Login

Privacy Policy

Last updated: 27 November 2025

At EORA Technologies Inc. ("EORA", "we", "us", "our"), we take your privacy seriously.
Please read this Privacy Policy to understand how we collect, use, and share personal data when you use the BoothPass platform ("Service", "Platform").

By using the Service, you accept the practices described here.

1. What This Privacy Policy Covers

This Privacy Policy covers how we treat personal data that we collect when you access or use the BoothPass Platform.
"Personal data" means information that identifies or relates to an identifiable individual.

This Policy does not cover the practices of third parties we do not control.
Our Terms of Service also apply to your use of the Platform.

2. Data Controller & Contact Information

Data Controller

EORA Technologies Inc.
1007 N Orange Street, 4th Floor, Suite #4478
Wilmington, Delaware 19801, USA
Email: [email protected]

EU Representative (Art. 27 GDPR)

IT.LAW GmbH
Colmantstraße 15
53115 Bonn, Germany
Email: [email protected]

UK Representative (UK GDPR)

Rickert Services Ltd UK
PO Box 1487
Peterborough PE1 9XX, UK
Email: [email protected]

3. Categories of Personal Data We Collect

We collect the following categories of personal data:

Account & Profile Data

Examples:
– Name, email
– Password hash
– Any profile details you choose to provide

Booking & Contract Data

Examples:
– Event details
– Agreement content
– Contact details of participants you enter

Device & Usage Data

Examples:
– IP address, device type, browser
– Basic usage data and interactions
– Cookies or similar technologies

Payment Data

Examples:
– Billing information
– Transaction metadata
(We do not store full card numbers. Payments are processed by our payment partners.)

Communication Data

Examples:
– Support messages
– Emails you send us

Other Data You Choose to Provide

Examples:
– Information you enter into free-form fields
– Files or details uploaded into booking workflows

Signature & Audit Trail Data

Examples:
– Timestamp of signature or confirmation
– IP address and approximate location (country, region, city) at time of signing
– Device, operating system, and browser information
– Viewing duration and interaction logs
– Consent acknowledgments and signature intent records

This data is collected when you sign or confirm a booking agreement and is used to maintain a tamper-evident audit record for verification, fraud prevention, and dispute-resolution purposes.

We do not intentionally collect sensitive data, biometric data, or children's data.

4. Sources of Personal Data

We collect personal data from:

You

  • When you create an account
  • When you create bookings or enter agreement details
  • When you communicate with us
  • When you use the Platform and data is collected automatically

Third Parties

  • Payment providers
  • Analytics or infrastructure providers
  • Other users when they include you in a booking workflow

5. How We Use Personal Data

We use personal data for the following business purposes:

Providing and Operating the Platform

  • Managing your account
  • Facilitating bookings and agreements
  • Storing and displaying booking history
  • Processing payments (through our payment partners)

Improving and Personalizing the Platform

  • Understanding how the Platform is used
  • Developing new features
  • Conducting internal analytics

(Where required, analytics operates based on your consent.)

Supporting You

  • Responding to messages
  • Sending service-related communications

Security and Fraud Prevention

  • Detecting and preventing unauthorized or fraudulent activity
  • Protecting the Platform, agreements, and users
  • Creating audit records when agreements are signed or confirmed, including technical metadata, to verify authenticity and support dispute resolution

Where required, these processing activities are based on our legitimate interests (Art. 6(1)(f) GDPR) in preventing fraud and maintaining contractual integrity, and where applicable, to comply with legal obligations (Art. 6(1)(c)).

Legal and Compliance

  • Meeting legal obligations
  • Enforcing our Terms
  • Responding to lawful requests

We will not use your personal data for purposes materially different from those described without providing notice.

6. How We Share Personal Data

We share personal data with the following categories of recipients:

Service Providers

Companies that help us operate the Platform, such as:

  • Hosting and infrastructure providers
  • Authentication and database providers
  • Analytics services
  • Email delivery providers
  • Payment processors

A current list of subprocessors is available at: Vendor list

Parties You Interact With

  • Other users when you create or participate in a booking
  • Parties you authorize to access booking information

Legal and Compliance

  • Authorities when legally required
  • Third parties when needed to enforce our Terms or protect rights

Business Transfers

If we undergo a merger, acquisition, or similar event, personal data may be transferred as part of that transaction.

Aggregated or De-Identified Data

We may use anonymized or aggregated data for analytics or business purposes.
This data cannot identify you.

We do not sell personal data.

7. Cookies and Tracking

We use cookies and similar technologies to operate and improve the Platform.
These may include:

  • Essential cookies (required for login, security, and basic functionality)
  • Optional analytics cookies (if enabled through consent tools)

You can manage cookie preferences through your browser or through our cookie settings interface.

8. International Data Transfers

We may process personal data outside your home country, including the United States.
Where required, transfers rely on recognized safeguards such as Standard Contractual Clauses.

9. Data Retention

We retain personal data as long as necessary to provide the Platform or meet legal requirements. When data is no longer needed, we delete or de-identify it.

Audit trail data linked to signed agreements is retained for up to seven (7) years after the agreement is completed or closed. Because this data forms part of a tamper-evident legal record, it may be retained even if an associated account is deleted, where necessary to comply with legal obligations, resolve disputes, prevent fraud, or enforce our Terms.

Where possible and appropriate, such data may be archived or restricted rather than deleted.

10. Your Rights (GDPR/UK GDPR)

Depending on your location, you may have the right to:

  • Access your personal data
  • Correct inaccurate data
  • Request deletion
  • Restrict processing
  • Object to processing
  • Withdraw consent (for consent-based processing)
  • Request data portability
  • Lodge a complaint with a supervisory authority

To exercise these rights, contact: [email protected]

11. Children's Privacy

The Service is not intended for individuals under 18.
We do not knowingly collect data from minors.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time.
If changes are material, we will notify you through the Platform or by email.
Continued use of the Service indicates acceptance of the updated Policy.

13. Contact

For questions about this Privacy Policy or our data practices, contact:

EORA Technologies Inc.
Email: [email protected]
1007 N Orange Street, Suite #4478
Wilmington, Delaware 19801, USA