Privacy & Security
How Connect by Boostly handles customer data, how responsibilities are split between Boostly and the customer, and the main steps taken to keep data secure.
Last updated May 4, 2026
1. Our role
When a customer uses Connect by Boostly with its own guest, booking, contact, listing, or account data, Boostly processes that data to provide the service. In that context:
- Where the customer is the controller of the personal data, Boostly acts as processor.
- Where the customer acts as processor for another party, Boostly acts as sub-processor.
Boostly does not use customer guest data processed through Connect for Boostly's own direct marketing.
2. Your role
The customer is responsible for:
- Ensuring it is the controller of the personal data, or has authority from the controller.
- Ensuring it is authorised to connect each PMS or third-party system.
- Ensuring it is authorised to disclose personal data to Boostly for the purpose of providing the service.
- Providing any required privacy notices.
- Obtaining any required permissions, approvals, or internal authority.
- Ensuring any marketing carried out using the service complies with applicable privacy and electronic-marketing laws.
3. What data may be processed
Depending on how the service is used, Connect by Boostly may process:
- Account owner details
- User account details
- Contact details
- Guest details
- Booking details
- Property and listing details
- Review content
- Support communications
- Security and login data
- Technical logs and usage records
4. How we use data
Connect by Boostly may process personal data for:
- Account creation and account management
- PMS connection and syncing
- Contact, booking, guest, and listing syncing
- Review and inquiry syncing
- Support and troubleshooting
- Security monitoring and login protection
- Data export and deletion
- Billing and payment processing where relevant
5. Security approach
Boostly uses technical and organisational measures appropriate to the nature of the service and the risks involved. These measures may include:
- Access controls and role-based permissions
- Password protection
- Two-factor authentication where enabled
- Session controls
- Login monitoring
- Suspicious-login detection
- Location and security alerts
- Logging and audit trails
- Backup and recovery processes
- Secure handling of integrations and API connections
6. Sub-processors
Boostly may use trusted third-party service providers in connection with the service. A current list is available at /sub-processors.
7. International transfers
Where personal data is transferred outside the United Kingdom or European Economic Area, Boostly will ensure that an appropriate transfer mechanism is in place where required by applicable law.
8. Data subject rights
Where the customer needs assistance responding to a request relating to access, correction, deletion, restriction, portability, or objection, Boostly will provide reasonable assistance where required and where the request cannot be fulfilled without Boostly's involvement.
9. Data breaches
If Boostly becomes aware of a personal data breach affecting customer personal data, Boostly will notify the customer without undue delay and provide reasonable information to support the customer's response obligations.