Slotara Logo Slotara

This English version is provided for convenience. The German version is legally binding.

Legal

Privacy policy

pursuant to Art. 13, 14 GDPR · As of: May 2026 — Version 1.1

Controller within the meaning of Art. 4 (7) GDPR

Marcus Marvin Mayer

intellimSystems (sole proprietor)

Am Himmelspfad 49
65474 Bischofsheim
Germany

Phone: +49 (0) 157 850 903 35

Email: info@intellimsystems.de

Website: slotara.de

1

Principles of data processing

We process personal data only where there is a legal basis under Art. 6 GDPR: consent (point (a)), performance of a contract (point (b)), legal obligation (point (c)) or legitimate interest (point (f)).

Personal data is stored only for as long as is necessary for the respective purpose or for as long as statutory retention obligations apply (§ 147 AO, German Fiscal Code: 10 years for tax-relevant data; § 257 HGB, German Commercial Code: 6 years for commercial letters).

2

Hosting & infrastructure

Slotara runs on servers operated by Strato AG (Otto-Ostrowski-Str. 7, 10249 Berlin, Germany). The core application data (bookings, staff, clients) is stored and processed exclusively in Germany. A data processing agreement pursuant to Art. 28 GDPR is in place with Strato AG. Payment data is handled through Mollie B.V. (Netherlands, EU); if the AI feature is used optionally, data is transferred to the USA on the basis of standard contractual clauses (Art. 46 (2) (c) GDPR).

Legal basis: Art. 6 (1) (b) and (f) GDPR (performance of a contract and legitimate interest in operating the infrastructure).

Server log files: Each time the website is accessed, our server automatically records the browser type/version, operating system, referrer URL, IP address, and the date and time of access. For technical and security reasons, this data is stored for a maximum of 7 days and is not combined with other personal data.

3

Registration & user account

When you register with Slotara, we collect the following data: name, company name, email address, password (stored encrypted), the plan selected, and the date and time of registration.

In addition, GDPR-related consents are logged: acceptance of the Terms and Conditions (timestamp), acceptance of the data processing agreement pursuant to Art. 28 GDPR (timestamp + version number). This logging is required by law (Art. 5 (2), Art. 7 (1) GDPR).

Legal basis: Art. 6 (1) (b) GDPR (performance of a contract), Art. 6 (1) (c) GDPR (legal obligation to provide GDPR records).

Retention period: account data is stored for the duration of use and beyond that in accordance with statutory retention periods.

4

Beta waiting list & access requests

Slotara is currently in a closed beta phase. Interested parties can request beta access using the form at slotara.de/de/registrieren.

In doing so, we collect the following data: name, email address, industry (optional), a short description of the intended use (optional), the sender's IP address, browser identification (user agent), the timestamp of the request, and a record of consent to the privacy policy and the Terms and Conditions (timestamp).

Purpose of recording the IP address and user agent: protection against automated bulk sign-ups (spam prevention), detection of misuse, and traceability of the consent given within the meaning of Art. 7 (1) GDPR.

Legal basis: Art. 6 (1) (a) GDPR (consent given by completing the form and agreeing to the terms) and Art. 6 (1) (f) GDPR (legitimate interest in spam prevention and in retaining evidence of consent).

Retention period: requests are stored for 24 months. Requests that have not been invited can be deleted at any time on request — an email to info@intellimsystems.de is sufficient.

Security notification: After the form has been submitted, the email address entered receives an automatic security confirmation stating the IP address and timestamp. This protects against misuse of a third party's email address.

5

Login log & security logs

To protect the platform against unauthorised access, we log every login attempt (successful or failed) with the following data: IP address, the route called (e.g. /login), timestamp, and whether the attempt was successful.

This data serves IT security purposes only: detecting brute-force attacks, automatically blocking suspicious IP addresses, and notifying the administrator of unusual behaviour.

Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in protecting the platform and its users against unauthorised access).

Retention period: login logs are deleted automatically after 90 days. Blocked IP addresses (blocklist) are managed manually by the administrator.

6

Data entered by customers (tenant data)

When using Slotara, customers (tenants) enter data relating to their own end customers, staff and services (e.g. names, contact details, appointment bookings). This data is processed exclusively on behalf of the customer.

In this respect, Slotara acts as a processor within the meaning of Art. 28 GDPR. The customer is the controller for this data. The rights and obligations are governed by the separate data processing agreement (DPA), which can be viewed in the account area after logging in.

7

Payment processing (Mollie)

We use Mollie B.V. (Keizersgracht 126, 1015 CW Amsterdam, Netherlands) to process payments. As a payment service provider, Mollie is responsible for processing payment data (credit card details, SEPA direct debit, etc.).

When a paid plan is taken out, the billing address and payment data are transmitted directly to Mollie. We do not store complete payment method details ourselves. Mollie B.V. is regulated as a financial services provider in the Netherlands and is subject to European financial and data protection law.

Legal basis: Art. 6 (1) (b) GDPR (performance of a contract). Mollie's privacy information: mollie.com/de/privacy.

8

Cookies & technical necessity

Slotara uses strictly necessary cookies only, which are required for the secure operation of the platform. These include, in particular, session cookies for authentication (deleted automatically after logout) and a CSRF cookie to protect against cross-site request forgery attacks.

We do not use any tracking, analytics or advertising cookies. No third-party cookies are set for analytics or marketing purposes.

Legal basis for necessary cookies: Art. 6 (1) (b) and (f) GDPR (performance of a contract and legitimate interest in secure operation).

9

Email communication

If you contact us by email, the data you send (email address, name, content of the enquiry) is stored in order to process your enquiry. It is not passed on to third parties.

Slotara sends system emails (registration confirmation, password reset, invoices, booking notifications). These serve the performance of the contract and are technically necessary.

Legal basis: Art. 6 (1) (b) GDPR (performance of a contract) or Art. 6 (1) (f) GDPR (legitimate interest in communication).

10

Transfers to third countries

Core application data is stored and processed on servers operated by Strato AG in Germany.

Payments are processed through Mollie B.V. (Netherlands) — within the European Union.

Optional, and only if expressly activated by the customer: use of AI features (Anthropic PBC, USA). This processing takes place exclusively on the customer's explicit instruction and is safeguarded by standard contractual clauses pursuant to Art. 46 (2) (c) GDPR.

11

Your rights as a data subject

Access (Art. 15 GDPR)

You have the right to obtain information about the data stored about you, as well as its origin, recipients and the purpose of processing.

Rectification (Art. 16 GDPR)

You have the right to have inaccurate personal data rectified without undue delay, or incomplete data completed.

Erasure (Art. 17 GDPR)

You have the right to have your data erased, provided that no statutory retention obligations stand in the way.

Restriction (Art. 18 GDPR)

You may request the restriction of processing, for example if the accuracy of the data is contested.

Data portability (Art. 20 GDPR)

You have the right to receive your data in a machine-readable format and to transmit it to another controller.

Objection (Art. 21 GDPR)

You may object at any time to the processing of your data based on legitimate interests.

Complaint (Art. 77 GDPR)

You have the right to lodge a complaint with the competent data protection authority. In Hesse: Hessischer Beauftragter für Datenschutz und Informationsfreiheit (HBDI), Gustav-Stresemann-Ring 1, 65189 Wiesbaden.

12

Data security

All data is transmitted in encrypted form via TLS/HTTPS. Passwords are stored exclusively using modern hashing methods (bcrypt) — never in plain text.

We apply technical and organisational measures (TOMs) pursuant to Art. 32 GDPR in order to protect your data against unauthorised access, loss or manipulation. The measures used reflect the current state of the art.

All staff and service providers engaged by us are bound to confidentiality.

13

Automated decision-making

We do not carry out any profiling or automated decision-making within the meaning of Art. 22 GDPR.

14

Changes to this privacy policy

We reserve the right to adapt this privacy policy if the legal framework or the scope of our services changes. The current version is always available at slotara.de/en/privacy-policy.

In the event of material changes, we will inform registered users by email.

Data protection requests

Questions or requests about data processing?

For all data protection enquiries (access, erasure, objection), please contact:

info@intellimsystems.de