Data Processing Agreement
Effective from: 22 August 2026
Last changed: 22 August 2026
This is a convenience translation of the Slovenian original, Pogodba o obdelavi osebnih podatkov. In case of any discrepancy, the Slovenian version prevails.
This agreement (the DPA) is an integral part of the Terms of Business of the Termina platform and governs the processing of personal data under Article 28 of the General Data Protection Regulation (GDPR) between:
- the provider — the business that accepts bookings through the platform (as controller), and
- Termina, računalniško programiranje, Neya Borysova s.p., Goriška ulica 4, 2000 Maribor, tax number 16782062, info@termina-booking.com (as processor; Termina).
The provider accepts the DPA at registration, together with the Terms of Business. There is no separate signature; acceptance is recorded with the document version and the time of acceptance.
1. Roles and demarcation
For the personal data of the provider's customers arising from bookings, messages and reviews, the controller is the provider and Termina is the processor acting on the provider's behalf.
For data Termina processes for its own purposes — the provider's account, subscription billing, platform security, legal obligations — Termina is an independent controller; that processing is governed by the Privacy Policy, not by this DPA.
2. Subject matter, duration, nature and purpose
- Subject matter: personal data of the provider's customers and staff, entered on the platform or arising from its use.
- Duration: for as long as the provider uses the platform, and after termination until the periods in section 9 expire.
- Nature and purpose: storing and displaying bookings, the calendar and customer details; sending confirmations, reminders and notifications; messages between provider and customer; displaying reviews; billing; backups.
3. Types of data and categories of data subjects
- The provider's customers: name, email address, phone number, booking details (service, date, time, price, notes), messages, reviews, online payment details (amount and status; no card numbers).
- The provider's staff: name, email address, working hours, assigned appointments.
The platform does not request special categories of data (Article 9 GDPR); service categories are designed so that no health data can be inferred from a booking. The provider must not enter special-category data into free-text fields.
4. Controller's instructions
Termina processes data only on the provider's documented instructions. The instructions are the defined functions of the platform and the settings the provider manages on their dashboard; individual instructions beyond the platform's functions are sent to info@termina-booking.com. If Termina considers an instruction to infringe data protection law, it will alert the provider.
The retention periods in section 9 are uniform for all providers, published in advance and part of this service; the provider accepts them with this DPA.
5. Confidentiality
Only persons who need the data for the platform to operate have access to it, and they are bound by confidentiality. Administrative access is protected by two-step sign-in, and administrative access to data is logged.
6. Security of processing (Article 32 GDPR)
Termina implements, among others, the following technical and organisational measures:
- encrypted transfer of all data (HTTPS);
- passwords stored only as hashes; sign-in sessions in HttpOnly cookies;
- role-based access: a customer sees their own data, a provider the data of their customers, a staff member their own calendar;
- sign-in rate limiting and security event logging (log kept 90 days);
- push notification content encrypted from the server to the device (RFC 8291);
- regular backups with restore testing;
- a security incident register with a reminder of the 72-hour reporting deadline.
7. Sub-processors
The provider gives general authorisation for engaging sub-processors. Their list is always published on the Sub-processors page and is derived from the platform's actual configuration, so it cannot lag behind reality.
Termina notifies providers by email of any intended change to the list 30 days before it takes effect. The provider may object to a change; if the objection cannot be resolved, the provider may cancel the subscription without notice. Termina has agreements with equivalent data protection obligations in place with every sub-processor.
8. Assistance to the controller
- Data subject rights: the provider can export or erase an individual customer's data directly on their dashboard; for requests the tools do not cover, Termina assists within a reasonable time.
- Data breaches: Termina notifies the provider without undue delay after becoming aware of a breach, describing the breach, its likely consequences and the measures taken.
- Impact assessments and consultations: on request, Termina provides the information the provider needs to meet its obligations under Articles 32 to 36 GDPR.
9. Deletion and return of data
- The provider can export their customers' data at any time on their dashboard (structured, machine-readable export).
- 24 months after the appointment date, the customer's name, email address and phone number are irreversibly anonymised; the booking remains as a business event without the person.
- Messages and communication are deleted no later than 24 months after they arise.
- Accounting records are kept for 10 years and then deleted in full.
- After the subscription ends, the data remains accessible for a further 12 months and is then deleted or anonymised under the same rules. A provider who needs the data for longer must export it before the deadline and is then solely responsible for it.
10. Demonstrating compliance and audits
On request, Termina makes available the information necessary to demonstrate compliance with Article 28 GDPR and allows audits, including inspections conducted by the provider or an auditor they authorise. An audit is announced at least 30 days in advance, takes place during normal working hours and must not touch other providers' data.
11. Transfers to third countries
Data is processed within the EEA as a rule. Where a sub-processor transfers data to a third country (visible in the sub-processor list), the transfer relies on an adequacy decision or on the European Commission's standard contractual clauses.
12. Validity
The DPA applies for as long as the contractual relationship under the Terms of Business exists and, as regards retention, until the periods in section 9 expire. In the event of a conflict between the DPA and the Terms of Business concerning data protection, the DPA prevails.
Questions: info@termina-booking.com