USM Boarding Privacy Notice
Controller: Maxamaze BV, a private limited liability company (besloten vennootschap) incorporated under the laws of Belgium, with registered office at Doortstraat 22, unit 25, 1745 Opwijk, Belgium, enterprise number BE 0899.080.429.
Contact for privacy matters: hello@maxamaze.com
Version 1.1, effective 22 September 2026
1. What this notice covers
This notice explains what personal data Maxamaze processes when you use USM Boarding: the desktop application, the online account and project builder, the public website, and the support and billing that go with them. It sits alongside the End User Licence Agreement, which governs the licence itself.
USM Boarding is sold to organisations, not to consumers. In practice the people whose data we process are the staff of our customers: operators at a venue, administrators of an account, and the people they invite.
2. Two roles, and why the difference matters
We handle personal data in two distinct capacities, and your rights are exercised differently in each.
As controller. For the account, the licence, billing, security and product diagnostics, we decide why and how the data is processed. This notice describes that processing, and you can exercise your rights against us directly (section 10).
As processor. Any personal data that appears inside Customer Content, meaning the artwork, video, playlists, project data and text that a customer uploads or plays out, is processed on that customer's instructions. The customer is the controller. We do not decide what goes into it and we do not use it for our own purposes. If you are, for example, a player or an employee whose image appears in content played out through USM Boarding, please contact the organisation that operates the screens. We will assist them in responding to you (section 14).
3. What we collect
3.1 Account and organisation data
Your email address, an encrypted (hashed) form of your password, the account and organisation you belong to, your role, whether your email has been verified, when your account was created, and when you last signed in. If someone invites you to an account, we hold the email address the invitation was sent to until it is accepted or withdrawn.
3.2 Billing data
Your billing contact details, VAT number, subscription configuration (base licence, extra screens, backup PC), billing interval, invoices and payment status.
Payments are handled by Stripe. We never see or store full card numbers. Stripe processes the card and returns only a reference, the last digits and the card brand.
3.3 Licence and machine data
To validate a licence and enforce entitlements, the desktop application sends us the licence key, a machine identifier derived from the computer's hardware characteristics, the application version, and basic operating status. We store the resulting validation record, including when a machine last validated successfully.
The machine identifier identifies a computer, not a person. Where a machine is used by one named operator it may nevertheless be capable of being linked to that person, so we treat it as personal data.
3.4 Session and security data
When you sign in, we record the session, its expiry, the IP address and the browser or device user agent used. Desktop sessions expire automatically after 90 days at most. We keep a record of administrative actions taken on an account for audit purposes.
3.5 Diagnostic and log data
The application records playout and system events, errors and crashes. Where enabled, it uploads a compressed log bundle to us, including the previous session's logs after a computer shuts down uncleanly.
These logs are technical. They can nevertheless contain, incidentally, the names of projects, playlists, media files, screens and network hosts that an operator chose. Please avoid putting information in those names that you would not want us to see.
We use logs to diagnose faults, to fix defects, to answer support requests and to plan capacity. We do not sell them, and we do not use customer data to train machine-learning models.
3.6 Support correspondence
Emails and messages you send us, and our replies, together with any screenshots, files or log bundles you attach.
3.7 Website and product usage
We count how the public website and the online account are used. We do it with our own analytics software (OpenPanel, self-hosted on the same infrastructure as the rest of the service, in Amsterdam). Our website carries no third-party analytics, advertising or tracking scripts: there is no Google, no advertising network and no measurement service. No third party receives this data, we do not sell or share it, and we do not track you across other websites.
For any visitor we record the page visited and when, the site or search engine that referred you if there was one, the country, region and city looked up from your IP address (with the approximate coordinates of that city, which the lookup returns alongside them), and your device type, operating system and browser. Your IP address is used for that lookup and is not stored with the record. To recognise a returning visit without setting a cookie, the software derives an identifier from your IP address and your browser using a secret value that we rotate; it cannot be turned back into an IP address.
When you are signed in, these records also say who you are: your user identifier, your email address, your name if you have given us one, your role, and the organisation you work in. That is deliberate. It is how we see which parts of the product our customers actually use, and how we can tell what a support question is about when you tell us a page misbehaved.
If you would rather not be counted, section 5 says how a browser can be excluded, and you can object to this processing at any time (section 10).
Our hosting provider also keeps standard server logs for security and troubleshooting.
4. Why we use your data, and our legal basis
| What we do | Data used | Legal basis (GDPR Art. 6) |
|---|---|---|
| Provide the account, the cloud services and the licence | Account, licence, machine, session | Performance of a contract, 6(1)(b) |
| Take payment and manage subscriptions | Billing, account | Performance of a contract, 6(1)(b) |
| Keep statutory accounting records | Billing, invoices | Legal obligation, 6(1)(c) |
| Validate licences and enforce entitlements | Licence, machine | Performance of a contract, 6(1)(b), and our legitimate interest in preventing unlicensed use, 6(1)(f) |
| Diagnose faults and improve reliability | Diagnostics, logs, crash reports | Legitimate interest in a product that works in live production, 6(1)(f) |
| Count visits and see which parts of the product are used | Website and product usage (3.7), account | Legitimate interest in knowing what to build, support and sell, 6(1)(f) |
| Protect accounts against unauthorised access and abuse | Session, IP address, user agent, audit records | Legitimate interest in security, 6(1)(f) |
| Answer support requests | Support correspondence, logs | Performance of a contract, 6(1)(b) |
| Send service messages (renewal, security, incident, version notices) | Account, licence | Performance of a contract, 6(1)(b) |
| Send marketing about our products, if we ever do | Account | Consent, 6(1)(a), withdrawable at any time |
| Defend or bring legal claims | As relevant | Legitimate interest in establishing and defending claims, 6(1)(f) |
Where we rely on a legitimate interest, we have weighed it against your interests and rights. You may object to that processing at any time (section 10).
5. Cookies and local storage
We use strictly necessary cookies only: an HttpOnly cookie holding your sign-in refresh token, and a companion cookie that protects against cross-site request forgery. Both exist to keep you signed in safely. Neither is used for advertising or measurement.
Our analytics is cookieless. It sets nothing on your device and reads nothing from it. It recognises a returning visit from the derived identifier described in section 3.7 instead, which is why measuring how the site is used costs you nothing to click away.
Your browser also stores a short list of recently opened projects locally, so that the project chooser can show them. That list stays in your browser and is not sent to us.
Because we set no analytics or advertising cookies, and store no identifier on your device for measurement, we do not show a consent banner. If that ever changes, we will ask for consent before setting anything beyond what is strictly necessary.
To exclude a browser from the counting altogether, set the key usm.analytics.optOut to 1 in
that browser's local storage for our site, or write to us and we will explain how. That entry
stays in your browser, and while it is there the site sends us nothing about what you look at.
6. Who we share your data with
We do not sell personal data and we do not share it for anyone else's marketing. We use the following service providers, who process data on our instructions under written terms:
| Provider | Purpose | Where |
|---|---|---|
| Fly.io | Hosting the application, API and analytics servers | Amsterdam, Netherlands |
| Neon | Managed Postgres database (accounts, licences, project metadata) | Frankfurt, Germany |
| Cloudflare R2 | Storage of media, log bundles and installer archives | Amsterdam, Netherlands |
| Stripe | Payment processing and subscription billing | European Union and United States |
| Resend or Brevo | Transactional email (verification, invitations, notices) | European Union and United States |
| GitHub | Installer and update delivery on the GitHub update channel | United States |
Our analytics provider is not on this list, because there is no analytics provider. The software (section 3.7) runs on our own servers at the hosting provider already named above, the records sit in our own databases there, and nobody else is sent a copy.
We may also disclose data to our professional advisers, to an acquirer in connection with a merger or sale of the business (subject to this notice continuing to apply), and to public authorities or courts where we are legally required to. If we are ever compelled to hand over customer data, we will tell the customer unless the law forbids it.
7. Where your data is stored, and international transfers
All of the infrastructure that holds your account, your projects and your media sits in the European Economic Area. Our application, API and analytics servers run in Amsterdam, in the Netherlands. The managed database is hosted in Frankfurt, in Germany. Object storage, meaning media, log bundles and installer archives, is in Amsterdam, in the Netherlands.
Three of our providers may nevertheless process limited personal data in the United States: Stripe (billing contact details and payment records), our transactional email provider (the recipient address and the content of service emails), and GitHub (the request a desktop makes when it downloads an installer on the GitHub update channel). For those transfers we rely on the European Commission's standard contractual clauses, or on an adequacy decision where one applies, together with the provider's own supplementary measures such as encryption in transit and at rest. You can ask us for details of the safeguards in place.
We do not transfer Customer Content held in the cloud services outside the European Economic Area.
8. How long we keep it
| Data | Retention |
|---|---|
| Account and organisation data | For the life of the account, then deleted within 30 days |
| Customer Content in the cloud | 30 days after the licence ends, matching the export window in the EULA, then deleted |
| Web and desktop sessions, including IP address and user agent | Until the session expires; desktop sessions expire after 90 days at most |
| Routine session log bundles | Rolling: only the most recent bundles per machine are kept, older ones are pruned automatically |
| Crash and incident reports | Kept until the incident is resolved and no longer needed, then deleted by an administrator |
| Website and product usage records (3.7) | 12 months, then deleted automatically by the analytics database itself |
| The record of who a signed-in person is, held by the analytics (name, email, organisation) | Kept while you hold an account with us, and deleted on request (section 10) |
| Billing, invoices and accounting records | 7 years, as Belgian accounting law requires |
| Support correspondence | 3 years after the matter is closed |
| Audit records of administrative actions | 3 years |
Where a longer period is required by law, or where data is needed for a legal claim that is live, we keep it for as long as that requires and no longer.
9. How we protect it
Traffic is encrypted in transit. Passwords are stored only as salted hashes and are never recoverable in readable form. Sign-in tokens are held in HttpOnly cookies with cross-site request forgery protection. Credentials stored on an operator's computer are encrypted using the operating system's own protected storage. Access to production systems is restricted to the people who need it, and administrative actions are logged.
No system is perfectly secure. If a personal data breach occurs that is likely to result in a risk to people's rights, we will notify the Belgian Data Protection Authority within 72 hours and, where the risk is high, tell the people affected without undue delay. Where the breach concerns a customer's data, we will inform that customer without undue delay so they can meet their own obligations.
10. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you, and receive a copy;
- have inaccurate data corrected;
- have data erased, where we no longer have grounds to keep it;
- restrict processing while a dispute about it is resolved;
- receive data you gave us in a portable, machine-readable form, and have it transmitted to another controller where technically feasible;
- object to processing based on our legitimate interests, including profiling, on grounds relating to your situation; and
- withdraw consent at any time, where we rely on consent, without affecting processing carried out before you withdrew it.
To exercise any of these, write to hello@maxamaze.com. We will respond within one month, and will tell you if we need longer because the request is complex. We may need to verify your identity first. Exercising your rights is free, unless a request is manifestly unfounded or excessive.
11. Complaints
If you are unhappy with how we handle your data, please tell us first so we can put it right. You also have the right to complain to the Belgian supervisory authority:
Gegevensbeschermingsautoriteit / Autorité de protection des données Drukpersstraat 35, 1000 Brussels, Belgium contact@apd-gba.be
You may also complain to the supervisory authority where you live or work.
12. Automated decision-making
We do not make decisions producing legal or similarly significant effects about you by automated means alone, and we do not carry out profiling for such purposes. Licence validation is automated, but it evaluates a licence and a machine, not a person.
13. Children
USM Boarding is a professional product. It is not directed at children and we do not knowingly collect data from them.
14. When we act as processor
Where we process Customer Content on a customer's behalf (section 2), we act only on that customer's documented instructions, we impose confidentiality on the people who handle it, we apply the security measures in section 9, we engage sub-processors only under equivalent terms, and we assist the customer with data subject requests, breach notification and impact assessments. On the customer's instruction we delete or return the content at the end of the relationship, subject to the 30 day export window.
Our data processing terms set this out in full and form part of the EULA. A signed copy is available on request.
15. Changes to this notice
We may update this notice as the product or the law changes. If a change materially affects how we use your data, we will tell account holders by email or in the application before it takes effect, and we will update the version and date at the top. Earlier versions are available on request.
16. Contact
Maxamaze BV, Doortstraat 22, unit 25, 1745 Opwijk, Belgium Enterprise number BE 0899.080.429 Privacy and legal: hello@maxamaze.com · Support: thibaut@maxamaze.com
USM Boarding · Vendor: Maxamaze BV · Powered by MAXAMAZE®