Skip to main content

Privacy Policy

Terminaro – offered by Sebastian Software GmbH

As of: August 23, 2026

1. Responsible Party

Sebastian Software GmbH

Dalheimer Straße 12

55128 Mainz

Germany

Phone: +49 6131 9729-830

Email: privacy@terminaro.eu

Legally represented by: Sebastian Fastner and Sebastian Werner (Managing Directors)

Data Protection Officer: The appointment of a data protection officer is not required pursuant to Art. 37 GDPR in conjunction with Section 38 BDSG. For data protection inquiries, please contact us directly at the email address stated above.

2. General Information

Terminaro is a web-based service for appointment booking and management. We take the protection of your personal data seriously and process it exclusively in accordance with legal regulations, in particular the General Data Protection Regulation (GDPR) and the German Telecommunications Digital Services Data Protection Act (TDDDG).

No cookies are set on the public website. In the logged-in area, technically necessary authentication and session mechanisms are used (see Section 4.3). For website analysis, we use Rybbit in a cookieless, privacy-friendly configuration (see Section 3.3).

3. Technical Infrastructure

3.1 Website Delivery and Infrastructure (Bunny.net)

For the delivery of our website and the underlying infrastructure, we use services from BunnyWay d.o.o., Cesta komandanta Staneta 4A, 1215 Medvode, Slovenia. Specifically, we use:

  • CDN (Content Delivery Network): Delivery of static website files (HTML, JavaScript, CSS) via a globally distributed server network
  • Edge Scripting: Server-side logic executed at Bunny.net nodes
  • Storage: Storage of static files and assets

With each page request, Bunny.net processes technical connection data, in particular IP address, timestamp, requested URL, and browser and device information. This data is technically required for website delivery. Under the data processing agreement, Bunny.net is contractually obligated to hold all raw log data including personal information exclusively in working memory (RAM) and to automatically delete it after 20–30 seconds. Bunny.net stores no IP addresses or connection data permanently.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the secure and reliable operation of the website).

Place of processing: The website is delivered exclusively via Bunny.net nodes located in EU member states. No connection data is transferred to third countries. This data is held exclusively in the working memory (RAM) of the respective CDN nodes and is automatically deleted after 20–30 seconds; no permanent storage takes place. Bunny.net contractually guarantees that all sub-processors employed implement appropriate technical and organizational safeguards in accordance with GDPR requirements.

Further information: bunny.net/privacy (opens in new tab) and bunny.net/gdpr (opens in new tab)

3.2 Application Data (netcup)

All user data – in particular account data, appointments, and booking information – is processed and stored exclusively on servers of netcup GmbH at its locations in Nuremberg (Germany), Vienna (Austria), and Amsterdam (Netherlands). No transfer of this data to third countries takes place.

Processing currently takes place exclusively at the Nuremberg location.

Legal basis: Art. 6(1)(b) GDPR (performance of contract) for the processing of user data such as account data, appointments, and booking information; Art. 6(1)(f) GDPR (legitimate interest) for the technical operation and ensuring the security and integrity of the application infrastructure.

3.3 Web Analytics (Rybbit)

For the statistical analysis of website usage, we use the open-source analytics software Rybbit. The Rybbit instance is operated by Sebastian Software GmbH itself on a server hosted by netcup GmbH in Nuremberg, Germany. No data is disclosed to external analytics services or independent controllers. netcup GmbH processes personal data solely as an instruction-bound processor pursuant to Art. 28 GDPR. No data is transferred outside the European Economic Area (EEA).

Rybbit works without cookies and does not track visitors across websites. Visitors are not recognized through cookies or through any client-side identifier stored for tracking purposes. Instead, anonymized visitor counts are derived from a hash of IP address and user agent using a salt that rotates daily. The IP address is used solely to compute this hash and to determine the country of origin and is discarded immediately thereafter; it is not logged or stored at any point.

The following data is collected in anonymized and aggregated form:

  • Page URL and referrer
  • Browser and operating system
  • Device type (desktop, mobile, tablet)
  • Country (derived from IP address, which is immediately discarded)

Legal basis: Art. 6(1)(f) GDPR (legitimate interest). We have a legitimate interest in understanding how our website is used in order to continuously improve it. Given the privacy-friendly design of Rybbit (no cookies, no cross-site tracking, no persistent client-side identifier for tracking, self-hosted in Germany), we consider the minimal impact on users' privacy to be proportionate to this interest.

4. Processing Areas

4.1 Public Website (Landing Page)

When visiting our public website, only the technical connection data described in Section 3.1 is processed by Bunny.net. No personal data is collected beyond this.

4.2 Registration and User Account

To use Terminaro, registration is required. We process the following data:

  • Name
  • Email address
  • Password (stored hashed)
  • Account-related settings and configurations
  • Date and version identifier of the accepted terms of service
  • Date and version identifier of the accepted data processing agreement, where the contract incorporates it
  • A record of each individual acceptance, including the channel it came in through: given during registration, given on the acceptance page in your account, or adopted from a previously stored acceptance

Legal basis: Art. 6(1)(b) GDPR (performance of a contract and pre-contractual measures taken at your request). The information is required to use the service; where a registration is never completed, no contract comes about and the pre-contractual alternative applies.

Retention period: Data is stored for the duration of account usage. After termination, data is deleted within 30 days. That deadline is postponed where a documented retention exception is recorded for the account – which is the case in particular where statutory retention obligations apply, notably Sections 257 HGB and 147 AO, which may require retention of commercial and tax-relevant records for up to 10 years – and it is postponed for 56 days after the most recent payment made by SEPA direct debit, for as long as that payment can still be reversed.

Incomplete registrations: A registration whose email address is never confirmed is deleted 7 days after sign-up. A registration that is confirmed but never completed is deleted 30 days after confirmation. In both cases no account is created and no registration data is kept.

4.3 Session Management

In the logged-in area, Better Auth uses technically necessary session mechanisms so users can remain signed in across the frontend and the Convex authentication endpoints without having to enter their password on every page visit.

This includes technically necessary session cookies and, depending on the authentication flow, additional browser-side session data. These mechanisms are used exclusively for authentication and are not used for tracking or advertising purposes.

Legal basis: Section 25(2) No. 2 TDDDG (technically necessary for the provision of the service). Consent is not required.

4.4 Booking Form

Persons who book an appointment through a publicly shared booking form submit the following data:

  • Name (required)
  • Email address (required)
  • Visitor language (required)
  • Company (optional)
  • Phone number (optional)
  • Reason for booking (optional)
  • Visitor time zone (required)

This data is stored to manage the appointment and process the booking. The account holder who provides the booking form is the sole data controller for the personal data of the persons booking through it. Terminaro processes this data exclusively as a data processor on behalf of the account holder pursuant to Art. 28 GDPR and acts solely in accordance with the account holder's instructions. Persons who book an appointment may exercise their data subject rights (e.g., access, rectification, erasure) with the respective account holder.

The visitor language is stored and used to send the booking confirmation in the visitor's language.

If provided, the company field is used to assign the booking to the visitor's business context, the phone number is used for short-notice contact in case of changes or cancellations, and the reason for booking is used to prepare for the appointment.

The visitor time zone is used to display the booked appointment in the visitor's local time, in particular on the booking page, in the cancellation flow, and in booking confirmation emails.

A data processing agreement pursuant to Art. 28 GDPR is concluded with account holders who use Terminaro for the processing of booking data. This agreement can be viewed at terminaro.eu/en/dpa.

Legal basis: Art. 6(1)(b) GDPR (implementation of pre-contractual measures at the request of the data subject).

Retention period: Booking data is stored until 90 days after the appointment date and then automatically deleted. The current product setup assumes that no statutory retention obligations apply to this booking data.

A reference to this privacy policy is displayed on the booking form.

4.5 Waitlist

Our website offers the option to sign up for early access to Terminaro via a waitlist. We collect only the email address of the person signing up.

Purpose: Notification about the launch of Terminaro.

Legal basis: Art. 6(1)(a) GDPR (consent). Registration is voluntary.

Retention period: The email address is stored until the launch of Terminaro, but no later than January 1, 2027, or until consent is withdrawn — whichever occurs first. Withdrawal is possible at any time by contacting: privacy@terminaro.eu

4.6 Calendar Integration

Customers can connect their own calendar with Terminaro in their account settings (e.g., Google Calendar, Apple Calendar, or any CalDAV-compatible service). This connection is used exclusively to check the customer's availability and prevent double bookings.

Terminaro accesses the connected calendar in read-only mode. No data is written back to the customer's calendar.

Booking data from visitors is never transmitted to the customer's calendar provider. It remains exclusively on our own servers within the European Union (netcup).

Additionally, Terminaro provides each customer with a CalDAV subscription link. Through this link, customers can integrate their appointment bookings into a calendar app of their choice. The use of this link is the customer's responsibility.

Important notice regarding the CalDAV link: When using the CalDAV subscription link with third-party calendar applications, booking data (including names and contact details of persons who booked) may be transmitted to the servers of the respective calendar provider. Depending on the provider, these servers may be located outside the European Economic Area (EEA). In such cases, an adequate level of data protection cannot be guaranteed by Terminaro. The use of the subscription link is therefore at the customer's own risk and responsibility.

Security recommendation: The CalDAV subscription link contains a unique access token and should be treated as confidential. Do not share this link with unauthorized third parties, as anyone in possession of the link can access the booking data it contains.

Legal basis: Art. 6(1)(b) GDPR (performance of contract). The connection can be disconnected at any time in the settings.

Note: The data processing by the respective calendar provider (e.g., Google, Apple) is governed by the provider's own privacy policy. Terminaro has no influence on this processing. Account holders who use the CalDAV subscription link are obligated to inform persons who book appointments about any such calendar integration in their own privacy policy.

4.7 Billing and Payments

For paid plans we work with two service providers. Fakturia, operated by Luminea IT Services GmbH in Germany, creates contracts, invoices and dunning notices on our behalf. Stripe Payments Europe, Limited in Ireland processes card payments and SEPA direct debits. Card numbers and IBANs are entered directly with Stripe; Terminaro never receives or stores them.

In our own system we store only the data required for billing, tax evidence and feature access: a reference to your customer record at the payment provider, a reference to your contract at the billing provider, your current plan, the subscription status, the payment state (dunning level and the end of the grace period), the payment method type (card or SEPA direct debit), a reference to the payment method or SEPA mandate, the current term end, the evidence of where you are established (the country of your billing address, each country you have stated together with the date you stated it, and the country of your payment method), the details of the SEPA mandate (the mandate reference, our creditor identifier, and the acceptance with its time, IP address, browser identification and the address of the mandate page), the record of the check of your VAT identification number, and — on the tax evidence record and on the mandate record — a keyed pseudonym of your email address.

That last item exists for one reason. Those two records outlive your account, and nothing else in them would lead from you to them once the account is gone. The pseudonym is computed from your email address with a secret only our server holds, so the address cannot be read back out of it, and it is what lets us find the records again in order to answer a request for access or an objection. It has a limit we would rather state than conceal: it is formed from the address on file at the moment of the payment, so it does not find the records of payments you made under an email address you have changed since.

Invoices, payment details and the SEPA mandate document itself are held by these providers. Your IBAN and your card number never reach Terminaro. The reference to the mandate and the acceptance details listed above are stored by Terminaro as well, because they are evidence we have to be able to produce ourselves, independently of any provider.

Purpose: Provision of paid plans, invoicing, determining and evidencing the place of taxation, and statutory bookkeeping.

Legal basis: Art. 6(1)(b) GDPR (performance of contract) for processing payments, for the SEPA mandate and for providing the plan; Art. 6(1)(c) GDPR (legal obligation) for retaining invoices and for the tax evidence record we keep for each payment, which holds the evidence of establishment required by Art. 24b of Implementing Regulation (EU) No 282/2011 and the confirmation of a VAT identification number under Section 18e of the German VAT Act (UStG); and Art. 6(1)(f) GDPR (legitimate interests) for the separate mandate record we keep for every direct debit we collect, which we hold in order to be able to show that the collection was authorized should it later be disputed. You can object to processing based on a legitimate interest under Art. 21 GDPR; Section 8 describes how.

Retention period: Invoice data is retained by our billing provider for the statutory bookkeeping periods. Stripe may retain data beyond the end of the contract where longer retention is legally required or permitted, in particular for anti-money-laundering purposes.

Three retention periods, but not for the same data: The mandate data — the mandate reference, our creditor identifier and the details of the acceptance, the IP address among them — is stored in two places, and each of them has its own period. As part of your payment method it serves the direct debit itself: it is deleted together with your account, and only where a SEPA direct debit can still be reversed is deletion of the related billing record deferred for up to eight weeks so a chargeback can be reconciled. For every direct debit we actually collect we additionally keep a separate mandate record — the mandate reference, our creditor identifier, the time of the acceptance, the browser identification, the address of the mandate page and the IP address of that acceptance — which documents that this collection was authorized, and when. That can still matter long after those eight weeks, because a direct debit disputed as unauthorized can be contested for up to 13 months. We keep the mandate record until claims arising from the collection have become time-barred: three years, counted from the end of the calendar year in which the collection took place (Sections 195 and 199(1) of the German Civil Code, BGB). The 13 months lie inside that period. Those two are the only places your mandate data is held. The copy on your payment method goes when your account does; the mandate record goes three years after the year of the collection — unless a tax audit is pending, which suspends that deletion by the same switch, and for the same reason, as it suspends the deletion of the tax evidence record described next. The third period belongs to a record that holds no mandate data at all: the tax evidence record we keep for each payment documents only where you were established at the time of the payment, and we have to keep it for eight years (Section 147 AO). That period starts on January 1 of the year following the payment, and the records are erased year by year once it has run. It does not expire while the records still matter for taxes whose assessment period is still open, in particular while a tax audit is pending (Section 147(3) sentence 5 AO, Section 171(4) AO). The IP address of the mandate acceptance is held with the mandate record and no longer in the tax evidence record, so once those three years have run, the tax evidence record for a SEPA payment carries one item of evidence of establishment fewer than before. Your mandate data can therefore already be gone from your payment method while the mandate record still holds it – and it can be gone from both while the tax evidence record for the same payment is still kept, because that record is about where you were established, not about your mandate. The eight years do not apply to your mandate data.

Account deletion: If you delete your account, neither the tax evidence records nor the mandate records are deleted with it. For the tax evidence records Art. 17(3)(b) GDPR permits this, for the mandate records Art. 17(3)(e) GDPR does, which covers the defence of legal claims. Instead we restrict the processing of both under Art. 18 GDPR, so they are kept solely for the statutory retention obligation and for answering a disputed direct debit, and used for nothing else. The keyed pseudonym of your email address described above is what still leads from you to them after the account itself is gone.

Stripe as an independent controller: Stripe processes part of this data for its own purposes, in particular fraud prevention, anti-money-laundering and identity checks, averting financial loss, and selecting the banks and payment method providers involved. For that part, requests for access or erasure have to be addressed to Stripe under its own privacy policy; we can neither grant access nor arrange erasure there. Where Stripe acts as our processor, it forwards such requests to us.

Note: Our contract for payment processing is with Stripe Payments Europe, Limited in Ireland; Stripe Technology Company Ltd. in Ireland is Stripe's main establishment under the GDPR. Stripe nevertheless transfers personal data to third countries. Transfers to the USA rest on the European Commission's adequacy decision for the EU-U.S. Data Privacy Framework, under which Stripe, LLC is certified. Transfers to India, where Stripe runs a group company for support and for specific regulated data, rest on the EU Standard Contractual Clauses. Luminea IT Services GmbH operates from Germany and hosts our billing data in a data center in Nuremberg. The processing by these providers is additionally governed by their own privacy policies.

5. Email Communication

Terminaro sends automated emails, such as booking confirmations and appointment reminders. These emails are sent via our own infrastructure operated in Germany. No third-party providers are used for sending emails.

If an email delivery fails permanently, we temporarily store delivery metadata such as recipient address, subject line, technical error message, and where applicable the booking reference so that super-admins can analyze and manually retry the issue.

Retention period: Failed email metadata is automatically deleted after 90 days.

Legal basis: Art. 6(1)(b) GDPR (performance of contract and execution of the booked appointment).

6. Data Processors

We use the following service providers as data processors within the meaning of Art. 28 GDPR:

BunnyWay d.o.o.CDN, Edge Scripting, Storage (Slovenia, EU; delivery exclusively via nodes in EU member states)

netcup GmbHServer hosting (Germany, Austria, Netherlands – all EU)

Luminea IT Services GmbHContracts, invoicing and dunning via the Fakturia platform (Germany; billing data hosted in a data center in Nuremberg)

Stripe Payments Europe, LimitedPayment processing for card payments and SEPA direct debit (Ireland)

Written contracts pursuant to Art. 28 GDPR exist with all data processors.

Stripe additionally acts as an independent controller for its own purposes, in particular fraud prevention, anti-money-laundering and identity checks, and the selection of the banks and payment method providers involved. That part of the processing is governed by Stripe's own privacy policy – see Section 4.7.

7. Your Rights

You have the following rights regarding your personal data:

  • Right of access (Art. 15 GDPR)
  • Right to rectification (Art. 16 GDPR)
  • Right to erasure (Art. 17 GDPR)
  • Right to restriction of processing (Art. 18 GDPR)
  • Right to data portability (Art. 20 GDPR)
  • Right to object to processing (Art. 21 GDPR) – see Section 8 below for detailed information

To exercise your rights, please contact: privacy@terminaro.eu

You also have the right to lodge a complaint with a data protection supervisory authority. The competent authority for Sebastian Software GmbH is:

The State Commissioner for Data Protection and Freedom of Information Rhineland-Palatinate (LfDI RLP)
Postfach 30 40
55020 Mainz
Germany
Phone: +49 6131 8920-0
Website: datenschutz.rlp.de (opens in new tab)

8. Right to Object (Art. 21 GDPR)

If we process your personal data on the basis of a legitimate interest (Art. 6(1)(f) GDPR), you have the right to object to this processing at any time for reasons arising from your particular situation.

This applies in particular to the processing described in Sections 3.1 (website delivery via Bunny.net), 3.2 (technical operation of the application infrastructure), and 3.3 (web analytics via Rybbit).

If you object, we will no longer process the data concerned unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights, and freedoms, or unless the processing serves the establishment, exercise, or defense of legal claims.

To exercise your right to object, please contact: privacy@terminaro.eu

9. Automated Decision-Making

No automated decision-making or profiling within the meaning of Art. 22 GDPR takes place.

10. Currency of this Privacy Policy

We reserve the right to amend this privacy policy in the event of changes to the service or the legal framework. The current version is always available on our website.

Registered users will be notified of material changes to this privacy policy in advance by email to the address stored in their account. This ensures that users in an existing contractual relationship are informed of any relevant changes in a timely manner.

11. Export Access for Customer-Designated Recipients

Account holders can issue a time-limited, read-only access credential in their account settings so that a recipient they designate themselves can retrieve the account's data export through our documented export interface.

Two roles meet in this feature. For the booking and team booking data contained in such an export, Terminaro remains a data processor bound by the account holder's instructions under the data processing agreement (see Section 4.4). For the operational and evidence metadata that we record about the access credential itself – who issued it, for whom, under which contract versions, and when it was used – Terminaro is the controller. This section describes only the processing for which we are the controller.

11.1 Data We Store About an Export Access Credential

For each access credential we store:

  • The designation of the recipient as entered by the account holder
  • The recipient's country code as declared by the account holder
  • The recipient's role marker, which always carries the fixed value of a customer-designated recipient and is not a statement about the recipient's role under data-protection law
  • The fixed read-only scope data-export:read:v1
  • The time of issuance and the time of expiry
  • The email address of the administrator who issued the credential
  • The time of first use, the time of the most recent use, and the number of uses
  • The time of revocation, where a credential was revoked
  • The declared transfer region – inside or outside the European Economic Area – and the time of that declaration
  • An unchangeable snapshot of the version identifiers of the terms of service and of the data processing agreement accepted at the time of issuance, together with the times of those acceptances

11.2 Recipients Outside the European Economic Area

Automated issuance requires a structured declaration by the account holder that the designated recipient is established in the European Economic Area, together with a country code that matches this declaration. Self-service issuance is therefore available for recipients in the European Economic Area only.

Where a designated recipient is located outside the European Economic Area, issuance stays blocked until a separate manual role and transfer review has been documented unchangeably for exactly that recipient, the stated country and the contract versions in force. For such a review we store the approval reference, the time of the approval, the person who granted it, the name and country of the recipient, and the two contract versions.

The record of the person who granted the approval remains internal to Terminaro. It is excluded from every customer data export and is disclosed neither to the account holder nor to the designated recipient.

We do not verify whether the declared details are correct. Neither the declaration nor a manual approval replaces the account holder's own responsibility or any transfer mechanism that may be legally required.

11.3 What We Do Not Store and What We Do Not Disclose

The access credential itself is displayed to the issuing administrator exactly once, at the moment it is created, and is not stored by us. What we keep instead is a keyed digest from which the credential cannot be reconstructed. This digest is never contained in a data export and is never displayed.

The internal document identifier of an access credential is visible inside the account holder's own account settings, because revoking a credential requires it. It is not part of any data export and it never reaches the designated recipient.

The reference of a manual approval is deliberately withheld from the export interface, so that no recipient can see the approval references belonging to other recipients.

11.4 The Designated Recipient Is Not One of Our Data Processors

The recipient is selected solely by the account holder and acts within the account holder's sphere of responsibility. The designation makes that recipient neither a data processor of Terminaro nor a sub-processor of Terminaro. Under data-protection law the recipient is either a controller in its own right or a data processor of the account holder; which of the two applies follows from how the account holder and the recipient have arranged their relationship and is determined by the account holder, and we neither make nor review that classification. We neither verify nor guarantee the recipient's identity or actual location.

For this reason a designated recipient appears neither in the list of our data processors in Section 6 nor in the list of sub-processors in the data processing agreement. Both lists belong to different contracts and deliberately do not have the same content.

11.5 Purpose, Legal Basis, Retention Period and Rights

Purpose: Operating and revoking the export access, documenting the account holder's instruction together with the contract versions in force at the time, and detecting misuse of an issued access credential.

Legal basis: Art. 6(1)(b) GDPR (performance of a contract) for operating the feature under the contract, that is issuance, revocation and the recipient details; Art. 6(1)(c) GDPR in conjunction with Art. 28(3)(a) and Art. 5(2) GDPR for documenting the instruction and the accompanying evidence; Art. 6(1)(f) GDPR (legitimate interest) for the usage counters and timestamps, which we keep in order to prevent misuse and to secure the interface.

Recipients: This metadata is stored on the same infrastructure as the remaining application data (see Section 3.2). A bounded part of it reaches the designated recipient: the designation of the recipient, the country code, the role marker, the read-only scope, the time of issuance and the time of expiry, the declared transfer region together with the time of that declaration, the accepted version identifiers of the terms of service and of the data processing agreement together with the times of those acceptances, and the email address of the administrator who issued the credential are emitted through the export interface to whoever holds a valid access credential. The export interface answers for the account rather than for a single credential, so a credential holder receives this metadata for every access credential of that account that is neither revoked nor expired, and not only for the credential being used. The keyed digest, the internal document identifier, the usage counters, the times of revocation and the record of a manual approval stay excluded from that disclosure. Beyond this disclosure we pass the metadata on to no one else; where a recipient outside the European Economic Area was approved through the manual review described in Section 11.2, the disclosure to that recipient is a transfer to a third country and takes place on the account holder's instruction.

Retention period: The validity period of an access credential changes neither the retention nor the deletion of these records. Access credential records and manual approval records are retained until the account holder's account is deleted. That deletion normally takes place 30 days after the end of the contract, together with the remaining account data. Where a documented retention exception applies to the account – in particular the statutory retention obligations named in Section 4.2 – or where a payment made by SEPA direct debit can still be reversed, the account deletion, and with it the deletion of these records, is postponed accordingly. There is no separate cleanup that removes expired credentials earlier. Access therefore ends with that deletion at the latest, even where the nominal validity of a credential – up to 90 days – would run longer. Once the 30-day return period has elapsed, no further access credential can be issued.

Your rights: The rights listed in Section 7 apply to this metadata as well. Where we rely on a legitimate interest, you can object to the processing under Art. 21 GDPR; Section 8 describes how.

The public data-export register describes the technical scope of the export interface. It documents the interface and does not expand the data processing agreement. The register can be viewed at terminaro.eu/en/data-export.