Data Processing Agreement

Effective from: 22 August 2026
Last changed: 22 August 2026

This is a convenience translation of the Slovenian original, Pogodba o obdelavi osebnih podatkov. In case of any discrepancy, the Slovenian version prevails.

This agreement (the DPA) is an integral part of the Terms of Business of the Termina platform and governs the processing of personal data under Article 28 of the General Data Protection Regulation (GDPR) between:

The provider accepts the DPA at registration, together with the Terms of Business. There is no separate signature; acceptance is recorded with the document version and the time of acceptance.

1. Roles and demarcation

For the personal data of the provider's customers arising from bookings, messages and reviews, the controller is the provider and Termina is the processor acting on the provider's behalf.

For data Termina processes for its own purposes — the provider's account, subscription billing, platform security, legal obligations — Termina is an independent controller; that processing is governed by the Privacy Policy, not by this DPA.

2. Subject matter, duration, nature and purpose

3. Types of data and categories of data subjects

The platform does not request special categories of data (Article 9 GDPR); service categories are designed so that no health data can be inferred from a booking. The provider must not enter special-category data into free-text fields.

4. Controller's instructions

Termina processes data only on the provider's documented instructions. The instructions are the defined functions of the platform and the settings the provider manages on their dashboard; individual instructions beyond the platform's functions are sent to info@termina-booking.com. If Termina considers an instruction to infringe data protection law, it will alert the provider.

The retention periods in section 9 are uniform for all providers, published in advance and part of this service; the provider accepts them with this DPA.

5. Confidentiality

Only persons who need the data for the platform to operate have access to it, and they are bound by confidentiality. Administrative access is protected by two-step sign-in, and administrative access to data is logged.

6. Security of processing (Article 32 GDPR)

Termina implements, among others, the following technical and organisational measures:

7. Sub-processors

The provider gives general authorisation for engaging sub-processors. Their list is always published on the Sub-processors page and is derived from the platform's actual configuration, so it cannot lag behind reality.

Termina notifies providers by email of any intended change to the list 30 days before it takes effect. The provider may object to a change; if the objection cannot be resolved, the provider may cancel the subscription without notice. Termina has agreements with equivalent data protection obligations in place with every sub-processor.

8. Assistance to the controller

9. Deletion and return of data

10. Demonstrating compliance and audits

On request, Termina makes available the information necessary to demonstrate compliance with Article 28 GDPR and allows audits, including inspections conducted by the provider or an auditor they authorise. An audit is announced at least 30 days in advance, takes place during normal working hours and must not touch other providers' data.

11. Transfers to third countries

Data is processed within the EEA as a rule. Where a sub-processor transfers data to a third country (visible in the sub-processor list), the transfer relies on an adequacy decision or on the European Commission's standard contractual clauses.

12. Validity

The DPA applies for as long as the contractual relationship under the Terms of Business exists and, as regards retention, until the periods in section 9 expire. In the event of a conflict between the DPA and the Terms of Business concerning data protection, the DPA prevails.

Questions: info@termina-booking.com