Privacy
Privacy Policy
This privacy policy explains how Terminov processes personal data in the app, the web dashboard and public booking pages, which service providers are used and how retention is determined.
This page is shown in your selected language as a convenience translation. The German version remains legally authoritative.
1. Controller and contact
Bassam Alahmad, trading as Terminov, Westerholter Weg 101, 45657 Recklinghausen, Deutschland, is the controller for platform, account, security, support and contract data.
Privacy requests can be sent to support@terminov.de. If a data protection officer is legally required or voluntarily appointed, their contact details will be added here.
2. Scope and roles
This privacy notice applies to the Terminov websites, mobile app, web dashboard, public company pages, booking pages, registration forms and student portal.
Terminov generally acts as controller for account, security, support, contract management and platform communication. Where a company uses Terminov to manage its own customers, students, employees, prospects or appointments, that company remains responsible for those contents and Terminov technically processes them on its behalf.
3. Data categories
Depending on use, Terminov processes in particular the following data:
- Account and profile data: name, email address, authentication and session data, role, language, phone number.
- Company data: name, industry, profile, address, booking link, branding, billing and contact details, public visibility.
- Employee data: names, roles, permissions, working times, absences, access codes and linked auth accounts.
- Customer, student or prospect data: contact details, appointments, notes, booking history, training or industry-specific data.
- Appointment data: service, employee, customer, resource, date, time, status, source, meeting point and notes.
- Communication data: team messages, voice messages, notifications, reminders and email delivery information.
- Device, security and diagnostic data: push tokens, sessions, app version and request metadata.
- Voluntary content: logos, profile images, uploaded files and optional media.
4. Purposes of processing
Terminov processes data to provide sign-in, authentication, team and permissions management, scheduling, customer management, online booking, public company pages, driving-school registration, student portal, notifications, reminders, support, abuse prevention, security, error analysis, contract administration and legal documentation.
5. Legal bases
The legal basis depends on the specific process. Possible bases include contract performance, pre-contractual steps, legitimate interests in secure and reliable platform operation, consent for optional features and legal obligations. For company-managed data, the using company determines the legal basis towards its data subjects.
6. Public booking and registration
When you request or book an appointment or register through a public Terminov page, the entered data is transferred to the relevant company and stored in Terminov. The company uses it to process the request, prepare the service and communicate further.
The student portal displays information accessible only via an individual link. Do not share such links with unauthorised persons. The relevant company remains responsible for the professional content and accuracy of displayed training data.
7. App permissions
Microphone is used only for voice messages, contacts for voluntary customer import, location only if requested for meeting or pickup points, photos for logos and profile images, and notifications for appointment, booking, reminder and team notices. Permissions are requested contextually and can be revoked in the operating system.
8. Cookies, local storage and similar technologies
Terminov uses storage and access technologies on websites and in the web dashboard, especially local storage and comparable browser storage. Necessary storage is separated from optional preference, analytics and marketing categories.
- Necessary: session and security functions, form protection, booking flows and saving the privacy selection.
- Preferences: convenience settings such as language or display.
- Analytics: no analytics provider is currently active.
- Marketing: no marketing provider is currently active.
Optional consents can be changed or withdrawn at any time through the privacy settings.
Withdrawing privacy consent is not the same as withdrawing from a contract. To withdraw from an online contract, use Withdraw contract.
9. Recipients and service providers
Where required for the function used, Terminov uses Supabase for authentication, database, storage and server functions; Vercel for public website hosting; Resend for transactional email; Expo for push delivery; Stripe for web subscriptions; RevenueCat for validating mobile subscriptions; and Apple or Google for app distribution, in-app purchases and optional Google Calendar synchronisation.
Only data required for hosting, delivery, billing, purchase validation or synchronisation is transferred. Terminov does not store complete payment-card details; these are processed by the relevant payment or store provider.
10. Third-country transfers
Where a provider processes data outside the EU or EEA, the transfer is based on an adequacy decision, including the EU-US Data Privacy Framework for certified recipients, or on standard contractual clauses and supplementary safeguards. European storage regions and encrypted transmission are used where available.
11. Retention and deletion
Personal data is retained only as long as required for the account, contract, enabled features, security and statutory records. Account and profile data remains during account use and the 30-day deletion period. Contract, invoice and purchase records are retained afterwards only where statutory commercial or tax duties require it. Security and delivery logs are deleted or anonymised when no longer required for troubleshooting, abuse prevention or evidence.
Account deletion can be confirmed in the app, web dashboard or via /daten-loeschen using an email code. After confirmation, final deletion is scheduled 30 days later.
Data managed by a company about its own customers, students or employees may also be subject to that company’s retention and deletion decisions.
12. Data subject rights
Data subjects may request access, rectification, deletion, restriction, portability and objection. Where processing is based on consent, consent can be withdrawn for the future. Requests can be sent to support@terminov.de.
You may also lodge a complaint with a data protection authority. The authority responsible for the provider’s registered address is the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia (LDI NRW). Contact details are available at ldi.nrw.de.
13. Security
Terminov uses technical and organisational measures to protect data against unauthorised access, loss, misuse and alteration. These include encrypted transmission, role-based permissions, authentication, session management and access restrictions.
14. Sensitive data, minors and industries
Terminov is designed as multi-industry scheduling software. In sectors such as driving schools, health, therapy or consulting, users may enter sensitive or particularly protected data, including data of minors. Companies must ensure suitable legal bases, information duties and protection concepts.
15. Automated decisions
Based on the current technical state, Terminov does not make automated decisions with legal effect or similarly significant impact within the meaning of Art. 22 GDPR.
16. App stores
Additional privacy information is maintained in the Apple App Store and Google Play developer consoles. These statements must match this privacy policy and the actually submitted app version.
17. Google Calendar integration
Signed-in company owners and employees may each voluntarily activate two independent personal Google Calendar connections: exporting the Terminov appointments assigned to them to Google Calendar and importing events from their own Google account into Terminov. Every person authorises their connections separately; export and import may use the same or different Google accounts and are not required for the rest of Terminov. Terminov requests only the following permissions:
- Manage events in the owned primary calendar (calendar.events.owned): Terminov creates, updates and removes only entries for Terminov appointments assigned to the person who connected the account. Appointments assigned to other employees and calendars merely shared with the account are not used.
- Read events in the owned primary calendar (calendar.events.owned.readonly): For the separately activated import, Terminov reads the title, start and end time, status and event ID of existing Google events in the connected account’s primary calendar. These data are displayed as private, read-only calendar notes only in the connecting person’s own employee calendar and are not visible to the company owner or other employees. Status is used to update changed or deleted notes. For each imported note, the connecting person may optionally choose whether it blocks their own public online-booking availability. Google events are not modified, and calendars merely shared with the account are not accessed.
- Account email address (userinfo.email): Terminov stores the address of the connected Google account so the settings show which account is connected.
Access and refresh tokens are stored encrypted and used only server-side. Google user data is processed solely for the appointment synchronisation described here. It is not sold, not used for advertising, not used for profiling and not used to train AI or machine-learning models. It is transferred only to technical hosting and database providers acting as instructed processors where required to operate the synchronisation, or where legally mandated.
Each connection can be disconnected separately at any time in the Terminov settings. Doing so deletes its stored Google tokens; disconnecting the import also removes calendar entries imported from Google out of Terminov. Independently, access can be revoked at any time in the Google account at myaccount.google.com/permissions.
Encrypted tokens, the account email and the granted scope value are retained only while the relevant connection is active and are deleted when it is disconnected. Imported Google events remain in Terminov only while the import connection is active, are updated when Google reports changes or deletions, and are removed immediately when import is disconnected. For export, Terminov retains the technical mapping between a Terminov appointment and its Google event ID for as long as the related appointment or company exists; it is used only to update or remove the same Google entry and prevent duplicates. Terminov does not create aggregated or anonymised profiles from Google data.
Terminov’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
18. Version
Version: 21 August 2026. This policy will be updated when features, recipients or legal requirements materially change.
