Data Processing Agreement
This Data Processing Agreement ("DPA") applies automatically to all customers of BoardTable and forms part of the Terms of Service. It describes how BoardTable Pty Ltd processes personal information on behalf of your organisation. If your board policy or procurement process requires a countersigned DPA, contact legal@boardtable.com.au.
1. Definitions
In this DPA:
- "Controller" means your organisation — the entity that determines the purposes and means of processing personal information entered into BoardTable.
- "Processor" means BoardTable Pty Ltd, which processes personal information on the Controller's behalf.
- "Personal Information" has the meaning given in the Privacy Act 1988 (Cth) and includes names, email addresses, roles, and any other identifying information about individuals stored in your BoardTable account.
- "Processing" means any operation performed on Personal Information, including collection, storage, retrieval, transmission, deletion, and all operations in between.
- "Sub-processor" means any third party engaged by BoardTable to assist in processing Personal Information.
2. Roles and Responsibilities
Your organisation is the Controller of all Personal Information your users upload to BoardTable. BoardTable is the Processor — we handle that data only to the extent necessary to provide and maintain the Service, and only in accordance with your documented instructions (as set out in your use of the platform and these Terms).
BoardTable does not determine the purpose of processing your organisation's Personal Information. We do not use it to train BoardTable-owned models, sell it, or share it with third parties for any purpose other than providing the Service. Customer-directed AI and transcription requests are processed by the providers disclosed in section 5 under their applicable API terms and our provider arrangements.
3. Controller Instructions
By using BoardTable, you instruct us to process Personal Information as necessary to:
- Provide and maintain access to the BoardTable platform.
- Authenticate users and enforce role-based access controls.
- Store, retrieve, and display governance records as directed by your administrators.
- Send transactional notifications (meeting reminders, document-signing requests, password resets).
- Generate backups and ensure service continuity.
- Comply with legal obligations applicable to BoardTable as a service provider.
If you require us to process data in a way not covered by these instructions, please contact legal@boardtable.com.au to discuss a supplementary arrangement.
4. Security Measures
BoardTable implements and maintains technical and organisational measures appropriate to the risk of processing Personal Information. These measures include:
- Application-level HTTPS enforcement and HSTS; production TLS versions and ciphers are verified at the Azure edge.
- Support for SQLCipher/AES-256 database encryption and AES-GCM protection of authenticator secrets when separately managed production keys are configured; Azure storage encryption is verified from the live subscription.
- Role-based access controls ensuring users can only access data they are authorised to see.
- Bcrypt password hashing (work factor 10).
- Audit logging of significant access, export, authentication, denial and administrative events. Production retention and immutable off-system storage are confirmed separately.
- Application support for scheduled online database snapshots, local rotation and optional off-host Azure Blob copies. Actual schedule, retention, encryption, location, recovery point and restore readiness depend on production configuration and are confirmed in customer security evidence.
- Microsoft Azure Australia East is the intended primary hosting region. Overseas and global processing by the sub-processors below is not represented as Australian-only hosting.
Independent penetration testing and SOC 2 Type II attestation are planned but not yet in place. Our Trust Centre lists what is current and what is still on the roadmap; we would rather you knew than assumed.
Full details are available on our Security page.
5. Sub-processors
BoardTable engages the following sub-processors to deliver the Service. All sub-processors are bound by confidentiality obligations and data processing terms consistent with this DPA.
| Sub-processor | Purpose | Location |
|---|---|---|
| Microsoft Azure | Cloud hosting, database, and file storage — all board content is stored here | Intended primary region: Australia East (Sydney); verified per production environment |
| Anthropic | Optional AI features: agenda drafting, pack summaries, minutes assistance, risk scanning and assistants. The selected text needed for a user-requested operation is sent to the API. Also used in the support desk to investigate a submitted ticket and draft a reply, which means the ticket's text and any screenshots attached to it are sent to the API for that purpose. Provider retention and model-training treatment are governed by the applicable API terms and BoardTable's provider agreement. | USA |
| OpenAI | Optional Whisper transcription. Audio selected by a user is sent to the API for transcription; no audio is sent when the feature is not used. Provider retention and model-training treatment are governed by the applicable API terms and BoardTable's provider agreement. | USA / global infrastructure |
| Stripe | Payment processing (billing information only — no board content) | USA / Australia |
| Resend | Transactional email delivery and inbound email processing. Email bodies can include meeting titles and agenda item names; content and attachments sent to a board's inbound address pass through Resend before BoardTable retrieves them. Also delivers support desk mail — the confirmation of a support request and any reply from us, which quote the ticket's subject and content back to you. | USA |
| Cloudflare | Turnstile bot protection on public authentication and contact surfaces, when enabled; processes request, device and network signals needed to assess abuse. It is listed here because the capability ships with the product; where the verifying key is not configured for an environment, no widget is served and no data reaches Cloudflare from that environment. | Global infrastructure |
Microsoft Clarity was previously listed here for behavioural analytics. It has been removed from the board application entirely and no session-replay or behavioural analytics tooling now runs on any authenticated screen.
5.1 Support desk
When you raise a support request we process it in a separate application from the board portal, reachable at support.boardtable.com.au. It is hosted on the same Microsoft Azure infrastructure and in the same region as the platform, and it is operated by the same people.
Two things about it are worth stating plainly, because they are not obvious from the board portal alone:
- Support tickets can contain board content. The form invites a screenshot or a screen recording, which is usually the fastest way to show us a problem — and a screenshot of the screen you were on is frequently a screenshot of a board paper. Those files, the text you write, and the name, email address and organisation carried across from your session are stored with the ticket.
- Its database is shared with another product. The same application serves the support desk for Stockroom, an unrelated internal system operated by Bendigo Heritage. Tickets are tagged by product and the two are administered through one console by the same BoardTable staff. No Stockroom user has access to BoardTable tickets.
Support tickets are retained while they are open and for as long as they remain useful as a record of an issue and its resolution. You may ask us to delete a specific ticket and its attachments at any time by writing to privacy@boardtable.com.au. Support data is not used for marketing and is not used to train any model of ours.
We will notify account administrators by email at least 14 days before adding or replacing a sub-processor. You may object to a new sub-processor by contacting legal@boardtable.com.au within 14 days of notification.
6. Data Breach Notification
In the event of a data breach involving your organisation's Personal Information, BoardTable will:
- Notify affected organisations without undue delay and ordinarily within 72 hours of becoming aware of the breach.
- Provide a written incident report describing the nature of the breach, the categories and approximate volume of Personal Information involved, likely consequences, and measures taken or proposed to address it.
- Comply with the mandatory Notifiable Data Breaches (NDB) scheme under the Privacy Act 1988 (Cth), including notifying the Office of the Australian Information Commissioner (OAIC) and affected individuals where required.
- Cooperate with your organisation's own notification obligations to the extent reasonably practicable.
To report a suspected security incident or data breach, contact privacy@boardtable.com.au immediately.
7. Data Retention and Deletion
While your subscription is active, BoardTable retains your organisation's governance records and the personal information in them so the Service can work. We do not impose a separate expiry on your board records while you are a customer.
Your organisation remains responsible for deciding what governance records it must retain. Export required records before account deletion. BoardTable will agree a written closure plan with the account administrator rather than implying that an automated post-termination read-only state exists when it does not.
Upon an authorised account-closure request:
- The administrator is given an agreed opportunity to export data before destructive deletion is authorised.
- Live tenant data is deleted using the platform's tenant-deletion process after identity, scope and timing are confirmed.
- Backup copies age out under the verified production backup-retention policy; the applicable period is provided in the closure plan.
- Legal holds, security investigations or applicable law may require identified records to be retained for longer, and we will explain that basis.
- We will provide written confirmation of deletion on request.
Earlier deletion of specific Personal Information (e.g. a departed director's profile) may be requested by your administrator via account settings or by contacting privacy@boardtable.com.au, subject to any applicable legal retention obligations.
8. Audit Rights
You may request information necessary to demonstrate BoardTable's compliance with this DPA, including copies of our security questionnaire responses and relevant certifications. Requests should be directed to legal@boardtable.com.au. We will respond within 15 business days.
On-site audits of BoardTable's infrastructure are not offered as a standard entitlement given the shared-infrastructure nature of the Service. Where available to BoardTable and permitted by provider terms, we will share relevant infrastructure-provider reports or attestations under appropriate confidentiality terms.
9. Assistance with Your Obligations
BoardTable will, taking into account the nature of processing and information reasonably available to us, assist your organisation to respond to:
- Requests from individuals exercising rights under the Australian Privacy Principles (access, correction, deletion, complaints).
- Requirements to conduct privacy impact assessments.
- Inquiries or investigations by the OAIC.
Contact privacy@boardtable.com.au to request assistance.
10. Confidentiality of Processing
BoardTable personnel who process Personal Information are bound by confidentiality obligations and have received appropriate privacy training. Access to customer data is limited to staff with a legitimate operational need, is logged, and requires manager approval for any access beyond routine platform maintenance.
11. Changes to This DPA
We may update this DPA from time to time to reflect changes in law, our sub-processors, or our security practices. We will notify account administrators by email at least 14 days before material changes take effect. The current version is always available at boardtable.com.au/dpa.
12. Countersigned DPA
If your organisation requires a countersigned DPA — for example to satisfy ACNC governance requirements, board policy, insurance conditions, or a procurement process — please contact legal@boardtable.com.au. We will issue a signed agreement promptly, typically within 3 business days.
13. Governing Law
This DPA is governed by the laws of the State of Victoria, Australia, consistent with the Terms of Service.