Last updated: August 28, 2026 · Version 1.2 beta
English is the legally authoritative version.
Terminia is a SaaS platform for attendance and member management in sports clubs, schools, and fitness centers. We act as Controller for organization accounts (admins, trainers) and as Processor for the member data that organizations enter into the platform.
Data Controller identity: Terminia is operated from Serbia. A registered legal entity will be established before public launch. For all data protection matters and to exercise your GDPR rights, contact: privacy@terminia.net.
From visitors: IP address, country (offline lookup), browser, pages visited, scroll depth — only after you accept cookies. Purpose: site analytics. Legal basis: consent (Art. 6.1.a).
From admins/trainers at registration: name, email, password (hashed), organization name and type, acceptance timestamp + IP. Purpose: account, authentication, plan administration, compliance proof. Legal basis: contract (Art. 6.1.b) and legal obligation (Art. 6.1.c).
From organizations on behalf of their members: name, contact, date of birth, parent contact (for minors), attendance, payments, optional photo, optional PIN/QR. Purpose: providing the service the club purchased. Legal basis: contract with the club; the club is responsible for its own legal basis toward members (typically legitimate interest or consent).
When an organization asks for a paid plan: the requested plan, the contact email and/or phone number entered in the request form, an optional message, and the number of active members at the moment of the request. Purpose: contacting you and enabling the plan manually. Legal basis: contract and steps taken at your request before entering into one (Art. 6.1.b).
Product news by email (optional, off by default): if an organization's admin enters an address in Settings → Messaging and ticks the consent box, we store that email address, the organization's language at the time of subscription, the date and time of the consent, the IP address from which it was given, and a token used for the unsubscribe link. Purpose: sending a message when a new version of Terminia is released. Legal basis: consent (Art. 6.1.a). No organization is ever subscribed automatically, and registering does not subscribe you. Every such message carries an unsubscribe link that works without logging in; the address can also be removed at any time in the same settings screen. These messages are sent through the same email provider (Resend) as our transactional email.
We do not sell personal data, use it for advertising, or make automated decisions that significantly affect you.
| Name | Stored as | Purpose | Lifetime | Type |
|---|---|---|---|---|
terminia_session | Cookie (HttpOnly) | Authentication session for logged-in users | 8 hours | Strictly necessary — no consent required |
lang | Cookie | Remembers the interface language you chose | 12 months | Strictly necessary — no consent required |
onb_skip | Cookie | Remembers which setup steps an admin chose to skip ("Skip for now") | 30 days | Strictly necessary — no consent required |
terminia_cookie_consent | localStorage | Your answer to the cookie banner (accepted / rejected) | Until you clear it | Strictly necessary — no consent required |
sidebar-settings, portal-tab | localStorage | Interface preferences: whether the sidebar section is open, which tab was last open in the member portal | Until you clear it | Strictly necessary — no consent required |
Analytics data is sent only while your stored answer to the banner is "accepted"; if you reject or do not answer, nothing is sent. We do not use third-party tracking cookies, Google Analytics, Facebook Pixel, or any similar third-party analytics service.
We use the following sub-processors, each bound by a Data Processing Agreement:
Email that you send to info@, privacy@ or legal@terminia.net reaches us through ImprovMX (email forwarding), which delivers it to a mailbox we operate with Microsoft (Outlook). Any personal data you put in such a message is therefore handled by those two providers as well.
We do not currently use a payment processor: the Service has no checkout and we do not collect or store card data (see Section 5 of the Terms). If that changes, this policy will list the provider before any payment data is collected.
We do not share data with anyone else unless required by law or to protect our rights.
Account data: for as long as the account exists. The Service has no self-service account deletion; when you ask us to delete an account (privacy@terminia.net) we do it manually and confirm once it is done. Anonymized member records: aggregated statistics retained; PII permanently erased. Financial records: 5–7 years (tax law). Server, session, and email-delivery logs: 30–90 days.
Site analytics records: 24 months, then deleted automatically by a scheduled job. These records are not aggregated while they are stored — each page view is kept as a separate row containing the visitor's IP address in full, country, browser, page, referrer, scroll depth and time on page.
Product news subscription: until the address is unsubscribed or the organization is deleted. After an unsubscribe, the record (address, time and IP of the consent, time of withdrawal) is kept as evidence that consent was given and later withdrawn, and no further messages are sent to it.
If you are in the EU/EEA (or covered by similar law) you may: access your data, correct it, request erasure, restrict or object to processing, receive it in a portable format (JSON), and withdraw consent at any time.
How to exercise:
Right to complain: you may lodge a complaint with your local data protection authority — see the EDPB list of EU/EEA DPAs — or with the Finnish DPA (where data is hosted) or the Serbian DPA (where Terminia is operated).
Terminia stores data about minors only when the organization (typically a school or sports club) enters it on their behalf. The organization must obtain parental consent before doing so. Where organizations use the in-app consent tool, we record timestamp, IP address, parent name and a signature. Minors do not create their own accounts.
We use HTTPS/TLS in transit, encryption at rest for sensitive identifiers using per-organization keys, password hashing, multi-tenant isolation, parameterized queries, a default-deny firewall, and intrusion detection. In the event of a personal data breach we will notify affected organizations within 72 hours of becoming aware, as required by GDPR Art. 33.
Material changes to this policy will be announced 30 days in advance by email or in-app notice. During beta, minor clarifications may be made without notice; the "Last updated" date reflects the most recent change.
Contact: privacy@terminia.net · info@terminia.net