Privacy Policy
Version 2026-04-14
Privacy notice for Zemio users and customer representatives.
Privacy Policy
1. Scope
This Privacy Policy explains how personal data is processed in connection with the Zemio service.
Zemio is a restricted-access software service for student initiatives, primarily in Germany, that supports the creation, review, and administration of expense reports and related organizational workflows.
This notice applies to:
- users of the Zemio application;
- representatives and contacts of customer organizations;
- invited users;
- recipients of operational emails sent by Zemio.
2. Provider and Controller Information
Provider:
Christoph Langer, trading as Zemio
Averkampstrasse 9-11
48151 Muenster
Germany
Email: christoph.langer@move-ev.de
Unless stated otherwise in this Privacy Policy, the controller for the processing described here is Christoph Langer, trading as Zemio.
No data protection officer has been appointed at this time.
3. Role Allocation
Zemio is provided to selected student initiatives and similar organizations on a restricted-access basis.
For personal data contained in customer-managed expense reports and related records, the relevant customer organization is generally the controller and Zemio acts as processor on the customer's behalf.
For certain processing activities, Zemio acts as an independent controller. This includes, in particular:
- account provisioning and access management at platform level;
- operation, security, and abuse prevention;
- billing and customer communication;
- service administration;
- operational logs and error monitoring;
- legal compliance and enforcement of contractual rights.
Where Zemio acts as processor for a customer organization, data subject requests concerning report content, expense data, attachments, and similar customer-controlled data may need to be handled by or coordinated with the relevant customer organization.
4. Categories of Personal Data
Depending on how Zemio is used, the following categories of personal data may be processed:
- account data, such as name, email address, profile image, Microsoft tenant identifier, organization memberships, and user role;
- authentication and session data, such as session tokens, session timestamps, IP address, user agent, and active organization context;
- invitation data, such as invitee email address, inviter identity, role, status, and expiry;
- report data, such as report titles, descriptions, status history, cost unit assignment, and internal identifiers;
- expense data, such as descriptions, amounts, dates, travel or receipt metadata, and structured form data;
- attachment data, such as uploaded receipt images, invoices, PDFs, filenames, size, and storage keys;
- banking data, such as IBAN and account holder name, which Zemio stores in encrypted form;
- notification and communication data, such as operational email delivery records and notification preferences;
- customer relationship data, such as organization name, customer representative details, billing contact data, and support correspondence;
- technical and security data, such as logs, error events, and diagnostic metadata required to operate and secure the service.
5. Purposes and Legal Bases
Zemio processes personal data for the following purposes and on the following legal bases under the GDPR:
5.1 Service Provision
Purposes:
- providing access to the application;
- authenticating users;
- assigning users to organizations;
- enabling creation, storage, review, export, and deletion of expense reports and related attachments;
- providing operational emails and in-app notifications.
Legal basis:
- Article 6(1)(b) GDPR where processing is necessary for the performance of a contract with the customer organization or to take steps at the request of the customer prior to entering into a contract;
- Article 6(1)(f) GDPR for related operational processing where Zemio has a legitimate interest in providing a secure and functional service.
5.2 Security and Abuse Prevention
Purposes:
- protecting the service against misuse, unauthorized access, fraud, and technical failures;
- logging authentication and session events;
- detecting, investigating, and remediating incidents.
Legal basis:
- Article 6(1)(f) GDPR based on Zemio's legitimate interest in securing the service, protecting customer data, and maintaining system integrity.
5.3 Billing, Contract Administration, and Customer Communication
Purposes:
- preparing offers and order arrangements;
- invoicing and payment follow-up;
- communicating with customer representatives and administrators;
- handling support requests and contract changes.
Legal basis:
- Article 6(1)(b) GDPR;
- Article 6(1)(c) GDPR where statutory accounting or tax obligations apply;
- Article 6(1)(f) GDPR for ordinary business administration.
5.4 Legal Compliance
Purposes:
- complying with legal obligations;
- documenting acceptance of contractual and legal documents;
- establishing, exercising, or defending legal claims.
Legal basis:
- Article 6(1)(c) GDPR;
- Article 6(1)(f) GDPR.
5.5 Error Monitoring and Reliability
Purposes:
- detecting crashes, application errors, and system malfunctions;
- improving stability and reliability;
- investigating service incidents.
Legal basis:
- Article 6(1)(f) GDPR based on Zemio's legitimate interest in operating a reliable and secure service.
Zemio does not currently use the service for marketing emails or behavioral advertising.
6. Authentication
Zemio currently uses Microsoft login for authentication.
Users may authenticate with Microsoft accounts from any Microsoft tenant. However, access to organization data is only granted if a user has been assigned to an organization in Zemio. Users without an assigned organization may authenticate successfully but will not receive access to customer data.
7. Cookies and Similar Technologies
Zemio uses only technically necessary cookies and similar mechanisms required for core service functionality, such as:
- authentication and session management;
- security-related state handling;
- user interface preferences that are necessary for the requested service.
Zemio does not currently use analytics cookies, advertising cookies, or comparable non-essential tracking technologies.
If non-essential tracking or analytics are introduced in the future, Zemio will update its legal documentation accordingly and obtain any consent required by applicable law before enabling such technologies.
8. Recipients and Processors
Personal data may be disclosed to the following categories of recipients where necessary:
- customer organizations and their authorized users;
- hosting and infrastructure providers;
- managed database providers;
- object storage providers;
- email delivery providers;
- authentication and identity providers;
- monitoring and logging providers;
- professional advisers where necessary;
- public authorities or courts where disclosure is legally required.
At the time of this version, Zemio expects to use the following main service providers:
- Vercel for application hosting;
- Neon for managed PostgreSQL database services;
- Hetzner for object storage;
- Resend for operational email delivery;
- Microsoft for identity authentication;
- Better Stack for error monitoring and operational observability.
An up-to-date subprocessor list is maintained separately by Zemio for customer contracting purposes.
9. International Data Transfers
Zemio aims to configure its service providers in a manner consistent with European data protection requirements.
Some service providers may process data outside the European Economic Area or may permit access from third countries. Where this occurs, Zemio will rely on an appropriate transfer mechanism under Chapter V GDPR, such as an adequacy decision or the European Commission's Standard Contractual Clauses, together with any supplementary measures considered appropriate.
Customers may request additional information on the applicable transfer safeguards through the contact details above.
10. Retention Periods
Unless a longer retention period is required by law or a shorter period is required by contract, Zemio currently applies the following target retention periods:
- account data: while the account exists, followed by a target 30-day deletion window unless legal or security reasons require longer retention;
- session and authentication logs: 90 days;
- invitations: 180 days after expiry;
- reports and report attachments: during the contract term and, as a default, up to 12 months after termination unless earlier deletion is requested by the customer and no legal retention obligation or legal hold applies;
- banking details: while required for active report workflows and, as a default, until account deletion or earlier deletion request unless the data remains necessary for retained reports or legal obligations;
- backups: up to 30 days;
- operational monitoring logs: up to 30 days;
- billing and accounting records: for the period required by applicable commercial or tax law.
Actual retention may vary where necessary to comply with legal obligations, resolve disputes, investigate incidents, or enforce contractual rights.
11. Data Subject Rights
Subject to the applicable legal requirements, data subjects have the right to:
- request access to their personal data;
- request rectification of inaccurate data;
- request erasure of personal data;
- request restriction of processing;
- object to processing based on Article 6(1)(f) GDPR;
- receive data portability where applicable;
- lodge a complaint with a competent supervisory authority.
Where Zemio processes data as processor on behalf of a customer organization, Zemio may forward or coordinate the request with the relevant customer organization.
12. Source of Data
Personal data is generally collected:
- directly from users;
- from customer administrators and inviters;
- from customer representatives during onboarding or contract administration;
- from Microsoft during authentication;
- automatically from user interaction with the service where technically necessary for operation and security.
13. Obligation to Provide Data
Certain data is required in order to use the service or administer a customer account. If such data is not provided, Zemio may be unable to provide access to the service or the relevant functionality.
14. Automated Decision-Making
Zemio does not currently carry out automated decision-making or profiling within the meaning of Article 22 GDPR that produces legal effects concerning users.
15. Security Measures
Zemio implements technical and organizational measures designed to protect personal data against unauthorized access, loss, destruction, or alteration. These measures include, among other things:
- access controls based on account and organization roles;
- encryption of banking data at rest within the application layer;
- restricted file access through authenticated access controls and time-limited download URLs;
- role-based administration within customer organizations;
- environment-based secrets management;
- logging and monitoring for incident detection.
No method of transmission or storage is completely secure. Zemio therefore cannot guarantee absolute security.
16. Changes to This Privacy Policy
Zemio may update this Privacy Policy from time to time, especially where legal requirements, service providers, or product features change.
Material updates may be presented through the service and may require renewed acceptance where Zemio considers this appropriate.
17. Contact
Questions relating to privacy or data protection may be sent to: