Legal
Privacy Policy
Last updated: April 2026
1. Data Controller
The data controller is Terima (hereinafter "Terima", "we", "us"). For any privacy-related request, write to: infoterima.ai@gmail.com.
2. Data We Collect
When you join the waitlist, we collect:
• Your email address — to send you a confirmation link and notify you when the app launches.
• A one-way cryptographic hash of your IP address — used solely for anti-fraud purposes (detecting duplicate or fake signups). The original IP is never stored: we hash it immediately with a secret salt and discard the original.
• Your country of origin (2-letter ISO code, e.g. "IT", "US") — detected automatically from your IP address via Vercel's infrastructure at the moment of signup. We use this aggregate data solely to understand which geographic markets are interested in Terima. The original IP is not stored.
• Your referral code — if you signed up through a friend's link, to credit them the referral.
• Optional: a Cloudflare Turnstile challenge token — used once at signup time to verify you are not a bot. It is not stored.
3. Purpose and Legal Basis
We process your data to:
• Manage your position on the waitlist.
• Send you a confirmation email and, at launch, an access notification.
• Prevent fraudulent activity (multiple accounts, fake emails, bots).
The legal basis is your explicit consent, given when you tick the checkbox and submit the form (Art. 6(1)(a) GDPR), and our legitimate interest in protecting the service from abuse (Art. 6(1)(f) GDPR).
4. Service Providers (Sub-processors)
We use the following GDPR-compliant providers to operate the waitlist:
• Resend (resend.com) — sends transactional emails (confirmation, position updates).
• Supabase (supabase.com) — stores the waitlist database in EU region.
• Vercel (vercel.com) — hosts the website.
• Cloudflare (cloudflare.com) — anti-bot protection (Turnstile) and CDN.
Your data is shared with these processors only as strictly necessary to deliver the service.
5. Data Retention
We keep your data until:
• You request deletion (use the unsubscribe link at the bottom of any of our emails, or see Section 7), or
• 12 months after the app launches without you having activated an account.
The hashed IP is retained for the same period as the rest of the record. Since it cannot be reversed back to your real IP, it carries no identifiability risk.
6. No Data Selling
We do not sell, rent, or share your personal data with third parties for marketing purposes. Full stop.
7. Your Rights
Under GDPR you have the right to:
• Access the data we hold about you.
• Correct inaccurate data.
• Request deletion of your data ("right to be forgotten") — instant, via the unsubscribe link in any of our emails or the page /unsubscribe.
• Restrict or object to processing.
• Data portability.
• Withdraw consent at any time.
To exercise any of these rights, email infoterima.ai@gmail.com. We will respond within 30 days.
8. Cookies
The waitlist site does not use any tracking, analytics, or profiling cookies.
If the Cloudflare Turnstile anti-bot challenge is active, Cloudflare may set a strictly necessary session cookie (__cf_bm) for the sole purpose of distinguishing human visitors from bots. This cookie expires within 30 minutes and contains no identifiers usable for tracking.
9. Changes to This Policy
We may update this policy as the product evolves. Material changes will be communicated via email if you are on the waitlist.
© 2026 Terima. All rights reserved.
