Features
Termeva

Privacy policy

Effective from 16 September 2026

This page explains in plain language what data we collect, why, who we share it with, how long we keep it and what we never do with it. If anything is unclear, write to [email protected].

Who we are

Termeva is an online booking and website service for small studios and restaurants. We have no physical office for visitors, all communication happens online.

For any question about personal data, write to [email protected]. We reply within 30 days, usually much sooner.

Two roles: controller and processor

  • For data about visitors to termeva.com, early access requests and studio owner accounts, we are the controller: we decide how this data is used and are responsible for it.
  • Data about clients who book with a studio through its website belongs to the studio. The studio is the controller and decides why it needs the data. We act as its processor and store and process the data only on the studio's instructions, so that bookings work. Questions about this data are best sent directly to the studio, but we will help if you write to us.

What data we collect and why

  • Website visitors: IP address and browser details in server logs, to keep the site running and protected from attacks. Visit analytics only with your consent, see the section on cookies.
  • Early access requests: email, studio name, what you do, team size, what you use now, language and ad link tags if you came from one. We use them to contact you about access and to understand who needs the product most.
  • Studio owner accounts: name, email, password in hashed form, language, two-factor login settings. Studio data: name, address, phone, services, staff, schedules, photos, website texts. We need them to run the dashboard and the studio website.
  • Studio clients: name, phone, email, language, chosen service, time, booking note and visit history. We need them to create the booking and send the confirmation, reminder and cancellation notice.
  • Support conversations: messages from the dashboard chat and emails. We need them to reply and to keep the history of your request.

What we do not do

  • We do not sell or rent data to anyone.
  • We do not show ads or share data with advertising networks.
  • We do not send studio clients anything except messages about their booking. No newsletters in our name.
  • We do not use one studio's clients for another studio and do not list them in any shared directory.
  • We do not store bank card details.
  • We do not make automated decisions that would have legal effects for you.

Who we share data with

Only with services the product cannot work without, and only what they need for their part of the job:

  • Hostinger: the server that hosts the website and the database. Data center in Lithuania, EU.
  • Cloudflare: website delivery, protection from attacks, certificates, connecting studios' own domains.
  • Brevo (France, EU): sending emails, such as confirmations and reminders.
  • Google: visit analytics, only if you have consented. Google Calendar, only if a studio staff member has connected their own calendar.
  • Telegram: notifications about new bookings, only if the studio has connected the bot. We also receive notifications about new early access requests there.
  • Twilio (USA): SMS to studio clients, when the studio uses them.

Where a service is located outside the EU, transfers are based on the European Commission's standard contractual clauses or an adequacy decision.

Cookies and analytics

  • Strictly necessary: a session cookie that keeps you logged in to the dashboard, and protection of forms against request forgery. The site does not work without them, so no consent is needed.
  • Your cookie choice is saved in browser storage, so we do not ask on every visit.
  • Google Analytics: turned on only after you click "Accept". Until then it sets no cookies and sends no identifiers. Your IP address is shortened.

Changed your mind? The button below opens the choice again. If you decline, analytics is turned off and its cookies are deleted.

How long we keep data

  • Account and studio data: for as long as the account exists. When the account is deleted, the data is deleted.
  • Studio clients: for as long as the studio keeps them. The studio can anonymise a client record at any time.
  • Early access requests: for as long as you are interested in the product. Write to us and we will delete yours right away.
  • Server logs: up to 14 days.
  • Database backups: up to 14 days, then overwritten.

Your rights

You can ask us to show what data we hold about you, correct it, delete it, restrict its processing, export it in a machine-readable format or object to its processing. You can withdraw consent to analytics at any time with the button on this page.

Write to [email protected]. If you are a studio client, these requests are handled first by the studio, and we help it.

You also have the right to lodge a complaint with a supervisory authority. In the Czech Republic this is Úřad pro ochranu osobních údajů (uoou.gov.cz), in Slovakia Úrad na ochranu osobných údajov (dataprotection.gov.sk).

Security

Connections to the site are always encrypted. Passwords are stored only as hashes. Data of different studios is kept separate, and an automated test checks this on every code change. Only the service administrator has access to the data of all studios.

Changes

If we change what data we collect or who we share it with, we will update this page and the date at the top. We will email studio owners about significant changes.