Privacy Policy

BootyBuilder.com · Operated by HAL HOLDING AS

Last Updated: February 27, 2026

1. Introduction

HAL HOLDING AS (“we”, “us”, “our”, or “BootyBuilder”) is a company registered in Norway and the operator of BootyBuilder.com. We are committed to protecting and respecting your privacy in accordance with applicable data protection laws, including the European Union General Data Protection Regulation (EU 2016/679) (“GDPR”), the Norwegian Personal Data Act (Personopplysningsloven), and other applicable privacy legislation in the jurisdictions in which we operate.

BootyBuilder operates globally, with products and services available in over 180 countries. This Privacy Policy applies to all personal data we collect and process in connection with our website, online store, customer support services (including our AI-powered chatbot), and any other services we provide.

This Privacy Policy explains what personal data we collect, why we collect it, how we use and protect it, who we share it with, and what rights you have in relation to your personal data.

By using our website or services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with this Privacy Policy, please do not use our website or services.

2. Data Controller

The data controller responsible for your personal data is:

HAL HOLDING AS

Registered in Norway

Website: www.bootybuilder.com

Email: info@bootybuilder.com

For questions about this Privacy Policy or our data processing activities, please contact us at the email address above.


3. Personal Data We Collect

We collect and process personal data in the following categories depending on how you interact with us:

3.1 Information You Provide Directly

  • Contact and identity information: full name, email address, phone number, and postal address when you place an order, create an account, or contact our support team.
  • Payment information: credit card details, billing address, and transaction records when you make a purchase. Payment processing is handled by third-party payment processors; we do not store your full payment card details.
  • Order information: details of products purchased, order history, shipping addresses, and delivery preferences.
  • Support correspondence: messages, emails, and other communications you send to us, including through our customer support channels.
  • Chatbot interactions: information you provide during conversations with our AI-powered chatbot (BootyBot), including your name, email address, and details of your support request (see Section 7 for more details).
  • Business information: if you are a gym, distributor, or B2B partner, we may collect company name, business registration details, and professional contact information.

3.2 Information Collected Automatically

  • Technical data: IP address, browser type and version, operating system, device type, screen resolution, and language preferences.
  • Usage data: pages visited, time spent on pages, click patterns, referring URLs, and navigation paths through our website.
  • Cookies and similar technologies: we use cookies, web beacons, and similar tracking technologies to collect information about your browsing behavior. See Section 10 for our Cookie Policy.
  • Location data: approximate geographic location derived from your IP address. We do not collect precise GPS location data.

3.3 Information from Third Parties

  • Payment processors and shipping providers may share transaction confirmation and delivery status information with us.
  • Analytics providers may share aggregated or pseudonymized data about website traffic and user behavior.

4. Legal Bases for Processing

We process your personal data on the following legal bases under GDPR Article 6(1):

Legal BasisDescriptionExamples
Contract performance (Art. 6(1)(b)) Processing necessary to fulfil our contract with you or to take steps at your request before entering into a contract. Processing orders, delivering products, managing your account, providing customer support.
Legitimate interest (Art. 6(1)(f)) Processing necessary for our legitimate interests, provided these are not overridden by your rights and freedoms. Improving our website and services, fraud prevention, analytics, operating the AI chatbot for efficient customer support.
Consent (Art. 6(1)(a)) Where you have given clear consent for us to process your personal data for a specific purpose. Marketing communications, non-essential cookies, newsletter subscriptions.
Legal obligation (Art. 6(1)(c)) Processing necessary to comply with a legal obligation to which we are subject. Tax records, accounting obligations, responding to lawful requests from authorities.

5. How We Use Your Personal Data

We use your personal data for the following purposes:

  • Order fulfilment: to process and deliver your orders, manage payments, and provide order-related communications.
  • Customer support: to respond to your inquiries, resolve complaints, and create support tickets, including through our AI-powered chatbot.
  • Account management: to create and manage your customer account, if applicable.
  • Service improvement: to analyse usage patterns, improve our website, products, and services, and develop new features.
  • Marketing: to send you promotional communications about our products and offers, where you have consented or where we have a legitimate interest to do so. You can opt out at any time.
  • Security and fraud prevention: to protect our website, services, and users from fraudulent, unauthorized, or illegal activity.
  • Legal compliance: to comply with applicable laws, regulations, and legal processes.
  • Gym locator service: to help you find gyms with BootyBuilder machines based on location information you provide voluntarily.

6. Data Sharing and Recipients

We do not sell your personal data to third parties. We may share your personal data with the following categories of recipients, only to the extent necessary for the purposes described in this Privacy Policy:

  • Service providers: third-party companies that provide services on our behalf, including payment processing, shipping and logistics, website hosting, email delivery, analytics, and customer support tools. These providers are contractually obligated to process your data only on our instructions and in compliance with applicable data protection laws.
  • AI and chatbot service providers: our AI-powered chatbot is operated using third-party AI infrastructure. Conversation data may be processed by these providers to deliver the chatbot service. See Section 7 for details.
  • Business partners: distributors, gyms, and other B2B partners, but only when necessary to fulfil your request (e.g., connecting you with a local distributor) and only with relevant business contact information.
  • Legal and regulatory authorities: where required by law, regulation, legal process, or governmental request, or to protect our rights, property, or safety, or that of our users or the public.
  • Corporate transactions: in connection with a merger, acquisition, reorganization, or sale of assets, your personal data may be transferred as part of that transaction. We will notify you of any such change.

7. AI-Powered Chatbot (BootyBot)

Our website features an AI-powered chatbot (“BootyBot”) to assist you with customer support, product information, and gym location queries. This section explains how your data is handled when you interact with the chatbot.

7.1 Data Collected by the Chatbot

  • Conversation content: all messages you send to and receive from the chatbot during your session.
  • Personal information you provide: if you request a support ticket, you will be asked to provide your name and email address. This information is collected solely for the purpose of creating a support ticket.
  • Location information: if you use the gym locator feature, you may voluntarily provide location information (country, city, or region) to find nearby gyms. This information is used only for the gym search and is not stored beyond the session.

7.2 How Chatbot Data Is Processed

  • The chatbot is powered by third-party AI infrastructure. Your conversation data is transmitted to and processed by these third-party services to generate responses.
  • Conversation data may be retained by us and/or our AI service provider for quality assurance, service improvement, and troubleshooting purposes.
  • Personal information collected for support tickets (name, email) is stored in our support ticketing system and processed in accordance with this Privacy Policy.
  • The chatbot does not make automated decisions that produce legal effects or similarly significant effects on you.

7.3 Chatbot Limitations

The chatbot operates in English only. Information provided by the chatbot is for general guidance and does not constitute professional, medical, or legal advice. The chatbot does not have access to your account, order history, or any existing customer records unless you provide this information during the conversation.

7.4 Your Choices

Use of the chatbot is voluntary. You may contact us directly at office@bootybuilder.com if you prefer not to interact with the chatbot.

8. International Data Transfers

BootyBuilder operates globally and serves customers in over 180 countries. Your personal data may be transferred to and processed in countries outside of the European Economic Area (EEA), including countries that may not provide the same level of data protection as your home country.

Where we transfer personal data outside of the EEA, we ensure that appropriate safeguards are in place in accordance with GDPR Chapter V, including:

  • Adequacy decisions: where the European Commission has determined that a country provides an adequate level of data protection (GDPR Article 45).
  • Standard Contractual Clauses (SCCs): where we rely on EU-approved Standard Contractual Clauses to ensure adequate protection for data transferred to third countries (GDPR Article 46(2)(c)).
  • Other safeguards: Binding Corporate Rules, certifications, or codes of conduct where applicable.

You may request a copy of the safeguards in place by contacting us at info@bootybuilder.com.

9. Data Retention

We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by applicable law. Our general retention periods are as follows:

  • Order and transaction data: retained for the duration required by applicable tax and accounting legislation (typically 5–10 years depending on jurisdiction).
  • Customer account data: retained for as long as your account is active, and for a reasonable period thereafter to handle any follow-up inquiries.
  • Support tickets: retained for up to 3 years after resolution, unless a longer retention period is required by law.
  • Chatbot conversation logs: retained for up to 12 months for quality assurance and service improvement purposes, unless a longer period is required for an ongoing support matter.
  • Marketing data: retained until you withdraw consent or opt out, plus a reasonable suppression period to ensure we honour your opt-out.
  • Website analytics data: retained in pseudonymized or anonymized form for up to 26 months.

When personal data is no longer needed, we will securely delete or anonymize it.


10. Cookies and Tracking Technologies

Our website uses cookies and similar tracking technologies to enhance your browsing experience, analyse website usage, and support our marketing efforts.

Cookies are small text files placed on your device when you visit our website. We use the following categories of cookies:

  • Strictly necessary cookies: required for the website to function properly (e.g., session management, shopping cart). These cannot be disabled.
  • Analytics cookies: help us understand how visitors interact with our website by collecting information about pages visited, time spent, and navigation patterns.
  • Marketing cookies: used to deliver relevant advertisements and track the effectiveness of our marketing campaigns. These may be set by third-party advertising partners.
  • Functional cookies: enable enhanced functionality and personalization, such as remembering your language preferences.

You can manage your cookie preferences through our cookie consent banner when you first visit our website, or by adjusting your browser settings at any time. Please note that disabling certain cookies may affect the functionality of our website.

For more information about the specific cookies we use and their purposes, please refer to our cookie consent tool on the website.

11. Data Security

We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These measures include, but are not limited to:

  • Encryption of data in transit using TLS/SSL protocols.
  • Access controls and authentication requirements for systems containing personal data.
  • Regular security assessments and vulnerability testing.
  • Employee training on data protection and information security.
  • Contractual obligations on all third-party service providers to maintain equivalent security standards.

While we take all reasonable precautions to protect your data, no method of transmission over the internet or electronic storage is completely secure. We cannot guarantee absolute security of your personal data.

12. Your Rights

Under applicable data protection laws, including the GDPR, you have the following rights in relation to your personal data:

Right of access (Article 15): You have the right to request a copy of the personal data we hold about you and information about how we process it.

Right to rectification (Article 16): You have the right to request correction of inaccurate or incomplete personal data.

Right to erasure (Article 17): You have the right to request deletion of your personal data where there is no compelling reason for us to continue processing it, subject to applicable legal obligations.

Right to restriction of processing (Article 18): You have the right to request that we restrict the processing of your personal data in certain circumstances.

Right to data portability (Article 20): You have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit it to another controller.

Right to object (Article 21): You have the right to object to processing based on our legitimate interests, including direct marketing. Where you object to direct marketing, we will stop processing your data for that purpose.

Right to withdraw consent (Article 7(3)): Where processing is based on your consent, you have the right to withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal.

Right to lodge a complaint: You have the right to lodge a complaint with a supervisory authority. In Norway, the relevant authority is the Norwegian Data Protection Authority (Datatilsynet) at www.datatilsynet.no.

To exercise any of these rights, please contact us at info@bootybuilder.com. We will respond to your request within 30 days, as required by the GDPR. We may ask you to verify your identity before processing your request.


13. Children’s Privacy

Our website and services are not directed at children under the age of 16. We do not knowingly collect personal data from children under 16. If we become aware that we have collected personal data from a child under 16 without verifiable parental consent, we will take steps to delete that data as soon as possible.

If you believe we may have collected data from a child under 16, please contact us at info@bootybuilder.com.

14. Third-Party Links

Our website may contain links to third-party websites, services, or platforms that are not operated by us. This Privacy Policy does not apply to those third-party sites. We encourage you to review the privacy policies of any third-party website you visit.

We are not responsible for the privacy practices or content of third-party websites.

15. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our data processing practices, legal requirements, or business operations. When we make material changes, we will:

  • Update the “Last Updated” date at the top of this policy.
  • Post a notice on our website informing you of the change.
  • Where required by law, obtain your consent before applying material changes to the processing of your personal data.

We encourage you to review this Privacy Policy periodically.

16. Jurisdiction-Specific Provisions

Depending on where you are located, additional rights and obligations may apply:

16.1 European Economic Area (EEA) and United Kingdom

If you are located in the EEA or the UK, your data is processed in accordance with the GDPR and/or the UK GDPR, as applicable. The rights described in Section 12 apply in full. Our lead supervisory authority is the Norwegian Data Protection Authority (Datatilsynet).

16.2 United States

If you are a resident of California, you may have additional rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA), including the right to know what personal information is collected, the right to request deletion, the right to opt out of the sale or sharing of personal information, and the right to non-discrimination. We do not sell your personal information. To exercise your rights, contact us at info@bootybuilder.com.

Residents of other US states with applicable privacy legislation (such as Virginia, Colorado, Connecticut, Utah, and others) may have similar rights. Please contact us to exercise any applicable rights.

16.3 Other Jurisdictions

If you are located in a jurisdiction with specific data protection laws (such as Brazil’s LGPD, Australia’s Privacy Act, Canada’s PIPEDA, or others), we will process your data in compliance with applicable local requirements. Please contact us if you have questions about your rights under local law.

17. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our handling of your personal data, please contact us:

HAL HOLDING AS

Email: info@bootybuilder.com

Website: www.bootybuilder.com

For complaints regarding our data processing, you may also contact the Norwegian Data Protection Authority (Datatilsynet):

Datatilsynet

Website: www.datatilsynet.no

Email: postkasse@datatilsynet.no