Legal

Privacy notice — the Booost app

How Alfercom Srl handles personal data inside the Booost application, including the data of the people you reach out to. Effective 1 September 2026.

Last updated · July 26, 2026
The Italian version is the only authoritative text. This page is an English summary provided as a courtesy. The binding document is the Informativa privacy dell'applicazione, in Italian, in force from 1 September 2026. Where the two differ, the Italian text prevails.

What this notice covers

This notice covers the Booost desktop application and the server services behind it — not the booost.network website, which has its own privacy notice.

It is addressed to two groups of people:

  • users who register for Booost and run it, under Article 13 GDPR;
  • the third parties whose data is processed through it — the prospects and contacts your campaigns reach — under Article 14 GDPR.

The data controller is Alfercom S.r.l., Via Altinate 125, 35121 Padua (PD), Italy — VAT IT05068010288, REA PD-440530. Data protection contact: the contact form, subject Data protection — no registration required.

The five things worth knowing

Your LinkedIn session never leaves your machine

Session cookies and tokens for the accounts you connect stay in the rendering engine's cookie store on your own device, in a separate partition per account. They are never transmitted to Alfercom's servers, for any feature. Your LinkedIn password is never known to us: registration happens through LinkedIn SSO.

This guarantee is about credentials and the session — not about data in general. Contact data does travel; see the next point.

The connection graph is synchronised to our servers, second degree included

Roughly every twelve hours the application sends our servers an incremental update of your connection network: name and profile identifier, job title, company, current role, location, work and education history, connection date and your own labels. Second-degree connections are included — the contacts of your contacts — for whom name, identifier, job title and company are sent.

That data is stored in Germany, in the European Union. The legal basis is legitimate interest. Anyone in the graph, second degree included, can object and ask for erasure through the contact form.

Campaigns act without a per-recipient review

Once a flow is started or scheduled, Booost walks the whole recipient list and performs the actions — profile visit, connection request, message, reaction — without asking you to confirm each recipient. Scheduled flows run without you present. Some branches depend on automatic assessments, such as the category a model assigns to an incoming message, and can lead straight to an action. If you enable automatic personalisation, the text of a message is produced at the moment it is sent.

The notice explains in full why Article 22(1) GDPR does not apply here — not because a human reviews each contact, which does not happen, but because receiving a professional message does not have the significant effect the Article requires.

Booost AI (Pro edition) runs through our servers, in the EU

In the Pro edition the content to be generated or assessed travels from the app to Alfercom's servers, which add our own writing instructions and forward it to the inference provider Scaleway S.A.S. in France — inside the European Union, so no transfer outside the EU takes place for this flow. We do not store the content of those requests and responses: what remains is an accounting record with no text in it (user, account, model, units processed, cost, timestamp).

In the Basic edition you use your own API key and the content goes straight from your device to the provider you chose, without passing through us. Note that this includes other people's data — for incoming-message classification, the full text of the message you received.

Profiling, and what you can ask us to do about it

Booost produces labels, scores and rankings about prospects — relevance, influence, fit with your target, a signal for "the right moment to reach out", a category for incoming messages. That is profiling under Article 4(4) GDPR. It is kept for as long as the underlying record and deleted with it, and a prospect can object to it.

Retention, in short

DataKept for
Account and registration dataContract + 5 years
Invoicing data10 years
Outreach data (prospects)24 months from the last interaction
Connection graph24 months from the last update of each link
Booost AI usage accountingContract + 24 months
AI prompts and outputsNot retained by Alfercom
Technical and device data12 months

Your rights

Access, rectification, erasure, restriction, portability, objection and the right not to be subject to solely automated decisions, under Articles 15–22 GDPR. Requests go through the contact form; we answer within 30 days. You can also lodge a complaint with the Italian supervisory authority, the Garante per la protezione dei dati personali.

Booost lets a single person be deleted along with everything about them — messages, automatic assessments, presence in the connection graph, search indexes — so one person's request can be honoured without affecting anyone else.

Read the binding text

The complete document, with all legal bases, recipients, sub-processors and retention periods, is the Italian one: Informativa privacy dell'applicazione.