本页面仅提供英文版本。
No paperwork
Applies automatically when you accept the terms.
Germany only
Servers and operations in Germany.
You stay in control
We only process on your instructions.
This agreement governs the processing of personal data by iqmeta GmbH, Am Sonnenhang 24, 71111 Waldenbuch, Germany (“processor” or “iqmeta”) on behalf of the organisation using drinklist.app or Getränkeliste.de – such as a club, a company or a group (“controller” or “customer”).
This agreement becomes part of the service contract upon acceptance of the terms and applies to the free plan as well as to paid subscriptions. A PDF version signed by iqmeta is available on request from support@drinklist.app.
§ 1 Subject matter, duration and purpose
- The subject matter is the provision of drinklist.app as an online service and app: storing and processing the data that the customer and its users record there – in particular accounts, bookings, cash register, settlements, payments, stock, news, reports and interfaces.
- The sole purpose of processing is the provision of these services, including operation, support, backups and troubleshooting.
- Processing lasts as long as the service contract. The provisions on deletion and return (§ 9) continue to apply thereafter.
§ 2 Types of data and data subjects
Data subjects
- Members, employees and other account holders of the organisation
- Users with roles in the organisation (e.g. owner, admin, cashier, viewer)
- Guests, e.g. on guest lists or when ordering by QR code
- Contact persons of the customer
Categories of data
- Master data: name or display name, account number, groups, optionally email address, date of birth with verification note (for youth protection), profile picture and custom fields defined by the customer
- Access data: PINs, invitations, device links – stored encrypted
- Booking and billing data: bookings, cancellations, balances, statements, settlements, reminders, cash transactions
- Payment data: amount, payment method, reference and status (no card numbers)
- Communication data: news from the organisation, read status, emails sent, support requests
- Log data: time, acting user, IP address and browser identifier for security-relevant actions
Special categories of personal data under Art. 9 GDPR are not intended for drinklist.app and must not be recorded by the customer.
§ 3 Instructions
- iqmeta processes the data only on documented instructions from the customer, including with regard to transfers to third countries, unless iqmeta is required to do so by law. In that case iqmeta informs the customer of the legal requirement before processing, unless the law prohibits this.
- Instructions result from this agreement, the terms and the customer's settings and actions in drinklist.app. Further instructions are given in text form to support@drinklist.app.
- If iqmeta considers that an instruction infringes data protection law, iqmeta informs the customer without undue delay and may suspend the instruction until it has been clarified.
§ 4 Obligations of the customer
The customer is responsible for the lawfulness of processing – in particular for informing its members, for a valid legal basis and for assigning roles and permissions to its users. If the customer discovers errors or irregularities in processing, it informs iqmeta without undue delay.
§ 5 Confidentiality
iqmeta only uses persons who are committed to confidentiality or are under a statutory obligation of secrecy. They access customer data only where necessary for operation, support or troubleshooting; such access is logged.
§ 6 Technical and organisational measures
iqmeta implements measures under Art. 32 GDPR that ensure a level of security appropriate to the risk and develops them further without lowering the level of protection. Currently these include in particular:
Confidentiality
- Operation on servers in Germany with physical and logical access control
- Encrypted connections (TLS) for website, app and interfaces
- Passwords, PINs and payment provider credentials encrypted with AES-256
- Role and permission model per organisation and list
- Strict separation of the data of different organisations
- Lockout after repeated failed sign-in attempts
Integrity
- Booking time is set exclusively by the server
- Cancellation instead of deletion, optionally with dual control
- Log of security-relevant actions with user, time and IP address
- Daily automatic consistency check of all balances
Availability and resilience
- Regular backups
- Monitoring of operations and background jobs
- Restoration from backups after an incident
Data minimisation
- No tracking or analytics tools
- Automatic deletion: export files after 90 days, email content after 12 months, security logs after 2 years
§ 7 Sub-processors
- The customer grants iqmeta general authorisation to engage sub-processors. iqmeta contractually binds them to the same data protection obligations as set out in this agreement.
- iqmeta informs the customer of intended changes at least 30 days in advance by email or in drinklist.app. The customer may object to the change for an important reason relating to data protection. If no agreement is reached, the customer may terminate the contract as of the date of the change.
- Sub-processors currently engaged:
iqmeta sends emails via its own mail server; no further service provider is involved.
Company Service Place of processing Hetzner Online GmbH
Industriestr. 25, 91710 Gunzenhausen, GermanyData centre and servers (hosting) Nuremberg, Germany - Services the customer selects and integrates under its own contract – such as Stripe, PayPal or SumUp for payments from its members – and sign-in services such as Google, Apple or Microsoft chosen by users themselves are not sub-processors. They act under their own responsibility.
§ 8 Assistance to the customer
- Data subject rights: drinklist.app provides the customer with its own functions for access, rectification, export (CSV, Excel, PDF) and deletion or anonymisation. If data subjects contact iqmeta directly, iqmeta forwards the request to the customer without undue delay.
- Data breaches: iqmeta informs the customer without undue delay after becoming aware of a personal data breach and provides the information the customer needs for a notification under Art. 33 and 34 GDPR.
- iqmeta also assists the customer with data protection impact assessments and prior consultations with the supervisory authority, insofar as the information is available to iqmeta.
§ 9 Deletion and return
- The customer can export its data at any time as CSV, Excel or PDF.
- After the end of the contract iqmeta deletes the customer's data unless there is a legal obligation to retain it. On request this happens earlier. Data disappears from backups when the backups are regularly overwritten.
- iqmeta retains its own invoices to the customer in accordance with commercial and tax retention periods.
- In addition, iqmeta deletes the data of an organisation that counts as an abandoned test environment under § 9 of the terms, after prior notice to the customer (owner and administrators, at least 30 days in advance, reminder 7 days before locking). The customer can object to the deletion at any time until final deletion by clicking the link in the notice or by using the service. Locked organisations can be restored for 30 days. The deletion is logged without personal data (identifier, reason, number of deleted records per table). Data subject to statutory retention (invoices, TSE data) is excluded; organisations with such data are not deleted.
§ 10 Evidence and audits
On request iqmeta provides the customer with the information necessary to demonstrate compliance with Art. 28 GDPR. The customer or an auditor appointed by the customer and bound to confidentiality may carry out audits after timely notice during normal business hours. Audits must not impair operations or the confidentiality of other customers' data.
§ 11 Place of processing
Processing takes place in Germany. Any relocation to a country outside the EU or the EEA requires the customer's prior consent and compliance with Art. 44 et seq. GDPR.
§ 12 Final provisions
Liability is governed by Art. 82 GDPR and otherwise by the liability provisions of the terms. In case of conflict this agreement takes precedence over the terms in matters of data protection. German law applies. Should any provision be invalid, the remaining provisions remain in effect.
Contact
iqmeta GmbHAm Sonnenhang 24
71111 Waldenbuch
Germany
Email: support@drinklist.app
How we process data under our own responsibility is explained in our privacy policy.