Legal

Privacy notice — the Booost app

How Alfercom Srl handles personal data inside the Booost application, including the data of the people you reach out to. Effective 1 September 2026.

Last updated · August 26, 2026
The Italian version is the only authoritative text. This page is an English summary provided as a courtesy. The binding document is the Informativa privacy dell'applicazione, in Italian, in force from 1 September 2026. Where the two differ, the Italian text prevails.

What this notice covers

This notice covers the Booost desktop application and the server services behind it — not the booost.network website, which has its own privacy notice.

It is addressed to two groups of people:

  • users who register for Booost and run it, under Article 13 GDPR;
  • the third parties whose data is processed through it — the prospects and contacts your campaigns reach — under Article 14 GDPR.

The data controller is Alfercom S.r.l., Via Altinate 125, 35121 Padua (PD), Italy — VAT IT05068010288, REA PD-440530. Data protection contact: the contact form, subject Data protection — no registration required.

The six things worth knowing

Your LinkedIn session never leaves your machine

Session cookies and tokens for the accounts you connect stay in the rendering engine's cookie store on your own device, in a separate partition per account. They are never transmitted to Alfercom's servers, for any feature. Your LinkedIn password is never known to us: you register with an email and password, or through LinkedIn SSO.

This guarantee is about credentials and the session — not about data in general. Contact data does travel; see the next point.

Your connections are synchronised to our servers

Roughly every twelve hours the application sends our servers an incremental update of your first-degree connections: name and profile identifier, job title, company, current role, location, work and education history, connection date and your own labels.

That data is stored in Germany, in the European Union, in an incremental archive tied to your account. The legal basis is legitimate interest. Anyone in it can object and ask for erasure through the contact form; we then stop the synchronisation that concerns them and delete their records from our servers.

The app sends us usage and diagnostic data

Like most software, Booost reports to our servers how it is doing: when it last started and which version it runs, whether the LinkedIn session is still valid, what is scheduled (posts, recurring flows, comments awaiting your review — with a short excerpt of the text), and aggregate outcomes of the automations (counts of actions that succeeded, failed or were skipped, with no recipient identifiers). We may also collect diagnostic data (errors, crashes, logs) to find and fix defects. We use this to run the service, keep it secure and improve it; the basis is the contract and our legitimate interest, and it is kept for 24 months. The diagnostic side also covers how the app is coping with LinkedIn's interface: for each group of technical references it uses to recognise page elements, how many readings matched and how many missed and when the last one was, plus your app version, operating system and the language LinkedIn's interface is in. Only types and counts leave your machine — never the content of messages or posts, never the names or profiles of the people you reach. You can switch this diagnostic collection off in Settings → Data and privacy, and automations keep working without it. You can also object under Article 21; the data needed to run the service cannot be switched off in the settings.

Campaigns act without a per-recipient review

Once a flow is started or scheduled, Booost walks the whole recipient list and performs the actions — profile visit, connection request, message, reaction — without asking you to confirm each recipient. Scheduled flows run without you present. Some branches depend on automatic assessments, such as the category a model assigns to an incoming message, and can lead straight to an action. If you enable automatic personalisation, the text of a message is produced at the moment it is sent.

The notice explains in full why Article 22(1) GDPR does not apply here — not because a human reviews each contact, which does not happen, but because receiving a professional message does not have the significant effect the Article requires.

Booost AI (Pro edition) runs through our servers, in the EU

In the Pro edition the content to be generated or assessed travels from the app to Alfercom's servers, which add our own writing instructions and forward it to the inference provider Scaleway S.A.S. in France — inside the European Union, so no transfer outside the EU takes place for this flow. Scaleway's own terms state that it does not read, reuse or train on the content. We do not store the content of those requests and responses: what remains is an accounting record with no text in it (user, account, model, units processed, cost, timestamp). The quality check on drafts uses deterministic rules on our servers plus a model at the same provider, under the same guarantees.

For profile analysis, what is sent about a prospect is what their public profile shows: name, title, role, company, location, your own labels, work and education history, follower count, bio and recent public posts with their engagement — not your conversation history. For incoming-message classification, the full text of the single message.

In the Basic edition you use your own API key and the same content goes straight from your device to the provider you chose, without passing through us. Note that this includes other people's data.

Profiling, and what you can ask us to do about it

Booost produces labels, scores and rankings about prospects — relevance, influence, fit with your target, a signal for "the right moment to reach out", a category for incoming messages. That is profiling under Article 4(4) GDPR. It is kept for as long as the underlying record and deleted with it, and a prospect can object to it.

Retention, in short

DataKept for
Account and registration dataContract + 5 years
Invoicing data10 years
Outreach data (prospects)24 months from the last interaction
Connections archive24 months from the last update, and in any case 30 days after the contract ends
Usage and diagnostic data24 months
Booost AI usage accountingContract + 24 months
AI prompts and outputsNot retained by Alfercom
Technical and device data12 months

Your rights

Access, rectification, erasure, restriction, portability, objection and the right not to be subject to solely automated decisions, under Articles 15–22 GDPR. Requests go through the contact form; we answer within 30 days. You can also lodge a complaint with the Italian supervisory authority, the Garante per la protezione dei dati personali.

Booost lets a single person be deleted along with everything about them on your machine — messages, automatic assessments, search indexes — so one person's request can be honoured without affecting anyone else; on request we delete the same person from the archive on our servers.

Read the binding text

The complete document, with all legal bases, recipients, sub-processors and retention periods, is the Italian one: Informativa privacy dell'applicazione.