Terms of Service

Last Updated: August 22, 2026

Effective: August 22, 2026

This is a non-binding convenience translation. The German version is legally binding.

Introduction

Welcome to Appointa. These Terms of Service ("Terms," "Agreement") constitute a legally binding agreement between you and the entity that owns and operates Appointa (the "Company," "we," "us," or "our") — a sole proprietorship (Einzelunternehmen) based in Munich, Germany; the full provider identification is set out in the Imprint and available on request. These Terms govern your access to and use of the Appointa website, platform, mobile applications, APIs, and all related services (collectively, the "Services").

By creating an account, accessing or using the Services, or clicking "I Accept" or "I Agree," you acknowledge that you have read, understood, and agree to be bound by these Terms, our Privacy Policy, our Provider Content & Acceptable Use Policy (Annex 1), and our Data Processing Addendum (Annex 2), all of which are incorporated by reference into this Agreement.

PLEASE READ THESE TERMS CAREFULLY. THEY CONTAIN IMPORTANT INFORMATION ABOUT YOUR RIGHTS AND OBLIGATIONS, INCLUDING THE GOVERNING LAW AND DISPUTE-RESOLUTION TERMS IN SECTIONS 17 AND 18. IF YOU ARE A CONSUMER, YOUR MANDATORY STATUTORY RIGHTS REMAIN UNAFFECTED.

If you do not agree to these Terms, you may not access or use the Services.

1. Definitions

The following definitions apply throughout these Terms:

TermDefinition
"Appointa" or "Platform"The cloud-based appointment booking and business management software platform.
"Provider" or "Subscriber"A business or individual professional who subscribes to manage appointments.
"End Customer" or "Client"An individual who books appointments with a Provider through our platform.
"Provider Content"All data, images, service descriptions, and materials uploaded by a Provider.
"Customer Data"Personal information of End Customers collected through the Services.
"Subscription"The plan selected by a Provider, subject to recurring fees.
"Booking Page"The public-facing webpage created by a Provider (e.g., businessname.appointa.eu).
"OTP"One-Time Password, a verification code sent via SMS during booking.

2. Description of Services

Appointa is a Software-as-a-Service (SaaS) platform that enables service-based businesses to manage their appointment scheduling, services, availability, and client relationships.

For Providers:

  • Branded public booking pages with custom subdomains
  • Service management with customizable names, descriptions, durations, and pricing
  • Availability and schedule management
  • Appointment management (confirm, reschedule, cancel)
  • Client relationship management (CRM)
  • Revenue tracking and business analytics dashboard
  • Portfolio gallery and voucher management
  • Multi-language and multi-currency support

For End Customers:

  • Public booking interface without account creation
  • SMS verification for secure booking confirmation
  • Booking management via secure token links
  • Location viewing with integrated mapping services

3. User Roles and Scope

3.1 B2B2C Model

Appointa operates as a B2B2C platform. We provide software services to Providers (B2B), who in turn use our platform to serve their End Customers (B2C).

3.2 Appointa's Role

Appointa's role is strictly limited to providing the software platform. We:

  • do not provide, perform, or guarantee any services offered by Providers;
  • do not process payments between Providers and End Customers;
  • do not employ, supervise, or control Providers;
  • are not responsible for the quality or legality of Provider services;
  • do not mediate disputes between Providers and End Customers.

4. Provider Account Registration

4.1 Account Registration

To use the Services as a Provider, you must register by providing accurate information. You agree to:

  • provide truthful and accurate registration information;
  • maintain and promptly update your account information;
  • maintain the security of your login credentials;
  • accept responsibility for all activities under your account;
  • notify us immediately of any unauthorized use.

4.2 Provider Responsibilities

As a Provider, you are solely responsible for:

  • the accuracy and legality of all Provider Content;
  • compliance with applicable laws and regulations;
  • obtaining necessary licenses and permits;
  • acting as the Data Controller for Customer Data;
  • providing appropriate privacy notices to End Customers;
  • all taxes and duties associated with your business.

4.3 Age Requirement

You must be at least 18 years of age to register for a Provider account.

5. End Customer Terms

5.1 Booking Appointments

End Customers may book appointments through public booking pages without creating an account. You may need to provide name, email, and phone number for verification.

5.2 SMS Verification

By providing your phone number and completing a booking, you consent to receive transactional SMS messages including OTP codes, confirmations, reminders, and notifications.

5.3 Relationship with Providers

Your appointment is a direct agreement with the Provider. Appointa is not a party to this agreement and has no responsibility for Provider services, practices, or disputes.

5.4 End Customer Responsibilities

As an End Customer, you agree to provide accurate information, honor appointments, and treat Providers with respect.

6. Subscription Fees, Billing, and Payments

6.1 Subscription Plans

Providers access the Services through paid Subscription plans:

  • Monthly Subscriptions: billed monthly in advance
  • Annual Subscriptions: billed annually at a discounted rate

6.2 Payment Processing

We use Stripe as our payment processor. By subscribing, you authorize charges to your payment method and agree to provide valid payment information.

6.3 Taxes

All fees are stated in euro and include applicable value added tax (VAT) at the statutory rate. The VAT amount is shown separately on your invoice. For business customers in other EU member states who provide a valid VAT identification number, the reverse-charge procedure may apply.

6.4 Refund Policy

All Subscription fees are non-refundable except as required by law or at our sole discretion. This does not affect your statutory right of withdrawal under Section 6.5, where applicable.

6.5 Right of Withdrawal (Consumers)

If you are a consumer (a natural person concluding the contract for purposes outside your trade, business, or profession), you have the right to withdraw from this contract within 14 days without giving any reason. The withdrawal period is 14 days from the day the contract is concluded.

To exercise your right of withdrawal, you must inform us — Appointa, Munich, Germany, contact@appointa.eu — of your decision by a clear statement (for example, a letter sent by post or an email). You may use the model withdrawal form, but this is not obligatory. To meet the deadline, it is sufficient to send your communication concerning the exercise of the right of withdrawal before the withdrawal period expires.

Effects of withdrawal: If you withdraw from this contract, we will reimburse all payments received from you without undue delay and no later than 14 days from the day on which we are informed of your decision, using the same means of payment you used for the original transaction.

Early performance and expiry of the right: If you expressly request that we begin providing the paid Services during the withdrawal period, you agree to pay a reasonable amount proportionate to the Services provided until you notify us. The right of withdrawal expires in the case of a contract for the supply of paid digital services once we have fully performed, provided you expressly consented to performance beginning during the withdrawal period and acknowledged that you thereby lose your right of withdrawal.

7. Free Trials and Promotional Offers

We may offer free trial periods for new Providers. During a free trial:

  • you will have access to the Services as specified;
  • you may be required to provide payment information;
  • unless you cancel before the trial ends, your Subscription will automatically convert to paid.

8. Term, Renewal, and Cancellation

8.1 Automatic Renewal

Your Subscription will automatically renew at the end of each term unless you cancel before the renewal date.

8.2 Cancellation

You may cancel your Subscription at any time through your account settings. Upon cancellation:

  • you retain access until the end of your current billing cycle;
  • you will not be charged for subsequent cycles;
  • no refunds are given for unused portions of the current cycle.

8.3 Effect of Termination

Upon termination, your access will be suspended, your content may be deleted after 30 days, and all outstanding fees become due.

9. Intellectual Property Rights

9.1 Appointa's Intellectual Property

The Services, software, designs, logos, and trademarks are the exclusive property of the Company. You may not copy, modify, distribute, or reverse engineer any part of the Services.

9.2 License to Use Services

We grant you a limited, non-exclusive, non-transferable license to access and use the Services during your Subscription Term for your internal business purposes.

9.3 Provider Content

You retain ownership of your Provider Content. By uploading content, you grant us a license to host, display, and make it available to End Customers through your booking pages.

9.4 Feedback

If you provide feedback or suggestions, you grant us a perpetual, royalty-free license to use and incorporate such feedback.

10. Data Protection and Privacy

10.1 Privacy Policy

Our collection and use of personal information is described in our Privacy Policy, incorporated by reference.

10.2 Provider as Data Controller

As a Provider, you are the Data Controller for Customer Data and must comply with applicable data protection law, in particular the GDPR, provide privacy notices, and respond to data subject requests.

10.3 Data Processing Addendum

Where we process Customer Data on your behalf, the Data Processing Addendum in Annex 2 applies and prevails over these Terms for the subject matter it governs.

10.4 Data Security

We implement appropriate security measures to protect personal data, but no method is 100% secure.

11. Acceptable Use Policy

11.1 Provider Content

Our Provider Content & Acceptable Use Policy, set out in Annex 1 to these Terms, forms part of these Terms for all Providers. It governs Provider Content, including your warranties that you hold all rights, licenses, and consents for uploaded material, prohibited content and uses, restrictions on sensitive personal data, the handling of reports of illegal content, and complaints against content decisions.

11.2 Prohibited Conduct

In addition, you agree not to use the Services for:

  • illegal activities, fraud, or financial crimes;
  • harmful, threatening, or objectionable content;
  • privacy violations or unsolicited communications (spam);
  • system abuse, unauthorized access, or security circumvention;
  • impersonation or misrepresentation.

11.3 Enforcement

We are not obligated to monitor content. We may review, restrict, remove, or disable access to any content, suspend or terminate accounts, preserve evidence, and report violations to competent authorities. For Provider Content, review, restriction, removal, and complaints follow the process described in Annex 1.

12. Third-Party Services

The Services integrate with third-party services including:

ServiceProviderPurpose
Database & AuthSupabaseData storage, authentication
PaymentsStripeSubscription billing
SMSTwilioOTP verification, notifications
HostingVercelApplication hosting
MapsGoogle MapsLocation services
EmailResendEmail delivery
AnalyticsPostHogUsage analytics

We are not responsible for the availability or practices of third-party services.

13. SMS and Communication Services

SMS services are provided through Twilio for transactional purposes only (booking confirmations, reminders, OTP). Marketing or promotional SMS messages are prohibited.

Standard message and data rates may apply. All communications must comply with applicable law, in particular the GDPR and applicable European telecommunications and consumer-protection rules.

14. Warranties and Disclaimers

We provide the Services with reasonable skill and care. We do not warrant that the Services will be uninterrupted, timely, secure, or error-free, or that they will meet your specific requirements. Planned maintenance and circumstances outside our reasonable control may affect availability.

We make no warranties regarding services offered by Providers. Providers are solely responsible for their services, their Provider Content, and their own legal compliance.

For business customers, strict (no-fault) liability for defects that already existed at the time the contract was concluded (§ 536a (1) BGB) is excluded. Your statutory rights remain unaffected to the extent they cannot be excluded or limited by law.

15. Limitation of Liability

We are liable without limitation:

  • for damage caused intentionally or by gross negligence;
  • for culpable injury to life, body, or health;
  • under the German Product Liability Act (Produkthaftungsgesetz);
  • under any guarantee we have expressly given; and
  • for fraudulently concealed defects.

In cases of slight negligence, we are liable only for the breach of essential contractual obligations (Kardinalpflichten) — obligations whose fulfillment makes the proper performance of this Agreement possible in the first place and on whose fulfillment you may regularly rely. In such cases, our liability is limited to the damage that is foreseeable and typical for this type of contract. The parties agree that the damage foreseeable and typical for this type of contract corresponds to the total fees paid by you in the twelve (12) months preceding the event giving rise to the claim.

Any further liability is excluded. The above limitations also apply in favor of our legal representatives and vicarious agents (Erfüllungsgehilfen).

16. Indemnification

As a Provider, you agree to indemnify the Company against third-party claims, including reasonable costs of legal defense, arising from:

  • your Provider Content;
  • your culpable violation of these Terms, the Provider Content & Acceptable Use Policy, or applicable law;
  • any dispute between you and your End Customers.

We will inform you of any such claim without undue delay and will not acknowledge it without your consent, which may not be unreasonably withheld. This indemnification obligation survives termination of these Terms.

17. Dispute Resolution

17.1 Informal Resolution

Before formal proceedings, contact us at contact@appointa.eu so we can attempt to resolve the matter informally within 45 days.

17.2 Consumer Dispute Resolution

We are neither obliged nor willing to participate in dispute resolution proceedings before a consumer arbitration board (Verbraucherschlichtungsstelle) within the meaning of § 36 VSBG.

18. Governing Law and Jurisdiction

These Terms are governed by the laws of the Federal Republic of Germany, excluding the UN Convention on Contracts for the International Sale of Goods (CISG). If you are a consumer, this choice of law does not deprive you of the protection afforded by the mandatory provisions of the law of your country of habitual residence.

For business customers, the exclusive place of jurisdiction for all disputes arising out of or in connection with these Terms is Munich, Germany. The statutory places of jurisdiction for consumers remain unaffected.

19. Suspension and Termination

19.1 Suspension by Company

We may suspend access immediately if you breach these Terms, have past due payments, pose a security risk, or are required by law. Content-related measures against Providers follow Section 11 and Annex 1.

19.2 Termination

We may terminate for cause (material breach) or for convenience with 30 days' notice. You may terminate by canceling your Subscription.

19.3 Effect of Termination

Upon termination, your access ceases, you must pay outstanding fees, and your content may be deleted after 30 days.

20. Modifications to Terms and Services

20.1 Grounds for Changes

We may modify these Terms where there is a valid reason, in particular changes in the law or case law, requirements of authorities, security requirements, changes to or extension of the Services, or changed technical or economic circumstances, and where the change is reasonable for you taking into account both parties' interests.

20.2 Notice

We will notify you of changes by email or by clearly visible notice in the Services at least 15 days before they take effect; for material changes that are disadvantageous to you, at least 30 days before they take effect. The notice will state the substance of the changes and their effective date.

20.3 Business Customers

If you are a business customer and do not agree to a change, you may terminate the Agreement with effect from the date the change takes effect. If you do not terminate and continue to use the Services after the notice period has expired, the changed Terms become effective; the notice will point this out.

20.4 Consumers

If you are a consumer, changes that materially affect the contractual balance to your disadvantage require your express consent. Your silence or mere continued use is not deemed consent to such changes.

20.5 Urgent Changes

A shorter notice period or immediate effect is permitted where necessary to comply with mandatory law, to avert a significant security or abuse risk, or to prevent imminent harm. We will inform you where legally and practically possible.

We may also modify or discontinue individual features of the Services at any time.

21. General Provisions

  • Entire Agreement: These Terms, including their Annexes, constitute the entire agreement between you and the Company.
  • Severability: Invalid provisions will be modified to the minimum extent necessary; the validity of the remaining provisions remains unaffected.
  • No Waiver: Failure to enforce any provision is not a waiver.
  • Assignment: You may not assign these Terms without our consent.
  • Force Majeure: Neither party is liable for failures due to causes beyond reasonable control.
  • Independent Contractors: The parties are independent contractors, not partners or employees.
  • Language: The German version of these Terms, including the Annexes, is legally binding. This English version and any other translations are non-binding convenience translations.

22. Contact Information

If you have questions about these Terms, please contact us:

Annex 1: Provider Content & Acceptable Use Policy (Richtlinie zu Anbieterinhalten und zulässiger Nutzung)

Effective: 22.08.2026
Version: 1.0

This Provider Content & Acceptable Use Policy (the "Policy") forms part of Appointa's Terms of Service for business customers (the "B2B Terms"). Appointa's provider identification is available in the Legal Notice.

In the event of conflicts between this Policy and the B2B Terms, the B2B Terms prevail unless they expressly provide otherwise. The German version of this Policy is authoritative. This English translation is provided for information only.

1. Scope

  1. This Policy applies to every company, self-employed person, and other business organization using an Appointa account as a provider (the "Provider"). It also applies to all persons who access the account or post content on the Provider's behalf or under the Provider's responsibility.
  2. "Provider Content" means all content that the Provider, or a person acting for the Provider, makes available via Appointa or posts to a public provider profile. This includes in particular business and service descriptions, prices, opening hours, contact details, photos of the salon or business, logos, links, and other profile information. Videos, public customer reviews, and public comment functions are not currently offered by Appointa.
  3. This Policy applies only to the use of the Appointa platform. It does not replace the Provider's own legal responsibility towards its customers or authorities.

2. Provider Responsibility for Content and Profile Information

  1. The Provider is solely responsible for its Provider Content, its public profile, the services it offers, and its relationship with the persons who book appointments with it.
  2. The Provider warrants that it holds all necessary rights, licenses, consents, permissions, and other authorizations for every item of content it posts. This includes in particular copyright, trademark, design, name, personality, and data protection rights.
  3. For every photo or other image in which a person is identifiable, the Provider must hold a valid authorization for publication and processing before publishing. Upon Appointa's request, the Provider must be able to reasonably evidence the authorization. For minors, the Provider must have obtained the required consents of the holders of parental responsibility.
  4. For stock material, commissioned photography, or third-party material, the license must cover commercial online use and display via a platform such as Appointa. The Provider must comply with any required attribution or license notices.
  5. The Provider keeps its business information, service descriptions, prices, availability, qualification claims, and contact information complete, correct, and up to date.
  6. The Provider indemnifies Appointa, to the extent permitted by law, against justified third-party claims, including reasonable costs of legal defense, where such claims are based on a breach of this Policy for which the Provider is responsible. Appointa will inform the Provider of such a claim without undue delay, where legally and practically possible, and will take the Provider's legitimate interests into account in the legal defense.

3. Prohibited Content and Uses

The Provider must not post, link to, transmit, or otherwise use via Appointa any content that:

  1. infringes third-party rights, in particular uses copyrighted photos, texts, graphics, music, trademarks, or logos without the required authorization;
  2. is unlawful, misleading, fraudulent, or deceptive, in particular contains false statements about identity, qualifications, licensing, experience, availability, pricing, discounts, awards, certificates, or the services offered;
  3. impersonates another person or company or falsely claims an affiliation with, endorsement by, or partnership with Appointa or third parties;
  4. discloses personal data, images, contact details, or information about the private life of third parties without legal authorization;
  5. is pornographic, sexualized, glorifies violence, is discriminatory, insulting, incites hatred, is terrorist, criminal, or otherwise unlawful;
  6. contains malware, phishing, spam, fraudulent links, harmful content, technical attacks, or instructions for misusing the platform;
  7. advertises, offers, or arranges services for which the Provider does not hold the required permits, licenses, registrations, insurance, or qualifications; or
  8. violates applicable consumer, competition, price-indication, professional, data protection, or other law.

4. Special Categories of Personal Data

  1. At launch, Appointa is not intended for the collection or processing of special categories of personal data via booking forms, profile fields, or free-text fields.
  2. In particular, the Provider must not request, have entered, or process via Appointa any information about health, disability, allergies, medication, religious or philosophical beliefs, sexual orientation, trade union membership, biometric characteristics, political opinions, or comparably sensitive information.
  3. The Provider must not ask customers to enter such information into free-text fields. The Provider must observe a corresponding notice provided by Appointa and must not circumvent it.
  4. Any future exception requires Appointa's prior written consent and a separate legal, technical, and data protection review. This Policy does not create any entitlement to approval of such processing.

5. Provider Obligations Towards Booking Customers

  1. The Provider is the contracting party for its own services towards booking customers. Appointa does not perform any hairdressing, salon, cosmetics, consulting, or other service advertised by the Provider and does not become a party to the contract between the Provider and the customer.
  2. The Provider is in principle itself responsible for the purposes and means of processing the personal data of its booking customers. Where Appointa processes booking data on the Provider's behalf, the data processing agreement concluded between Appointa and the Provider additionally applies.
  3. Before a public booking profile is activated, the Provider must completely and correctly enter the legal and business information required by Appointa. This includes, where applicable, in particular:
    1. the correct legal name, an address at which legal service can be effected, and a direct means of contact;
    2. the Provider's own privacy policy;
    3. clear service descriptions and total prices or a clear pricing basis;
    4. the Provider's own booking, cancellation, and, where applicable, no-show terms; and
    5. all other information the Provider is legally required to make available to consumers or other customers.
  4. Appointa may restrict the publication or continued visibility of a profile until the Provider has added or corrected missing, incorrect, or legally required information.

6. Review, Restriction, and Removal of Content

  1. Appointa is not obliged to generally monitor all Provider Content before or after publication or to review it for legality. Voluntary reviews of individual content do not create a general duty to review.
  2. Appointa may, exercising due discretion, review, restrict, remove, block, or reduce the visibility of Provider Content or profiles where there are concrete indications of a breach of this Policy, third-party rights, applicable law, or the B2B Terms.
  3. When taking measures, Appointa considers the nature, gravity, repetition, and urgency of the breach as well as the legitimate interests of those involved. Possible measures include in particular:
    1. a request for correction or removal;
    2. temporary restriction of individual content or features;
    3. removal or deactivation of content;
    4. restriction or blocking of the public profile;
    5. temporary suspension of the account; or
    6. termination for cause in accordance with the B2B Terms and applicable law.
  4. In the case of manifestly unlawful content or a serious risk to persons, third-party rights, the platform, or the public, Appointa may restrict or remove content or profiles immediately without prior hearing. Where legally required and possible, Appointa will subsequently inform the Provider of the essential reasons for the measure and the available complaint options.
  5. Appointa may preserve and process removed content, relevant metadata, and moderation records to the extent necessary to comply with legal obligations, handle complaints, safeguard rights, defend against claims, or cooperate with competent authorities.

7. Reporting Illegal Content and Rights Infringements

  1. Any person or organization may report allegedly illegal content or rights infringements on Appointa by email to contact@appointa.eu. Please use the subject line: "Meldung rechtswidriger Inhalte".
  2. So that Appointa can review a report, it should contain:
    1. a comprehensible explanation of why the content is unlawful or infringes rights;
    2. the exact location, in particular the URL of the profile or content and, where helpful, a screenshot;
    3. the name and email address of the reporting person or organization, where a response is desired;
    4. a statement that the information provided is accurate and complete to the best of the reporter's knowledge; and
    5. for reports concerning copyright, trademark, or other protected rights, a description of the protected right and of the authority to act on behalf of the rights holder.
  3. Appointa generally confirms receipt of a proper report, where contact details were provided, in an automated manner or promptly. Appointa reviews reports carefully, objectively, and without undue delay. For ordinary, non-urgent reports, Appointa aims to reach a decision within seven working days. This is not a guaranteed processing or response level; complex matters, missing information, multiple parties involved, or legal requirements may require more time.
  4. Where legally required or objectively appropriate, Appointa informs the reporting person and the affected Provider of the decision and the essential reasons. Reports do not automatically create an entitlement to removal.
  5. This reporting channel is a European contact route for handling allegedly illegal content and rights infringements. It is not a registration of a US DMCA agent and not a statement that Appointa offers a DMCA procedure.

8. Complaints Against Content Decisions

  1. A Provider may lodge a complaint against a decision under Section 6 within 14 calendar days of receipt of the notification. The complaint must be sent to contact@appointa.eu with the subject line "Beschwerde Inhaltsentscheidung".
  2. The complaint must identify the affected profile or content, the decision, the grounds for the complaint, and any evidence.
  3. Appointa reviews the complaint through a person who was not involved in the original decision, insofar as this is practically possible given Appointa's size and organization. If the review shows that the measure is not or is no longer justified, Appointa lifts it without undue delay.
  4. This section does not limit any statutory remedies. In cases of manifest illegality, significant risk, abuse, or repeated violations, Appointa may maintain measures until a complaint has been resolved.

9. Repeated Violations and Abusive Reports

  1. Appointa may document confirmed violations by the Provider and, in the case of repeated or serious violations, escalate the measures set out in Section 6.
  2. Repeated infringements of third-party rights, misleading or unlawful business information, misuse of booking functions, or a single particularly serious violation may justify suspension or termination for cause.
  3. Appointa may temporarily restrict the processing of reports where a reporting person, after prior warning, repeatedly submits manifestly unfounded reports. In doing so, Appointa considers the circumstances of the individual case and the legitimate interests of those involved.

10. Changes to This Policy

  1. Appointa may amend this Policy where necessary for legal, security-related, technical, organizational, or legitimate economic reasons.
  2. Appointa will give at least 30 days’ notice of material changes that are disadvantageous to Providers before they take effect, by email or by clearly visible notice in the account. The notice will state the material changes and the date they take effect.
  3. If a change materially extends the Provider's obligations, Appointa's rights to Provider Content, or the Provider's economic risk, Appointa may require renewed express consent. If consent is required and not given, the Provider cannot continue to use the affected features and may terminate the contract in accordance with the B2B Terms.
  4. A shorter notice period or immediate effect is permitted where necessary to comply with mandatory law, to avert a significant security or abuse risk, or to prevent imminent harm. Appointa will inform the Provider of this where legally and practically possible.

11. Point of Contact

The central point of contact for reports under Section 7, complaints under Section 8, and other questions about this Policy is:

Email: contact@appointa.eu

Annex 2: Data Processing Addendum (Art. 28 GDPR)

Effective: 22.08.2026
Version: 1.0

This Data Processing Addendum (the "DPA") forms part of Appointa's Terms of Service for business customers and applies between the Provider as controller and Appointa as processor within the meaning of Regulation (EU) 2016/679 (the "GDPR"). For its subject matter, this DPA prevails over the other provisions of the Terms. The German version is authoritative.

1. Subject Matter, Duration, and Specification of the Processing

  1. Appointa processes personal data of the Provider's End Customers on the Provider's behalf to the extent necessary to provide the booking and management functions of the platform.
  2. The duration of the processing corresponds to the term of the main contract. Section 9 remains unaffected.
  3. Nature and purpose of the processing: hosting and storage, display in the Provider's account, transmission of booking confirmations, reminders, and verification codes (SMS/email), and related technical support and maintenance services.
  4. Types of personal data: name, phone number, email address, appointment and booking data, booking-related communication.
  5. Categories of data subjects: the Provider's End Customers and, where applicable, its staff.
  6. Special categories of personal data (Art. 9 GDPR) are not part of the processing engagement; Annex 1 Section 4 applies accordingly.

2. Instructions of the Provider

  1. Appointa processes the engagement data only on the Provider's documented instructions, unless Appointa is required to process by Union or Member State law; in such a case, Appointa informs the Provider of that legal requirement before processing, unless that law prohibits such information.
  2. The Provider's use of the platform functions constitutes documented instructions. Supplementary instructions require text form to contact@appointa.eu.
  3. Appointa informs the Provider without undue delay if, in Appointa's opinion, an instruction infringes the GDPR or other data protection provisions. Appointa may suspend the execution of such an instruction until it is confirmed.

3. Confidentiality

Appointa ensures that the persons authorized to process the engagement data have committed themselves to confidentiality or are subject to an appropriate statutory obligation of secrecy.

4. Security of Processing (Art. 32 GDPR)

Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing as well as the risk, Appointa implements appropriate technical and organizational measures, in particular:

  • transport encryption (TLS 1.2 or higher) for all data transmissions;
  • encryption of stored data (encryption at rest);
  • role-based access controls on a need-to-know basis;
  • tenant isolation at database level (row level security) so that providers can only access their own data;
  • logging of security-relevant events and incident response procedures.

Appointa may develop these measures further, provided the agreed level of protection is not reduced.

5. Sub-Processors

The Provider grants general authorization for the engagement of the following sub-processors:

Sub-processorService
SupabaseDatabase, authentication, storage
VercelApplication hosting
TwilioSMS dispatch (confirmations, reminders, verification codes)
ResendEmail dispatch
SentryError monitoring

Appointa informs the Provider of intended changes concerning the addition or replacement of sub-processors at least 30 days in advance in text form or by clearly visible notice in the account. The Provider may object to the change for an important data protection reason within 14 days. In the case of a justified objection that cannot be remedied, both parties have a right of termination in accordance with the Terms.

Appointa imposes on each sub-processor, by contract, the same data protection obligations as set out in this DPA. Where a sub-processor fails to fulfil its data protection obligations, Appointa is liable to the Provider for the performance of that sub-processor's obligations in accordance with statutory provisions.

6. Transfers to Third Countries

Processing in third countries outside the European Economic Area takes place only where the requirements of Art. 44 et seq. GDPR are met, in particular on the basis of an adequacy decision of the European Commission or standard contractual clauses, supplemented by additional measures where necessary.

7. Assistance to the Provider

  1. Taking into account the nature of the processing, Appointa assists the Provider with appropriate technical and organizational measures in responding to requests from data subjects under Chapter III of the GDPR. Data subject requests received by Appointa are forwarded to the Provider without undue delay.
  2. Taking into account the nature of the processing and the information available to Appointa, Appointa assists the Provider in complying with the obligations under Art. 32 to 36 GDPR.

8. Notification of Personal Data Breaches

Appointa notifies the Provider of personal data breaches concerning the engagement data without undue delay after becoming aware of them. The notification contains the information required under Art. 33 (3) GDPR, to the extent available to Appointa.

9. Deletion and Return

After the end of the main contract, Appointa deletes the engagement data in accordance with the periods stated in the Privacy Policy or, at the Provider's request, returns it in a common format, unless a legal obligation requires further storage. The Provider may export its data during the contract term via the platform's export functions.

10. Evidence and Audits

  1. Appointa makes available to the Provider all information necessary to demonstrate compliance with the obligations laid down in Art. 28 GDPR.
  2. The Provider may request reviews in the form of written requests for information; Appointa may also provide current attestations, certifications, or reports concerning the sub-processors used. On-site audits require reasonable advance notice and take place during normal business hours without disrupting operations.

11. Liability

The liability of the parties is governed by Art. 82 GDPR and the liability provisions of the Terms.


Document Version: 2.0