Privacy statement

BoothManager is booth-planning software. Using it means processing personal data — customer names, contacts, what you discussed. This page explains what we process, why, where it lives and the rights people have.

Version: 17 July 2026.

This is an honest working draft based on how the system actually runs today. It still needs review by a lawyer / data-protection officer before it is relied on, and the fields marked “to be completed” need your organisation’s legal details.

Who is responsible

Two roles, because it matters who decides what happens with the data.

Your company is the controller for customer data
The company using BoothManager decides which fair contacts and customers are stored and why. Heide Ventures (the company behind BoothManager) only processes that data on their instructions (a “processor”). A data processing agreement between you and Heide Ventures is being prepared.
Heide Ventures is the controller for account data
For the login accounts of app users (name, e-mail), Heide Ventures (KvK 30252428, trading as BoothManager) is the controller. Contact: info@boothmanager.eu. DPO details: to be completed.

What we process

Account
Name and e-mail address of colleagues who log in.
Customers & fair contacts
Name, company, role, e-mail, phone, country, notes and a tag — as entered or imported by your team.
Planning & logistics
Meetings and who attended, travel (arrival/departure, hotel, and a licence plate for parking), check-in times, and any badge or ticket a colleague uploads for themselves.
No tracking
Only functional cookies (theme, language) and the login session. No analytics, advertising or third-party tracking — so no cookie banner is needed.

Why, and on what basis

To run the service
Data is processed to provide booth planning to your company under our agreement with them. Login data rests on that contract and our legitimate interest in running a secure product.
Fair contacts
Storing leads and customers is normally based on your company’s legitimate interest (following up business contacts), or on consent where that applies. Your company sets and documents this basis as the controller.

Where it is stored

In the EU
Database and application both run in Frankfurt, Germany (Supabase eu-central-1, Vercel fra1). Nothing is processed outside the EU.
Protected
Encrypted in transit (HTTPS) and at rest (AES-256), separated per company by row-level security. See the security page for the details.

Who else touches the data

The full list of sub-processors, stated plainly.

Supabase — database & login
Runs on AWS in Frankfurt. Supabase Inc. is a US company; the data itself stays in the EU.
Vercel — hosting
Runs in Frankfurt. Vercel Inc. is a US company; the data itself stays in the EU.
Push notifications (only if enabled)
If a colleague turns on notifications, the browser’s push service (Google, Apple or Mozilla) delivers the alert. Only a device token and the message are involved.

How long we keep it

While in use, until deleted
Data is kept while the account is active and removed when you delete it or close the account. A fixed retention period per data type is still to be set by your organisation.

Your rights

Everyone whose data is processed can exercise these under the GDPR.

Access & portability
Ask what is stored and get a copy. Admins can export a customer’s data from the app; for other data, contact us.
Rectification
Have incorrect data corrected — customer and account records are editable in the app.
Erasure
Have data deleted. Deleting a customer removes their record and links; ask if you need a full erasure across older meetings.
Object & complain
Object to processing, and complain to a supervisory authority (in the Netherlands, the Autoriteit Persoonsgegevens).

Exercising a right or a question?

For customer/lead data, requests go through the company using BoothManager (the controller) and we help them. For account data or anything about this statement: info@boothmanager.eu.

Read the security details →

Back to home