Legal
Privacy notice
Technopolis GmbH · Last updated: 13.09.2026
Privacy at a glance
- Location: Production hosting and operations in Germany (Hetzner).
- Purpose limitation: We process data for digital vehicle registration and the associated legal obligations, not for unnecessary profiling or advertising.
- Identity & signature: Qualified electronic signatures (QES) through Yousign under eIDAS.
- Authority transmission: Data is sent to the Federal Motor Transport Authority (KBA) through the large-customer interface (GKS) where required for your order.
- Your rights: Access, rectification, erasure and other GDPR data subject rights. Contact: datenschutz@zulago.de
The following sections provide the information required under Articles 12-14 GDPR. The German version is authoritative.
1. Controller
Technopolis GmbH
Trading under the brand Zulago.de
Nobelstr. 3-5
41189 Mönchengladbach
Germany
Represented by: Karim Hajou (Managing Director)
Email: info@zulago.de
Privacy: datenschutz@zulago.de
Website: https://zulago.de
2. Privacy contact
No company data protection officer has currently been appointed. For all privacy enquiries, contact datenschutz@zulago.de.
3. Principles of processing
We process personal data only to the extent necessary to operate the website, perform contracts, particularly vehicle registration orders, comply with legal obligations or pursue narrowly defined legitimate interests.
Legal bases under Article 6(1) GDPR:
- point (b) - contract or pre-contractual measures (registration order, payment, signature and status communication)
- point (c) - legal obligation (including FZV requirements, commercial and tax retention duties and GKS requirements)
- point (f) - legitimate interests (IT security, prevention of misuse and fraud, and technical logs)
- point (a) - consent where requested separately, for example for optional processing
Retention periods (summary): Registration-related documents are generally kept for at least two years in the FZV/SDÜ context; invoices and accounting records for up to eight or ten years under AO/HGB; and technical logs usually for a few months unless security or evidentiary requirements justify longer retention. Data is then deleted or anonymised unless statutory reasons prevent this.
4. Website and technical data
When the website is accessed, technically necessary connection data is processed, such as the IP address, timestamp, requested resource and user agent, to deliver the website and ensure security under Article 6(1)(f) GDPR. IP addresses are retained only as long as necessary for operations and security.
Cookies: We use technically necessary cookies or similar storage technologies for sessions, authentication and security. Optional Google Ads conversion measurement is activated only after your express consent. Without consent, the Google tag is not loaded and no data is transmitted to Google.
Technical analysis of the application flow
To identify technical errors and points where online applications are abandoned, we store a random session identifier together with high-level progress events, such as “application opened”, “step viewed” or “payment confirmed”. The identifier is retained in your browser’s local storage for no more than 24 hours. Form data, names, email addresses, VINs, IBANs, IP addresses and user agents are not included in these progress events.
If the session results in an order, the pseudonymous session identifier may be linked internally to that order so that a payment confirmed server-side can be attributed to the relevant application flow. The identifier is not sent to the KBA or to Google as part of this internal measurement. The legal basis is our legitimate interest in a reliable and user-friendly application process under Article 6(1)(f) GDPR.
Application drafts and reminders
Once you provide an email address in the online application, we may store your previous entries as an encrypted application draft so that you can continue using a personal, secret link. Uploaded documents are not included in the draft. If you do not continue, we send transactional reminders after approximately four and 48 hours and archive the draft after seven days. For an order that has already been created but remains unpaid, reminders are scheduled after approximately one and 48 hours, followed by archiving after seven days. Open reminders stop once the application is completed, cancelled or archived, or once payment is confirmed.
Optional Google Ads conversion measurement
With your consent, we use Google Ads Conversion Tracking provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. This enables us to measure whether a click on a Google ad resulted in a paid order. In particular, technical browser and device data, any available Google click identifier, transaction ID, payment amount and currency may be processed. We do not send names, email addresses, VINs or application documents to Google for this measurement.
The legal bases are your consent under Article 6(1)(a) GDPR and section 25(1) TDDDG. We use Basic Consent Mode v2, which means that no Google script is loaded before consent. Google Analytics, remarketing, personalised advertising and enhanced conversions are not enabled, and the consent signal for personalised advertising remains denied. Google may also process data in third countries. Details about transfers and safeguards are available in Google’s Privacy Policy.
Your selection is stored in your browser’s local storage for 180 days. You can change it at any time using the permanently available “Privacy settings” control and withdraw consent with effect for the future. On withdrawal, we remove accessible Google Ads cookies for our domain and do not load the Google tag again.
If you contact us by email or through a form, we process the information you provide to handle the enquiry under Article 6(1)(b) or (f) GDPR.
5. Vehicle registration (core service)
When you place a registration order, we process the data required for the relevant transaction, in particular:
- Holder and contact data such as name, address, date of birth, email and phone
- Vehicle data including VIN, HSN/TSN, registration number, eVB and registration certificate information
- Payment and invoice data including payment status; IBAN only where required for SEPA or vehicle tax direct debit; access is restricted to required server-side processes
- Power of attorney and QES data including signature process, status and signed documents
- Documents uploaded by you or created during the process, such as ID, registration certificates and CoC, in each case only for the relevant purpose
Purposes: Performing the registration order, transmitting data to the KBA through GKS, communicating with you, payment and invoicing, support, and compliance with statutory and supervisory obligations.
Recipients where required:
- Federal Motor Transport Authority (KBA) and the competent registration authority through the GKS/SABRINA channel
- Yousign for identity verification and qualified electronic signatures in Germany
- Stripe for payment processing (PCI DSS; third-country transfers only with appropriate safeguards, in particular Standard Contractual Clauses)
- Resend for transactional email, with appropriate safeguards where a third-country transfer is involved
- License plate and shipping partners for stamping and dispatch where you order license plates
We do not disclose personal data to third parties for advertising purposes.
6. Hosting and infrastructure
The production application, database, authentication and file storage run on servers operated by Hetzner Online GmbH in Germany. The Supabase components in use (PostgreSQL, Auth and Storage) are operated by us as an open-source stack on this infrastructure and not as a Supabase Cloud tenant in a third country.
Backups are encrypted and retained on controlled infrastructure. Legal basis: Article 6(1)(b), (c) and (f) GDPR.
7. Processors and third countries
Where service providers process data on our behalf, this is based on data processing agreements under Article 28 GDPR where required. For transfers to countries outside the EEA, we use appropriate safeguards, in particular EU Standard Contractual Clauses under Article 46 GDPR, and limit access to what is necessary.
8. Security
We implement appropriate technical and organisational measures, including TLS transport, access restrictions, role-based permissions, logging of security-relevant events, additional access protection for sensitive fields such as IBAN, and separate production and test environments.
9. Your rights under Articles 15-21 and 77 GDPR
Within the statutory framework, you have the right to:
- access personal data stored about you
- rectification of inaccurate data
- erasure where no statutory retention obligation applies
- restriction of processing
- data portability
- object to processing based on legitimate interests
- withdraw consent with effect for the future
- lodge a complaint with a supervisory authority, in particular the competent data protection authority in North Rhine-Westphalia
To exercise your rights, send an informal request to datenschutz@zulago.de.
10. No automated decision-making
We do not use solely automated decision-making within the meaning of Article 22 GDPR that produces legal effects concerning you or similarly significantly affects you. Registration decisions are made by the competent authorities under the statutory process.
11. Changes to this notice
We update this privacy notice when the law, our services or the processing activities in use change. The version published on this page with the stated date applies.
12. Contact
Technopolis GmbH
Nobelstr. 3-5, 41189 Mönchengladbach
Privacy: datenschutz@zulago.de
General: info@zulago.de
Further provider information: Imprint
Last updated: 4 August 2026
For privacy questions, contact datenschutz@zulago.de.
