Privacy Policy
Boardroom Revenue Control OS ("Boardroom", "we") is a business software service. Companies ("customers") use it to run their revenue operations: their CRM data, their marketing channels, and an AI assistant that helps them answer the people who contact them.
This policy explains what we collect, why, how long we keep it, and how to have it deleted. It covers the whole service, including the parts that connect to Meta platforms (Instagram and Facebook) and to Google (Calendar, Drive and Gmail) — see Google user data.
Who controls the data
For data about our own customers — the businesses that sign up — Boardroom is the controller. For data about the end users those businesses talk to (for example, a person who sends an Instagram message to a customer's business account), the customer is the controller and Boardroom is a processor acting on their instructions.
What we collect
| Data | Why |
|---|---|
| Account details of our customers — name, work email, company, workspace role | To create and secure an account and to bill it |
| Messages exchanged in a connected channel, and the sender's platform-scoped ID and display name | To let the AI assistant read the conversation, answer in context, and show the customer's team a shared inbox |
| Access tokens issued by a connected platform (CRM, Meta, Google, Telegram, telephony) | To read the customer's own data from that platform and, where the customer has enabled it, to reply on their behalf |
| Aggregate metrics — message counts, response times, campaign performance | To produce the dashboards the customer signed up for |
| Technical logs — request timestamps, status codes, error types | Security, abuse prevention and debugging |
We do not collect special-category data deliberately, we do not buy data about you from third parties, and we do not build advertising profiles.
Data we receive from Meta
When a customer connects their Instagram professional account or Facebook Page, they sign in to their own Meta account and grant the permissions themselves. We never ask for, see, or store a Meta password. With that grant we receive:
- the name and ID of the Pages and Instagram accounts they administer, so they can choose which to connect;
- the content of messages sent to those accounts, and the platform-scoped sender ID and name, so the assistant can read and answer them;
- access tokens scoped to those accounts.
We request the narrowest permission set that makes two-way messaging work:
instagram_basic, instagram_manage_messages, pages_messaging,
pages_manage_metadata, pages_show_list, pages_read_engagement
and business_management. We do not request permissions for content publishing,
advertising audiences, or friend lists through this integration.
Data received from Meta is used only to deliver the messaging feature to the customer whose account it came from. We do not sell it, do not share it with data brokers, do not use it for advertising, and do not use it to train general-purpose AI models.
Data we receive from Kommo
When a customer connects Kommo, they sign in to their own account and authorise the connection themselves. We never ask for, see, or store their Kommo password. With that authorisation we receive their pipeline, stage, lead and contact data, and access tokens scoped to that account, so the assistant can read and, where the customer enables it, update their own CRM. This data is used only to deliver the integration to the customer whose account it came from — never sold, never shared with data brokers, never used for advertising.
Google user data
A customer can connect a Google account to their workspace. The workspace owner or admin signs in on Google's own consent screen and grants the permissions there; we never ask for, see, or store a Google password. The connection is made in two separate steps, and each step asks only for the permissions it names. The second step is optional.
| Google permission | What we access, and why |
|---|---|
| Step 1 — the Google connection | |
calendar.eventsView and edit events on your calendars | Events on the connected calendar. We create an event when the customer's AI agent or team books a meeting (title, time, the guest email the customer's contact supplied, and a Google Meet link), and read upcoming events to show the customer their own agenda in the app. |
calendar.freebusySee the availability on your calendars | Free/busy time of the connected calendar — and, when a colleague is responsible for a customer, of that colleague's calendar if it is shared with the connected account — so the agent only offers meeting slots that are actually free. Only busy/free blocks are read, not event details; we do not change calendar settings or sharing. |
drive.fileFiles this app creates | Only the files Boardroom itself creates in the customer's Google Drive — the accounting export spreadsheet. We cannot see or open any other file in the customer's Drive. |
gmail.sendSend email on your behalf | Sending email from the customer's own address when the customer instructs it: a reply a team member approved, or a letter composed in the app. This permission cannot read any message. |
openid, emailYour Google account address | To show the customer which Google account is connected, and to make sure a later step is granted by the same account. |
| Step 2 — optional: «Allow reading incoming mail» | |
gmail.readonlyRead your email | Requested only if the customer presses «Allow reading incoming mail» in the app and approves it on a separate Google screen. We read new messages in the inbox so the customer's AI agent can answer enquiries in the same conversation (from the customer's address, using gmail.send), and so invoices and receipts that arrive as attachments can be taken into the customer's own accounting. Newsletters and automated mail are recorded for the customer but never answered. Without this step Boardroom reads no email at all. |
How we use Google user data.
- Only to provide the features described above, to the customer whose Google account it came from, and to keep those features working and secure.
- We do not sell Google user data.
- We do not use Google user data for advertising — including retargeting, personalised or interest-based advertising — and we do not use it to determine creditworthiness or for lending.
- We do not transfer Google user data to data brokers or other information resellers.
- We do not use Google user data to develop, improve or train generalised (non-personalised) AI or machine-learning models. When a feature needs AI — for example, drafting a reply to an email the customer allowed us to read, or answering the customer's own question about their agenda — only the content needed for that answer is sent to our AI provider (Anthropic), solely to produce that answer for that customer, under terms that do not allow it to be used for model training.
- We transfer Google user data only to the service providers that run these features for us — Supabase (database), Netlify (hosting) and Anthropic (AI replies) — each under contract and only as necessary to provide the feature; and otherwise only when required by law, for security, or as part of a merger or acquisition with notice to the customer.
- No Boardroom employee reads Google user data, except where the customer has given explicit consent for specific data (for example, to investigate a support request they sent us), where it is necessary for security purposes such as investigating abuse or a bug, where required by law, or where the data has been aggregated and anonymised for internal operations.
Limited Use. Boardroom's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Storage. The long-lived Google token is stored encrypted in a dedicated secret store and is never sent to a browser. Short-lived access tokens are created for a single request and discarded. Transport is TLS throughout.
Retention and deletion. The stored Google token and the list of granted permissions are kept while the connection exists. Emails the agent answered, meetings it booked and documents taken into accounting are kept as part of the customer's workspace for the life of the account, unless the customer deletes them sooner. The workspace owner or admin can disconnect Google at any time in the app: open Settings → Integrations, press Disconnect on the Google Calendar or Email (Google) card, and press it again to confirm. We then ask Google to revoke Boardroom's access, and immediately delete the stored Google token and the connection record; the app reports both results separately — whether Google confirmed the revocation, and that the stored token was deleted. If Google does not confirm, the token is still deleted, and the app asks the customer to remove Boardroom in their Google Account as well. The customer can also revoke Boardroom's access directly in their Google Account at myaccount.google.com/permissions; from that moment the stored token no longer works and we can no longer reach any Google data. Disconnecting does not delete the emails, meetings and documents already in the workspace; to have that Google-derived data deleted too, email us at the address below or follow the data deletion instructions; we complete it within 30 days. When a workspace is closed, its Google token and Google-derived data are deleted with it.
Advertising measurement on our public website
Our public pages (the home page, pricing, this policy, terms and support) use the Meta Pixel to measure whether our own advertising works: a page view, and clicks on «Book a demo», «Experience Boardroom AI», WhatsApp and the voice orb. Meta may set cookies for this. We also keep the advertising tags a visitor arrived with (utm parameters, ad, ad set and campaign ids, fbclid) in the browser's local storage, so a demo booked later can be matched to the ad that brought it. The pixel is not loaded inside the Boardroom cabinet after sign-in, and no customer, conversation or CRM data is sent to Meta by it. You can block it with your browser's tracking protection or an ad blocker; the site keeps working.
AI processing
Message content is sent to our AI provider (Anthropic) to generate a reply for the customer's team. It is processed to answer that conversation and is not used by us or by the provider to train foundation models. Where a customer has not enabled outbound sending, the generated reply is stored as a draft for a human to review and is never delivered to the end user. The same applies to Google user data, as described in Google user data.
Storage, security and location
Data is held in managed infrastructure (Supabase and Netlify). Access tokens are stored encrypted at rest in a dedicated secret store and are never exposed to a browser. Each workspace's data is isolated at the database level, and access is limited to the roles the customer assigns. Transport is TLS throughout.
How long we keep it
- Conversation content: for the life of the customer's account, unless they delete it sooner.
- Access tokens: until the customer disconnects the integration or the token expires, whichever is first.
- Technical logs: up to 90 days.
- Billing records: as long as tax law requires.
When an account is closed we delete customer data within 30 days, except records we are legally required to retain.
Sharing
We share data only with the infrastructure and AI providers needed to run the service, each under contract and only for that purpose, and where the law compels disclosure. We do not sell personal data.
Your rights
You may ask us to access, correct, export or delete your data, or to restrict how it is used. If you contacted a business that uses Boardroom, please contact that business first — they control the conversation. If that is not practical, write to us and we will route the request.
Deletion is documented separately, including the one-click route: Data deletion instructions.
Children
The service is for businesses and is not directed at anyone under 16.
Changes
If this policy changes materially we will update the date above and notify account owners by email.
Contact
Boardroom Digital Intelligence, United Arab Emirates
boardroom.gen@gmail.com
Политика конфиденциальности
Boardroom Revenue Control OS («Boardroom», «мы») — сервис бизнес-программного обеспечения. Компании («клиенты») используют его для управления своими продажами: данными CRM, маркетинговыми каналами и ИИ-ассистентом, который помогает отвечать людям, обратившимся к ним.
Эта политика объясняет, что мы собираем, зачем, как долго храним и как удалить данные. Она охватывает весь сервис, включая части, подключённые к платформам Meta (Instagram и Facebook), к Kommo, а также к Google (Календарь, Диск и Gmail) — см. Данные пользователей Google.
Кто контролирует данные
В отношении данных наших собственных клиентов — компаний, которые регистрируются в сервисе — контролёром данных является Boardroom. В отношении данных конечных пользователей, с которыми общаются эти компании (например, человека, написавшего в Instagram аккаунту клиента), контролёром является клиент, а Boardroom выступает обработчиком по его поручению.
Что мы собираем
| Данные | Зачем |
|---|---|
| Данные аккаунта наших клиентов — имя, рабочий email, компания, роль в рабочем пространстве | Для создания и защиты аккаунта, а также для выставления счетов |
| Сообщения из подключённых каналов, а также ID и имя отправителя в рамках платформы | Чтобы ИИ-ассистент мог читать переписку, отвечать по контексту и показывать команде клиента общий инбокс |
| Токены доступа, выданные подключённой платформой (CRM, Meta, Google, Telegram, телефония) | Чтобы читать собственные данные клиента с этой платформы и, если клиент это включил, отвечать от его имени |
| Агрегированные метрики — количество сообщений, время ответа, эффективность кампаний | Для дашбордов, на которые подписан клиент |
| Технические логи — время запросов, коды статуса, типы ошибок | Безопасность, защита от злоупотреблений и отладка |
Мы намеренно не собираем данные особых категорий, не покупаем данные о вас у третьих лиц и не строим рекламные профили.
Данные, которые мы получаем от Meta
Когда клиент подключает свой профессиональный аккаунт Instagram или Facebook Page, он сам входит в свой аккаунт Meta и сам предоставляет разрешения. Мы никогда не запрашиваем, не видим и не храним пароль от Meta. С этим разрешением мы получаем:
- название и ID страниц и аккаунтов Instagram, которыми он администрирует, — чтобы выбрать, какие подключить;
- содержание сообщений, отправленных на эти аккаунты, а также ID и имя отправителя в рамках платформы, — чтобы ассистент мог их читать и отвечать;
- токены доступа, ограниченные этими аккаунтами.
Мы запрашиваем минимальный набор разрешений, необходимый для двусторонней переписки:
instagram_basic, instagram_manage_messages, pages_messaging,
pages_manage_metadata, pages_show_list, pages_read_engagement
и business_management. Мы не запрашиваем разрешения на публикацию контента,
рекламные аудитории или списки друзей через эту интеграцию.
Данные, полученные от Meta, используются только для предоставления функции переписки клиенту, чей это аккаунт. Мы их не продаём, не передаём брокерам данных, не используем для рекламы и не используем для обучения универсальных ИИ-моделей.
Данные, которые мы получаем от Kommo
Когда клиент подключает Kommo, он сам входит в свой аккаунт и сам авторизует подключение. Мы никогда не запрашиваем, не видим и не храним его пароль от Kommo. С этой авторизацией мы получаем данные его воронки, этапов, лидов и контактов, а также токены доступа, ограниченные этим аккаунтом, — чтобы ассистент мог читать и, если клиент это включил, обновлять его собственную CRM. Эти данные используются только для предоставления интеграции клиенту, чей это аккаунт, — никогда не продаются, не передаются брокерам данных, не используются для рекламы.
Данные пользователей Google
Клиент может подключить к своему рабочему пространству аккаунт Google. Владелец или администратор пространства входит на экране согласия самого Google и выдаёт разрешения там; мы никогда не запрашиваем, не видим и не храним пароль от Google. Подключение делается в два отдельных шага, и каждый шаг запрашивает только названные в нём разрешения. Второй шаг — по желанию.
| Разрешение Google | К чему мы получаем доступ и зачем |
|---|---|
| Шаг 1 — подключение Google | |
calendar.eventsПросмотр и изменение событий календаря | События подключённого календаря. Мы создаём событие, когда ИИ-агент или команда клиента назначает встречу (название, время, адрес гостя, который сообщил сам контакт клиента, и ссылка Google Meet), и читаем ближайшие события, чтобы показать клиенту его собственное расписание в приложении. |
calendar.freebusyПросмотр занятости в календарях | Занятость (свободно/занято) подключённого календаря — а если за клиента отвечает коллега, то и календаря этого коллеги, если он открыт подключённому аккаунту, — чтобы агент предлагал только действительно свободное время. Читаются только интервалы занятости, без содержания событий; настройки календаря и доступ к нему мы не меняем. |
drive.fileФайлы, созданные этим приложением | Только файлы, которые Boardroom сам создаёт на Google Диске клиента, — таблица выгрузки бухгалтерии. Никакие другие файлы на Диске клиента мы не видим и открыть не можем. |
gmail.sendОтправка писем от вашего имени | Отправка писем с собственного адреса клиента по его указанию: ответ, одобренный сотрудником, или письмо, составленное в приложении. Это разрешение не позволяет прочитать ни одного письма. |
openid, emailАдрес вашего аккаунта Google | Чтобы показать клиенту, какой аккаунт Google подключён, и убедиться, что следующий шаг разрешает тот же аккаунт. |
| Шаг 2 — по желанию: «Разрешить читать входящие письма» | |
gmail.readonlyЧтение писем | Запрашивается, только если клиент сам нажал в приложении «Разрешить читать входящие письма» и подтвердил это на отдельном экране Google. Мы читаем новые письма во входящих, чтобы ИИ-агент клиента мог отвечать на обращения в той же переписке (с адреса клиента, через gmail.send), и чтобы счета и чеки, приходящие вложениями, попадали в собственную бухгалтерию клиента. Рассылки и автоматические письма записываются для клиента, но на них никогда не отвечают. Без этого шага Boardroom не читает почту вообще. |
Как мы используем данные пользователей Google.
- Только для работы описанных выше функций для клиента, чей это аккаунт Google, и для того, чтобы эти функции работали исправно и безопасно.
- Мы не продаём данные пользователей Google.
- Мы не используем данные пользователей Google для рекламы — в том числе для ретаргетинга, персонализированной рекламы и рекламы по интересам, — а также для оценки кредитоспособности и кредитования.
- Мы не передаём данные пользователей Google брокерам данных и иным перепродавцам информации.
- Мы не используем данные пользователей Google для разработки, улучшения или обучения обобщённых (не персонализированных) моделей ИИ и машинного обучения. Когда функции нужен ИИ — например, чтобы подготовить ответ на письмо, которое клиент разрешил нам читать, или ответить на вопрос клиента о его расписании, — нашему ИИ-провайдеру (Anthropic) передаётся только то, что нужно для этого ответа, и только чтобы подготовить этот ответ этому клиенту, на условиях, не допускающих использования для обучения моделей.
- Мы передаём данные пользователей Google только поставщикам, которые обеспечивают работу этих функций, — Supabase (база данных), Netlify (хостинг) и Anthropic (ответы ИИ), — каждому по договору и только в объёме, необходимом для работы функции; в остальных случаях — только если этого требует закон, для обеспечения безопасности или в рамках слияния или поглощения с уведомлением клиента.
- Сотрудники Boardroom не читают данные пользователей Google, кроме случаев, когда клиент дал явное согласие на конкретные данные (например, чтобы разобраться в его обращении в поддержку), когда это необходимо для безопасности — например, для расследования злоупотребления или ошибки, — когда этого требует закон, или когда данные агрегированы и обезличены для внутренних нужд.
Ограниченное использование (Limited Use). Использование и передача Boardroom информации, полученной через API Google, любому другому приложению соответствуют Правилам в отношении данных пользователей сервисов Google API (Google API Services User Data Policy), включая требования ограниченного использования (Limited Use). Boardroom's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Хранение. Долгоживущий токен Google хранится зашифрованным в выделенном хранилище секретов и никогда не передаётся в браузер. Краткоживущие токены доступа создаются на один запрос и сразу отбрасываются. Передача данных всегда идёт по TLS.
Срок хранения и удаление. Сохранённый токен Google и список выданных разрешений хранятся, пока существует подключение. Письма, на которые ответил агент, назначенные им встречи и документы, принятые в бухгалтерию, хранятся в пространстве клиента в течение срока действия аккаунта, если клиент не удалит их раньше. Владелец или администратор пространства может в любой момент отключить Google в самом приложении: откройте Настройки → Интеграции, нажмите Отключить на карточке Google Calendar или «Почта (Google)» и нажмите ещё раз для подтверждения. Тогда мы просим Google отозвать доступ Boardroom и сразу удаляем сохранённый токен Google и запись о подключении; приложение сообщает оба результата по отдельности — подтвердил ли Google отзыв доступа и удалён ли сохранённый токен. Если Google отзыв не подтвердил, токен всё равно удаляется, а приложение просит клиента дополнительно удалить Boardroom в своём аккаунте Google. Клиент также может отозвать доступ Boardroom напрямую в своём аккаунте Google на странице myaccount.google.com/permissions; с этого момента сохранённый токен перестаёт работать, и доступа к данным Google у нас больше нет. Отключение не удаляет письма, встречи и документы, уже находящиеся в пространстве; чтобы удалить и эти полученные из Google данные, напишите нам по адресу ниже или воспользуйтесь инструкцией по удалению данных; мы выполняем это в течение 30 дней. При закрытии пространства его токен Google и полученные из Google данные удаляются вместе с ним.
Измерение рекламы на публичном сайте
На публичных страницах (главная, цены, эта политика, условия и поддержка) стоит пиксель Meta — чтобы понимать, работает ли наша собственная реклама: просмотр страницы и нажатия «Записаться на демо», «Попробовать Boardroom AI», WhatsApp и голосового шара. Meta может ставить для этого cookie. Метки рекламы, с которыми пришёл посетитель (utm-параметры, id объявления, группы и кампании, fbclid), мы храним в локальном хранилище браузера, чтобы связать записанное позже демо с объявлением. Внутри кабинета Boardroom после входа пиксель не загружается, и никакие данные клиентов, переписки и CRM через него в Meta не уходят. Его можно заблокировать защитой от отслеживания в браузере или блокировщиком рекламы — сайт продолжит работать.
Обработка ИИ
Содержание сообщений отправляется нашему ИИ-провайдеру (Anthropic) для генерации ответа команде клиента. Оно обрабатывается только для ответа на эту переписку и не используется нами или провайдером для обучения базовых моделей. Если клиент не включил исходящую отправку, сгенерированный ответ сохраняется как черновик для проверки человеком и никогда не доставляется конечному пользователю. То же относится к данным пользователей Google — см. Данные пользователей Google.
Хранение, безопасность и расположение
Данные хранятся на управляемой инфраструктуре (Supabase и Netlify). Токены доступа хранятся зашифрованными в выделенном хранилище секретов и никогда не раскрываются браузеру. Данные каждого рабочего пространства изолированы на уровне базы данных, доступ ограничен ролями, назначенными клиентом. Передача данных всегда идёт по TLS.
Сколько мы храним данные
- Содержание переписки: в течение всего срока действия аккаунта клиента, если он не удалит его раньше.
- Токены доступа: до отключения интеграции клиентом или истечения срока токена — что наступит раньше.
- Технические логи: до 90 дней.
- Records по биллингу: столько, сколько требует налоговое законодательство.
При закрытии аккаунта мы удаляем данные клиента в течение 30 дней, за исключением записей, которые обязаны хранить по закону.
Передача данных
Мы передаём данные только инфраструктурным и ИИ-провайдерам, необходимым для работы сервиса, каждому по договору и только для этой цели, а также когда этого требует закон. Мы не продаём персональные данные.
Ваши права
Вы можете запросить у нас доступ, исправление, экспорт или удаление ваших данных, либо ограничение их использования. Если вы обращались к компании, использующей Boardroom, пожалуйста, сначала свяжитесь с ней — переписку контролирует она. Если это невозможно, напишите нам, и мы направим запрос по назначению.
Удаление описано отдельно, включая способ в один клик: Инструкция по удалению данных.
Дети
Сервис предназначен для бизнеса и не рассчитан на лиц младше 16 лет.
Изменения
При существенном изменении этой политики мы обновим дату выше и уведомим владельцев аккаунтов по email.
Контакты
Boardroom Digital Intelligence, Объединённые Арабские Эмираты
boardroom.gen@gmail.com