Privacy Policy

Effective from: 22 August 2026
Last changed: 22 August 2026

This is a convenience translation of the Slovenian original, Politika zasebnosti. In case of any discrepancy, the Slovenian version prevails.

1. Who we are

The controller of personal data collected through the Termina platform (termina-booking.com) is:

Termina, računalniško programiranje, Neya Borysova s.p. Goriška ulica 4, 2000 Maribor, Slovenia Tax number: 16782062 Registration number: 7558252000 Email: info@termina-booking.com

We are committed to protecting your personal data and process it in accordance with the General Data Protection Regulation (GDPR) and the Slovenian Personal Data Protection Act (ZVOP-2).

We have not appointed a data protection officer, as we do not meet the statutory conditions requiring one. For any privacy question, write to the email address above.

For customer data that arises from a booking with a provider, the controller is the provider and Termina is the processor; that relationship is governed by the Data Processing Agreement.

2. Which data we process

2.1 Provider data

2.2 Data of providers' staff

Where a provider works in a team: name, email address, working hours and assigned appointments. This data is entered by the provider, who is its controller; a staff member with an account sees their own calendar.

2.3 Customer data

2.4 Data of all visitors

2.5 Payment data

We do not collect, process or store payment card data. Payments are executed entirely by the payment provider Stripe. We receive only the payment outcome, the last four digits of the card and the card type.

PurposeLegal basis
Concluding and performing the platform usage contractContract performance (Art. 6(1)(b) GDPR)
Processing bookings and passing details to the providerContract performance (Art. 6(1)(b) GDPR)
Confirmations, reminders and appointment notifications (email, SMS, push)Contract performance (Art. 6(1)(b) GDPR)
Messages between customer and provider, and HelpContract performance (Art. 6(1)(b) GDPR)
Displaying reviews tied to a real bookingLegitimate interest — trust and transparency (Art. 6(1)(f) GDPR)
Subscription billing and invoicingContract performance and legal obligation (Art. 6(1)(b) and (c) GDPR)
Verifying providers in business registersLegitimate interest and the legal obligation of trader traceability (Art. 6(1)(f) and (c) GDPR)
User support and answering questionsContract performance or legitimate interest (Art. 6(1)(b) and (f) GDPR)
Retention of accounting recordsLegal obligation (Art. 6(1)(c) GDPR)
Security and abuse preventionLegitimate interest (Art. 6(1)(f) GDPR)
Anonymous platform usage analyticsLegitimate interest — developing and improving the service (Art. 6(1)(f) GDPR)
Sending news and product updatesConsent (Art. 6(1)(a) GDPR)
Establishing or defending legal claimsLegitimate interest (Art. 6(1)(f) GDPR)

You can switch off non-essential notifications at any time; notifications about a cancelled or rescheduled appointment reach you even after opting out, because they are necessary for performing the contract.

4. Who receives the data

We do not sell personal data. We pass it on only to the extent necessary for the platform to operate:

To providers. When a customer books an appointment, the provider receives the details needed to perform the service. For any further processing of that data the provider is an independent controller and is responsible for it.

To processors that perform individual services for us (hosting, payments, sending email and SMS, delivering push notifications, the map, traffic measurement). Their list is always published on the Sub-processors page; it is derived from the platform's actual configuration, so it cannot lag behind reality. Providers are notified of changes to the list 30 days before they take effect. We have data processing agreements under Art. 28 GDPR with all processors.

To public authorities, where the law requires it.

5. Transfers outside the EU

We process data within the European Economic Area as a rule. If a processor transfers data to a third country (visible on the Sub-processors page), the transfer relies on a European Commission adequacy decision or on standard contractual clauses.

6. How long we keep the data

After these periods expire, the data is deleted or irreversibly anonymised.

7. Your rights

Under the GDPR you have the right to:

You can export and erase your data directly in the app, in your account settings — no waiting and no request needed. For everything else, send a request to info@termina-booking.com; we reply within one month of receipt at the latest. For security we may ask for additional confirmation of your identity.

If you believe we process your data unlawfully, you have the right to lodge a complaint with the supervisory authority:

Information Commissioner of the Republic of Slovenia Dunajska cesta 22, 1000 Ljubljana gp.ip@ip-rs.si | www.ip-rs.si

8. Cookies

We use only essential cookies, needed for the site to work, for sign-in and for security. The law requires no consent for these, so you will not see a cookie banner on the platform. Exactly what is stored in your browser and for how long is described on the Cookies page.

We use no analytics cookies or trackers. For measuring traffic we use Umami, which sets no cookies, creates no visitor identifiers and cannot track individuals across visits or across websites. The collected data is aggregated and anonymised.

Stripe may set its own fraud-prevention cookies during payment; these are necessary for the secure execution of the payment.

9. Security

We implement appropriate technical and organisational measures: encrypted data transfer (HTTPS), passwords stored only as hashes, role-based access, security event logging, regular software updates and backups with restore testing. Push notification content is encrypted from the server to the device.

Nevertheless, no system is completely secure. In the event of a personal data breach posing a high risk to your rights, we will notify you in accordance with Art. 34 GDPR.

10. Children

The platform is not intended for persons under 16 years of age. We do not knowingly collect children's personal data.

11. Changes to this policy

We may update this policy. We will notify you of material changes by email or with a notice on the platform. The current version is always published on this page, together with the date of the last change.