Data processing agreement
Version dated 17 September 2026
When you use Boothcore, you place personal data about your customers in the platform. You decide why that data is there; we process it on your behalf. This agreement sets out what we may and may not do. It forms part of the terms of service and applies as soon as you open an account.
1. Parties and precedence
This agreement is made between you as controller and Sven Pelgrims, trading as Flitsbak, established at Oude Mechelbaan 59, 2220 Heist-op-den-Berg, Belgium, company number 0737.725.778, as processor.
If this agreement conflicts with the terms of service on a matter concerning personal data, this agreement takes precedence.
2. Scope of processing
| Subject matter | Providing Boothcore as software for photobooth rental and planning |
| Duration | For the duration of your subscription and the retention period in section 10 |
| Nature and purpose | Storing, organising, displaying, sending and deleting data to perform the functions you choose to use |
| Types of data | Contact details, addresses, event and booking data, quotes and invoices, payment status, messages and participant photos |
| Data subjects | Your customers and their contacts, guests at events you serve, and your own staff |
The platform is not intended for special categories of personal data. You must not deliberately enter or infer such data unless we agree this in writing beforehand and you have a valid legal basis and appropriate safeguards.
3. Your instructions
We process data only on your documented instructions. Those instructions consist of this agreement, the terms of service and the actions you take in the platform. We ask for your permission before doing anything outside that scope.
If the law requires processing without your instruction, we will tell you beforehand unless the law prohibits this. If we believe one of your instructions infringes data protection law, we will inform you.
As controller, you are responsible for a valid legal basis, clear information to data subjects and accurate data. You handle their requests and may give us documented instructions, request information, object to a new sub-processor, arrange an audit and choose between return and deletion when the service ends.
4. Confidentiality
Everyone authorised to access your data is bound by confidentiality, including after their work with us ends. Access is limited to people who need it for their role.
5. Security
We maintain appropriate technical and organisational measures. They currently include:
- Encrypted traffic between your browser and the platform.
- Passwords stored using one-way hashing; credentials for external services encrypted in the database.
- Strict separation between businesses: every request is scoped to the business for which the user is signed in.
- Blocking after repeated failed sign-in attempts.
- Access to servers and production environments limited to people who need it for their role.
These measures may evolve as long as the overall level of protection does not decrease.
6. Sub-processors
You give us general authorisation to engage sub-processors. The public page describes their categories. After signing in, you can find the current names, addresses, purposes and usage conditions under Settings → Legal & privacy.
Each sub-processor is contractually bound by the same data protection obligations set out in this agreement to the extent relevant to its services. If a sub-processor fails to meet those obligations, we remain responsible to you for its performance.
If we add or replace a sub-processor, we will notify you at least thirty days in advance. You may raise a reasoned objection within that period. If we cannot resolve it, you may cancel without charge for the unused part of your subscription.
7. Transfers outside Europe
The platform's core data is stored in the European Union. If a feature uses a supplier outside the European Economic Area, the transfer relies on a valid mechanism, such as an adequacy decision or the European Commission's Standard Contractual Clauses. We assess and implement supplementary safeguards where needed. You can request more information or a copy of the relevant safeguards via ✉ E-mail.
8. Assistance with your obligations
If someone asks to access, correct, transfer, restrict or erase their data, we assist you while taking account of the nature of the processing. You can perform many actions directly in the platform, such as finding, changing and deleting data. Contact us if reasonable additional assistance is required.
If such a request is sent directly to us, we do not decide on it ourselves; we forward it to you.
Taking account of the nature of the processing and the information available to us, we also provide reasonable assistance with security, assessing and reporting personal data breaches, data protection impact assessments and prior consultation with a supervisory authority.
9. Personal data breaches
If we become aware of a personal data breach involving your personal data, we notify you without undue delay. As information becomes available, we describe what happened, the data and data subjects involved, the likely consequences and the measures taken or proposed.
As controller, you are responsible for notifying the supervisory authority and, where required, the affected individuals. We provide the information reasonably needed for those notifications.
10. End of the service
When the service ends, we return the personal data to you in a commonly used format or delete it, at your choice. We carry out that choice within 30 days and delete remaining copies, unless European Union or Member State law requires storage.
If you need a different arrangement before the service ends, record it in good time as a documented instruction with a clear purpose and valid legal basis.
11. Audit and information
On request, we provide the information reasonably needed to demonstrate compliance with this agreement. We allow and contribute to audits by you or an independent auditor bound by confidentiality. You give reasonable advance notice and minimise disruption and access to other customers' data. Reasonable external costs are yours unless the audit identifies a material failure on our part.