01Datenschutz

Legal

Privacy Policy

1. Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG) is:

Booklera UG (haftungsbeschränkt)
represented by die Geschäftsführerin Nadine Glamngiw
Landsberger Straße 155, Haus 1, 80687 München
Germany
Email: n.glamngiw@booklera.de

Booklera is a SaaS platform for commercial providers from the trades, fitness, alternative health, holiday home rental and e-commerce (online shop) sectors. Personal data is processed either as an independent controller (registration, contract handling, technical logs) or as a processor on behalf of the registered tenants (end-customer and employee data of the tenants).

2. Collection and processing of personal data

2.1 Registration and user account

When registering on booklera.de, we collect the following data: name, email address, password (stored bcrypt-encrypted with rounds = 12, never in plain text), company name, chosen subdomain slug and the selected vertical (trades, fitness, alternative health, holiday home or e-commerce). This data is required to provide our SaaS service and to perform the contract. The legal basis is Art. 6 (1) (b) GDPR (performance of a contract). Your user account and the associated data are stored for as long as the contract exists. After termination, the data is deleted within 30 days unless statutory retention obligations prevent this (see Section 10).

To prevent abusive registrations (e.g. spam accounts or sign-ups with third-party email addresses), we additionally store the IP address and browser identifier (user agent) of the registering device during registration. The legal basis is Art. 6 (1) (f) GDPR (legitimate interest in the security of the service and the prevention of misuse). This information is not merged with other data sources, is not used for advertising or profiling and is deleted together with the user account. For early misuse detection, the platform operator is informed internally by email about every new registration. The tenant email mailbox created during registration is only enabled for sending after the email address has been confirmed (double opt-in).

2.2 End-customer, employee and order data (data processing on behalf)

As a SaaS platform, Booklera processes data on behalf of the registered tenants. The tenants' end customers book appointments or classes or request work services via the respective tenant website. In doing so, personal data of the end customers (name, email address, telephone, address, booking details, payment data where applicable) and — for trade tenants — employee data (see Section 2.4) is collected and processed.

In this relationship, the respective tenant is the controller within the meaning of the GDPR, and Booklera acts as a processor pursuant to Art. 28 GDPR. Processing takes place exclusively on the instructions of the tenant and within the framework of a data processing agreement (DPA). The legal basis is Art. 6 (1) (b) GDPR (performance of the contract between end customer and tenant) in conjunction with Art. 28 GDPR.

2.3 Server log files

When you visit our website, technical access data is automatically stored in server log files. This includes: IP address, date and time of access, page accessed, browser and operating system used, referrer URL. This data is not merged with other data sources and serves exclusively to technically secure operations and detect misuse. The legal basis is Art. 6 (1) (f) GDPR (legitimate interest in the security of the service). The log files are automatically deleted after 7 days at the latest.

2.3a Audience measurement without cookies

On our public pages (booklera.de, booklera.com) we count page views to learn which pages are visited and where visitors come from. Only daily counters are stored: date, page visited, referring website, campaign parameters of the address, the country derived from the IP address, device type and browser language. The IP address itself is not stored; to count unique visitors, a hash of the IP address and browser identifier with a random value that changes daily is created for the current day and deleted at the end of the day. No cookies are set and no external analytics services are used. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in measuring the reach of our website).

2.4 Employee and subcontractor data (trade tenants)

For trade tenants, Booklera processes the following employee data as a processor — the tenant is and remains the controller for this data and must ensure lawful processing (e.g. informing employees, works agreement where applicable):

  • Planning board data: Daily assignments per employee (date, job, time, duration, notes, weather metadata).
  • Time tracking: Working hours per employee (date, hourly rate, job assignment), punch card timestamps.
  • GPS geolocation for punch-in events, provided the employee has previously consented in an explicit browser dialog (Art. 6 (1) (a) GDPR). Without consent, no GPS coordinates are stored; punching in also works without GPS.
  • Absences: Holiday, sickness, public holiday, off, training per employee with date range.
  • Logbook: when using the vehicle feature (Business): date, mileage, purpose (business / private / commute), job assignment. Private journeys are kept separate from business journeys; the tenant decides which data is recorded.
  • Payroll data: Wage hourly rate per employee, wage calculation per month (Pro+ only).

This data is stored tenant-isolated (see Section 7) and is only visible to the respective tenant. Retention follows statutory obligations (generally 6 years under Section 257 HGB for payroll-relevant data, longer periods for tax-relevant or GoBD-relevant data — see Section 10).

2.4a Shop customer and order data (e-commerce tenants)

If a tenant operates an online shop, Booklera processes the data of that shop's end customers as a processor. The controller within the meaning of the GDPR is and remains the shop operator; they must inform their customers and provide their own privacy policy for their shop. The following is processed:

  • Customer account: Name, email address, password (only as a cryptographic hash), customer type (private or business customer), for business customers additionally company name, VAT identification number and approval status. The shop customer account is technically completely separate from the accounts of Booklera users.
  • Addresses: Delivery and billing addresses that the customer stores or provides during the order process — including as a guest without a customer account.
  • Order data: ordered items, quantities, prices, tax amounts, shipping method, order status, tracking numbers, returns and credit notes. The delivery and billing address is stored immutably at the time of the order because invoices must not be changed retrospectively (GoBD).
  • Invoices and credit notes including electronic invoice formats; these are subject to the statutory retention obligation (generally 10 years, see Section 10) and therefore cannot be removed immediately even after a deletion request.
  • Product reviews: Review text, star rating and displayed name, if the customer submits a review. Reviews only become publicly visible after approval by the shop operator.
  • Shop usage data: Page views and shopping cart events for creating anonymous sales statistics. This analysis takes place exclusively on the provider's server; no external analytics services (e.g. Google Analytics) are used.

Transmission to customs authorities for deliveries outside the EU: If a shop operator ships goods to a country outside the European Union, the platform generates a commercial invoice and a customs declaration (form CN23). These documents contain the name and address of the recipient, the contents of the shipment, its value and, where applicable, the customs tariff number and country of origin. They are attached to the parcel and presented to the customs authorities of the dispatch and destination countries. This transmission is legally required to comply with customs and export regulations (Art. 6 (1) (c) GDPR) and cannot be avoided for an international delivery.

2.5 Special categories of personal data (Art. 9 GDPR) — employers' liability insurance reports

For trade tenants, the system can process special categories of personal data pursuant to Section 193 SGB VII (statutory accident insurance reporting obligation), in particular:

  • Accident data: Date, place, course of the accident, severity (minor/medium/severe/death), days of incapacity for work, treating doctor, person concerned.
  • Health data: only to the extent required for the accident report (e.g. type of injury, sick days).

The legal basis for this processing is Art. 9 (2) (b) GDPR in conjunction with Section 193 SGB VII (fulfilment of the employer's social-law reporting obligations). The official accident report is generated as a PDF and can be sent by the tenant to the responsible employers' liability insurance association — the sending itself is carried out by the tenant on their own responsibility. The accident file is retained for 10 years (GoBD Sections 146, 147 AO as well as internal retention obligations of the insurance association) — see Section 10.

2.6 Cookies and comparable technologies (granular consent pursuant to GDPR Art. 7)

Booklera uses a granular cookie consent system. On the first visit to the website (both booklera.de and every tenant subdomain), a modal is displayed in which the user can decide per cookie category. Consent is logged in an audit trail (browser ID, IP, user agent, page, timestamp) and can be changed or revoked at any time via the footer link “Cookie settings”.

Technically necessary cookies (always active, no consent required pursuant to Section 25 (2) No. 2 TTDSG):

  • bl_session — Login session (HttpOnly, Secure, SameSite=Lax).
  • bl_csrf — CSRF protection token.
  • bl_platform_session — Platform admin session (internal only).
  • bl_cookie_consent — Storage of the cookie consents themselves (lifetime: 365 days).
  • bl_force_lang_* — Language override (only if actively chosen by the user).
  • bl_2fa_dismiss — temporary skip for the 2FA recommendation banner (lifetime: 7 days).

Cookies requiring consent (default OFF, only after active consent):

  • __stripe_mid, __stripe_sid — Stripe cookies for online payments and fraud prevention. Provider: Stripe Payments Europe Ltd., Dublin. Used only if the user makes an online payment and has previously consented to “Stripe cookies”. Without consent, online payment is not possible; alternatively, on-site payment can be offered.

We do not use tracking cookies, analytics cookies or marketing cookies. There is no user tracking by third parties. The audit trail of consents is stored for a maximum of 3 years pursuant to GDPR Art. 7 (1) (accountability); upon revocation, the old entry is marked with the time of revocation and a new entry with the current values is created so that the history remains fully traceable.

2.7 Audit log (compliance, immutable)

Security- and compliance-relevant actions (login, logout, password change, 2FA activation/deactivation, finalization of construction diary and safety documents, cancellations, backdating attempts) are logged in an audit log with the following data: tenant ID, user ID, action, old value, new value, reason, IP address, user agent, timestamp.

The audit log is immutable pursuant to GoBD Section 146 AO — the database triggers block UPDATE and DELETE on the audit table. Retention: 10 years pursuant to Section 147 AO (see Section 10). Legal basis: Art. 6 (1) (c) GDPR (legal obligation — tax and compliance duties) and Art. 6 (1) (f) GDPR (legitimate interest in security and misuse detection).

3. AI-supported features

Booklera offers eight AI-supported features. These are based on a local, open-source-based AI language model that is operated entirely on our own server in Germany (Hetzner Online GmbH). No data whatsoever is transmitted to external AI providers such as OpenAI, Google, Anthropic, Microsoft or other third parties. The model currently used is qwen2.5:14b (as of April 2026, Apache 2.0 license). The model is regularly checked against the state of the art in accordance with an internal 3-month re-check procedure and updated if a significantly better model becomes available.

All AI features are marked as such in the admin panel in accordance with EU AI Act Art. 52 (purple “AI” badge), contain result disclaimers and are explained in the tool info entries (what the AI does, where it runs, which model is used).

3.1 AI assistant (admin panel)

Operating-help chatbot for tenant owners in the admin panel. Requests are limited by a monthly quota per plan (Basic: 20 / Pro: 200 / Business: ∞ / Enterprise: ∞). Usage is counted anonymously (context, timestamp, tenant ID). The content of requests is not stored in plain text; a prompt injection filter with 22 patterns (DE+EN) blocks obvious manipulation attempts.

3.2 AI customer chat (FAQ bot on the tenant website)

Answers questions from end customers on the tenant website about services, prices, bookings or enquiries (from the Pro plan). Quotas: Basic 0 (not available) / Pro 500 / Business ∞ / Enterprise ∞. Customer questions are not stored in plain text. For security analysis, only an anonymized hash (SHA-256) of the request together with the IP address is stored for a maximum of 60 minutes. The raw data is not logged and not used to train the model.

3.3 AI invoice scanner (Business)

Processes photos or PDF files of incoming invoices. Text recognition is performed using Tesseract OCR (open source, local). The local language model then extracts relevant fields (supplier, amount, date, category). The uploaded receipts are stored permanently in a tenant-isolated folder on our server (retention obligation pursuant to Sections 147 AO, 257 HGB). Invoice data is not transmitted to third parties — all processing takes place locally.

3.4 Universal scan (Pro+)

OCR function for receipts, invoices, delivery notes. Same tech stack as the invoice scanner, more broadly applicable. Quotas: Basic 0 / Pro 50 / Business 300 / Enterprise ∞.

3.5 AI quote generator (Pro+, trades)

Converts a free-text or voice description of a trade project into a complete bill of quantities (items, quantities, descriptions). Quotas: Basic 0 / Pro 30 / Business 200 / Enterprise ∞. Voice input takes place browser-locally via the Web Speech API; the transcribed input is sent to the local AI model.

3.6 AI voice measurement (Pro+, trades)

Measurement values can be dictated via microphone; the AI extracts dimensions and calculates areas. Web Speech API browser-local; server-side AI processing local. Quotas: Basic 0 / Pro 30 / Business 200 / Enterprise ∞.

3.7 AI time tracking (Pro+, trades)

Employees can summarize their working day verbally; the AI extracts structured time entries (job, date, hours, description) with fuzzy matching against existing jobs. Up to 10 entries per batch. Quotas: Basic 0 / Pro 50 / Business 300 / Enterprise ∞.

3.8 Construction docs autopilot (Pro+, trades)

Structures voice and photo notes into construction progress reports. Quotas: Basic 0 / Pro 50 / Business 300 / Enterprise ∞.

3.9 AI features in the online shop (Pro+, e-commerce)

For shop tenants, additional AI features are available that also run exclusively on the provider's local language model: creation of product descriptions and short texts for search engines, suggestions for assigning products to categories, and suggestions for customs tariff numbers and countries of origin. Only the tenant's product data is processed — no customer or order data.

During goods receipt, delivery notes can be read in as a photo or PDF. The image content and the recognized text are processed to record items and quantities. If such a document contains personal details of the supplier (such as the name of a contact person), these are processed as well; processing takes place locally on the provider's server. All AI suggestions are presented to the user for review and only adopted after their confirmation.

The legal basis for all AI features is Art. 6 (1) (b) GDPR (performance of a contract) and Art. 6 (1) (f) GDPR (legitimate interest in preventing misuse and in efficient task completion).

4. Payment processing (Stripe)

For processing payments (SaaS subscriptions as well as end-customer payments via Stripe Connect, including on-site card payments via Stripe Terminal), we use the Stripe service.

  • Provider: Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland; parent company: Stripe Inc., 354 Oyster Point Blvd, South San Francisco, CA 94080, USA.
  • Purpose: Secure processing of SaaS subscription payments (Basic, Pro, Business, Enterprise), end-customer payments via Stripe Connect and on-site card payments via Stripe Terminal (POS).
  • Data processed: Name, email address, payment data (credit card data, SEPA direct debit, debit card data for POS). Your payment data is transmitted directly to Stripe and is not stored on our servers. For POS payments, the card data is processed exclusively by the Stripe card reader — neither Booklera nor the tenant has access to the card number.
  • Stripe Terminal (POS): For on-site card payments, the card reader communicates directly with Stripe. The transaction data (amount, timestamp, terminal ID) is stored in our system to create payment receipts and accounting entries. On request, a payment receipt is sent to the end customer by email.
  • Platform fee: For payments via Stripe Connect (online and POS), Booklera charges a platform fee of 1.5% of the transaction amount, which is automatically retained by Stripe.
  • Legal basis: Art. 6 (1) (b) GDPR (performance of a contract).
  • Third-country transfer: Data may be transferred to the USA. Stripe has joined the EU-US Data Privacy Framework and additionally uses standard contractual clauses (SCCs) pursuant to Art. 46 (2) (c) GDPR.
  • Webhook reliability: Stripe webhook events are processed with an internal retry worker (backoff: 5 min → 15 min → 1 h → 6 h → 24 h, idempotency via event_id) to rule out data loss during temporary Stripe outages.
  • Cookies: Stripe only sets cookies if the user has actively consented to “Stripe cookies” via the cookie consent modal (see Section 2.6).
  • Stripe's privacy notices: stripe.com/de/privacy

5. Video embedding and upload

5.1 YouTube embedding

Videos from YouTube can be embedded on tenant websites. We use the extended privacy mode (youtube-nocookie.com), in which YouTube only sets cookies when the user actively plays the video.

  • Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
  • Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in displaying video content)
  • Privacy notices: policies.google.com/privacy

5.2 Vimeo embedding

Alternatively, videos from Vimeo can be embedded. We use the dnt=1 parameter (Do Not Track).

  • Provider: Vimeo Inc., 555 West 18th Street, New York, NY 10011, USA
  • Legal basis: Art. 6 (1) (f) GDPR
  • Privacy notices: vimeo.com/privacy

5.3 Video upload

From the Business plan, tenants can upload their own videos (MP4, WebM, up to 100 MB per file) directly to the platform. These videos are stored exclusively on our server in Germany (Hetzner) and are not passed on to third parties. Storage limits: Pro 2 GB / Business 10 GB.

6. Hosting and custom domains (Hetzner)

This website and the SaaS platform are hosted on a dedicated server of Hetzner Online GmbH (Industriestr. 25, 91710 Gunzenhausen, Germany). The server is located in Germany. All data (database, files, emails, AI model, backups) is stored and processed exclusively in Germany. Hetzner is contractually bound as a processor pursuant to Art. 28 GDPR. hetzner.com/de/legal/privacy-policy

For the optional custom domain feature (from Pro), we use the Hetzner DNS API: the tenant enters the DNS records with their own domain provider, and an automatic worker checks the DNS configuration every 30 minutes. SSL certificates are generated via Let's Encrypt and renewed automatically.

Backup concept: 4 independent layers (Restic every 15 min to offsite storage, PostgreSQL WAL archive every minute, daily offsite dump, offline copy twice a day). All backups are encrypted (Restic AES-256, separate master key).

7. Tenant separation (multi-tenant isolation)

Booklera is a multi-tenant platform. Technical measures for tenant separation:

  • Row-level security (RLS) with FORCE on 22+ database tables. Every database query is automatically filtered by tenant; access to other tenants' data is technically impossible.
  • Separate database roles: The application uses a restricted role without BYPASS RLS privilege; only maintenance operations use the owner role.
  • Tenant context per request: The app sets the tenant context automatically during the auth check, and the RLS predicate then filters.
  • Webhooks: Stripe webhooks and other externally triggered actions also set the tenant context before every DB operation.

Every tenant automatically receives a data processing agreement (DPA) pursuant to Art. 28 GDPR by email immediately after registration. The DPA is also available at any time in the admin panel under Settings → DPA / Privacy and can be re-sent from there. If you have any questions about data protection, please contact info@booklera.de.

8. SSL/TLS encryption and two-factor authentication

This website and all tenant subdomains use SSL/TLS encryption (HTTPS, at least TLS 1.2, HTTP/2 supported). You can recognize an encrypted connection by the browser address bar changing from “http://” to “https://”. All data you transmit to us cannot be read by third parties. In addition, HSTS (HTTP Strict Transport Security) is active for one year.

Two-factor authentication (2FA, TOTP per RFC 6238) is available for access to the admin panel — mandatory for platform admins (Booklera-internal access), opt-in for tenant owners with a gentle reminder. During setup, ten single-use recovery codes are generated; the TOTP secrets are stored encrypted in the database.

9. Cross-tenant features (trades pool and transport marketplace)

For trade tenants, Booklera provides a cross-tenant network (trades pool and transport marketplace, reading from the Pro plan, posting from the Business plan). If a tenant actively uses these features, certain data becomes visible to other users of the platform:

  • Trades pool — connections: If the tenant invites another trade business or accepts an invitation, both sides see the company name, trade and email address of the other.
  • Trades pool — signals (seeking/offering): When posting a signal, the company name, trade and signal content (description, urgency, address where provided, period) are displayed to the connected trade businesses.
  • Trades pool — expressions of interest: In the case of an expression of interest, the company name and contact details of the bidder are sent to the signal poster by email.
  • Transport marketplace: When a transport request is posted, key data (route, material, period) is displayed to other tenants in the feed; for offers, the contact details of the offerer are disclosed.

The visibility of the data is limited to your own network (accepted connections) or to the recipients of a posting. There is no automatic data sharing between tenants — all data transfers only take place after an active action by the user (sending/accepting an invitation, posting a signal, expressing interest, submitting a transport offer).

Legal basis: Art. 6 (1) (b) GDPR (performance of a contract — the cross-tenant network is part of the booked plan features) and Art. 6 (1) (a) GDPR (consent of the user through active use of the feature). The user can disconnect a connection at any time, delete their own signal or revoke an expression of interest — the associated data is then removed from the network.

10. Data storage and deletion periods

Personal data is only stored for as long as is necessary for the respective processing purpose or as long as statutory retention obligations exist. In detail:

Data categoryRetention periodLegal basis
Active user accountfor the duration of the contractArt. 6 Abs. 1 lit. b DSGVO
After termination — tenant data30 days soft delete for data export, then hard deleteArt. 17 DSGVO
Server log files7 daysArt. 6 Abs. 1 lit. f DSGVO
AI chatbot: anonymized hashes60 minutesArt. 6 Abs. 1 lit. f DSGVO
Cookie consent audit3 yearsGDPR Art. 7 (1) (accountability)
Tax-relevant data (invoices, payment records)10 years§§ 147 AO, 257 HGB
Construction diary, site meeting minutes, acceptance protocol, safety documents, safety accidents10 years after finalizationSections 146, 147 AO (GoBD)
Audit log (immutable)10 years, UPDATE/DELETE blocked§ 146 AO
Payroll and salary data6 years§ 257 HGB, § 147 AO
Accident file (special categories Art. 9)10 yearsSection 147 AO + internal retention obligations of the insurance association
Internal error tracking (resolved errors)30 daysArt. 6 Abs. 1 lit. f DSGVO
Webhook failures (resolved)30 daysArt. 6 Abs. 1 lit. f DSGVO
Sessions (expired)7 days after expiryArt. 6 Abs. 1 lit. f DSGVO
Domain health log (resolved)30 daysArt. 6 Abs. 1 lit. f DSGVO

11. Your rights

Under the GDPR, you have the following rights vis-à-vis us regarding your personal data:

  • Right of access (Art. 15 DSGVO): You can request information about your personal data stored by us at any time.
  • Right to rectification (Art. 16 DSGVO): You can request the correction of inaccurate data or the completion of incomplete data.
  • Right to erasure (Art. 17 DSGVO): You can request the deletion of your personal data, provided that no statutory retention obligations (see Section 10) or legitimate reasons prevent this.
  • Right to restriction of processing (Art. 18 DSGVO): You can request the restriction of the processing of your data, e.g. if you dispute the accuracy of the data.
  • Right to data portability (Art. 20 DSGVO): You can request that we provide you with your data in a structured, commonly used and machine-readable format. Booklera offers a GDPR export function in the administration area for this purpose (for trades additionally the job ZIP export from Business).
  • Right to object (Art. 21 DSGVO): You can object to the processing of your data on the basis of Art. 6 (1) (f) GDPR (legitimate interest) at any time.
  • Right to withdraw consent: Insofar as processing is based on consent (e.g. cookie consent, GPS geolocation), you can withdraw it at any time with effect for the future — e.g. via the footer link “Cookie settings”. The lawfulness of the processing carried out until the withdrawal remains unaffected.

To exercise your rights, please contact us by email at n.glamngiw@booklera.de. We will respond to your request without delay, at the latest within one month.

12. Right to lodge a complaint with the supervisory authority

You have the right to complain to a data protection supervisory authority if you believe that the processing of your personal data violates the GDPR. The supervisory authority responsible for us is:

Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
Promenade 18
91522 Ansbach
www.lda.bayern.de