Privacy
Privacy Policy
Last updated: July 2026.
1. Who we are
Boardroom (“Boardroom”, “we”, “us”) is a board-governance software product operated by Balayogesh Alagesan, based in Doha, Qatar. This policy describes what data we collect when you or your organisation (“you”, the “customer”) use Boardroom, and how we handle it.
2. What we collect
We collect four categories of data:
- Account & identity — name, email, and profile photo from Google OAuth or your company's SAML identity provider. We never see or store a password: Boardroom has none to leak.
- Board content — the packs, minutes, resolutions, votes, e-signatures, files, notes, and messages you and your organisation create. This is your data; we process it only to run the product for you.
- Billing — your plan, seat count, and usage counters. Card numbers are never sent to or stored by Boardroom — Stripe, our payment processor, handles them directly.
- Operational logs — sign-in events, error reports, and audit-trail entries (who did what, when) needed to run and secure the product.
3. How we use it
To provide the service you signed up for; to authenticate you and enforce your organisation's access controls; to send transactional notifications you or your admin configured (email, push, WhatsApp); to bill your subscription; to detect and prevent abuse; and to fix bugs. We do not sell your data, and we do not use your board content to train any AI model. AI features (minutes drafting, ask-the-boardroom) only process a record when you or a teammate explicitly triggers that action.
4. Legal basis (GDPR)
Where GDPR applies, we process account and board-content data under contract (to provide the service you subscribed to), operational logs under legitimate interest (security and abuse prevention), and any marketing communication only with your consent.
5. Who else sees it
We share data only with the subprocessors needed to run the product (hosting, email delivery, payment processing, and optional integrations you turn on, like WhatsApp or an AI provider). We do not sell or rent your data to third parties for marketing. The full, current subprocessor list is published on our Trust page.
6. Retention
Governance records (packs, minutes, resolutions, audit log) are retained per your organisation's configured retention policy, or indefinitely by default, since these are your corporate records. Deleted items go to Trash first and can be restored; permanent deletion follows your retention settings. Account data is retained until you close your account, after which it is deleted or anonymised per our data-retention schedule.
7. Your rights
You can access, correct, or export your data at any time from inside the product (self-service tenant export, in open formats). To request erasure, object to processing, or ask a question about this policy, contact us (below) — we aim to respond to any subject access request within 30 days.
8. International transfers
Boardroom is hosted in the EU. If you are located outside the EU/EEA, your data may be transferred internationally to provide the service; we rely on appropriate safeguards (such as Standard Contractual Clauses) where required. A data processing agreement (DPA) covering these terms is available on request.
9. Security
We encrypt stored secrets and backups, isolate every organisation's data, and publish our security architecture in detail on our Trust page, including what we do and do not store.
10. Cookies
Boardroom uses only the cookies needed to keep you signed in (session cookies) and to remember your preferences. We do not use third-party advertising or tracking cookies, and we do not load any third-party analytics or ad scripts on the product surface.
11. Children
Boardroom is a business tool and is not directed at, or knowingly used by, children under 16.
12. Changes to this policy
We'll update the “last updated” date above when this policy changes, and post a notice in the product for material changes.
13. Contact
Questions about this policy or your data: balayogesh@gmail.com.