← Terminia Terms of Service

Privacy Policy

Last updated: August 28, 2026 · Version 1.2 beta

⚠️ Beta version: This Privacy Policy is provisional and will be finalized before public launch. Material changes will be communicated 30 days in advance.

English is the legally authoritative version.

Who this applies to

  • Visitors of terminia.net — basic site analytics and cookies (read this section).
  • Admins / trainers who register an organization on Terminia — full policy applies.
  • Members of clubs using Terminia — your club controls your data; contact them first. We process it on their behalf as a technical Processor (see GDPR Art. 28 in our Terms).

1. Who we are

Terminia is a SaaS platform for attendance and member management in sports clubs, schools, and fitness centers. We act as Controller for organization accounts (admins, trainers) and as Processor for the member data that organizations enter into the platform.

Data Controller identity: Terminia is operated from Serbia. A registered legal entity will be established before public launch. For all data protection matters and to exercise your GDPR rights, contact: privacy@terminia.net.

2. What we collect and why

From visitors: IP address, country (offline lookup), browser, pages visited, scroll depth — only after you accept cookies. Purpose: site analytics. Legal basis: consent (Art. 6.1.a).

From admins/trainers at registration: name, email, password (hashed), organization name and type, acceptance timestamp + IP. Purpose: account, authentication, plan administration, compliance proof. Legal basis: contract (Art. 6.1.b) and legal obligation (Art. 6.1.c).

From organizations on behalf of their members: name, contact, date of birth, parent contact (for minors), attendance, payments, optional photo, optional PIN/QR. Purpose: providing the service the club purchased. Legal basis: contract with the club; the club is responsible for its own legal basis toward members (typically legitimate interest or consent).

When an organization asks for a paid plan: the requested plan, the contact email and/or phone number entered in the request form, an optional message, and the number of active members at the moment of the request. Purpose: contacting you and enabling the plan manually. Legal basis: contract and steps taken at your request before entering into one (Art. 6.1.b).

Product news by email (optional, off by default): if an organization's admin enters an address in Settings → Messaging and ticks the consent box, we store that email address, the organization's language at the time of subscription, the date and time of the consent, the IP address from which it was given, and a token used for the unsubscribe link. Purpose: sending a message when a new version of Terminia is released. Legal basis: consent (Art. 6.1.a). No organization is ever subscribed automatically, and registering does not subscribe you. Every such message carries an unsubscribe link that works without logging in; the address can also be removed at any time in the same settings screen. These messages are sent through the same email provider (Resend) as our transactional email.

We do not sell personal data, use it for advertising, or make automated decisions that significantly affect you.

2.1 Cookies and local storage

NameStored asPurposeLifetimeType
terminia_sessionCookie (HttpOnly)Authentication session for logged-in users8 hoursStrictly necessary — no consent required
langCookieRemembers the interface language you chose12 monthsStrictly necessary — no consent required
onb_skipCookieRemembers which setup steps an admin chose to skip ("Skip for now")30 daysStrictly necessary — no consent required
terminia_cookie_consentlocalStorageYour answer to the cookie banner (accepted / rejected)Until you clear itStrictly necessary — no consent required
sidebar-settings, portal-tablocalStorageInterface preferences: whether the sidebar section is open, which tab was last open in the member portalUntil you clear itStrictly necessary — no consent required

Analytics data is sent only while your stored answer to the banner is "accepted"; if you reject or do not answer, nothing is sent. We do not use third-party tracking cookies, Google Analytics, Facebook Pixel, or any similar third-party analytics service.

3. Who sees your data

We use the following sub-processors, each bound by a Data Processing Agreement:

  • Hetzner (EU, Finland) — hosting and database.
  • Resend (US) — transactional emails — under Standard Contractual Clauses (SCCs).
  • Anthropic (US) — AI Help chat only; no member PII transmitted — SCCs.
  • MaxMind — offline GeoIP database (no data leaves our server).

Email that you send to info@, privacy@ or legal@terminia.net reaches us through ImprovMX (email forwarding), which delivers it to a mailbox we operate with Microsoft (Outlook). Any personal data you put in such a message is therefore handled by those two providers as well.

We do not currently use a payment processor: the Service has no checkout and we do not collect or store card data (see Section 5 of the Terms). If that changes, this policy will list the provider before any payment data is collected.

We do not share data with anyone else unless required by law or to protect our rights.

4. How long we keep it

Account data: for as long as the account exists. The Service has no self-service account deletion; when you ask us to delete an account (privacy@terminia.net) we do it manually and confirm once it is done. Anonymized member records: aggregated statistics retained; PII permanently erased. Financial records: 5–7 years (tax law). Server, session, and email-delivery logs: 30–90 days.

Site analytics records: 24 months, then deleted automatically by a scheduled job. These records are not aggregated while they are stored — each page view is kept as a separate row containing the visitor's IP address in full, country, browser, page, referrer, scroll depth and time on page.

Product news subscription: until the address is unsubscribed or the organization is deleted. After an unsubscribe, the record (address, time and IP of the consent, time of withdrawal) is kept as evidence that consent was given and later withdrawn, and no further messages are sent to it.

5. Your rights

If you are in the EU/EEA (or covered by similar law) you may: access your data, correct it, request erasure, restrict or object to processing, receive it in a portable format (JSON), and withdraw consent at any time.

How to exercise:

  • Admins/trainers: email privacy@terminia.net — we respond within 30 days.
  • Account deletion: there is no delete button in the Service. Send the request to privacy@terminia.net and we delete the account and its data manually.
  • Withdrawing consent: for analytics, reject cookies in the banner (or clear the stored answer); for product news, use the unsubscribe link in any such email or remove the address in Settings → Messaging.
  • Members of a club: contact your club first. The Service includes built-in export and anonymization tools that the club can use immediately.

Right to complain: you may lodge a complaint with your local data protection authority — see the EDPB list of EU/EEA DPAs — or with the Finnish DPA (where data is hosted) or the Serbian DPA (where Terminia is operated).

6. Children

Terminia stores data about minors only when the organization (typically a school or sports club) enters it on their behalf. The organization must obtain parental consent before doing so. Where organizations use the in-app consent tool, we record timestamp, IP address, parent name and a signature. Minors do not create their own accounts.

7. Security and breach notification

We use HTTPS/TLS in transit, encryption at rest for sensitive identifiers using per-organization keys, password hashing, multi-tenant isolation, parameterized queries, a default-deny firewall, and intrusion detection. In the event of a personal data breach we will notify affected organizations within 72 hours of becoming aware, as required by GDPR Art. 33.

8. Changes and contact

Material changes to this policy will be announced 30 days in advance by email or in-app notice. During beta, minor clarifications may be made without notice; the "Last updated" date reflects the most recent change.

Contact: privacy@terminia.net · info@terminia.net