TERNO PRIVACY POLICY

Effective Date: 1 August 2026


1. INTRODUCTION

This Privacy Policy explains how Terno (Gulf) FZ-LLC and its regional Affiliates ("Terno," "we," "us," or "our") collect, use, disclose, and protect personal data when you use the Terno booking and appointment management platform (the "Services" or "Platform"), as described in our Terms of Service.

This Policy uses the same defined terms as our Terms of Service, including "Merchant" (the business using Terno), "Customer" (an individual who books an appointment with a Merchant through Terno), "User" (a Merchant's staff or authorized representative), and "Business" (the Merchant's salon, barbershop, or other service business).

Terno's collection, use, and protection of personal data referenced in Section 8.2 of our Terms of Service is governed by this Policy. By using the Services, you consent to the practices described here.


2. WHO THIS POLICY APPLIES TO

This Policy applies to personal data we process about:

Where Terno processes Customer data on a Merchant's behalf, the Merchant — not Terno — is generally the data controller for that data, and Terno acts as a data processor under our Data Processing Agreement. See Section 12 (Controller and Processor Roles) below for what this means in practice.


3. INFORMATION WE COLLECT

3.1 Information Merchants Provide Directly

When a Merchant registers for and uses the Services, we collect:

We do not, and are not able to, collect Social Security Numbers, passport numbers, or other government ID numbers directly. Where identity verification is required to enable payouts, this is handled entirely within Stripe Connect's own onboarding flow — Terno never receives or stores the underlying documents.

3.2 Information About Customers (Collected on Behalf of Merchants)

When a Customer books an appointment with a Merchant through Terno, we collect, on the Merchant's behalf:

3.3 Information Collected Automatically

When anyone uses our Services or visits a Terno-hosted page, we automatically collect:

3.4 Information Collected via WhatsApp and Other Communication Channels

Terno uses the WhatsApp Business Platform (operated by Meta Platforms, Inc.) to send booking confirmations, reminders, and to power the Terno Receptionist automated booking assistant. When a Customer messages a Merchant's connected WhatsApp number:

We only use WhatsApp messaging for the purposes a Customer would reasonably expect from booking or communicating with a Merchant — we do not use WhatsApp contact information for unrelated marketing without consent.

Automated decision-making. The Terno Receptionist can independently confirm, reschedule, or cancel a Booking based on a Customer's message, without a human reviewing that specific exchange before it happens. A Customer can ask to speak with a staff member at any point in the conversation; this triggers a handoff notification to the Merchant's staff, who can take over the conversation directly. Merchants (and Terno, for quality and safety purposes) may review flagged or escalated conversations after the fact to correct mistakes and improve the assistant's accuracy — this internal review uses conversation content already collected under this Policy and is not a separate collection of new data. By messaging a Merchant's WhatsApp number, a Customer consents to their message being processed by the Terno Receptionist and, where relevant, reviewed internally for the quality and safety purposes described above.

Who can see this content. Conversation transcripts are visible to the Merchant whose number was messaged (through their inbox) and to a limited set of trained Terno personnel who need access to operate, support, or improve the Service. Access is role-restricted and logged, consistent with Section 8 (Data Security).

Transactional vs. marketing messages. Booking confirmations, reminders, and replies needed to complete a booking are operational messages a Customer cannot opt out of while keeping an active booking, since they are necessary to provide the Service. Optional marketing messages (e.g., promotions from a Merchant) require opt-in consent and can be opted out of at any time.

3.5 Website Content and AI-Assisted Generation

Terno lets Merchants build and publish a business website and booking page. In connection with this feature:


4. HOW WE USE INFORMATION

We use the information described above to:

We do not sell personal data, and we do not use Customer data collected on a Merchant's behalf for our own independent marketing purposes.


5. LEGAL BASES FOR PROCESSING

For users in the UK, EU, and other regions with similar requirements, we rely on the following legal bases:


6. HOW WE SHARE INFORMATION

We share personal data only as necessary to provide the Services, and with the following categories of recipients:

Sub-processors and service providers:

Sub-processor Purpose Location
Supabase, Inc. Database hosting, storage, and backups EU region
Stripe, Inc. Payment processing and payouts (Stripe Connect) Multiple (see Stripe's privacy policy)
Meta Platforms, Inc. WhatsApp Business Platform messaging Multiple (see Meta's privacy policy)
360dialog GmbH WhatsApp message transmission (legacy/alternate integration) EU region (Germany)
Twilio Inc. SMS fallback for time-sensitive notifications Multiple (see Twilio's privacy policy)
Google LLC (Google Cloud / Vertex AI, Google Gemini API) AI processing for the Terno Receptionist booking assistant; AI-assisted generation of website, service and marketing content; AI-assisted summarisation of the Merchant's own analytics; calendar sync; Maps/Places autocomplete Multiple (see Google's privacy policy); for the details in Section 3.2, see the AI processing table below
Vercel Inc. Application hosting and content delivery Multiple (see Vercel's privacy policy)
Google Ads (Google LLC) Optional: Merchant-initiated Customer Match audience uploads for the Merchant's own ad campaigns Multiple (see Google's privacy policy)
Meta Platforms, Inc. (Meta Ads) Optional: Merchant-initiated Custom Audience uploads, and server-side booking conversion events (Meta Conversions API), for the Merchant's own ad campaigns Multiple (see Meta's privacy policy)

Where the Terno Receptionist's AI processing happens. For most Merchants, requests are processed in Google Cloud's data centre for the Merchant's own region (for example, an EU Merchant's requests are processed in the Netherlands). For some EU-region Merchants, this processing may instead take place in the United Kingdom (London), when doing so lets us run an improved version of the underlying AI model that is not yet available in an EU data centre. This transfer is made under the European Commission's adequacy decision for the UK (renewed 19 December 2025, in force until 27 December 2031), which finds that the UK provides a level of data protection equivalent to the EU's — the strongest available basis for this kind of transfer under EU law, and the reason no separate contractual safeguard (such as the Standard Contractual Clauses referenced in Section 7) is needed for it. This does not change where the sensitive service-preference details described in Section 3.2 are processed — those follow the separate table below.

AI providers that may process service preference and suitability details (Section 3.2):

Sub-processor Entity and role Purpose Where processing happens
Google Cloud Vertex AI (Google LLC / Google Cloud EMEA Ltd.) Processor, under Google Cloud's Data Processing Addendum Generating treatment and product suggestions for salon staff from hair and skin details Routed by the Merchant's data region: Gulf → Netherlands · EU → Netherlands · UK → London · North America → Iowa, USA · Latin America → São Paulo, Brazil · Asia-Pacific → Singapore · Australia/NZ → Sydney · Africa → Belgium
Anthropic PBC Processor, under Anthropic's commercial terms Same purpose United States
OpenAI, L.L.C. Processor, under OpenAI's business terms Same purpose United States

What is and is not sent to these providers. Only hair and skin details (hair pattern, porosity, density, scalp condition, Fitzpatrick skin type) are sent. Cultural and accessibility answers are never sent to any AI provider, in any form — this is enforced in our systems, not only by policy. Suggestions are shown to salon staff, who decide; no booking, price, or service is decided automatically on the basis of these details.

This list is exhaustive for this category of data. We do not send service preference or suitability details to any AI provider not named in this table. If we add one, we will update this Policy and notify affected Merchants and Customers before the change takes effect, not after.

No training. These providers process this information solely to return a suggestion to us. They do not use it to train or fine-tune their models.

Other disclosures:

We update this Policy when our sub-processors change materially.


7. INTERNATIONAL DATA TRANSFERS

Terno operates globally, and your data may be transferred to and processed in countries other than your own. The specific destinations for each sub-processor are stated in the tables in Section 6.

Where we transfer personal data outside the UK/EEA, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum (as referenced in our Data Processing Agreement). You may request a copy of the safeguards applying to any transfer by emailing privacy@terno.io.

For the EU-to-UK transfer described in Section 6 (Terno Receptionist processing that may take place in London), the applicable safeguard is different: the European Commission's own adequacy decision for the UK, rather than the Standard Contractual Clauses. An adequacy decision is a formal finding, published by the European Commission, that a country's data protection law is equivalent to the EU's — it is a public legal instrument, not a private contract, so there is no separate document to request a copy of; you can read the decision itself at the European Commission's website.

For the service preference and suitability details described in Section 3.2, which we treat as sensitive personal data, the destinations are limited to those in the AI processing table in Section 6 and are, for Google Cloud Vertex AI, routed to the region shown there for the Merchant's data region.

Where you are in a country with additional transfer requirements — including Saudi Arabia, Brazil, Québec (Canada), Japan or Australia — additional safeguards, assessments or consents may apply before we transfer sensitive personal data outside your country, and we will not make such a transfer until they are in place.


8. DATA SECURITY

We implement technical and organizational measures to protect personal data, including:

No method of transmission or storage is completely secure. We cannot guarantee absolute security, but we work to protect your information using the measures above.


9. DATA RETENTION

We retain personal data for as long as necessary to provide the Services and for the purpose it was collected, and generally:

We may retain data longer where necessary to resolve disputes, enforce our agreements, or comply with a legal obligation.


10. YOUR RIGHTS

Depending on your location, you may have the right to:

  1. Access a copy of the personal data we hold about you;
  2. Correct inaccurate or incomplete personal data;
  3. Delete your personal data, subject to legal retention requirements;
  4. Restrict or object to certain processing, including direct marketing;
  5. Port your data to another provider in a machine-readable format; and
  6. Withdraw consent at any time, where processing is based on consent.

To exercise these rights, contact us at privacy@terno.io. If you are a Customer and your request relates to a specific Merchant's records, we may direct you to that Merchant, who is generally the data controller for your booking information.

If you are not satisfied with our response, you have the right to lodge a complaint with your local data protection authority (for example, the UAE's Data Office, a EU/EEA supervisory authority, the UK Information Commissioner's Office, or South Africa's Information Regulator, as applicable to your location).


11. ADDITIONAL RIGHTS FOR U.S. RESIDENTS

If you are a resident of a U.S. state with a consumer privacy law (such as California, Colorado, or Virginia), the following additional disclosures apply:


12. CONTROLLER AND PROCESSOR ROLES

Terno acts in different capacities depending on the data involved:


13. CHILDREN'S PRIVACY

The Services are intended for business use by Merchants and their staff, who must be at least 18 years old. We do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal data, please contact us at privacy@terno.io and we will take steps to delete it.


14. COOKIES & TRACKING TECHNOLOGIES

We and our service providers use cookies and similar technologies (such as pixels and device identifiers) on our website and Merchant booking pages to:

Separately from cookies, a Merchant may choose to sync their own Customers' contact information to Google Ads or Meta Ads for that Merchant's advertising — see Section 6 ("Merchant advertising tools") for how that works and how to opt out.

You can control cookies through your browser settings. Disabling cookies may affect the functionality of the Services.


15. TERNO 3RD PARTY CALENDAR SYNC BROWSER EXTENSION

Some Merchants who already use a supported booking platform connect that account to Terno so we can synchronise bookings between the two platforms. As of the effective date of this Policy, the only supported platform is Fresha; more may be added over time. Where a Merchant is signed in to a supported platform in their own browser, they may optionally install the Terno 3rd Party Calendar Sync Chrome extension to complete that connection without re-entering their login on Terno's website.

What the extension does. After a Merchant has signed in to Fresha themselves, on Fresha's own login page, the extension reads the session cookies Fresha's website has already set in that browser (using Chrome's cookies permission, scoped only to fresha.com) and sends them once, over HTTPS, to Terno's own servers to complete the connection described above.

What the extension does not do. It never displays, requests, stores, or has access to a Merchant's Fresha password. It does not run on, or request permission for, any website other than fresha.com and Terno's own domain. It does not track browsing activity, and it makes no use of the captured session data beyond the one-time connection handshake.

This feature is optional. A Merchant who prefers not to install the extension can complete the same Fresha connection through Terno's standard, password-based sign-in flow instead.

The extension's full source code, along with a plain-language explanation of exactly what data it reads and where it sends it, is published alongside its listing.


16. THIRD-PARTY LINKS

Our Services may contain links to third-party websites or services (including payment providers and WhatsApp itself). We are not responsible for the privacy practices of those third parties. We encourage you to review their privacy policies before providing any personal data.


17. CHANGES TO THIS POLICY

We may update this Policy from time to time to reflect changes in our practices or legal requirements. We will post the updated Policy on this page and update the "Effective Date" above. If we make a material change, we will notify Merchants by email or through the Platform.


18. CONTACT US

If you have questions about this Privacy Policy or how we handle personal data, contact us at:

Terno (Gulf) FZ-LLC Email: privacy@terno.io Data Protection queries: dpo@terno.io


This Privacy Policy should be read together with our Terms of Service and Data Processing Agreement.