Privacy statement
BoothManager is booth-planning software. Using it means processing personal data — customer names, contacts, what you discussed. This page explains what we process, why, where it lives and the rights people have.
Version: 17 July 2026.
This is an honest working draft based on how the system actually runs today. It still needs review by a lawyer / data-protection officer before it is relied on, and the fields marked “to be completed” need your organisation’s legal details.
Who is responsible
Two roles, because it matters who decides what happens with the data.
- Your company is the controller for customer data
- The company using BoothManager decides which fair contacts and customers are stored and why. Heide Ventures (the company behind BoothManager) only processes that data on their instructions (a “processor”). A data processing agreement between you and Heide Ventures is being prepared.
- Heide Ventures is the controller for account data
- For the login accounts of app users (name, e-mail), Heide Ventures (KvK 30252428, trading as BoothManager) is the controller. Contact: info@boothmanager.eu. DPO details: to be completed.
What we process
- Account
- Name and e-mail address of colleagues who log in.
- Customers & fair contacts
- Name, company, role, e-mail, phone, country, notes and a tag — as entered or imported by your team.
- Planning & logistics
- Meetings and who attended, travel (arrival/departure, hotel, and a licence plate for parking), check-in times, and any badge or ticket a colleague uploads for themselves.
- No tracking
- Only functional cookies (theme, language) and the login session. No analytics, advertising or third-party tracking — so no cookie banner is needed.
Why, and on what basis
- To run the service
- Data is processed to provide booth planning to your company under our agreement with them. Login data rests on that contract and our legitimate interest in running a secure product.
- Fair contacts
- Storing leads and customers is normally based on your company’s legitimate interest (following up business contacts), or on consent where that applies. Your company sets and documents this basis as the controller.
Where it is stored
- In the EU
- Database and application both run in Frankfurt, Germany (Supabase eu-central-1, Vercel fra1). Nothing is processed outside the EU.
- Protected
- Encrypted in transit (HTTPS) and at rest (AES-256), separated per company by row-level security. See the security page for the details.
Who else touches the data
The full list of sub-processors, stated plainly.
- Supabase — database & login
- Runs on AWS in Frankfurt. Supabase Inc. is a US company; the data itself stays in the EU.
- Vercel — hosting
- Runs in Frankfurt. Vercel Inc. is a US company; the data itself stays in the EU.
- Push notifications (only if enabled)
- If a colleague turns on notifications, the browser’s push service (Google, Apple or Mozilla) delivers the alert. Only a device token and the message are involved.
How long we keep it
- While in use, until deleted
- Data is kept while the account is active and removed when you delete it or close the account. A fixed retention period per data type is still to be set by your organisation.
Your rights
Everyone whose data is processed can exercise these under the GDPR.
- Access & portability
- Ask what is stored and get a copy. Admins can export a customer’s data from the app; for other data, contact us.
- Rectification
- Have incorrect data corrected — customer and account records are editable in the app.
- Erasure
- Have data deleted. Deleting a customer removes their record and links; ask if you need a full erasure across older meetings.
- Object & complain
- Object to processing, and complain to a supervisory authority (in the Netherlands, the Autoriteit Persoonsgegevens).
Exercising a right or a question?
For customer/lead data, requests go through the company using BoothManager (the controller) and we help them. For account data or anything about this statement: info@boothmanager.eu.
← Back to home