Bookboost AB engages the sub-processors listed below to deliver the Service. Customers give general written authorisation to these engagements under Article 28(2) GDPR.
Bookboost gives at least 30 days' prior notice by email before adding or replacing a sub-processor. Customers may object on reasonable data protection grounds within that period. The objection procedure is set out in the Data Processing Agreement.
Where customer data is hosted
Customer personal data is hosted at rest within the European Economic Area, in Amazon Web Services' Ireland region. This covers the application, the primary database, search indexing, caching, file storage and message queuing.
Bookboost personnel do not access production systems from outside the EEA. All support, engineering and administrative access takes place within the EEA.
Bookboost does not generate embeddings of customer personal data and does not store customer personal data in any vector database.
Some processing necessarily takes place outside the EEA:
- Message delivery. Delivering an SMS, WhatsApp message or email to its recipient routes through the relevant provider's network, which may be outside the EEA.
- AI features, where the Customer enables them. See the AI section below.
- Pipeline orchestration, where analytics pipelines execute. See the data platform section below.
Each such transfer takes place under the European Commission's Standard Contractual Clauses, and, where the provider holds one, an additional certification under the EU-US Data Privacy Framework.
Core platform
Engaged for all customers.
| Sub-processor | Contracting entity | Purpose | Personal data | Location |
|---|---|---|---|---|
| Amazon Web Services | AWS EMEA SARL, Luxembourg | Cloud infrastructure — application hosting, database, storage, queuing, encryption key management | All customer personal data | Ireland (EEA) |
| Elasticsearch | Elasticsearch B.V., Netherlands | Search indexing of guest profiles | Name, email address, phone number | Ireland (EEA) |
| Cloudflare | Cloudflare, Inc., United States | Edge delivery, security, and edge data storage for conversational features | Guest conversation history, staff profile data | European Union |
| Zendesk | Zendesk International Limited, Ireland | Messaging orchestration across WhatsApp, SMS, email and web chat | Guest message content and contact identifiers | European Union |
| Twilio | Twilio Ireland Limited, Ireland | SMS delivery | Phone numbers, message content | Ireland (EEA), and the recipient's network on delivery |
| Mailgun | Sinch AB (publ), Sweden | Email delivery | Recipient email addresses, message content | Germany (EEA), and the recipient's mail provider on delivery |
| Meta | Meta Platforms Ireland Limited, Ireland | WhatsApp Business and Messenger delivery | Guest phone numbers, message content | European Union |
| Pusher | Pusher Ltd, United Kingdom | Real-time message delivery within the Service | Message payloads | European Union |
| Sentry | Functional Software, Inc., United States | Application error monitoring | IP addresses, user identifiers, diagnostic data | European Union |
| PostHog | PostHog, Inc., United States | Product analytics | Usage events, guest and staff identifiers | European Union |
Data platform and analytics
Bookboost replicates production data into a managed analytics platform to power reporting, guest segmentation and profile matching.
| Sub-processor | Purpose | Personal data | Location |
|---|---|---|---|
| RisingWave Cloud | Streaming replication from the production database into the analytics warehouse | Guest and reservation data as replicated from production | European Union |
| Snowflake | Analytics data warehouse | Guest and reservation data as replicated from production | European Union |
| Estuary | Change-data-capture streaming from the production database | Guest and reservation data as replicated from production | European Union |
| Omni | Business intelligence and reporting over the analytics warehouse | Guest and reservation data held in the warehouse | European Union |
| Dagster+ | Pipeline orchestration and scheduling | Pipeline metadata; may reference guest records in logs | United States |
Artificial intelligence
Engaged only where the Customer enables AI features.
| Sub-processor | Contracting entity | Purpose | Personal data | Location |
|---|---|---|---|---|
| OpenAI | OpenAI Ireland Ltd, Ireland | Suggested and automated responses to guest messages | Guest message content, property context | United States |
| Anthropic | Anthropic PBC, United States | Staff assistant and guest-facing AI agent | Guest name, email address, stay details, message content | United States |
| Google Cloud | Google Ireland Limited, Ireland | Intent and sentiment detection, translation | Guest message content | European Union |
| DeepL | DeepL SE, Germany | Translation | Guest message content | Germany (EEA) |
Customer-enabled integrations
The Services allow the Customer to connect third-party systems — its own property management system, channel manager, smart locks, data hub, and the services listed in the Bookboost Marketplace.
These are not sub-processors. Where the Customer enables a connection, that is an instruction to Bookboost to exchange with that third party the data the integration requires. The third party acts as the Customer's own processor or as an independent controller, under the Customer's agreement with it. Bookboost transmits only what the integration requires, and only while the Customer keeps it enabled.
This covers, among others:
| Category | Examples |
|---|---|
| Property management systems | Mews, Apaleo, Oracle, Shiji, ClockPMS+ |
| Channel managers | SiteMinder |
| Hotel data hubs | Hapi |
| Smart locks and mobile keys | Seam, Goki, 4SUITES |
| Reputation and guest feedback | ReviewPro, Mara, GuestRevu |
| Operations and upselling | Hotelkit, Oaky, Welcome Pickups |
The current list is maintained at bookboost.io/integrations.
Bookboost's own service providers
These providers do not process guest data. They are listed for transparency and are covered by the Privacy Policy rather than the Data Processing Agreement.
| Provider | Purpose | Personal data |
|---|---|---|
| Intercom | Customer support for Bookboost's own customers | Staff name and email address. No guest data |
| Stripe | Subscription billing | Customer billing contact details. No guest data |