← Terminia Terms of Service

Privacy Policy

Last updated: April 17, 2026 · Version 1.1 beta

⚠️ Beta version: This Privacy Policy is provisional and will be finalized before public launch. Material changes will be communicated 30 days in advance.

English is the legally authoritative version.

Who this applies to

  • Visitors of terminia.net — basic site analytics and cookies (read this section).
  • Admins / trainers who register an organization on Terminia — full policy applies.
  • Members of clubs using Terminia — your club controls your data; contact them first. We process it on their behalf as a technical Processor (see GDPR Art. 28 in our Terms).

1. Who we are

Terminia is a SaaS platform for attendance and member management in sports clubs, schools, and fitness centers. We act as Controller for organization accounts (admins, trainers) and as Processor for the member data that organizations enter into the platform.

Data Controller identity: Terminia is operated from Serbia. A registered legal entity will be established before public launch. For all data protection matters and to exercise your GDPR rights, contact: privacy@terminia.net.

2. What we collect and why

From visitors: IP address, country (offline lookup), browser, pages visited, scroll depth — only after you accept cookies. Purpose: site analytics. Legal basis: consent (Art. 6.1.a).

From admins/trainers at registration: name, email, password (hashed), organization name and type, acceptance timestamp + IP. Purpose: account, authentication, billing, compliance proof. Legal basis: contract (Art. 6.1.b) and legal obligation (Art. 6.1.c).

From organizations on behalf of their members: name, contact, date of birth, parent contact (for minors), attendance, payments, optional photo, optional PIN/QR. Purpose: providing the service the club purchased. Legal basis: contract with the club; the club is responsible for its own legal basis toward members (typically legitimate interest or consent).

We do not sell personal data, use it for advertising, or make automated decisions that significantly affect you.

3. Who sees your data

We use the following sub-processors, each bound by a Data Processing Agreement:

  • Hetzner (EU, Finland) — hosting and database.
  • Resend (US) — transactional emails — under Standard Contractual Clauses (SCCs).
  • LemonSqueezy (US) — subscription billing as Merchant of Record — SCCs.
  • Anthropic (US) — AI Help chat only; no member PII transmitted — SCCs.
  • MaxMind — offline GeoIP database (no data leaves our server).

We do not share data with anyone else unless required by law or to protect our rights.

4. How long we keep it

Active account data: while the account is active. Deleted accounts: 30-day recovery window, then permanently deleted. Anonymized member records: aggregated statistics retained; PII permanently erased. Financial records: 5–7 years (tax law). Server, session, and email-delivery logs: 30–90 days. Aggregated analytics: 24 months.

5. Your rights

If you are in the EU/EEA (or covered by similar law) you may: access your data, correct it, request erasure, restrict or object to processing, receive it in a portable format (JSON), and withdraw consent at any time.

How to exercise:

  • Admins/trainers: email privacy@terminia.net — we respond within 30 days.
  • Members of a club: contact your club first. The Service includes built-in export and anonymization tools that the club can use immediately.

Right to complain: you may lodge a complaint with your local data protection authority — see the EDPB list of EU/EEA DPAs — or with the Finnish DPA (where data is hosted) or the Serbian DPA (where Terminia is operated).

6. Children

Terminia stores data about minors only when the organization (typically a school or sports club) enters it on their behalf. The organization must obtain parental consent before doing so. Where organizations use the in-app consent tool, we record timestamp, IP address, parent name and a signature. Minors do not create their own accounts.

7. Security and breach notification

We use HTTPS/TLS in transit, encryption at rest for sensitive identifiers using per-organization keys, password hashing, multi-tenant isolation, parameterized queries, a default-deny firewall, and intrusion detection. In the event of a personal data breach we will notify affected organizations within 72 hours of becoming aware, as required by GDPR Art. 33.

8. Changes and contact

Material changes to this policy will be announced 30 days in advance by email or in-app notice. During beta, minor clarifications may be made without notice; the "Last updated" date reflects the most recent change.

Contact: privacy@terminia.net · info@terminia.net