Boosthis

Boosthis — Data Processing Agreement

In force from 2026-09-29 · Published at https://www.boosthis.com/processing · Incorporated into the Terms of Service by reference

You do not sign this. It is published, and accepting the Boosthis Terms accepts it — the same way Sentry, PostHog and other tools in this category do it. There is no countersigned copy to chase and no signature round-trip before you can buy.

The companies that receive data are not listed in this document. They are at https://www.boosthis.com/subprocessors, on 14 days' notice before a new company starts receiving data, so a change of provider does not require amending an agreement you have already accepted.

The contact address in this agreement is not working. One thing you need to know before you use that address: as of 2026-09-21 it is not delivering — messages are rejected at the mail exchanger after the body is sent, so the sender receives a bounce and nothing arrives here. The fault is ours and it is being repaired; until it is, a message sent there will bounce rather than reach us. It is named below anyway because it is the right address and it will work again; while it does not, this agreement cannot be relied on to reach us by email, and we would rather say so here than let you discover it after you have bought.

1. Who this is between, and what it covers

This agreement is between you — the account holder, referred to here as the customer — and Veqtara Tech Company, the company that operates Boosthis (commercial registration 7054832287, Rabwa District, Al Noaim Street, Riyadh, Saudi Arabia).

It governs personal data that Boosthis processes on your behalf when you install a Boosthis kit in your own application: the measurements the kit takes, the identifiers it carries, and anything about your application's end users that reaches us as a result. For that data you are the controller and we are the processor, and this agreement is the written record of that.

It does NOT cover your own account with us — your name, your email address, your billing details, and what you do while signed in. For that data we are the controller in our own right, and what we do with it is set out in the privacy half of the Terms rather than here.

This agreement is incorporated into the Boosthis Terms of Service by reference. Accepting the Terms accepts this, and there is no separate signature: it is published at https://www.boosthis.com/processing and changes there, visibly, rather than in a document neither side can find later.

2. Subject matter, duration, nature and purpose

Subject matter: performance and reliability measurement of your application. Nature and purpose: taking, storing, aggregating and reporting those measurements back to you, and deriving from them the findings, comparisons and written advice the product exists to produce.

Categories of data subject: the end users of your application, and the developers on your own team who install and operate the kit.

Categories of personal data: technical and behavioural measurements — timings, screen and route labels, error and crash signatures, device and runtime characteristics, and an installation identifier that is generated by the kit rather than taken from a person. Boosthis does not ask for and has no field for a name, an email address, a postal address or a payment detail belonging to one of your end users. What may be sent at all is a closed vocabulary that the kit cannot add to and the server drops terms it does not recognise.

Duration: for as long as your account is open and the kit is installed, and then for the periods in clause 8.

3. We act on your instructions

We process the data described above only on your documented instructions, and for no purpose of our own beyond operating, securing and improving the service you are paying for. Your instructions are: this agreement, the Terms, the settings you choose in your dashboard, and what the kit you installed is configured to send.

If we believe an instruction of yours requires us to break a law that applies to us, we will tell you rather than quietly comply or quietly refuse.

If a law that applies to us requires us to process the data in some other way, we will tell you before doing so unless that same law forbids telling you.

We do not sell the data, we do not rent or trade it, and we do not use it for anybody's advertising. We do not use your end users' measurements to train a general-purpose AI model. Where the product derives a pattern that is useful beyond your own project, what leaves your project is an aggregate or a rule — never one of your end users' records.

4. Confidentiality

Everybody who can reach the data is bound to keep it confidential, and that obligation outlives their involvement. Boosthis is operated by a small team; access is limited to the people who need it to run the service, and privileged actions taken inside the product's own administrative pages are recorded in an audit trail.

5. Security

We keep appropriate technical and organisational measures in place. Concretely, and in the words of what the code actually does: data travels over TLS and the site is served with a strict transport policy; credentials are stored as hashes or encrypted at rest rather than in the clear; what a kit may send is a closed vocabulary rather than free text, and the one free-text field a developer can send is screened for identifiers before it leaves; outbound requests are pinned to a checked address; the database is backed up daily and a full restore is rehearsed weekly against real backups; and the public surfaces are checked from outside our own network.

We do not claim a certification we do not hold. Boosthis has no ISO 27001 or SOC 2 report, and this agreement does not promise one.

No storage region is offered. Everything is processed where clause 7 says it is, and you cannot select a different region — stating that plainly is more useful than leaving it unsaid.

6. Sub-processors

You give a general authorisation for us to engage the sub-processors published at https://www.boosthis.com/subprocessors, and that page — not this agreement — is the list. It is separate on purpose, so a company can be added or replaced without amending a contract you have already accepted.

Before another company starts receiving your data it is named on that page at least 14 days beforehand, unless a change has to be made sooner to keep the service running or secure, in which case it is named as soon as it takes effect. You can subscribe to double opt-in email change notices at https://www.boosthis.com/trust without an account, or follow the additional feed at https://www.boosthis.com/subprocessors.xml.

If you object to a new sub-processor within the notice period, tell us at support@boosthis.com. We may not be able to keep serving you without it — in which case your remedy is to stop using the service and close your account, and we will say so plainly rather than leave you to discover it.

Each sub-processor is engaged under terms that bind it to the purpose it is named for. Where a company is not, in truth, bound to act only on our instructions — a licensed payment institution handling card data under its own regulatory duties, for example — the list says so in those words rather than claiming a term nobody can keep.

We remain responsible to you for what a sub-processor does with what we give it.

7. Where it is processed, and onward transfers

Where the service runs: the Boosthis servers and the database behind them run in the United States.

Whether your data crosses a border: some of it does. Moyasar holds what reaches it in the Kingdom of Saudi Arabia; Resend, Replit and Google Cloud hold what reaches them in the United States; what reaches OpenAI leaves the Kingdom of Saudi Arabia too, but which country processes it is not confirmed.

Resend, OpenAI, Replit, Google Cloud process what reaches them outside the Kingdom of Saudi Arabia. That transfer is necessary in order to provide the hosted service you asked for: there is no version of the hosted dashboard, email or assistant that does without them. The basis recorded for each one, and whether an in-Kingdom alternative exists, is published on https://www.boosthis.com/subprocessors.

Onward transfer — a sub-processor handing the data to somebody further down its own chain — is covered by the position recorded against each company on https://www.boosthis.com/subprocessors, together with what that company's own published practice is. Those published lists are re-read on a weekly clock and compared with what was recorded, so a change in somebody else's chain is something we find out about rather than something we assume away. Two of the companies on our list are reached on another company's account, and that is the only place such a change shows up at all.

8. Deletion and return at the end

You can take a machine-readable copy of everything we hold for your account at any time, from your dashboard, without asking anyone. Take it before you close the account: after deletion we cannot produce one.

When you close your account it is frozen for 24 hours — a window in which you can change your mind — and then the data is deleted or de-identified in place. Where a payment or tax record must be kept by law, it is kept for that reason and nothing else.

An unpaid account is frozen rather than purged: we do not delete somebody's data as a debt-collection measure. Where a purge does run on a countdown, that countdown is 60 days and it is shown to you while it is running.

Backups are a separate clock. A routine backup is kept for 30 days and then rotated out, so deleted data can persist in a backup for up to that long after it has gone from the live database. We do not restore a backup to recover data you asked us to delete.

Independently of any of that, an installation's measurements can be erased immediately from inside your own application, by the kit, without an email to anybody. See https://www.boosthis.com/your-data.

9. Help with requests and incidents

If one of your end users comes to us directly, we will not answer for you. We will tell them that their request belongs with you — the company whose application they used — and tell you that it reached us. What we will do without you is the self-serve erasure described at https://www.boosthis.com/your-data, which needs no decision from either of us because it is proved by control of the installation rather than by anything we hold.

If one of your end users' requests reaches you and you need our help to answer it, we will help: we can tell you what is stored for a given installation, produce it, correct it, or erase it. There is no charge for this.

If we become aware of a personal-data breach affecting data we process for you, we will tell you without undue delay, with what we know at the time, and keep telling you as we learn more. We will not wait until we have a complete picture to make the first contact.

We will give you the information you reasonably need for your own impact assessments and for any consultation with a supervisory authority, to the extent it is about what we do.

How to reach us for any of this: support@boosthis.com. We answer within 30 days.

10. Audit

You can ask us for the information needed to show that this agreement is being kept, and we will provide it. Most of it is already published: who receives what, where it is processed, how long it lives, and what the product does and does not collect are all on the public pages and are generated from the records the code itself is held to.

We do not currently offer an on-site inspection or a third-party audit report, and this agreement does not pretend otherwise. If an audit is a condition of your purchase, write to support@boosthis.com and we will tell you honestly what we can and cannot do. One thing you need to know before you use that address: as of 2026-09-21 it is not delivering — messages are rejected at the mail exchanger after the body is sent, so the sender receives a bounce and nothing arrives here. The fault is ours and it is being repaired; until it is, a message sent there will bounce rather than reach us.

11. Governing law, and how this changes

This agreement is governed by the law of the Kingdom of Saudi Arabia, and disputes go the same way as under the Terms: Saudi Center for Commercial Arbitration (SCCA), seated in Riyadh, Kingdom of Saudi Arabia.

Changes to this agreement are published here with the date they came into force, and every earlier revision stays listed below so you can see what changed and when. The recipient list has its own address and its own notice period, and moves independently of this document.

12. Nobody in Europe

Boosthis is operated only from the Kingdom of Saudi Arabia, by Veqtara Tech Company, and has appointed no representative in the European Union or the United Kingdom. There is no European address to write to and no European entity behind this service: the contact for everything in this agreement is support@boosthis.com, answered from Riyadh. If you are in the EU or the UK and this matters to your purchase, say so before you buy rather than after — the decision, its reasoning and the condition that would change it are recorded at docs/decisions/eu-uk-representative.md in the Boosthis repository.

13. Revisions

  • 2026-09-29 — First published. Incorporated into the Terms by reference, with the recipient list moved to an address of its own so it can change without amending this agreement.