Privacy Policy
StartBook — operated by XaniaCode SRL Version 1.0 · Last updated 31 July 2026
1. In short
We run a booking platform for service businesses. This policy explains what we do with personal data.
The most important thing to understand is that we act in two different roles, and your rights depend on which one applies:
- When you are a business using StartBook, we decide how your account data is handled. We are the controller and this policy applies in full.
- When you are a client booking an appointment with a business that uses StartBook, that business decides what happens with your data. They are the controller; we only process it on their instructions. We are the processor. Contact the business directly, or see clause 7 below.
We do not sell personal data. We do not use your clients' data for our own marketing. We do not run advertising trackers on the platform.
2. Who is responsible
XaniaCode SRL (SRL / BV), trading as StartBook TO BE COMPLETED, TO BE COMPLETED TO BE COMPLETED, Belgium Company number: TO BE COMPLETED · VAT: TO BE COMPLETED
For anything about personal data, write to privacy@startbook.be or info@startbook.be.
We have not appointed a Data Protection Officer, because our processing does not meet the criteria in Article 37 GDPR. Requests are handled by the person responsible for the platform at the address above.
3. Data we hold about you as a business customer
Account data. Business name, chosen subdomain, the name and email address of the account owner, hashed password, and the language you use.
Business content. Locations, addresses, opening hours, services and prices, staff or resource names, and any photographs you upload. Where staff photos or names are involved, this is personal data about your staff and you are responsible for having their agreement — see clause 8.
Billing data. Subscription plan, payment status, dates, amounts, invoices, and the customer and subscription identifiers issued by our payment provider. We never see or store your full card number.
Communications. Emails and messages you send us, including support requests, and our replies.
Technical data. IP address, browser and device information, pages requested, timestamps, error traces, and security-relevant events such as failed logins.
Usage data. Which features are used and how often, for the purpose of keeping the Service working and improving it.
4. Why we use it, and on what legal basis
| What we do | Why | Legal basis (GDPR) |
|---|---|---|
| Create and run your account, publish your booking page, process appointments | To deliver what you subscribed to | Article 6(1)(b) — performance of a contract |
| Take payment, issue invoices, chase unpaid amounts | To be paid for the Service | Article 6(1)(b), and 6(1)(f) for recovery of debts |
| Send service emails: verification, confirmations, trial and payment notices | To operate the account | Article 6(1)(b) |
| Keep the platform secure, prevent abuse, investigate incidents | To protect the Service, you and your clients | Article 6(1)(f) — legitimate interest in security |
| Diagnose faults and improve reliability | To keep the Service usable | Article 6(1)(f) — legitimate interest in a working product |
| Keep accounting records and invoices | Because the law requires it | Article 6(1)(c) — legal obligation |
| Answer your support requests | To help you | Article 6(1)(b) and 6(1)(f) |
| Send occasional emails about important product changes | To inform you of things that affect your use | Article 6(1)(f), and you may object at any time |
| Defend or bring legal claims | To protect our rights | Article 6(1)(f) |
Where we rely on legitimate interest, we have weighed our interest against your rights and concluded that the processing is limited to what is necessary and does not override them. You may object at any time — see clause 10.
We do not use automated decision-making that produces legal effects for you within the meaning of Article 22 GDPR.
5. Where the data goes
We share personal data only with parties who need it to run the Service:
| Provider | What they do | Where |
|---|---|---|
| Xania Hosting | Server hosting and storage of all platform data | European Union |
| Mollie B.V. | Payment processing for subscriptions and credit purchases | Netherlands, European Union |
| CM.com | Delivery of text messages, when the SMS add-on is switched on | Netherlands, European Union |
We may also disclose data:
- to professional advisers, such as accountants or lawyers, bound by confidentiality;
- to public authorities, courts or regulators, where we are legally required to;
- to a buyer or successor if our business is transferred, in which case we will inform you and this policy continues to apply until replaced.
We do not sell personal data, and we do not share it with advertising networks or data brokers.
6. Where the data is stored
All platform data is stored on servers located in the European Union. Our payment and messaging providers are established in the EU.
If a provider ever needs to process data outside the EEA, we will only allow it under a transfer mechanism recognised by Chapter V of the GDPR — an adequacy decision, or Standard Contractual Clauses with supplementary measures where needed — and we will update the list in clause 5 before it happens.
7. When we are only the processor
Businesses using StartBook collect data about their own clients: name, email address, telephone number, appointment details, and anything the client writes in a booking note or a custom field.
For that data:
- the business is the controller — they decide why it is collected and what happens to it;
- we are the processor — we store it and act on the business's instructions, under the Data Processing Agreement that forms part of our Terms;
- we do not use it for our own purposes, do not sell it, and do not contact those clients except to deliver the messages the business has configured (booking confirmations and reminders);
- if you booked an appointment and want your data corrected or deleted, contact the business you booked with. If you cannot reach them, write to privacy@startbook.be and we will help you identify the right contact, and inform the business of your request.
8. Staff data you publish
If you add colleagues as bookable resources with their name or photograph, that is personal data about them and it becomes publicly visible on your booking page. You are the controller for that data. Make sure they know and agree, and remove them promptly when they leave.
9. How long we keep things
| Data | Kept for |
|---|---|
| Active account and its content | While the account exists |
| Account data after closure | 90 days, then permanently deleted |
| Backups containing deleted data | A further 30 days, then overwritten |
| Invoices and accounting records | 7 years, as required by Belgian law |
| Technical and security logs | 90 days |
| Support correspondence | 2 years after the last message |
| Records of messages sent (recipient, time, status) | 12 months, for billing and troubleshooting |
Data held on behalf of a business is deleted according to the business's instructions and the DPA, and in any case when their account is deleted.
10. Your rights
Under the GDPR you have the right to:
- Access the personal data we hold about you, and receive a copy.
- Rectify data that is inaccurate or incomplete.
- Erase data, where one of the grounds in Article 17 applies.
- Restrict processing in the situations listed in Article 18.
- Portability: receive data you provided in a structured, commonly used, machine-readable format, and have it sent to another provider where technically feasible.
- Object to processing based on legitimate interest, including profiling. If you object, we stop unless we can show compelling legitimate grounds that override your interests.
- Withdraw consent, where processing is based on consent, without affecting what happened before.
To exercise any of these, write to privacy@startbook.be. We reply within one month. If a request is complex we may extend by two further months and will tell you why. We may ask for information to confirm your identity, so that we do not disclose data to the wrong person. Exercising your rights is free, unless a request is manifestly unfounded or excessive.
Right to complain. If you are not satisfied, you may lodge a complaint with the Belgian supervisory authority:
Gegevensbeschermingsautoriteit / Autorité de protection des données Drukpersstraat 35 / Rue de la Presse 35, 1000 Brussels, Belgium contact@apd-gba.be · www.gegevensbeschermingsautoriteit.be
You may also complain to the authority in your own EU country of residence.
11. Security
We take the protection of your data seriously. Our measures include:
- encryption in transit using TLS for every connection to the platform;
- passwords stored only as salted one-way hashes, never in readable form;
- payment card data never touching our servers — it is handled entirely by our payment provider;
- strict separation between businesses, so one account cannot read another's data;
- access to production data limited to the people who need it, with individual accounts;
- authentication of outgoing email using SPF, DKIM and DMARC to reduce impersonation;
- regular backups, kept for 30 days;
- logging of security-relevant events and monitoring for unusual activity;
- keeping the platform and its dependencies up to date with security fixes.
No system is perfectly secure. If a personal data breach occurs that is likely to result in a risk to your rights, we will notify the supervisory authority within 72 hours where required, and inform you without undue delay when the risk to you is high.
12. Cookies and similar technology
We use a strictly necessary cookie to keep you signed in and to protect forms against cross-site request forgery. It is required for the platform to function and cannot be switched off.
We do not use advertising cookies, analytics trackers, social media pixels or third-party profiling on the platform. Because we only set strictly necessary cookies, no consent banner is required under the ePrivacy rules.
Fonts are loaded from a privacy-friendly provider that does not set cookies or log visitor IP addresses for tracking purposes.
If we ever introduce analytics or marketing cookies, we will ask for your consent first and update this policy before doing so.
13. Children
The Service is intended for businesses and is not directed at children. We do not knowingly collect data from children for our own purposes. A business using the platform may book appointments for minors; in that case the business is the controller and is responsible for the appropriate legal basis, including parental consent where required.
14. Changes to this policy
We may update this policy. The version and date at the top always tell you which text is current. If a change materially affects how we use your data, we will notify you by email before it takes effect.
15. Contact
Questions, requests or complaints:
privacy@startbook.be XaniaCode SRL, TO BE COMPLETED, TO BE COMPLETED TO BE COMPLETED, Belgium
We answer in English, Dutch, French and Romanian.