Security & data protection

Your customers leave personal data with every booking. Here is where that data sits, who can see it and when it disappears automatically.

Hosted in Germany

All data is stored on servers in German data centres and delivered via the Frankfurt am Main location. 100% German servers – your customer data does not leave Germany.

GDPR compliant

timum is built for the General Data Protection Regulation: only what an appointment requires is collected – and you decide what happens to it afterwards.

Automatic retention periods

Under Settings → Data protection you define after how many days customer data is deleted. What counts is a person's most recent appointment; deletion runs automatically the night the period expires.

Participants never see each other

Even for group and collective appointments, no prospect learns who else booked. timum sends no participant information to other participants; booked times appear – if at all – anonymously as "Busy".

Encrypted transmission

timum is only reachable over HTTPS. All data between browser, booking widget and timum is transmitted via SSL/TLS.

DPA and TOMs on request

We provide the data processing agreement (DPA) and the overview of our technical and organisational measures (TOMs) on request – for your data protection documentation or an internal audit.