Privacy Policy

Effective: 5 September 2026

1. Scope and overview

This privacy policy explains how personal data is processed on the public Timevex website and when the Timevex appointment, calendar and communication platform is used. It covers, in particular, email and telephone contact, booking and calendar functions, WhatsApp Business communication and the optional use of artificial intelligence.

2. Controller and roles

Lars Birndt · Timevex

Neugasse 13

01662 Meissen

Germany

Email: datenschutz@timevex.com

Timevex is the controller for this website, direct enquiries and its own contract administration. When a business customer uses Timevex to process its customers', prospects' or employees' data, that business customer generally determines the purposes and means of processing and is the controller; Timevex acts as its processor under Art. 28 GDPR.

If your enquiry concerns an appointment or a conversation with a Timevex business customer, please contact that business first. Timevex supports the business in responding to data subject requests.

3. Website hosting and server logs

The website and production platform are hosted on infrastructure provided by Hetzner Online GmbH in Germany. When pages are accessed, technically necessary connection data is processed, including IP address, time, requested URL, HTTP status, referrer and browser/user-agent information. This is required to deliver the service, detect attacks and ensure stable operation (Art. 6(1)(f) GDPR).

Reverse-proxy access logs are kept locally on the hosting infrastructure and rotate after seven days; application container logs are size-limited and rotated. No separate external analytics or monitoring recipient was identified in the current production path.

4. Contact and trial enquiries

If you contact us or request a trial, we process the information you provide, such as company, name, email address, telephone number, requested modules and message content, in order to answer the enquiry, verify the email address and prepare or perform a contract. The legal basis is Art. 6(1)(b) GDPR and, for abuse prevention and service security, Art. 6(1)(f) GDPR. Statutory documentation duties are based on Art. 6(1)(c) GDPR.

5. Platform, booking and calendar data

Depending on the modules selected by the business customer, Timevex processes tenant, location, service and employee assignments, customer contact details, appointments, availability, booking holds, confirmations, rescheduling and cancellations, communication events, delivery status and audit/security records. This data is used to provide the requested appointment and communication workflow, prevent duplicates and document authorised changes.

For this customer-controlled processing, the business customer's instructions and legal basis apply. Typical bases are contract performance or pre-contractual measures (Art. 6(1)(b) GDPR), legitimate interests in efficient customer communication and appointment management (Art. 6(1)(f) GDPR), legal obligations (Art. 6(1)(c) GDPR), or consent where required (Art. 6(1)(a) GDPR).

6. WhatsApp Business and Meta

If a business customer activates the WhatsApp channel, messages are exchanged through the WhatsApp Business Platform of Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland. Meta receives and processes the data required to operate WhatsApp under its own terms. Depending on the processing step, Meta may act as an independent controller or service provider.

Timevex processes the following categories from incoming WhatsApp events:

  • sender telephone number and pseudonymous/masked sender references;
  • message text or the title/identifier of a button or list response;
  • Meta message ID, timestamp and reply-context ID;
  • WhatsApp Business Account and phone-number IDs for tenant routing;
  • processing, delivery, duplicate-prevention and security status.

Purposes are authentication of the webhook, assignment to the correct business customer, answering enquiries, preparing and—only after the required confirmation—performing booking actions, human handover, delivery documentation, security and duplicate prevention. Media that is not supported by the configured workflow is not sent to the AI service.

Using WhatsApp is voluntary. You may use another contact channel offered by the relevant business. WhatsApp messages are also subject to Meta's privacy information.

7. Artificial intelligence and OpenAI

Where the business customer has activated the AI assistant, Timevex uses OpenAI Ireland Limited, 1st Floor, The Liffey Trust Centre, 117-126 Sheriff Street Upper, Dublin 1, D01 YC43, Ireland, as a processor. The current production integration uses the OpenAI Responses API (POST /v1/responses) with the model gpt-5.6-sol.

The request contains the current, length-limited message, at most six previous bounded conversation messages (together at most 1,800 characters), the assistant instructions required for the business and a pseudonymous execution reference. Message content may contain personal data that the sender entered. Meta access tokens, application secrets and the complete raw Meta webhook envelope are not included in the OpenAI request. No external OpenAI tools are enabled.

Timevex sets store=false. OpenAI states that API data is not used to train its models unless the customer explicitly opts in. The setting prevents application-state storage for this Responses request; independent abuse-monitoring logs may nevertheless contain content and, under OpenAI's standard controls, be retained for up to 30 days. No exclusive EU data residency is promised for the currently used global API endpoint.

Further information: OpenAI API data controls, DPA · OpenAI subprocessors

8. How the AI assistant works

The language model recognises the likely intent, extracts limited booking details and formulates a response proposal. It does not independently access customer databases, execute tools or create, reschedule or cancel appointments. Tenant assignment, availability checks, duplicate protection, confirmation requirements and every binding booking mutation are performed by deterministic Timevex application logic.

No decision producing legal effects or similarly significantly affecting a person is currently intended to be made solely by the AI model (Art. 22 GDPR). A human contact or handover can be requested.

9. Recipients and processors

Timevex uses the following processors or integration providers in the currently verified production architecture. Optional providers receive data only if the relevant business customer has activated that function.

ProviderFunctionData categories
Hetzner Online GmbHHosting, databases, queues, local logs, email infrastructure and backup artifactsAll platform data required for operation
OpenAI Ireland LimitedOptional AI language processingBounded message content, business instructions and pseudonymous execution metadata
seven communications GmbH & Co. KG (seven.io)Optional SMS dispatchRecipient number, sender, SMS content and delivery metadata
Tillhub GmbHOptional POS and business-system integrationMapped appointment, service, employee, customer/contact and transaction data, depending on configuration

Meta Platforms Ireland Limited is additionally a recipient when WhatsApp is used. Source-code and container registries such as GitHub/GHCR and locally used software libraries do not receive production message or customer data through the verified runtime data path. No separate external CDN, DNS proxy, monitoring or backup recipient was identified.

Where required, Timevex enters into a data processing agreement under Art. 28 GDPR with its business customers. The agreement, technical and organisational measures and the current subprocessor list can be requested at datenschutz@timevex.com.

10. International data transfers

Core hosting is located in Germany. When Meta, OpenAI or their subprocessors are used, data may also be processed outside the European Economic Area. Depending on the recipient and destination, transfers are based on an adequacy decision, including the EU-US Data Privacy Framework where applicable, or the EU Standard Contractual Clauses together with supplementary technical and organisational safeguards. The current global OpenAI API path and Meta's worldwide service infrastructure do not justify a statement that all processing remains exclusively in the EU.

11. Retention and deletion

  • WhatsApp message bodies receive a 30-day redaction deadline in the current system. After expiry, the cleanup mechanism removes the readable body; security, routing, duplicate-prevention and audit metadata may remain where still required.
  • OpenAI receives requests with store=false. Separate OpenAI abuse-monitoring retention is described in section 7.
  • Technical access logs rotate after seven days; application logs rotate according to configured size limits.
  • Booking, customer, account, consent and contractual records are retained for as long as required for the customer instruction, the service purpose, contract performance, security evidence or statutory retention and limitation periods, and are then deleted or anonymised.
  • Backups and rollback artifacts follow the same purpose limitation and are overwritten or deleted in their normal rotation; restoration can temporarily reintroduce data until the deletion cycle runs again.

12. Cookies and consent settings

The website currently uses the necessary tvx_consent cookie to store the selected consent categories and policy version for 180 days. When a choice is saved, Timevex also records the selected categories, consent version, source, an available country/region signal and a pseudonymised user-agent hash for proof and troubleshooting. The legal basis is Art. 6(1)(f) GDPR and section 25(2) no. 2 TDDDG.

The consent interface technically provides optional preference, analytics and marketing categories. At the time of this policy, however, no Google Analytics, Google Ads or Meta Pixel tag is embedded or loaded—neither before nor after consent. If an optional service is activated in the future, it will be blocked until consent and this policy and the provider list will be updated before activation. The legal basis would be consent under Art. 6(1)(a) GDPR and section 25(1) TDDDG.

You can change or withdraw your choice at any time through “Cookie settings” in the footer. Withdrawal does not affect the lawfulness of processing before withdrawal.

13. Your rights

Subject to the statutory requirements, you have the right to:

  • access (Art. 15 GDPR), rectification (Art. 16 GDPR) and erasure (Art. 17 GDPR);
  • restriction of processing (Art. 18 GDPR) and data portability (Art. 20 GDPR);
  • objecting to processing based on Art. 6(1)(e) or (f) GDPR (Art. 21 GDPR);
  • withdrawing consent at any time with effect for the future;
  • lodging a complaint with a data protection supervisory authority, in particular in your habitual residence, workplace or the place of the alleged infringement.

For data processed by Timevex on behalf of a business customer, that business customer is the primary contact. You may also contact datenschutz@timevex.com; we will securely assign the request and assist the controller.

14. Security and changes

Timevex uses TLS encryption, tenant separation, role and authorisation controls, encrypted secrets, webhook signature verification, duplicate protection, restricted service networks, audit records and controlled backup/rollback procedures. Absolute security cannot be guaranteed.

We update this policy when processing activities, providers or legal requirements change. The version published here is authoritative.

Cookies & privacy

We use a necessary cookie for your consent choice. Optional categories are technically prepared, but no analytics or marketing provider is currently embedded. Privacy Policy · Imprint