Privacy Policy
BoostGood Privacy Policy
Version: 2.0
Effective date: 15 July 2026
Last updated: 15 July 2026
This Privacy Policy explains how Except Integrated Sustainability BV ("BoostGood," "we," "us," or "our") handles personal data when you use the BoostGood platform ("Service"). It is provided under the General Data Protection Regulation (EU) 2016/679 ("GDPR"), in particular Articles 13 and 14.
The short version. BoostGood runs on a dedicated server that belongs to you. Your prompts, conversations, uploaded files, and knowledge-base content live on that server and stay there. BoostGood the company does not collect or process them, and does not keep a copy. What we hold at our end is limited to what we need to run your account: your name and email, billing and order records, and server health metrics such as uptime and disk usage, which contain no content. Support staff can enter your system only when you switch on a time-limited support session yourself. Read Section 3 for the exact detail, including the beta caveats, which we state plainly rather than hide.
1. Data Controller
The data controller for the processing described here is:
Except Integrated Sustainability BV
Registered in the Netherlands
Contact: hello@boostgood.eco
Website: boostgood.eco
For questions or requests about your personal data, contact us at hello@boostgood.eco.
2. Two data planes: what this means for your privacy
BoostGood is built so that your working data stays with you. Understanding the architecture is the clearest way to understand this policy, so we describe it in plain terms.
2.1. Your dedicated server (your data)
When you order BoostGood, we provision a dedicated virtual private server (VPS) that is yours. The applications you use day to day run on that server: the chat and AI tools, the file storage (Nextcloud), automation (n8n), the knowledge base, and their databases. Everything those applications hold lives on your server:
- Your prompts, queries, and AI conversations
- Files and documents you upload
- Knowledge-base document content
- Anything your users create inside those applications
BoostGood does not collect, process, or store this data, and keeps no copy of it. It does not pass through our central systems in the ordinary course of using the Service. Two exceptions are honest and worth stating: (a) when you send a query to a third-party AI model, the query text is transmitted to that model provider to generate a response (Section 6); and (b) during beta we retain a technical access path to your server for provisioning and support, described in Section 3.3.
2.2. The BoostGood portal (data we do hold)
Separately from the applications on your server, the BoostGood portal is the account and control surface we operate centrally. To run it, we hold a limited set of data at our end. This is listed in full in Section 3.
3. Personal Data We Hold
3.1. Account information
- Full name
- Email address
- Organization name
- Account credentials (passwords stored in hashed form only)
- Role within the organization (for example administrator or user)
3.2. Billing and order information
- Billing address
- Order details and plan selection
- Payment method details (processed and stored by Stripe; we do not store full card numbers)
- Invoices and payment records
3.3. Platform health metrics (no content)
To keep your server running and to alert you before something breaks, we collect operational metrics: CPU load, memory use, disk use, uptime, service and container status, and error events. These metrics contain no prompts, no conversations, and no file content. They describe the health of the machine, not what you do on it.
3.4. Usage and credit accounting (no message content)
- Login timestamps and session activity
- AI credit consumption: which model was used, token counts, and credits charged
- Feature usage at the level of counts and events
Credit accounting records the fact and size of a request so we can meter it. It does not store the text of your messages.
3.5. Support communications
Support tickets, emails, and messages you send us, and our replies.
3.6. Knowledge-base metadata (not content)
For knowledge-base documents managed through the portal, we hold metadata only: file name, size, owner, and processing status. The document content itself lives on your server, not ours.
3.7. Portal-native agent conversations
Beta caveat. Some agents can be used directly inside the BoostGood portal (the "quick chat" panel on the dashboard), as opposed to the full applications on your server. For these in-portal agents, the text of the conversation is currently stored in BoostGood's central database so the portal can show your history and meter credits. This is the one category of conversation content we hold centrally today.
We are working to remove this: after beta, portal-native agent conversations will either be stored on your own server like the rest of your data, or encrypted at rest under a key you control so that BoostGood cannot read them. Until that ships, we disclose it here rather than imply otherwise. Conversations held inside the applications on your server are never affected by this and remain on your server only.
3.8. Technical data
- IP address
- Browser type and version
- Operating system and device type
4. Access model: customer-controlled access
BoostGood is designed so that entering your running system is something you control, not something we do at will.
4.1. What we can do without entering your system
Two actions are unilateral, and both happen at the infrastructure level without logging into your system or reading its contents:
- Suspend your access, for non-payment or at your request. This is a status change on our side; your data is untouched.
- Delete your server, for non-payment after notice, a legal requirement, or your request. Deletion destroys the server through our hosting provider's controls. We do not read its contents to delete it.
4.2. Support access is granted by you, and is time-limited
When you want us to look at your system to help with a problem, you switch on a support session from your portal settings. This generates a time-limited token (24 hours by default, up to 7 days) that authorizes support actions on your server. You can end the session at any time, which revokes the token immediately. Without an active session that you enabled, support-level actions on your server are refused.
4.3. Beta caveat on retained access
Beta caveat. During the beta period, BoostGood retains a technical administrative access path to every server for provisioning, automated health metrics, and support fixes. In practice this means (a) an administrative key that lets our provisioning and monitoring systems reach your server, and (b) automated health checks that read machine metrics (not content) on a schedule. We use this to set your server up, keep it healthy, and fix issues quickly during the early period.
Our committed direction for general availability is to move health metrics to a model where your server reports them to us rather than us reaching in, and then to remove the standing administrative key, so that after beta the only way into your running system is a support session you grant. We describe the current state honestly here rather than claim an absolute we cannot yet back in code.
5. Purposes and Legal Bases
| Purpose | Data used | Legal basis (GDPR Art. 6(1)) |
|---|---|---|
| Providing and operating the Service and your server | Account info, health metrics, usage data | Contract (b) |
| Authentication and account management | Account info, technical data | Contract (b) |
| Billing and payment processing | Billing and order info | Contract (b) / Legal obligation (c) |
| Routing AI queries to third-party models you choose | Prompt text you submit | Contract (b) |
| Keeping the platform healthy, secure, and fixing bugs | Health metrics, technical data, error events | Legitimate interest (f) |
| Providing support when you request it | Support communications; system access only during a session you grant | Contract (b) |
| Communicating with you about the Service | Account info (name, email) | Legitimate interest (f) / Contract (b) |
| Complying with legal obligations | Billing info, account info | Legal obligation (c) |
| Marketing communications, where you opt in | Name, email | Consent (a) |
Where processing relies on legitimate interest, we balance it against your rights and do not use it to override them. Where it relies on consent, you may withdraw consent at any time by contacting hello@boostgood.eco, without affecting processing carried out before withdrawal.
6. Sub-Processors
We use the following third parties to deliver the Service. Each processes data only for the purpose shown. AI model providers receive only the query text you choose to send them; they do not receive your account or billing data.
| Sub-Processor | Purpose | Data processed | Location |
|---|---|---|---|
| Anthropic | AI model provider (Claude) | Prompt and response text you submit | United States |
| OpenAI | AI model provider (GPT) | Prompt and response text you submit | United States |
| Google (Gemini) | AI model provider | Prompt and response text you submit | EU / United States |
| Mistral | AI model provider | Prompt and response text you submit | France (EU) |
| DeepSeek | AI model provider (optional) | Prompt and response text you submit | China |
| Stripe | Payment processing | Billing info, payment details | United States (with EU entity) |
| Contabo | VPS hosting infrastructure | Hosts your dedicated server (encrypted at rest) | Germany (EU) |
| Hetzner | VPS hosting infrastructure | Hosts your dedicated server (encrypted at rest) | Germany / Finland (EU) |
| Scaleway | Transactional email delivery | Email address, email content | France (EU) |
We maintain written data processing agreements with each sub-processor under GDPR Article 28.
7. International Data Transfers
7.1. Transfers to the United States (Anthropic, OpenAI, Stripe)
Protected by the EU-U.S. Data Privacy Framework where the recipient is certified, or by Standard Contractual Clauses adopted by the European Commission.
7.2. Transfers to China (DeepSeek)
Protected by Standard Contractual Clauses, with a transfer impact assessment on file. DeepSeek models are optional: if you prefer, simply do not select them, and no data is sent to DeepSeek.
7.3. Data minimization for AI providers
Only the conversation content needed to generate a response is sent to a model provider. Your account information and billing data are never shared with AI model providers.
8. Data Retention
| Data category | Retention | Rationale |
|---|---|---|
| Account information | Active subscription + 90 days | Service delivery and post-termination export window |
| Data on your server (prompts, conversations, files, KB content) | Held by you on your server; archived 90 days after termination, then destroyed | It is your data on your server |
| Portal-native agent conversations (Section 3.7) | Removed when the tenant is purged, at the latest after the 90-day archive | Deleted with the account on purge |
| Health metrics and usage accounting | Active subscription + 90 days | Operations and troubleshooting; no content |
| Billing records | 7 years from the transaction | Dutch tax law (Algemene Wet inzake Rijksbelastingen) |
| Personal data after purge | Permanently deleted | PII scrubbed on purge after the 90-day archive; only minimized billing records remain |
After termination, your data is archived for 90 days, during which you may request an export. After that period, personal data is permanently deleted, except billing records retained for the legally required period with identifiers minimized.
9. Data Subject Rights
Under the GDPR you have the rights of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20), objection (Art. 21), and withdrawal of consent (Art. 7(3)). Because most of your working data lives on your own server, you can also export or delete much of it directly.
To exercise any right, contact hello@boostgood.eco. We respond within 30 days, extendable by up to 60 days for complex requests, in which case we tell you within the first 30 days. We may verify your identity before acting, to protect your data against unauthorized access.
10. Right to Lodge a Complaint
If you believe our processing violates the GDPR, you may complain to a supervisory authority. In the Netherlands this is the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl). You may also complain to the authority in your country of residence.
11. Security
Each customer runs on a dedicated, network-isolated server. Data is encrypted in transit and at rest. Passwords are stored hashed. Access to your running system is controlled as described in Section 4. We keep audit logs of administrative actions and follow a documented incident-response process.
12. Changes to this Policy
We may update this policy as the Service evolves, in particular to remove the beta caveats in Sections 3.7 and 4.3 once the underlying changes ship. Material changes will be notified by email or in the portal, and the version and effective date above will be updated.
13. Contact
Questions about this policy or your data: hello@boostgood.eco.