing outside Japan in so far as it relates to offering goods or services to persons in Japan. The fact that our contracting party is a trade business and not a consumer changes nothing: what is protected are the persons whose data is processed — a business's employees, its contacts and its customers — not the contracting party.

The statements to be disclosed under Art. 32 (1) APPI are already in this privacy policy: the name and address of the business handling the personal information in § 1, the purposes of processing in § 4 and § 5, the procedure for access, rectification and erasure in § 9, and the security measures in § 10.

Complaints body in Japan. In addition to the right to lodge a complaint under Art. 77 GDPR (§ 9), data subjects in Japan may contact the Japanese data protection commission:

個人情報保護委員会 (Personal Information Protection Commission) 〒105-0001 東京都港区虎ノ門二丁目2-3 虎ノ門アルセアタワー12階代表電話 03-6457-9680 · 個人情報保護法相談ダイヤル 03-6457-9849

12 · Changes to this privacy policy

We adapt this privacy policy when the processing changes — in particular when there is a new service provider, a new category of data or a new country. What governs is the version published here at any given time, bearing the date stated above.