Privacy Policy

Last Updated: June 8, 2026

1. Data Controller

Boost360 DH (hereinafter "we", "Controller"), operating the BoostSEO platform, is the data controller for personal data collected through this site and the SaaS platform. Contact: privacy@boostseo.ai.

2. Categories of data processed

  • Account data: name, email, encrypted password, profile photo.
  • Support data: messages sent to our team, attachments.
  • Technical/usage data: IP address, device identifiers, application logs, product events.
  • Linked site data: URLs, public content, SEO keywords, and metrics you connect to the platform.
  • Billing data: managed directly by Paddle (Merchant of Record); we only receive customer identifiers, subscription status, and invoices.

3. Purposes and legal bases

  • Account creation and service delivery — performance of contract.
  • Billing and subscription management — performance of contract / legal obligation.
  • Security, fraud prevention, and abuse — legitimate interest.
  • Product improvement and aggregate analysis — legitimate interest.
  • Customer support — performance of contract.
  • Direct marketing and newsletters — consenso (revocable at any time).

4. Recipients and data sharing

We share personal data with the following categories of recipients:

  • Paddle.com Inc. / Paddle.com Market Ltd. — our Merchant of Record for sales, subscription management, payments, tax compliance, and billing.
  • Hosting and cloud infrastructure providers (e.g., Supabase, Cloudflare) as data processors.
  • Analytics and monitoring providers for Service performance and diagnostics.
  • AI Providers for processing prompts and content via language models, exclusively to provide requested AI functionalities.
  • Professional consultants (legal, tax, accounting).
  • Competent authorities when required by law.

5. Retention

We retain account data for the duration of the contractual relationship and for 24 months after closure, except for longer legal obligations (e.g., billing: 10 years). Usage data is kept in identifiable form for 12 months, then anonymized.

6. Extra EU/EEA transfers

Some providers (e.g., Paddle, AI providers) may process data outside the EU/EEA. In such cases, we apply Safeguards provided by GDPR: adequacy decisions, standard contractual clauses approved by the EU Commission, and supplementary technical measures.

7. Data subject rights (GDPR)

You have the right to: access, rectification, erasure, restriction, portability, objection, withdrawal of consent, and to lodge a complaint with the Supervisory Authority (Privacy Guarantor). We respond within 1 month. Write to privacy@boostseo.ai.

8. Security

We adopt appropriate technical and organizational measures: encryption in transit (TLS) and at rest, role-based access controls, logging, environment segregation, and periodic dependency reviews.

9. Cookies

We use essential technical cookies for authentication and security, and (subject to consent) analytical cookies to improve the Service. You can manage preferences from the cookie banner or browser settings.