Legal · Privacy

Privacy policy.

Applies to the Tern connector and MCP server · Last updated 5 October 2026

01

Who we are

Tern is a service of SurplusMap AS, a company registered in Norway, with its office in Oslo. SurplusMap AS is the data controller for the personal data described in this policy. Contact us at support@surplusmap.com.

02

What this policy covers

This policy covers the Tern MCP server and the Tern connector for AI assistants such as Claude. It explains what happens to your data when you connect Tern and when an assistant calls its tools for you.

03

What we collect

DataWhy we collect it
Account details: name, work email, company and team, from your SurplusMap accountTo sign you in and apply your team's plan
Sign-in tokens issued when you connect TernTo check each request comes from you
Request logs: which tool was called, its inputs (for example station IDs, dates, coordinates and place names), time, team, result status and a request IDTo count usage against your quota, fix errors, prevent abuse and keep the service secure
Support messages you send usTo answer you

We receive only the inputs an assistant sends to a Tern tool. We do not receive your conversation, your prompts, files you share with the assistant or the assistant's replies.

04

The charging data Tern returns

Tern returns statistics about public charging stations: sessions, charging minutes, utilisation, peaks and comparisons. We build these from public charge point status data. They describe stations and charge points. They do not identify drivers, vehicles or payment cards.

When a tool computes an answer, the detailed observations behind it are held in temporary storage for that call only and deleted before the answer is returned.

05

Legal basis

  • Contract: we process account details and sign-in tokens to provide the service your team has agreed to use.
  • Legitimate interests: we keep request logs to run, secure and improve the service and to enforce usage limits.

06

Who we share it with

We share data only with providers that run the service for us, under data processing agreements:

  • Google Cloud (hosting and data storage, EU region)
  • Supabase (sign-in and account management)

The results a tool returns go back to the AI assistant you use, such as Claude. How that provider handles your conversation is covered by its own terms and privacy policy.

We may disclose data if the law requires it. We do not sell personal data and do not use it for advertising.

07

Where data is stored

We store data in the European Economic Area. If a provider processes data outside the EEA, we rely on the European Commission's standard contractual clauses or another lawful transfer mechanism.

08

How long we keep it

DataKept for
OAuth sign-in attemptsEntries older than 10 minutes
Tern OAuth authorization codesCodes are valid for 10 minutes, and deleted within 90 days after the code closes
Sign-in tokensUntil they expire or you disconnect Tern
Request logs12 months
Calculation data for a single callDeleted before the call returns
Support messagesUp to 24 months after the case is closed

09

Security

All traffic to Tern is encrypted with HTTPS. Every request needs a valid sign-in token or API key. Access to stored data is limited to staff who need it to run the service.

10

Your rights

You can ask us to give you a copy of your personal data, correct it, delete it, limit how we use it, or object to processing based on legitimate interests. You can also ask for your data in a portable format. Email support@surplusmap.com and we will reply within 30 days.

You can disconnect Tern at any time in your AI assistant's connector settings. You also have the right to complain to the Norwegian Data Protection Authority (Datatilsynet) at datatilsynet.no.

11

Children

Tern is a business service and is not meant for anyone under 18.

12

Changes

If we change this policy, we update the date at the top. If a change materially affects how we use your data, we tell account holders by email before it takes effect.