Powered by My Zeit

Privacy Policy

Last updated: [TO BE DEFINED: LAST_UPDATED] Effective date: [TO BE DEFINED: EFFECTIVE_DATE]

This Privacy Policy explains how [TO BE DEFINED: ENTITY_NAME] ([TO BE DEFINED: ENTITY_TYPE]), registered under EIN [TO BE DEFINED: ENTITY_REG_NUMBER], with registered office at [TO BE DEFINED: ENTITY_ADDRESS] ("My Zeit", "we", "us" or "our"), collects, uses, shares and protects your personal data when you use My Zeit and the website https://www.myzeit.com (the "Service").

We act as a data controller for personal data of our account holders and website visitors. For personal data that our business customers upload about their own clients, we act as a data processor on their behalf (see Section 9).

1. Who we are and how to contact us

For any question about this Policy or your personal data, contact us at privacy@myzeit.com or by post at [TO BE DEFINED: ENTITY_ADDRESS].

Data Protection Officer / privacy contact: [TO BE DEFINED: DPO_NAME] — [TO BE DEFINED: DPO_EMAIL].

Representative in the European Union (GDPR, Art. 27): [TO BE DEFINED: EU_REP_NAME], [TO BE DEFINED: EU_REP_ADDRESS] — [TO BE DEFINED: EU_REP_EMAIL].

2. What data we collect

  • Account & identity data: name, email, phone number, password (hashed), business name and business identifiers.
  • Customer-relationship data entered by business users: client names, contact details, appointment history, notes and intake forms.
  • Transaction & billing data: subscription plan, payment status and invoices. Card data is handled directly by our payment processor (Stripe); we do not store full card numbers.
  • Technical data: IP address, device and browser information, and usage logs.
  • Cookies and similar technologies: see our Cookie Policy.

3. Why we use your data and our legal bases

PurposeLegal basis (GDPR Art. 6)
Providing and operating the ServicePerformance of a contract
Billing and subscription managementPerformance of a contract
Security, fraud prevention and logsLegitimate interests
Service-related communicationsPerformance of a contract / legitimate interests
Marketing communicationsConsent (withdrawable at any time)
Analytics and non-essential cookiesConsent
Compliance with legal obligationsLegal obligation

4. Sharing your data

We share personal data only with: (a) service providers ("sub-processors") acting on our instructions, such as cloud hosting, payment processing (Stripe), email and messaging providers; (b) authorities where required by law; and (c) parties to a corporate transaction (e.g. merger or acquisition). We do not sell your personal data.

5. International data transfers

Where personal data is transferred outside the European Economic Area (EEA) or the United Kingdom, we rely on appropriate safeguards, in particular the European Commission's Standard Contractual Clauses (SCCs) and equivalent UK transfer mechanisms.

6. Data retention

We keep personal data only as long as necessary for the purposes described above, for the duration of your account, and thereafter as required to comply with legal, accounting or reporting obligations. You can request deletion at any time (Section 7).

7. Your rights

Depending on your location, you have the right to access, rectify, erase, restrict or object to processing, to data portability, and to withdraw consent at any time. To exercise these rights, contact privacy@myzeit.com. We respond to requests within one month (extendable by up to two further months for complex requests, with prior notice). To protect your data, we may ask you to verify your identity before acting on a request.

7.1 European Economic Area and United Kingdom (GDPR / UK GDPR)

You may also lodge a complaint with your local supervisory authority. In France this is the CNIL (www.cnil.fr).

7.2 California (CCPA/CPRA)

California residents have the right to know, delete, correct and opt out of the "sale" or "sharing" of personal information, and not to be discriminated against for exercising these rights. We do not sell personal information.

7.3 Brazil (LGPD)

Data subjects in Brazil have the rights set out in Art. 18 of the LGPD, including confirmation, access, correction, anonymisation, portability and deletion. You may contact our privacy team at privacy@myzeit.com.

8. Security

We implement appropriate technical and organisational measures, including encryption in transit, hashed passwords, access controls and monitoring, to protect personal data against unauthorised access, loss or alteration.

9. Data processed on behalf of business customers

When a business uses My Zeit to manage its own clients, that business is the controller of its clients' data and My Zeit is the processor. Such data is governed by our Data Processing Agreement (DPA), available on request at privacy@myzeit.com.

10. Children

The Service is not directed to children under the age required by local law to consent to online services, and we do not knowingly collect their data.

11. Changes to this Policy

We may update this Policy from time to time. Material changes will be notified through the Service or by email. The "Last updated" date above indicates the latest revision.


This document is also available in French, Portuguese and Spanish. In the event of any discrepancy, the English version prevails, except where mandatory local law provides otherwise.