zerocrumb
ImpressumDatenschutzAGBAVV

Privacy policy

Stand / last updated: 2026-09-03

This policy covers personal data for which ZeroCrumb is the controller. For data a bakery processes through ZeroCrumb, the bakery is the controller — see the data processing agreement.

ENTWURF — inhaltlich an der tatsächlichen Systemarchitektur ausgerichtet, aber noch nicht rechtlich geprüft. Vor dem Livegang von einer Rechtsberatung prüfen lassen. // DRAFT — written against the real architecture but NOT yet legally reviewed. Have a qualified DE/AT advisor review before launch.

1. Controller

[Firmenname, Anschrift, E-Mail — identisch zum Impressum]

2. Two roles — please distinguish

ZeroCrumb acts in two distinct roles. This is not a formality — it determines who is accountable for which data:

DataRoleGoverned by
Bakery account: email, business name, role, language, sign-in dataControllerthis policy
The bakery's receipt data: product, quantity, price, time, payment method. Customer name, VAT ID and address are NO LONGER collected or stored as of 6 September 2026.ProcessorDPA

3. Data processed and legal bases

3.1 Account data

Email address, business name, role and language preference. Authentication runs on Amazon Cognito, which additionally processes sign-in times and security events. Legal basis: Art. 6(1)(b) GDPR (performance of a contract).

3.2 Business and sales data

Sales figures, product catalogue, opening days, and the business country and city. Largely non-personal, but linked to an account. Used to produce demand forecasts — the purpose of the service. Legal basis: Art. 6(1)(b) GDPR.

3.3 Server logs

Technically necessary data is processed on each request (IP address, timestamp, requested resource, status code). Legal basis: Art. 6(1)(f) GDPR (operational security).

4. No tracking, no cookie banner

ZeroCrumb uses no analytics, advertising or tracking services. Only strictly necessary cookies/storage entries are set, for sign-in and language preference. These require no consent under §25(2) TTDSG — which is why there is deliberately no cookie banner. This statement must be revisited the moment any analytics tool is added.

5. Recipients and sub-processors

ServicePurposeLocation
Amazon Web Services (Cognito)AuthenticationEU (eu-north-1, Sweden)
netcup GmbHServer and database hosting (application and database run on the same server)Vienna, Austria
Vercel Inc.Frontend hostingEU (fra1)
OpenWeatherWeather per location — only country and city are sent, no personal datamay be outside the EU
helloCashCash-register import — data flows from the register to ZeroCrumb, not the reverseAustria

Server provider: netcup GmbH, Emmy-Noether-Straße 10, 76131 Karlsruhe, Germany (HRB 705547, Amtsgericht Mannheim). The server is located in the Vienna, Austria datacentre, so processing takes place exclusively within the EU.

For providers with a possible third-country element, appropriate safeguards (standard contractual clauses) must be verified and documented. Status of the Art. 28 GDPR processing agreements: [conclude and file the DPA with netcup GmbH — still outstanding]

6. Retention

  • Account data: until the account is deleted.
  • Forecast history: automatically deleted after 180 days.
  • Register receipts: while the account exists, imported receipts are not deleted individually. If an import is rolled back the receipt is kept and marked as voided with a timestamp and reason, so the import history stays auditable.
  • On account deletion ALL of the business’s data is removed, including imported receipts. The statutory retention duty (RKSV, roughly seven years) rests with the bakery and is met by its own cash register — ZeroCrumb holds only a working copy as processor and returns or deletes it at the end of the contract (Art. 28(3)(g) GDPR).

Deletion can be triggered in the application itself (Account → Data) and requires typing the business name to confirm. It removes the data from the database and the user account from the authentication service.

7. Automated forecasting

ZeroCrumb produces demand forecasts from each business’s own sales data. Models are trained per business only — one bakery’s data never informs another’s forecast. A forecast is decision support for production planning and has no legal effect on any individual, so Art. 22 GDPR is not expected to apply.

8. Your rights

You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and objection (Art. 21), and the right to lodge a complaint with a supervisory authority (Art. 77). Requests to: [datenschutz@…]

Where a request concerns data a bakery processes through ZeroCrumb (for example customer details on a receipt), the bakery is the controller. We forward such requests to them without delay.

Impressum·Datenschutz·AGB·AVV