Privacy policy

Booth Beam is a B2B digital signage platform operated by MP Solutions, based in Serbia. We collect only the data necessary to provide our service — account details, billing information, device data, and usage analytics. We do not sell your data. We process it lawfully and protect it in line with the Serbian Law on Personal Data Protection and the EU General Data Protection Regulation (GDPR) where applicable.

Effective date: 5th May 2026. Last updated: 5th May 2026. Version: 1.0

1. Who We Are and How to Contact Us

Booth Beam is a cloud-based digital signage software-as-a-service (SaaS) platform developed and operated by MP Solutions, a company registered in the Republic of Serbia (hereinafter “we”, “us”, “our”, or “the Company”).

For any questions, requests, or concerns about this Privacy Policy or how we handle your personal data, please contact our designated data protection contact:

  • Company: MP Solutions
  • Address: J.Marcoka BB, 21000 Novi Sad, Serbia
  • Email: [email protected]

2. Scope and Applicability

This Privacy Policy applies to all personal data processed by MP Solutions in connection with the Booth Beam platform, including our website boothbeam.com, web application, and any associated APIs, integrations, or services (collectively, “the Service”).

Booth Beam is designed exclusively for business customers (B2B). Our direct customers are companies, organizations, and professionals who use our Service to manage digital signage displays. We do not knowingly collect data from individuals under the age of 18.

Where our customers display content through Booth Beam that involves personal data of their own end-users or audiences, our customers act as the data controller for such data, and MP Solutions acts as the data processor. This policy covers data MP Solutions controls independently as a controller.

3. Personal Data We Collect

We collect and process the following categories of personal data:

CategoryExamplesSource
Account & Identity DataFull name, business email address, job title, company name, password (hashed)Provided by you during registration
Billing & Payment DataBilling name, billing address, VAT/tax ID, payment method details (card type, last four digits, expiry)Provided by you; processed via our payment processor [Paddle]
Device & Screen DataDisplay device identifier, screen name/label, hardware model, operating system, firmware version, IP address, connectivity status, last-seen timestampAutomatically collected from registered display devices
Usage & Analytics DataFeature interactions, pages visited, content published, session duration, error logs, browser/OS typeAutomatically collected via the platform and analytics tools
User-Uploaded ContentImages, videos, HTML files, and other media uploaded to display on screensProvided by you; stored in our cloud infrastructure
Support & Communication DataMessages sent to us, support tickets, emails, feedback formsProvided by you during communication

What we do not collect: We do not collect sensitive personal data (e.g., health data, racial or ethnic origin, political opinions, biometric data). We do not collect personal data of your end-users or display audiences unless you expressly upload such content.

4. How We Use Your Data

We use the personal data we collect for the following purposes:

  • Service provision: To create and manage your account, provision and operate your digital signage displays, process subscriptions, and provide technical support.
  • Billing and payments: To process subscription fees, issue invoices, manage renewals and cancellations, and prevent fraud.
  • Device management: To register, monitor, authenticate, and communicate with your display devices.
  • Service improvement: To analyze usage patterns, fix bugs, develop new features, and improve the performance and security of our platform.
  • Communication: To send transactional emails (account confirmations, invoices, password resets), service notices, and, where you have consented, product updates and newsletters.
  • Legal compliance: To comply with applicable laws, respond to lawful requests from authorities, and exercise or defend legal claims.
  • Security: To detect, investigate, and prevent unauthorized access, fraud, abuse, and other harmful activities.

MP Solutions processes personal data in compliance with the Law on Personal Data Protection of the Republic of Serbia (“LPDP”) and, where our processing activities fall within the scope of EU data subjects, the General Data Protection Regulation (GDPR). Our legal bases are as follows:

  • Contract performance (Art. 12(1)(b) LPDP / Art. 6(1)(b) GDPR): Processing necessary to perform the service agreement with you — account management, service delivery, billing.
  • Legitimate interests (Art. 12(1)(f) LPDP / Art. 6(1)(f) GDPR): Analytics, platform security, fraud prevention, and service improvement, where our interests do not override your rights.
  • Legal obligation (Art. 12(1)(c) LPDP / Art. 6(1)(c) GDPR): Processing required by applicable law, such as retaining financial records.
  • Consent (Art. 12(1)(a) LPDP / Art. 6(1)(a) GDPR): Marketing communications and non-essential cookies, where you have given explicit, freely withdrawable consent.

6. How We Share Your Data

We do not sell, rent, or trade your personal data. We share data only in the following limited circumstances:

6.1 Service Providers (Data Processors)

We engage trusted third-party processors who act strictly on our instructions under data processing agreements:

  • [Paddle] — payment processing and subscription management
  • [Cloudflare / other] — cloud infrastructure and file storage
  • [Analytics provider, e.g., Umami] — usage analytics
  • [Email provider, e.g., MailJet / SendGrid] — transactional email delivery
  • [Support tool, e.g., Intercom / Crisp] — customer support

We may disclose your data if required to do so by applicable law, court order, or a legitimate request from a competent governmental or regulatory authority in Serbia or any other applicable jurisdiction.

6.3 Business Transfers

In the event of a merger, acquisition, sale of assets, or business restructuring, personal data may be transferred to the successor entity, subject to equivalent privacy protections and prior notice to affected users where required by law.

7. International Data Transfers

MP Solutions is based in Serbia. The European Commission has recognized Serbia as providing an adequate level of personal data protection for EU personal data transfers. Where personal data of EU/EEA data subjects is processed by our sub-processors outside the EEA without an adequacy decision, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs) approved by the European Commission.

8. Data Retention

We retain your personal data only for as long as necessary for the purposes described in this policy or as required by law:

  • Account data: Retained for the duration of your active subscription plus [30] days after account closure, to allow for reactivation or data export.
  • Billing records: Retained for 10 years in accordance with Serbian accounting and tax law.
  • Device and usage data: Retained for [12 months] from the date of collection.
  • Uploaded content: Deleted within [30 days] of account closure upon your written request.
  • Support communications: Retained for [3 years] from the date of the last interaction.

After the applicable retention period, data is securely deleted or irreversibly anonymized.

9. Data Security

We implement appropriate technical and organizational security measures to protect your personal data against unauthorized access, disclosure, loss, or destruction. These measures include:

  • Encryption of data in transit (TLS/HTTPS) and at rest (AES-256 or equivalent)
  • Secure, hashed storage of passwords (bcrypt or equivalent)
  • Role-based access controls and principle of least privilege
  • Regular security assessments and vulnerability monitoring
  • Organizational policies governing data access and handling

While we take security seriously, no method of transmission or storage is 100% secure. If you believe your account has been compromised, please contact us immediately at [email protected].

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Commissioner for Information of Public Importance and Personal Data Protection (Poverenik) within 72 hours and, where required, notify affected users without undue delay.

10. Cookies and Tracking Technologies

We use cookies and similar tracking technologies on our website and application. These include:

  • Strictly necessary cookies: Required for the platform to function (session management, authentication). These cannot be disabled.
  • Analytics cookies: Used to understand how the platform is used, which features are most popular, and where errors occur. These require your consent.
  • Preference cookies: Used to remember your settings and preferences. These require your consent.

You can manage your cookie preferences through our cookie consent banner or your browser settings. Note that disabling certain cookies may affect the functionality of the Service.

11. Your Rights as a Data Subject

Under Serbian data protection law and the GDPR (where applicable), you have the following rights with respect to your personal data:

  • Right of Access - Request a copy of the personal data we hold about you.
  • Right to Rectification - Request correction of inaccurate or incomplete data.
  • Right to Erasure - Request deletion of your data where there is no overriding legal basis to retain it.
  • Right to Restriction - Request that we restrict processing of your data in certain circumstances.
  • Right to Portability - Receive your data in a structured, machine-readable format.
  • Right to Object - Object to processing based on legitimate interests or for direct marketing.
  • Right to Withdraw Consent - Withdraw consent at any time where processing is consent-based.
  • Right to Complain - Lodge a complaint with a supervisory authority.

To exercise any of these rights, contact us at [email protected]. We will respond within 30 days. In complex cases, we may extend this by a further 60 days with prior notice. We may ask you to verify your identity before processing your request.

If you are dissatisfied with our response, you may file a complaint with the Commissioner for Information of Public Importance and Personal Data Protection of Serbia (www.poverenik.rs), or — if you are an EU resident — with the supervisory authority in your EU Member State.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or service features. When we make material changes, we will notify you via email or a prominent notice within the platform at least 14 days before the changes take effect. The updated policy will always display the new effective date at the top of this page.

Your continued use of the Service after the effective date constitutes your acceptance of the revised policy.

13. Governing Law

This Privacy Policy is governed by and construed in accordance with the laws of the Republic of Serbia, in particular the Law on Personal Data Protection (Zakon o zaštiti podataka o ličnosti, “Sl. glasnik RS”, No. 87/2018).