Privacy Policy
Effective date: July 31, 2026
Last updated: July 31, 2026
1. Who we are
BOOSTERBERG s. r. o., a company incorporated in the Slovak Republic, European Union, with its registered office at Nám. Hraničiarov 37, 851 03 Bratislava – mestská časť Petržalka, company registration number (IČO) 51 086 506, is the data controller for the personal data described in this policy ("Boosterberg", "we", "us").
This policy explains what personal data we collect through boosterberg.com, its subdomains and the Boosterberg web application (the "Service"), why we collect it, who we share it with, how long we keep it, and what rights you have. It applies alongside our Terms of Service .
Questions, requests or complaints: info@boosterberg.com.
2. What Boosterberg does with platform data
Boosterberg automates paid promotion of the posts you have already published on your own social media accounts. To do that, you connect your accounts on the supported platforms — currently Meta (Facebook and Instagram) and TikTok — through each platform's official authorisation flow, and grant us a limited set of permissions.
We request only the permissions our features need. We use platform data solely to operate the Service for you: to show you your posts and their performance, to evaluate them against the automation rules you configure, and to create and manage advertising campaigns in your own ad account. We do not sell platform data, we do not use it for advertising to third parties, we do not use it to train machine learning models, and we do not combine it with data from other users.
3. Data we collect from Meta (Facebook and Instagram)
Subject to the permissions you grant, we access:
- your basic profile information and the list of Facebook Pages and Instagram accounts you manage;
- your published posts and their public performance metrics (reach, engagement and similar);
- your ad account identifiers, campaign structures, ad performance and spend data.
We use this to identify posts eligible under your rules, to create and manage campaigns in your Meta Ads Manager account, and to report results back to you inside the Service. We do not access your private messages, your friends list, or the personal data of people who see or interact with your ads beyond the aggregated metrics the platform provides.
4. Data we collect from TikTok
Subject to the permissions you grant through TikTok's authorisation flow, we access:
- Basic profile information (TikTok Display API, user.info.basic): your open ID, display name, username and avatar, used to identify the connected account in the Service.
- Your public video list and metrics (TikTok Display API, video.list): the videos you have published, their thumbnails, captions, and their public performance metrics such as views, likes, comments and shares. We use these to display your posts in the Service and to evaluate which of them meet the automation rules you have configured.
- Advertising data (TikTok Marketing API): your TikTok Ads Manager advertiser account identifiers, and the campaigns, ad groups, ads, budgets, spend and performance data associated with the campaigns created through the Service. We use these to create, adjust, pause and report on the campaigns that promote your existing posts.
What we do not do with TikTok data. We do not publish, schedule, edit or delete organic content on your TikTok account. We do not download, repost, re-upload or redistribute your videos or anyone else's, and we do not remove or alter watermarks, attribution or other creator protections. We do not access your direct messages. We do not access, collect or store personal data about other TikTok users, and we do not share your TikTok data with any third party for their own purposes.
Your control. You can disconnect your TikTok account at any time inside the Service, or revoke Boosterberg's access directly in TikTok under Settings and privacy → Security and permissions → Manage app permissions. On disconnection, and in any case within 30 days, we delete the TikTok data we hold for that account, except where we must retain records for legal or accounting reasons (see Section 9). You can also request deletion at any time at info@boosterberg.com.
Your use of TikTok itself remains governed by TikTok's own Privacy Policy and Terms of Service.
5. Other data we collect
- Account data. Your email address, name and, optionally, a contact phone number, provided when you register or contact us.
- Billing data. Billing name and address, VAT identifier where applicable, and subscription and invoice records. Card details are entered directly with our payment provider and are never stored on our systems.
- Support data. The content of messages you send us through the contact form or by email.
- Usage and technical data. Log data such as IP address, browser and device type, pages viewed and actions taken in the Service, used for security, debugging and product improvement.
- Cookies and analytics. See Section 7.
6. Why we process your data, and on what legal basis
- To provide the Service — creating and running your account, connecting your channels, evaluating your rules, creating and managing campaigns, reporting results. Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
- To bill you and keep accounting records. Legal basis: performance of a contract and compliance with a legal obligation (Art. 6(1)(b) and (c) GDPR).
- To provide support and send service and security notices. Legal basis: performance of a contract and our legitimate interest in operating the Service reliably (Art. 6(1)(b) and (f) GDPR).
- To secure, debug and improve the Service, and to prevent abuse. Legal basis: our legitimate interest (Art. 6(1)(f) GDPR).
- To send product news and marketing emails, and for advertising cookies. Legal basis: your consent, which you may withdraw at any time (Art. 6(1)(a) GDPR).
7. Cookies and tracking
We use cookies and similar technologies to keep you signed in, remember your preferences, measure how the Service is used, and — only with your consent — for marketing and remarketing. Strictly necessary cookies are set without consent because the Service cannot work without them.
For signed-in users we associate a unique user ID with the active session, which lets us run A/B tests and identify usability problems. We do not use cookies to collect personally identifiable information about visitors for third parties.
In line with the GDPR and the ePrivacy Directive, analytics, preference and advertising cookies are set only after you opt in. You can change or withdraw your consent at any time from our cookie declaration, which also lists every cookie in use. Cookie consent expires after 6 months, after which you are asked again.
8. Who we share data with
We do not sell or rent your personal data. We share it only with the following categories of recipients, and only as far as necessary:
- The advertising platforms you connect — Meta Platforms, Inc. and TikTok — because creating and managing your campaigns necessarily means sending instructions to their APIs on your behalf. See Meta's privacy policy and TikTok's privacy policy.
- Subprocessors that host our infrastructure, process payments and provide analytics, listed in Section 11. They act on our instructions under written data processing agreements.
- Professional advisers and authorities, where we are legally required to disclose data or need to establish, exercise or defend legal claims.
- An acquirer, in the event of a merger, acquisition or sale of assets, subject to this policy continuing to apply.
9. How long we keep data
- Platform data (Meta, TikTok) — deleted or irreversibly anonymised within 30 days of you disconnecting the channel, revoking access on the platform, or deleting your account.
- Account and profile data — kept while your account is active, and deleted within 30 days of account deletion. Dormant accounts and their personal data are deleted automatically within 36 months of the trial or subscription expiry date.
- Billing and invoice records — retained for as long as tax and accounting law requires, currently 10 years under Slovak law.
- Support correspondence — up to 24 months after the issue is resolved.
- Server and security logs — up to 12 months.
10. Your rights
Under the GDPR you have the right to access your personal data, to correct it, to have it deleted, to restrict or object to its processing, to data portability, and to withdraw consent at any time without affecting processing carried out before withdrawal.
You can exercise most of these directly:
- see and correct your data in your Boosterberg account and billing settings;
- disconnect a channel to stop us processing that platform's data;
- delete your account, and with it your personal data, from your account settings;
- or write to info@boosterberg.com for anything else. We respond within one month.
If you believe we have handled your data unlawfully, you may complain to your local data protection authority. In Slovakia this is the Office for Personal Data Protection of the Slovak Republic (dataprotection.gov.sk).
11. Subprocessors and international transfers
As required by the GDPR, these are the processors that may handle our customers' data:
- Amazon Web Services (AWS) — application hosting and data storage. AWS and data privacy.
- Cloudflare — content delivery, DNS and web application security for our website. Cloudflare privacy policy.
- Braintree (a PayPal service) — subscription payment processing. Braintree privacy policy.
- Meta Platforms, Inc. — required for Facebook and Instagram functionality. Meta privacy policy.
- TikTok — required for TikTok functionality. TikTok privacy policy.
- Google — website analytics and marketing measurement. Google privacy policy.
Some of these providers are established outside the European Economic Area. Where personal data is transferred outside the EEA, we rely on the European Commission's Standard Contractual Clauses or an adequacy decision, together with appropriate technical and organisational safeguards.
12. Security
We protect your information with appropriate technical and organisational measures. Data is transmitted over encrypted connections (TLS) and stored encrypted at rest. Access tokens for connected platforms are stored encrypted and are used only to perform the actions you have authorised. Access to personal data inside our organisation is limited to staff who need it for a specific job, such as billing or customer support, and our infrastructure providers maintain physically and logically secured environments (see Section 11).
No system is completely secure. If a personal data breach occurs that is likely to result in a risk to your rights, we will notify the competent supervisory authority within 72 hours and inform you where the law requires it.
13. Children
The Service is a business tool intended for users aged 18 and over. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.
14. Changes to this policy
We may update this policy, for example when we add features or supported platforms. The current version is always published on this page with its "Last updated" date. We will notify you by email or in the Service before any change that materially affects how we handle your personal data takes effect.
15. Contact
BOOSTERBERG s. r. o.
Nám. Hraničiarov 37, 851 03 Bratislava – mestská časť Petržalka, Slovak Republic, European Union
IČO: 51 086 506
Email: info@boosterberg.com
Web: boosterberg.com