Data Processing Agreement

Processor: Maxamaze BV, a private limited liability company (besloten vennootschap) incorporated under the laws of Belgium, with registered office at Doortstraat 22, unit 25, 1745 Opwijk, Belgium, enterprise number BE 0899.080.429 ("Maxamaze").

Controller: the organisation that holds a licence for USM Boarding under the End User Licence Agreement ("Customer", "you").

Version 1.0, effective 22 August 2026

This agreement is concluded when you accept the End User Licence Agreement, and forms part of it. A countersigned copy is available on request from hello@maxamaze.com.


1. Why this agreement exists

Article 28(3) of the General Data Protection Regulation requires a written contract wherever one party processes personal data on behalf of another. When Maxamaze stores and serves the artwork, video, project data and text that you upload to USM Boarding, some of that material can contain personal data, and Maxamaze processes it on your instructions. This agreement sets out the terms the GDPR requires for that processing.

2. Which data this covers, and which it does not

Covered. "Customer Personal Data" means personal data contained in Customer Content, in your projects, playlists, sequences, screen configurations and media, and in the records of the users you invite to your account, which Maxamaze processes on your behalf in providing USM Boarding. For this data you are the controller and Maxamaze is the processor.

Not covered. Maxamaze acts as an independent controller, not as your processor, for the data it processes for its own purposes: account administration, billing and statutory accounting, licence validation and entitlement enforcement, security, and product diagnostics. That processing is described in the USM Boarding Privacy Notice and is governed by it, not by this agreement.

Annex 1 sets out the subject matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subjects, as Article 28(3) requires.

3. Duration

This agreement applies for as long as Maxamaze processes Customer Personal Data on your behalf. It begins when you accept the End User Licence Agreement and ends when the processing ends under clause 10.

4. Processing on documented instructions

4.1 Maxamaze will process Customer Personal Data only on your documented instructions, including as to transfers to a third country, unless required to do otherwise by European Union or Member State law. Where such a law applies, Maxamaze will inform you before processing, unless that law prohibits it on important grounds of public interest.

4.2 Your instructions are: this agreement, the End User Licence Agreement, the documented functions of the product as you configure and operate them, and any further written instruction you give. Operating the product is itself an instruction: uploading media, building a playlist, syncing a project or playing out content instructs Maxamaze to store, transmit, render and serve that content.

4.3 Maxamaze will inform you if, in its opinion, an instruction infringes the GDPR or other applicable data protection law. Maxamaze may suspend the affected processing until the instruction is withdrawn, confirmed or changed.

4.4 Maxamaze will not use Customer Personal Data for its own purposes. It will not sell it, will not use it for advertising, and will not use it to train machine-learning models.

5. Your responsibilities

5.1 You warrant that you have a lawful basis for the processing you instruct, that you have given the notices and obtained any consents required, and that you hold the rights and clearances needed for the content you upload and play out.

5.2 You are responsible for what goes into Customer Content. Maxamaze does not choose it, does not monitor it, and cannot know from the file itself whether an image contains an identifiable person.

5.3 You must not use USM Boarding to process special categories of personal data under Article 9, or data relating to criminal convictions under Article 10, unless you have agreed this with Maxamaze in writing beforehand. The product is not designed for it and Annex 2 is not calibrated to it.

6. Confidentiality

Maxamaze will ensure that every person authorised to process Customer Personal Data is bound by an appropriate obligation of confidentiality, and will limit access to those who need it to provide the service, to support you, or to keep the service secure.

7. Sub-processors

7.1 You give Maxamaze general written authorisation to engage sub-processors. The sub-processors engaged at the effective date of this agreement are listed in Annex 3.

7.2 Maxamaze will impose on each sub-processor, by written contract, data protection obligations no less protective than those in this agreement. Maxamaze remains fully liable to you for the performance of its sub-processors' obligations.

7.3 Maxamaze will give you at least 30 days' notice before adding or replacing a sub-processor. Notice is given by email to your account's administrative contact.

7.4 You may object to a new sub-processor within that 30 day period on reasonable grounds relating to data protection. Maxamaze will work with you in good faith to resolve the objection. If it cannot be resolved, you may terminate the affected part of the service and receive a pro-rata refund of fees prepaid for the unused period.

8. Security

8.1 Maxamaze will implement and maintain the technical and organisational measures set out in Annex 2, taking account of the state of the art, the costs of implementation, and the nature, scope, context and purposes of the processing, as Article 32 requires.

8.2 Maxamaze may update those measures as the product and the threat landscape change, provided the level of protection is not reduced. The current version of Annex 2 is available on request.

9. Assisting you

9.1 Data subject requests. Taking account of the nature of the processing, Maxamaze will assist you by appropriate technical and organisational measures, insofar as possible, to respond to requests to exercise rights under Chapter III of the GDPR. If a data subject contacts Maxamaze directly about Customer Personal Data, Maxamaze will not respond substantively. It will refer them to you and tell you without undue delay.

9.2 Personal data breach. Maxamaze will notify you without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. The notification will describe the nature of the breach, the categories and approximate number of data subjects and records concerned so far as known, the likely consequences, the measures taken or proposed, and a contact point for further information. Where the full picture is not yet available, Maxamaze will provide it in phases as the investigation progresses.

9.3 Impact assessments. Maxamaze will provide reasonable assistance with data protection impact assessments and any prior consultation with a supervisory authority, insofar as they relate to processing by Maxamaze and taking into account the information available to it.

9.4 Assistance under this clause is provided at no charge where the request is proportionate. Maxamaze may charge a reasonable fee for assistance that is excessive or repetitive.

10. Deletion and return

10.1 On expiry or termination of the End User Licence Agreement, you may export your project data and media during a 30 day window, matching the End User Licence Agreement.

10.2 At the end of that window, Maxamaze will delete Customer Personal Data from its live systems, unless European Union or Member State law requires it to be kept. Backups are overwritten on their ordinary cycle and are not selectively edited; data present in a backup is deleted when that backup expires.

10.3 Maxamaze will certify deletion in writing on request.

11. Audits and information

11.1 Maxamaze will make available to you the information necessary to demonstrate compliance with Article 28, and will allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate.

11.2 In practice, Maxamaze will first provide its current security documentation, Annex 2, and written answers to a reasonable security questionnaire. Where that does not answer your question, you may conduct an audit subject to the following: not more than once in any 12 month period, unless a supervisory authority requires otherwise or a breach has occurred; on at least 30 days' written notice; during business hours; without unreasonable disruption; and subject to confidentiality. Each party bears its own costs.

11.3 An audit may not require Maxamaze to disclose another customer's data, or information that would compromise the security of its systems or of its other customers.

12. International transfers

12.1 Customer Personal Data is stored in the European Economic Area. The application and API servers are in Amsterdam, in the Netherlands, the managed database is in Frankfurt, in Germany, and object storage is in Amsterdam, in the Netherlands.

12.2 Maxamaze will not transfer Customer Personal Data outside the European Economic Area without first putting in place a valid transfer mechanism under Chapter V of the GDPR, being an adequacy decision or the European Commission's standard contractual clauses, together with any supplementary measures a transfer impact assessment shows to be necessary.

12.3 Where a sub-processor listed in Annex 3 processes data outside the European Economic Area, the mechanism relied on is stated in that annex.

13. Liability

Each party's liability under this agreement is subject to the limitations and exclusions in the End User Licence Agreement. Nothing in this clause limits either party's liability to a data subject, or its liability under Article 82 of the GDPR, in a way the GDPR does not permit.

14. Precedence and general

14.1 This agreement forms part of the End User Licence Agreement. If there is a conflict between them on the processing of Customer Personal Data, this agreement prevails.

14.2 If a supervisory authority, a court, or a change in law requires this agreement to be amended, the parties will negotiate the necessary amendment in good faith and without delay.

14.3 If any provision is held invalid, the rest remains in force.

15. Governing law

This agreement is governed by Belgian law. The Dutch-speaking courts of the judicial district of Brussels, Belgium, have exclusive jurisdiction, without prejudice to any mandatory rule that gives jurisdiction elsewhere.


Annex 1: Details of the processing

Subject matter. Provision of the USM Boarding desktop application and its associated cloud services, being the online account, project builder, media storage, synchronisation and playout support.

Duration. For the term of the End User Licence Agreement, plus the 30 day export window in clause 10.1.

Nature of the processing. Collection, storage, organisation, structuring, retrieval, transcoding, rendering, transmission, display, backup and deletion, by automated means.

Purpose. To enable you to build, store, synchronise and play out content on LED screens, and to support you in doing so.

Types of personal data. Determined by you, since you choose what to upload. Typically:

  • images and video of identifiable people appearing in sponsor artwork, player graphics, team line-ups and scoreboard content;
  • names, squad numbers and similar identifiers used in line-up, substitution and scoreboard features;
  • names and email addresses of the users you invite to your account, and their roles;
  • file, project, playlist and screen names chosen by your operators, which can incidentally contain personal data.

Categories of data subjects. Determined by you. Typically: your staff and operators; players, officials and other individuals appearing in content you play out; and representatives of your sponsors and partners.

Special categories. None, unless separately agreed in writing under clause 5.3.


Annex 2: Technical and organisational measures

Encryption in transit. Traffic between the desktop application, the web application and the API is encrypted using TLS.

Encryption at rest. Object storage and the managed database encrypt data at rest. Credentials stored on an operator's computer are encrypted using the operating system's own protected storage.

Authentication. Passwords are stored only as salted hashes and are never recoverable in readable form. Sign-in uses HttpOnly cookies with cross-site request forgery protection. Sessions expire automatically, and desktop sessions expire after 90 days at most.

Access control. Access to production systems is limited to the people who need it. Application access is scoped by account and by role, so one customer's data is not reachable from another customer's session.

Media access. Stored media is served through time-limited signed links rather than public URLs, so an object is not readable by anyone holding a stale address.

Licence integrity. Entitlement assertions are cryptographically signed and verified by the desktop application, so a tampered entitlement is rejected offline.

Logging and audit. Administrative actions on an account are recorded. Diagnostic log bundles are size-capped and scanned on upload, retained on a rolling basis, and access to them is restricted to support staff investigating an incident.

Segregation. Development and production environments are separate. Production data is not copied into development environments.

Resilience. The managed database provider maintains regular backups with point-in-time recovery. Object storage is redundant within its region.

Review. Changes to security-relevant code are reviewed before release, and the cloud surface is audited periodically, with findings tracked to closure.

Breach response. Suspected incidents are triaged on discovery, with customer notification under clause 9.2 where Customer Personal Data is affected.


Annex 3: Authorised sub-processors

Sub-processor Purpose Location Transfer mechanism
Fly.io Hosting of the application and API servers Amsterdam, Netherlands Within the EEA
Neon Managed Postgres database holding project and account metadata Frankfurt, Germany Within the EEA
Cloudflare R2 Object storage for media, log bundles and installer archives Amsterdam, Netherlands Within the EEA
Resend or Brevo Transactional email to the users you invite European Union and United States Standard contractual clauses

Stripe and GitHub are not sub-processors under this agreement. Stripe processes billing data, and GitHub serves installer downloads, in each case for processing where Maxamaze acts as an independent controller under its Privacy Notice, not on your behalf.


Signature

Where a countersigned copy is required, this agreement may be signed below. Otherwise it takes effect on acceptance of the End User Licence Agreement.

For Maxamaze BV

Name: ................................ Title: ................................

Signature: ................................ Date: ....................

For the Customer

Organisation: ................................

Name: ................................ Title: ................................

Signature: ................................ Date: ....................


Maxamaze BV, Doortstraat 22, unit 25, 1745 Opwijk, Belgium Enterprise number BE 0899.080.429 Privacy and legal: hello@maxamaze.com

USM Boarding · Vendor: Maxamaze BV · Powered by MAXAMAZE®