Terms of Service
1. Who we are and acceptance. These Terms of Service ("Terms") govern the use of Zipfixy (the "Service"), provided by Marc Romans Roca, self-employed, trading as Zipfixy, Antoni Kyriakou 7, Ypsonas, 4187 Limassol, Cyprus ("Zipfixy", "we", "us"). You accept these Terms, the Data Processing Agreement ("DPA") and the Privacy Policy, which form part of them, by ticking the acceptance box when creating an account. We keep a record of the date, time and version you accepted. The person accepting confirms that they are authorised to bind the business they register ("you").
2. Business customers only. The Service is offered only to businesses and self-employed professionals for use in their trade or profession. By accepting these Terms you confirm that you are not acting as a consumer. Consumer-protection rules, including any right of withdrawal, therefore do not apply.
3. The Service. An online platform to manage appointments, clients, sales, marketing and a website for your business at a Zipfixy sub-domain or on your own domain. The features of each plan are described on our pricing page. We may improve, change or remove features. We will not materially reduce the core functions of your plan during a period you have already paid for. Custom work agreed with you in a written proposal (for example a website built by us, or set-up help) is governed by that proposal and, for everything it does not cover, by these Terms.
4. Your account. You must provide accurate information and keep it up to date. Each account corresponds to one business. You are responsible for all activity under your account, for the people you invite and the permissions you give them, and for keeping access to your email address secure. Tell us at once at hello@zipfixy.com if you suspect unauthorised access. We may refuse, suspend or close accounts opened with false information or to obtain repeated free trials.
5. Free trial. A new business gets a free trial of 14 days with all features, add-ons included. No payment card is required. We may review new sign-ups before activating them; in that case the trial starts on the day the account is activated. If you do not choose a plan by the end of the trial, you get 3 further days of grace. After that, new online bookings, online shop orders and online pass sales are paused until you choose a plan. Your panel, your existing appointments and your data remain available. Trial accounts that stay without a plan for 90 days may be closed after notice by email, following section 9.
6. Plans, fees and payment.
- Prices are shown on the pricing page, per business, per month or per year (the yearly price equals 11 months). No VAT is charged, because we are not registered for VAT. If we become VAT-registered, VAT will be added to the prices at the applicable rate from your next renewal, and we will tell you by email at least 30 days before.
- Subscriptions renew automatically for the same period until cancelled. You authorise us, through our payment provider, to charge the payment method on file at each renewal. Invoices are sent by email and are available in your panel.
- If a payment fails, we will notify you and retry. If it is not settled within 7 days, new online bookings are paused as in section 5 until payment is made. If it remains unpaid after 30 days, we may terminate under section 7.
- You may change plan at any time from your panel. Moving to a higher plan applies immediately and the difference for the rest of the period is charged pro rata. Moving to a lower plan applies from the next renewal. Changing plan never deletes data; modules not included in the new plan are locked.
- We may change prices by giving at least 30 days' notice by email. New prices apply from your next renewal after that notice. If you do not accept them, you may cancel before they apply.
- Fees are non-refundable, and there is no refund for unused parts of a period, except (a) where required by law, or (b) where you cancel a yearly plan because of a price increase or a change to these Terms that is to your detriment, in which case we refund the unused whole months.
7. Cancellation, suspension and termination.
- You may cancel at any time from your panel. The Service continues until the end of the period already paid and is not renewed.
- We may terminate the Service for convenience by giving 30 days' notice by email, refunding any fees paid for the period after termination.
- We may suspend or terminate the Service immediately, by notice by email, if you seriously or repeatedly breach these Terms or the DPA, use the Service unlawfully, put the security of the Service or of other users at risk, or fail to pay as described in section 6. Where the breach can be remedied, we will first ask you to remedy it within 7 days.
- Sections 8 to 10 and 13 to 21 survive termination.
8. Your responsibilities and acceptable use. You must use the Service lawfully. In particular you must:
- have a valid legal basis for all personal data of your clients and staff that you enter or import, and give them the information that data-protection law requires (the Service includes a model notice for your booking page);
- when you import data from another system, only import data you are entitled to use and transfer;
- send marketing messages only to clients who have given the necessary consent, which the Service records;
- not store health data or any other special category of personal data (such as medical conditions, allergies, medication, pregnancy, religion or sexual orientation) anywhere in the Service, including in notes and consultation forms, which are meant only for preferences, service details and consent to the service;
- publish photos of people only with their consent, or a parent's or guardian's consent for a minor, keep proof of that consent and show it to us on request;
- hold the rights to all content you publish (texts, logos, photos, prices) and make sure it is accurate and lawful;
- not send spam, not upload malicious code, not try to access other businesses' data, and not overload or interfere with the Service.
9. Your data. You own your data and your clients' data. We process it only to provide the Service, as set out in the DPA. You can export it from your panel at any time and free of charge. After cancellation or termination your data remains available for export for 90 days; after that it is deleted as described in the DPA. You grant us a non-exclusive, worldwide, royalty-free licence to host, reproduce and display the content you publish, only for the purpose of providing the Service to you, for as long as you use it.
10. Our rights. The software, templates, designs, texts and brand of Zipfixy belong to us or our licensors. You receive a non-exclusive, non-transferable right to use the Service while your subscription is active. You must not copy, resell, sublicense or reverse-engineer it. If you send us suggestions, we may use them freely.
11. Third-party services. Payments from your clients are processed by the payment provider you connect (for example Revolut Business or Stripe), under that provider's terms and fees. Zipfixy takes no commission and never holds those funds. Google (reviews, maps), email providers and other third-party services are governed by their own terms, and we are not responsible for them.
12. Availability and support. We use reasonable efforts to keep the Service available and secure: we monitor it continuously, keep daily backups and publish its status at status.zipfixy.com. We announce planned maintenance in advance where possible. We do not guarantee that the Service will be uninterrupted or error-free, and we do not offer a service-level agreement. Support is provided by email and through the help centre; the Pro plan receives priority support within one working day.
13. Disclaimer. Except as expressly stated in these Terms, the Service is provided "as is" and "as available", and all implied warranties are excluded to the extent permitted by law. We do not guarantee any business result, such as a number of bookings or revenue.
14. Limitation of liability.
- Nothing in these Terms limits liability for death or personal injury caused by negligence, for fraud, for gross negligence or wilful misconduct, or any other liability that cannot be limited by law.
- Subject to that, neither party is liable for indirect or consequential loss, loss of profit, revenue, business or goodwill.
- We are not liable for loss or corruption of data to the extent you could have avoided it by using the export tools, or where it results from your instructions, your staff or your devices.
- Subject to the above, our total liability arising out of or in connection with the Service and the DPA in any 12-month period is limited to the fees you paid us in the 12 months before the event giving rise to the claim. During the free trial it is limited to EUR 100.
15. Indemnity. You will compensate us for any claim, fine or cost brought by a third party (including your clients, your staff or a data-protection authority) that results from your breach of these Terms, of the DPA or of data-protection law, or from content you publish. The limitation in section 14 does not apply to this indemnity.
16. Data protection. Each party complies with the EU General Data Protection Regulation (GDPR). For the data of your clients and staff you are the controller and Zipfixy is your processor under the DPA. For the data of your account, Zipfixy is the controller as described in the Privacy Policy.
17. Force majeure. Neither party is liable for delay or failure caused by events beyond its reasonable control, including failures of hosting or telecom providers, power outages, cyber-attacks not caused by that party's negligence, natural disasters or acts of authorities.
18. Changes to these Terms. We may update these Terms. We will notify material changes by email at least 30 days before they apply. If you do not agree, you may cancel before they apply, with the refund in section 6(b) where relevant. Continuing to use the Service after that date means you accept the new Terms.
19. Notices. We send notices to the email address of your account. You send notices to hello@zipfixy.com.
20. General. You may not transfer your account without our written consent. We may transfer these Terms to a company that takes over the Service, by notice to you. If a provision is invalid, the rest remains in force. These Terms, the DPA and the Privacy Policy are the entire agreement between us about the Service. If they are translated, the English version prevails.
21. Governing law and disputes. These Terms are governed by the laws of the Republic of Cyprus. Before starting court proceedings, the parties will try in good faith to settle any dispute within 30 days of a written notice describing it. The courts of Limassol, Cyprus, have exclusive jurisdiction. This does not prevent either party from seeking urgent interim measures.
Data Processing Agreement
Part of the Terms of Service and accepted with them.
1. Parties and scope. This Data Processing Agreement ("DPA") is between the business that accepts the Terms of Service ("Controller") and Marc Romans Roca, trading as Zipfixy, Antoni Kyriakou 7, Ypsonas, 4187 Limassol, Cyprus ("Processor"). It applies to personal data that the Processor processes on the Controller's behalf when providing the Service, and meets the requirements of Article 28 of the GDPR. If this DPA and the Terms conflict on data protection, this DPA prevails.
2. Subject matter, duration, nature and purpose. Hosting and processing of booking, client, staff and sales data so the Controller can take bookings online, manage its calendar, clients and sales, publish its website, send transactional messages (confirmations, reminders, receipts) and, where the client has consented, marketing messages. The processing lasts while the Controller uses the Service and until the data is deleted under section 10.
3. Data subjects. The Controller's clients (people who book, buy or are registered by the Controller) and the Controller's staff who appear in the Service.
4. Categories of personal data.
- Identification and contact: name, email, phone, preferred language.
- Appointments, services, purchases, payment status, passes, memberships, loyalty points and no-show history.
- Notes written by the Controller or the client; marketing consent and unsubscribe status; optional date of birth; satisfaction-survey answers.
- Data imported by the Controller from its previous system.
No special categories. Consultation and consent forms hold only preferences, service details, the client's signature and, with consent, photos of the work done. The Service is not designed for health data or any other special category of personal data (Article 9 GDPR), and the Controller must not enter such data anywhere in it, including notes and forms. If it does, it is solely responsible under section 7.
5. Controller's instructions. The Processor processes personal data only on the Controller's documented instructions. These Terms, this DPA and the Controller's use and configuration of the Service are the Controller's complete instructions. The Processor will inform the Controller if, in its opinion, an instruction infringes the GDPR, and may then refuse to follow it. The Processor may process data otherwise only where EU or Cyprus law requires it, informing the Controller unless the law forbids it.
6. Processor obligations. The Processor shall:
- ensure that anyone authorised to process the data is bound by confidentiality;
- implement the security measures in Annex A and keep them up to date;
- help the Controller, through the Service's tools (search, correction, export, erasure) and otherwise where reasonable, to answer requests from data subjects, and forward any request it receives directly;
- help the Controller with security, breach notification, data-protection impact assessments and prior consultation, taking into account the nature of the processing and the information available to the Processor;
- not sell personal data, and not use it for its own purposes except to operate, secure and improve the Service using aggregated or anonymised information.
7. Controller obligations. The Controller warrants that it has a lawful basis for all data it enters or imports; that it informs its clients as required by law (the Service provides a model notice for the booking page); that marketing is sent only to clients who have consented; that it does not enter special-category data, as stated in section 4; and that its instructions comply with the GDPR.
8. Sub-processors. The Controller gives general authorisation for the Processor to use the sub-processors below. The Processor imposes on each of them data-protection obligations equivalent to this DPA and remains responsible for them. The Processor will give at least 30 days' notice by email of any addition or replacement. The Controller may object on reasonable data-protection grounds within that period. If the parties cannot resolve the objection, the Controller may terminate the Service and receive a refund of fees paid for the period after termination.
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase Inc. | Database, authentication, file storage | EU (Ireland) |
| Vercel Inc. | Application hosting and delivery | EU (Dublin) for processing; global delivery network |
| Resend Inc. | Transactional and marketing email | United States (EU–US Data Privacy Framework and Standard Contractual Clauses) |
| Functional Software Inc. (Sentry) | Error monitoring, with personal data minimised | EU |
| Cloudflare Inc. | Bot protection on public forms | Global network |
| Stripe or Revolut | Online payments, only when the Controller connects its own account | As set by each provider |
9. International transfers. The Processor's database and application run in the European Economic Area. Where a sub-processor stores data outside the EEA (the email provider, in the United States) or it or its parent company may access data from outside the EEA, the transfer relies on an adequacy decision (including the EU–US Data Privacy Framework for certified companies) or on the European Commission's Standard Contractual Clauses concluded with that sub-processor, together with any supplementary measures needed.
10. Return and deletion. The Controller can export its data at any time. After the Service ends, the data remains available for export for 90 days and is then deleted from the live systems. Copies in backups are overwritten in the normal backup cycle, within 30 days after that. Data is kept longer only where EU or Cyprus law requires it. On request, the Processor confirms the deletion in writing.
11. Personal data breaches. The Processor will notify the Controller without undue delay, and in any case within 72 hours, after becoming aware of a breach affecting the Controller's data. The notice will include the information then available (nature of the breach, categories and approximate number of people and records concerned, likely consequences, measures taken or proposed), completed as more information becomes available, so that the Controller can meet its obligations under Articles 33 and 34 of the GDPR.
12. Demonstrating compliance and audits. The Processor makes available the information needed to show compliance with this DPA, primarily in writing (description of the security measures, answers to reasonable questionnaires). If this is not enough, or a supervisory authority requires it, the Controller may carry out an audit, itself or through an independent auditor bound by confidentiality, no more than once a year, with at least 30 days' notice, during business hours, without disrupting the Service or accessing other customers' data, and at the Controller's own cost.
13. Supervisory authority, liability and law. The competent authority for the Processor is the Office of the Commissioner for Personal Data Protection of Cyprus. Liability under this DPA is subject to the limitation in section 14 of the Terms, except where the GDPR provides otherwise. This DPA is governed by the laws of the Republic of Cyprus, including for the Standard Contractual Clauses where the clauses allow the choice.
Annex A — Security measures
- Isolation of each business's data at database level (row-level security) and role-based permissions for staff.
- Encryption in transit (HTTPS/TLS) and encryption at rest by the hosting providers.
- Sign-in by one-time email code or link or Google account; no stored passwords for business owners; two-factor authentication for Zipfixy's internal administration.
- Rate limiting and bot protection on public forms and sign-in.
- Daily database backups kept for at least 7 days.
- Continuous uptime and error monitoring, with alerts.
- Tools in the panel to export, correct and erase data.
- Administrative access to production data limited to the Processor personally, used only for support, security or legal reasons.
Version 1.0, in force since 2026-09-26. Questions: hello@zipfixy.com. See also: Privacy policy · Cookie policy.