Personal data
Privacy policy
This policy explains how BISTROTS.be processes personal data on its website and application.
Last updated: 10 August 2026
1. Controller and contact
The controller is NPMA SRL, Belgian company number/VAT BE 0508.450.739, Clos de la Pépinière 5, 1420 Braine-l’Alleud, Belgium.
For questions or to exercise your rights, contact privacy@npma.be. The designated Data Protection Officer is Philippe Dupriez, reachable at the same address.
2. Data we process
We only process data necessary for the features you use.
- Account and profile data: first name or nickname, email, encrypted password, phone number, date of birth, picture and preferences.
- Social-login data: identifier, name, email and picture when you use Facebook, Google or Apple.
- Outing data: outings created or joined, messages, check-ins, invitations, friends and preferences.
- Location: city, approximate or precise location when authorised in device settings.
- Technical data: IP address, device identifiers, security logs, usage data, cookies, analytics and crash reports.
3. Purposes and legal bases
We use data to create and secure your account and provide outings, messages, invitations and check-ins: performance of a contract.
We prevent fraud, misuse and security incidents: legitimate interest or legal obligation. We improve the service and fix errors: legitimate interest or consent where required.
Marketing communications, non-essential cookies and personalised advertising are based on consent, which you may withdraw at any time.
4. Visibility, recipients and transfers
Your first name or nickname, picture, availability, outings and location linked to an outing may be visible to other users according to your settings. We do not provide venues with your personal data.
We may use processors for hosting, databases, authentication, maps, emails, notifications, payments, support, analytics, security and advertising. They act only on our instructions. Meta, Google and Apple also process some data under their own policies.
Some providers may process data outside the EEA. We use a recognised transfer mechanism, including an adequacy decision or European Commission standard contractual clauses.
5. Cookies and communications
Strictly necessary cookies run the website. Analytics, social-media and advertising cookies are set only after consent where required. You can change choices in the cookie tool or browser settings.
We may send essential service messages. You can unsubscribe from marketing or object to it at any time, free of charge.
6. Retention
- Active account: up to one year of inactivity.
- Messages and outing history: up to two years.
- After a deletion request: active data erased or anonymised within 24 hours, except where legal, rights-defence or security retention is necessary.
- Backups: deleted no later than one month after replacement.
7. Children
BISTROTS may be used by minors. For consent-based processing, a user under 13 must obtain authorisation from a parent or legal guardian. We take reasonable verification measures where necessary.
8. Profiling and automated decisions
We may use automated systems to recommend relevant outings, people or places, personalise the experience and detect misuse. These may use location, preferences and in-app activity.
No decision producing legal effects or significantly affecting a person is made solely by automation without applicable safeguards. You may request human intervention or challenge a decision at privacy@npma.be.
9. Your rights
You may request access, rectification, erasure, restriction, portability or object to processing, notably direct marketing. You may withdraw consent at any time.
Write to privacy@npma.be. We may request reasonable proof of identity. You may lodge a complaint with the Belgian Data Protection Authority.
10. Security and updates
We apply appropriate technical and organisational measures. We may update this policy and will notify you of material changes by an appropriate means.