Privacy Policy
BoardTable Pty Ltd ("BoardTable", "we", "us") is committed to protecting the privacy of individuals who use our board governance platform. This Privacy Policy explains what personal information we collect, how we use it, with whom we share it, and the rights you have in relation to your information.
We comply with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). By using the BoardTable platform you consent to the collection and use of your information as described in this Policy.
1. Information We Collect
We collect information that is necessary to provide you with access to the BoardTable board portal. This includes:
- Account information: name, email address, role (administrator, staff, chair or director — and, for BoardTable's own support staff, a platform superadmin role), and a securely hashed password.
- Profile information: optional profile photo, board role or title, and contact details you choose to add.
- Governance records: meeting agendas and minutes, board papers, conflict of interest declarations, action items, risk register entries, and calendar events that you or your organisation create within the platform.
- Communication content: messages posted to the board message board.
- Usage data: log data including IP address, browser type, pages visited, and timestamps, used for security monitoring and service improvement.
- Billing information: processed by our payment provider (Stripe). We do not store full credit card details on our servers.
2. How We Use Your Information
We use personal information to:
- Provide, maintain, and improve the BoardTable platform.
- Authenticate users and enforce access controls.
- Send transactional emails such as meeting notifications, password resets, and document-signing requests.
- Respond to support enquiries.
- Comply with legal obligations, including requirements under the Corporations Act 2001 (Cth) relevant to board governance records.
- Analyse aggregated, de-identified usage patterns to improve features.
We do not sell personal information to third parties. We do not use personal information for direct marketing without your explicit consent.
3. Disclosure of Information
We may disclose personal information to:
- Other board members in your organisation — names and profiles are visible to other users in the same BoardTable account as necessary for governance functions.
- Service providers — the sub-processors listed in our DPA: Microsoft Azure (primary hosting and storage), Anthropic (optional text-based AI), OpenAI (optional audio transcription), Stripe (payments), Resend (transactional and inbound email) and Cloudflare (bot protection). Data sent depends on the feature used; provider handling is governed by the applicable API terms and our provider arrangements. Microsoft Clarity was previously used for behavioural analytics and has been removed from the authenticated application.
- Law enforcement or regulators — where required by Australian law or a valid court order.
We do not transfer personal information outside Australia except where our sub-processors operate overseas infrastructure with appropriate safeguards.
4. Ownership of Your Data
Your organisation owns all the governance data and content it puts into BoardTable. We act as the custodian and processor of that data on your behalf — we do not acquire ownership of it. We do not sell your data, share it with third parties for marketing, or use it to train BoardTable-owned models. Customer-directed AI and transcription requests are processed by the providers disclosed in our DPA under their applicable API terms and our provider arrangements. You may export your data while the account is active and request deletion under the process below.
5. Data Retention
We retain personal information and governance records while your organisation is a BoardTable customer. Before an authorised tenant deletion, we agree an export and closure plan with the account administrator. Live data is then deleted through the tenant-deletion process; backup copies expire under the verified production backup-retention policy. We provide the applicable timing in the closure plan rather than promising an automated 30/60/90-day lifecycle that the product does not currently enforce.
Your organisation remains responsible for its own governance-record retention obligations. Legal holds, security investigations or applicable law may require identified records to be retained for longer. See the full process in our Data Processing Agreement.
You may request earlier deletion of your personal profile information (see Section 7 below), subject to our legal obligations to retain certain records.
6. Security
We take reasonable steps to protect personal information from misuse, interference, loss and unauthorised access. Application controls include HTTPS enforcement, optional application-managed database encryption when production keys are configured, role-based access controls, mandatory TOTP authentication and security audit logging. Azure region, storage encryption, backup location and edge TLS configuration are deployment controls that require live-environment evidence. For current and planned controls, see our Trust Centre.
7. Access, Correction, and Complaints
Under the Australian Privacy Principles you have the right to access the personal information we hold about you and to request corrections. You may also make a complaint if you believe we have breached the APPs.
To exercise these rights or to lodge a complaint, contact our Privacy Officer at privacy@boardtable.com.au. We will respond within 30 days.
If you are unsatisfied with our response, you may contact the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
8. Cookies and Analytics
The BoardTable application uses one essential cookie, bt_session, to keep you signed in. It is httpOnly — page scripts cannot read it — and it is cleared when you sign out. We use no advertising cookies, no tracking pixels and no third-party analytics inside the application, and we do not sell your data.
We do not run session-replay or behavioural analytics on any signed-in screen. Microsoft Clarity was previously loaded in the application; it has been removed. Your meeting titles, agenda text, board papers, conflict declarations and director details are not sent to any analytics provider.
Server logs record IP address, browser type, the pages requested and timestamps, for security monitoring. The audit trail records significant actions taken in your board — who viewed, changed or downloaded what — and is visible to your own administrators.
9. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify account administrators by email and update the "Last updated" date at the top of this page. Continued use of the platform after changes constitutes acceptance of the revised policy.
10. Contact
BoardTable Pty Ltd
ABN 89 897 023 385
Email: privacy@boardtable.com.au