Privacy policy
Data controller
The data controller for data processing on this website is: Semir Webdesign, Inhaber Oguz Selim Semir Widemannstr. 7 30625 Hannover Deutschland Phone: +49 178 9274590 Email: kontakt@semirwebdesign.de
Hosting and server log files
When you visit this website, our hosting provider automatically collects information in so-called server log files that your browser transmits. This includes browser type, operating system used, referrer URL, hostname of the accessing computer, and time of the server request.
Purposes of processing and legal bases
We process personal data for the following purposes: providing and operating the dashboard to perform our contract with our customers (Art. 6(1)(b) GDPR); sending transactional emails such as booking confirmations and account notifications to perform that contract (Art. 6(1)(b) GDPR); creating and analyzing server log files to ensure operational security and reliability, on the basis of our legitimate interest (Art. 6(1)(f) GDPR); maintaining audit logs and retaining them to meet statutory record-keeping obligations (Art. 6(1)(c) GDPR); and handling data-subject requests under Art. 15 and Art. 17 GDPR to fulfil our legal obligations (Art. 6(1)(c) GDPR).
Booking widget
Bookerino provides businesses with an embeddable booking widget. When you book an appointment through a business's widget, your details (e.g. name, email address, phone number) are transmitted to that business as the data controller and processed to manage the appointment and send confirmation emails. You can find that business's own privacy policy inside the booking widget.
Processors we use
We use carefully selected service providers as processors under Art. 28 GDPR: Vercel Inc. (hosting and delivery of the application), Supabase, Inc. (database hosting), and Resend, Inc. (delivery of transactional emails). We have data processing agreements in place with all processors, binding them to our instructions and to the GDPR's level of data protection.
International data transfers
Some of our processors (Vercel, Supabase, Resend) also process data in the United States, a third country without an EU adequacy decision. For these transfers we have put appropriate safeguards under Art. 46 GDPR in place, in particular the European Commission's Standard Contractual Clauses, as well as — where offered by the respective provider — its certification under the EU-U.S. Data Privacy Framework.
Storage duration
We store personal data only for as long as necessary for the respective purpose or as required by statutory retention obligations: booking data is kept for 730 days, customer data for 730 days, booking-widget event data (funnel events) for 180 days, and audit logs for 365 days after collection, after which it is automatically deleted or anonymized.
Customer account ("My bookings")
If you create a customer account to see your appointments across every provider in one place, we additionally process the following categories of personal data: your account data (email address, name, password hash) to provide the login and the bookings overview (Art. 6(1)(b) GDPR); the link between your account and your bookings with each provider, so that only you can see your own appointments (Art. 6(1)(b) GDPR); and, while a signup is in progress, a time-limited signup attempt (email address, password hash), which is automatically deleted after 24 hours regardless of whether the signup was completed — the deletion run happens daily, so the signup attempt is removed after 48 hours at the latest (Art. 6(1)(b) GDPR, pre-contractual measure). We store your account data (email address, name, password hash) for as long as your customer account exists, and delete it only once you delete your account yourself under /account/settings. Recipients are exclusively the processors listed under "Processors we use"; we only transmit to the respective provider what a booking itself requires. For your customer account, in addition to the rights listed under "Your rights", you specifically have a right to access (Art. 15 GDPR) and to data portability (Art. 20 GDPR); contact kontakt@semirwebdesign.de to exercise them — a self-service export is not currently available for the customer account.
Your rights
You have the right to access, rectify, erase, and restrict the processing of your personal data, as well as a right to object to processing and a right to data portability. You also have the right to lodge a complaint with a data protection supervisory authority.