Data Processing Agreement
BoostGood Data Processing Agreement
Version: 2.0
Effective date: 15 July 2026
Last updated: 15 July 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service ("Agreement") between:
- Controller: The organization subscribing to the BoostGood Service ("Client," "Controller," or "you")
- Processor: Except Integrated Sustainability BV, operating the BoostGood platform ("BoostGood," "Processor," "we," or "us")
This DPA is entered into pursuant to Article 28 of the General Data Protection Regulation (EU) 2016/679 ("GDPR") and governs the processing of personal data by BoostGood on behalf of the Controller in connection with the Service. It should be read alongside the BoostGood Privacy Policy v2.0, which describes the two-plane data architecture in full.
Architecture note. BoostGood operates on a two-plane model. The central plane (portal, billing, account management) is operated by BoostGood and is the subject of this DPA. The tenant plane (your dedicated VPS running LibreChat, Nextcloud, n8n, and the knowledge base) is your own server: you are both controller and operator of that server. BoostGood's role there is infrastructure provider, and our access to it is constrained as described in Section 4. This distinction changes what counts as GDPR "processing by the processor" and what does not.
1. Definitions
1.1. "Personal Data" means any information relating to an identified or identifiable natural person, as defined in GDPR Article 4(1).
1.2. "Processing" means any operation performed on Personal Data, as defined in GDPR Article 4(2).
1.3. "Central Plane" means the BoostGood-operated portal, billing system, account management infrastructure, and any other systems hosted centrally by BoostGood.
1.4. "Tenant Plane" means the dedicated virtual private server (VPS) provisioned for the Controller, on which the Controller's applications run. The Controller is the operator of the Tenant Plane.
1.5. "Sub-Processor" means any third party engaged by BoostGood to process Personal Data on behalf of the Controller in connection with the Central Plane.
1.6. "Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data.
1.7. "Service" means the BoostGood AI agent ecosystem platform as described in the Terms of Service.
1.8. "Supervisory Authority" means the competent data protection authority, in particular the Autoriteit Persoonsgegevens (Dutch Data Protection Authority).
2. Subject Matter and Duration
2.1. Subject matter. This DPA governs BoostGood's processing of Personal Data in the Central Plane on behalf of the Controller. It does not govern data that the Controller stores on the Tenant Plane, over which the Controller exercises independent control as operator of that server.
2.2. Duration. This DPA remains in effect for the duration of the Agreement, plus the 90-day archive period following termination, plus any additional period required to delete or return Personal Data in accordance with Section 12.
2.3. Termination. This DPA automatically terminates when BoostGood no longer processes Personal Data on behalf of the Controller.
3. Scope of Processing: Two Planes Explained
3.1. Central Plane: what BoostGood processes on your behalf
BoostGood processes the following Personal Data in the Central Plane on behalf of the Controller:
- Account information: names, email addresses, organization details, hashed passwords, and user roles for accounts in the BoostGood portal
- Billing and order data: billing addresses, order records, plan selections, payment method details (processed by Stripe), and invoice records
- Platform health metrics: CPU load, memory use, disk use, uptime, container status, and error events collected from the Tenant Plane. These metrics contain no conversation content and no file content; they describe machine state only
- Usage and credit accounting: login timestamps, session activity, AI model selections, token counts, and credits charged. Credit accounting records the fact and size of a request; it does not store message content
- Support communications: tickets, emails, and messages between the Controller and BoostGood
- Knowledge-base metadata (not content): file name, size, owner identifier, and processing status for documents managed via the portal. Document content lives on the Tenant Plane
- Technical data: IP addresses, browser type, and session identifiers associated with portal access
Beta caveat: portal-native agent conversations. Some agents can be used directly inside the BoostGood portal (the "quick chat" panel on the dashboard). For these in-portal agents, conversation text is currently stored in BoostGood's central database. This is the one category of conversation content held centrally today. We are working to remove this after beta. See also Section 3.7 of the Privacy Policy v2.0.
3.2. Tenant Plane: data the Controller operates independently
The conversations, files, documents, and application data held in LibreChat, Nextcloud, n8n, and the knowledge base live on the Controller's dedicated VPS. BoostGood does not collect, store, or process this data in the Central Plane, and keeps no copy of it. The Controller is the operator of the Tenant Plane and is responsible for its lawful use. Two limited technical interactions are disclosed honestly:
- AI query routing: when a user submits a query to an AI model, the query text is transmitted from the Tenant Plane to the relevant third-party model provider (see Section 9 and Section 10). This transmission passes through our gateway only for routing and credit metering; we do not retain the content
- Infrastructure access during beta: see Section 4.3
Because the Controller operates the Tenant Plane independently, this DPA does not govern data held there. The Controller is responsible for its own GDPR compliance in respect of that data, including providing appropriate notices to its own users.
3.3. No "processing" claim where none exists
Earlier versions of this DPA listed conversation content and uploaded files as data processed by BoostGood. That was inaccurate for the architecture in place since March 2026. This version corrects that statement. BoostGood does not process conversation content or uploaded files from the Tenant Plane in the GDPR Article 4(2) sense, other than the transit routing described in Section 3.2 and the beta caveat in Section 3.1.
4. Access to the Tenant Plane
4.1. Infrastructure actions without entering the system
Two actions are unilateral and occur at the infrastructure level, without logging into your server or reading its contents:
- Suspend access, for non-payment or at your request. This is a status change; your data is untouched.
- Delete the server, for non-payment after notice, a legal requirement, or your request. Deletion destroys the server through the hosting provider's controls. We do not read its contents to delete it.
4.2. Support access is granted by the Controller and is time-limited
When the Controller wants BoostGood to look at its system to help with a problem, the account administrator switches on a support session from the portal settings. This generates a time-limited token (24 hours by default, up to 7 days maximum) that authorizes support actions on the Tenant Plane. The Controller can end the session at any time, revoking the token immediately. Without an active session that the Controller has enabled, support-level access to the Tenant Plane is refused.
4.3. Beta caveat on retained administrative access
Beta caveat. During the beta period, BoostGood retains a technical administrative access path to each Tenant Plane for provisioning, automated health metrics, and emergency support. In practice this means (a) a shared administrative SSH key used by our provisioning and monitoring systems, and (b) automated health checks that read machine metrics (not content) on a schedule. We use this to set up each server, keep it healthy, and resolve issues quickly during the early period.
Our committed direction for general availability is to move health metrics to a push model (the Tenant Plane reports to us rather than us reaching in) and then remove the standing administrative key, so that after beta the only way into a running Tenant Plane is a support session the Controller grants. We describe the current state honestly here rather than claim an absolute we cannot yet back in code. See also Section 4.3 of the Privacy Policy v2.0.
5. Obligations of the Processor
BoostGood shall:
5.1. Process Personal Data in the Central Plane only as necessary to provide the Service and as described in Section 3.1, unless required to do so by EU or Dutch law.
5.2. Ensure that persons authorized to access Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
5.3. Implement and maintain appropriate technical and organizational measures to ensure a level of security appropriate to the risk, as described in Annex B.
5.4. Respect the conditions for engaging Sub-Processors as set out in Section 9.
5.5. Assist the Controller, by appropriate technical and organizational measures and to the extent possible, in fulfilling the Controller's obligations to respond to requests from data subjects exercising rights under GDPR Chapter III, in respect of data held in the Central Plane.
5.6. Assist the Controller in ensuring compliance with GDPR Articles 32 to 36, taking into account the nature of processing and the information available to BoostGood.
5.7. At the Controller's choice, delete or return all Personal Data in the Central Plane after the end of the provision of services, in accordance with Section 12, and delete existing copies unless EU or Dutch law requires storage.
5.8. Make available to the Controller all information reasonably necessary to demonstrate compliance with this DPA, and allow and contribute to audits as described in Section 11.
5.9. Immediately inform the Controller if, in BoostGood's opinion, an instruction from the Controller infringes the GDPR or other applicable data protection provisions.
6. Obligations of the Controller
The Controller shall:
6.1. Ensure that there is a lawful basis for processing instructed under this DPA.
6.2. Ensure that data subjects have been provided with appropriate privacy notices in accordance with GDPR Articles 13 and 14, including in respect of the Controller's own use of the Tenant Plane.
6.3. Be solely responsible for the accuracy, quality, and legality of Personal Data provided to or processed through the Central Plane.
6.4. Be responsible for its own GDPR compliance in respect of the Tenant Plane, including any data stored there by or for the Controller's users.
6.5. Provide processing instructions that comply with applicable law.
6.6. Be responsible for determining whether BoostGood's security measures are appropriate for the nature of the Personal Data in the Central Plane.
7. Data Breach Notification
7.1. BoostGood shall notify the Controller without undue delay, and in any event within 72 hours of becoming aware, of a Data Breach affecting Personal Data in the Central Plane processed on behalf of the Controller.
7.2. The notification shall include, to the extent available:
- (a) A description of the nature of the Data Breach, including the categories and approximate number of data subjects and Personal Data records affected
- (b) The name and contact details of a point of contact from whom more information can be obtained
- (c) A description of the likely consequences of the Data Breach
- (d) A description of the measures taken or proposed to address the Data Breach, including measures to mitigate its possible adverse effects
7.3. Where it is not possible to provide all information at the same time, BoostGood shall provide information in phases without further undue delay.
7.4. BoostGood shall cooperate with the Controller and take reasonable steps to assist in the investigation, mitigation, and remediation of the Data Breach.
7.5. Notification of a Data Breach shall not be construed as an acknowledgment of fault or liability.
7.6. The Controller is independently responsible for detecting and responding to breaches affecting the Tenant Plane, which the Controller operates.
8. Data Subject Rights
8.1. BoostGood shall assist the Controller in responding to data subject rights requests (access, rectification, erasure, restriction, portability, objection) in respect of Personal Data held in the Central Plane. Because most working data lives on the Tenant Plane, which the Controller operates, the Controller can also export or delete much of that data directly.
8.2. BoostGood shall forward to the Controller, promptly and without acting on them, any requests BoostGood receives directly from data subjects relating to Personal Data held on the Tenant Plane.
9. Sub-Processors
9.1. General authorization. The Controller provides general written authorization for BoostGood to engage Sub-Processors to carry out specific processing activities in the Central Plane, as described in Annex C.
9.2. Current Sub-Processors. The current list of Sub-Processors is set out in Annex C of this DPA.
9.3. Notification of changes. BoostGood shall inform the Controller of any intended changes concerning the addition or replacement of Sub-Processors at least 30 days before engaging the new Sub-Processor, giving the Controller the opportunity to object.
9.4. Right to object. If the Controller objects to a new Sub-Processor on reasonable data protection grounds, the parties shall discuss the concerns in good faith. If no resolution is reached, the Controller may terminate the affected portion of the Service or the Agreement.
9.5. Sub-Processor agreements. BoostGood shall impose on each Sub-Processor the same data protection obligations as set out in this DPA by written contract, and remains fully liable to the Controller for each Sub-Processor's performance.
9.6. AI model providers and the Tenant Plane. AI model providers listed in Annex C receive query text when a user selects a given model. This transmission is made from the Tenant Plane through the BoostGood gateway for routing and credit metering only. The content is not retained by BoostGood. The Controller can control which AI models are available to its users.
10. International Data Transfers
10.1. BoostGood shall not transfer Personal Data from the Central Plane outside the EEA unless appropriate safeguards are in place as required by GDPR Chapter V.
10.2. For transfers to Sub-Processors outside the EEA, the following safeguards apply:
- (a) United States (Anthropic, OpenAI, Stripe): EU-U.S. Data Privacy Framework certification or Standard Contractual Clauses (SCCs) pursuant to Commission Decision 2021/914
- (b) China (DeepSeek): Standard Contractual Clauses (SCCs), supplemented by a transfer impact assessment on file
10.3. BoostGood has conducted transfer impact assessments for transfers to countries not covered by an adequacy decision. The Controller may request a copy of the relevant assessment.
10.4. The use of DeepSeek and other optional AI models is at the Controller's discretion. If the Controller does not enable a model, no data is transferred to that provider.
11. Audit Rights
11.1. BoostGood shall make available to the Controller all information reasonably necessary to demonstrate compliance with this DPA, in respect of processing in the Central Plane.
11.2. The Controller (or a mandated independent auditor bound by confidentiality obligations) may request an audit of BoostGood's processing activities, subject to the following conditions:
- (a) The Controller shall provide at least 30 days' written notice of an audit request
- (b) Audits shall be conducted during normal business hours and shall not unreasonably interfere with BoostGood's operations
- (c) The Controller shall bear the costs of the audit
- (d) Audits are limited to once per 12-month period, unless a Data Breach has occurred or a Supervisory Authority requires an additional audit
- (e) The auditor must execute a confidentiality agreement before accessing any BoostGood facilities or documentation
11.3. BoostGood may satisfy audit requests by providing relevant certifications, audit reports, or other evidence of compliance where available.
11.4. If an audit reveals non-compliance with this DPA, BoostGood shall promptly take corrective action at its own expense and inform the Controller of the measures taken.
12. Data Deletion and Return
12.1. Upon termination of the Agreement, BoostGood shall:
- (a) Continue to store the Controller's Personal Data from the Central Plane in an archived state for 90 days, to allow the Controller to request export
- (b) Upon request from the Controller during the 90-day archive period, export and return all Personal Data in a structured, commonly used, and machine-readable format
- (c) After the 90-day archive period, permanently delete all Personal Data from the Central Plane within 30 days
12.2. For data on the Tenant Plane, the Controller's server is archived for 90 days after termination and then destroyed. Because the Controller operates the Tenant Plane, the Controller may also request early export or deletion.
12.3. Exceptions to deletion. BoostGood may retain:
- (a) Billing records for 7 years from the transaction date, as required by Dutch tax law (Algemene Wet inzake Rijksbelastingen), with personal identifiers minimized to the extent possible
- (b) Any Personal Data that BoostGood is required to retain by EU or Dutch law
12.4. BoostGood shall provide written confirmation of deletion upon request from the Controller.
13. Liability
13.1. Each party's liability under this DPA is subject to the limitations of liability set out in the Agreement.
13.2. Both parties acknowledge their respective obligations under GDPR Article 82 regarding the right of data subjects to compensation for damage suffered as a result of a GDPR infringement.
13.3. The Controller is solely liable for compliance in respect of the Tenant Plane, which the Controller operates independently. BoostGood accepts no liability for the Controller's processing activities on the Tenant Plane.
Annex A: Description of Processing
| Element | Description |
|---|---|
| Subject matter | Provision of the BoostGood AI agent ecosystem platform (Central Plane only) |
| Duration | Duration of the subscription agreement plus 90-day archive period |
| Nature of processing | Collection, storage, retrieval, transmission (to AI model providers for routing), deletion |
| Purpose of processing | User authentication and account management; billing and payment processing; platform health monitoring (metrics only); usage and credit accounting; support communications; transactional email; AI query routing and credit metering |
| Categories of data subjects | Employees, contractors, and agents of the Controller who are authorized users of the BoostGood portal |
| Types of Personal Data (Central Plane) | Names, email addresses, organization details, hashed passwords, user roles, billing addresses, order records, payment tokens (via Stripe), platform health metrics (no content), usage event logs, IP addresses, support communications; portal-native agent conversation text (beta only) |
| Types of Personal Data (Tenant Plane, not processed by BoostGood) | Conversation content, uploaded files and documents, knowledge-base content, application data in LibreChat/Nextcloud/n8n and their databases. The Controller is the operator of this data. |
| Sensitive data | None processed intentionally in the Central Plane. The Controller is responsible for any special category data on the Tenant Plane under GDPR Article 9. |
Annex B: Technical and Organizational Measures
BoostGood implements the following technical and organizational measures to protect Personal Data in the Central Plane:
B.1. Data Isolation
- Each Controller receives a dedicated VPS for the Tenant Plane; no data is shared between Controller environments
- Central Plane data is logically separated by tenant identifier
- Network-level isolation between VPS instances
B.2. Encryption
- All data in transit is encrypted using TLS 1.2 or higher
- Data at rest is encrypted at the filesystem level on all servers
- Backups are encrypted before storage
B.3. Access Control
- Administrative access to Central Plane infrastructure is restricted to authorized BoostGood personnel
- SSH key-based authentication is required for server access; password authentication is disabled
- User authentication uses hashed passwords (bcrypt or equivalent)
- Role-based access control applied within the portal
- Principle of least privilege applied to all administrative access
- Access to the Tenant Plane requires either a support session token granted by the Controller or, during beta, the provisioning system key (see Section 4.3)
B.4. Network Security
- Firewall rules restrict access to necessary ports only (22, 80, 443)
- Regular security updates and patching of operating systems and software
- Monitoring for unauthorized access attempts
- DDoS mitigation through hosting provider infrastructure
B.5. Backup and Recovery
- Regular automated backups of Central Plane data
- Backups are encrypted and stored separately from production systems
- Tested recovery procedures
B.6. Incident Management
- Documented incident response procedures
- Breach notification process within 72 hours as described in Section 7
- Post-incident review and remediation
B.7. Personnel Measures
- Confidentiality obligations for all personnel with access to Personal Data
- Access granted only on a need-to-know basis
- Security awareness practices
B.8. Vendor Management
- Written data processing agreements with all Sub-Processors
- Assessment of Sub-Processor security measures before engagement
- Regular review of Sub-Processor compliance
B.9. Data Minimization
- Only data necessary for the specified purposes is processed in the Central Plane
- AI model providers receive only the query text needed to generate a response; no account or billing data is shared
- Personal identifiers are minimized in retained billing records after account termination
- Health metrics contain no conversation content or file content
Annex C: Sub-Processor List
The following Sub-Processors are authorized to process Personal Data on behalf of the Controller in connection with the Central Plane. The Sub-Processor list is current as of the effective date shown at the top of this DPA. Changes will be communicated in accordance with Section 9.3.
| Sub-Processor | Location | Processing Activity | Data Processed | Transfer Safeguard |
|---|---|---|---|---|
| Anthropic PBC | United States | AI model inference (Claude) — query routing only | Query text submitted by the Controller's users; no account or billing data | EU-U.S. Data Privacy Framework / SCCs |
| OpenAI Inc. | United States | AI model inference (GPT) — query routing only | Query text submitted by the Controller's users; no account or billing data | EU-U.S. Data Privacy Framework / SCCs |
| Google LLC | United States (with EU processing) | AI model inference (Gemini) — query routing only | Query text submitted by the Controller's users; no account or billing data | EU-U.S. Data Privacy Framework / SCCs |
| Mistral AI SAS | France (EU) | AI model inference — query routing only | Query text submitted by the Controller's users; no account or billing data | N/A (within EEA) |
| DeepSeek | China | AI model inference (optional) — query routing only | Query text submitted by the Controller's users when DeepSeek is enabled; no account or billing data | Standard Contractual Clauses (SCCs) |
| Stripe Inc. / Stripe Payments Europe Ltd. | United States / Ireland (EU) | Payment processing | Billing addresses, payment method tokens, transaction records | EU-U.S. Data Privacy Framework / SCCs |
| Contabo GmbH | Germany (EU) | VPS hosting infrastructure (Central Plane and Tenant Plane servers) | Encrypted server images; Contabo does not access application data | N/A (within EEA) |
| Hetzner Online GmbH | Germany / Finland (EU) | VPS hosting infrastructure (Central Plane and Tenant Plane servers) | Encrypted server images; Hetzner does not access application data | N/A (within EEA) |
| Scaleway SAS | France (EU) | Transactional email delivery | Email addresses, transactional email content | N/A (within EEA) |
Notes:
- AI model Sub-Processors receive query text only when a user selects the corresponding model. No account information, billing data, or other Central Plane Personal Data is transmitted to AI model providers.
- The use of each AI model is optional and under the Controller's control.
- VPS hosting providers host the physical infrastructure. They do not have access to application data, which is encrypted at rest.
Except Integrated Sustainability BV
hello@boostgood.eco
boostgood.eco