Legal center

Legal

Terms of Service (incl. DPA)

The rules for using B2Booster, billing terms, and our Data Processing Agreement (DPA).

Public · Read-onlyTrust & compliance readyBack to sign up
Updated December 9, 2025Living document
Legal
Last updated:

These Terms and Conditions ("Terms") govern your access to and use of the B2Booster Cold Marketing Engine (the "Service"), provided by B2Booster AB. By accessing the Service, you agree to these Terms and the Data Processing Agreement (DPA) included in Annex A.

1. Use of Service

The Service is a B2B lead generation and outreach tool intended solely for professional and business use. You agree to use the Service in full compliance with all applicable laws, including GDPR (Europe), CAN-SPAM (USA), and CASL (Canada).

2. Accounts and Security

You are responsible for safeguarding your account credentials (email, password, and MFA tokens). You agree to notify us immediately of any unauthorized use. B2Booster is not liable for any loss resulting from stolen credentials.

3. Acceptable Use & Anti-Spam

We maintain a zero-tolerance policy for spam. You agree not to:

  • Send unsolicited emails to individuals who have not consented or do not have a legitimate business interest.
  • Use the service to transmit phishing content, malware, or illegal goods.
  • Upload purchased lead lists that violate third-party privacy rights.

We reserve the right to suspend accounts with excessive bounce rates or spam complaints.

4. Billing and Credits

Services are billed via Stripe. Subscription fees and credit purchases (for lead lookups or AI generation) are non-refundable except where required by law. If you cancel, access continues until the end of your current billing cycle.

5. Intellectual Property & Content

  • Your Data: You retain ownership of the leads and email content you upload. You grant us a license to process this data solely to provide the Service.
  • Our IP: B2Booster retains all rights to the platform code, design, and AI workflows.
  • AI Content: You are responsible for reviewing AI-generated outputs (email copy, classifiers) for accuracy before use.

6. Google API Compliance

B2Booster's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

7. Termination

We may suspend or terminate your access immediately if you violate these Terms, particularly regarding spam or abuse. Upon termination, your right to use the Service ceases.

8. Disclaimer & Liability

The Service is provided "as is". To the fullest extent permitted by law, B2Booster disclaims all warranties. Our liability is limited to the amount you paid for the Service in the 12 months preceding any claim.

9. Governing Law

These Terms are governed by the laws of Sweden. Any disputes shall be resolved in the district courts of Gothenburg, Sweden.

10. Contact

For legal inquiries, contact support@b2booster.com.


Annex A

Data Processing Agreement (DPA)

This DPA governs B2Booster AB's processing of Customer Data when providing the Service.

1. Roles and Scope

B2Booster AB acts as the Processor. The Customer acts as the Controller (or processor for its own controller).

  • Subject Matter: Operation of the B2Booster service for email outreach, lead management, AI-assisted content, and billing.
  • Duration: For the term of the Agreement or until Customer deletes the data using the provided controls.

2. Categories of Personal Data Processed

The codebase processes the following categories based on Customer inputs:

  • Account Data: User IDs, emails, full names, password hashes, verification tokens, role assignments, avatars, preferences (MFA, language, timezone), and login timestamps.
  • Organization & Billing: Org name, branding assets, API keys, subscription packages, Stripe customer/subscription IDs, payment amounts, and credit counters.
  • Mailbox Connection: SMTP/IMAP credentials, OAuth scopes/tokens (Gmail), DNS settings, and warm-up configurations.
  • Campaign Content: Email bodies (HTML/text), sender/recipient details, prompts/tones, tracking flags, message IDs, and open/reply timestamps.
  • Lead & Prospect Data: Names, emails, phone numbers, job titles, LinkedIn/X profiles, company firmographics (domain, industry, size), and verification status.
  • Product Inputs: Product descriptions, AI prompts, and lead search requests (domain, location, industry).
  • Security Data: JWT session identifiers (httpOnly cookies), CAPTCHA results, and API logs.

3. Google Login and Gmail Integration

  • Authentication: Google Sign-In verifies ID tokens and reads verified email/display names to create your user record.
  • Scopes: We request restricted scopes (gmail.readonly, gmail.send, gmail.settings.basic) to operate the Service.
  • Data Access: We send campaign emails via the Gmail API and read INBOX headers (Subject, Message-ID) and bodies to detect replies. Reply text may be classified to automate campaigns.
  • Storage: Access/refresh tokens are stored securely. We do not use this data for advertising.

4. Subprocessors

Provider Purpose
AWS (eu-central-1) Infrastructure, S3 storage (images), SQS queues (lead search).
Google Gmail API, OAuth, reCAPTCHA verification.
Stripe Billing, subscriptions, and payment processing.
OpenAI LLM processing for content generation and classification.

5. Security and Confidentiality

Access to Customer Data is authenticated using JWTs and scoped to specific organizations. Mailbox tokens are stored encrypted. B2Booster personnel access data only as strictly necessary to support the Service.

6. Deletion and Return

Customers can delete users, mailboxes, campaigns, and lists via the platform at any time. Unsubscribe timestamps are retained to honor opt-outs. Upon account termination, we will delete all related data within 30 days unless legal retention is required.