Boardroom Revenue Control OS · Last updated 14 September 2026

Privacy Policy

Boardroom Revenue Control OS ("Boardroom", "we") is a business software service. Companies ("customers") use it to run their revenue operations: their CRM data, their marketing channels, and an AI assistant that helps them answer the people who contact them.

This policy explains what we collect, why, how long we keep it, and how to have it deleted. It covers the whole service, including the parts that connect to Meta platforms (Instagram and Facebook) and to Google (Calendar, Drive and Gmail) — see Google user data.

Who controls the data

For data about our own customers — the businesses that sign up — Boardroom is the controller. For data about the end users those businesses talk to (for example, a person who sends an Instagram message to a customer's business account), the customer is the controller and Boardroom is a processor acting on their instructions.

What we collect

DataWhy
Account details of our customers — name, work email, company, workspace roleTo create and secure an account and to bill it
Messages exchanged in a connected channel, and the sender's platform-scoped ID and display nameTo let the AI assistant read the conversation, answer in context, and show the customer's team a shared inbox
Access tokens issued by a connected platform (CRM, Meta, Google, Telegram, telephony)To read the customer's own data from that platform and, where the customer has enabled it, to reply on their behalf
Aggregate metrics — message counts, response times, campaign performanceTo produce the dashboards the customer signed up for
Technical logs — request timestamps, status codes, error typesSecurity, abuse prevention and debugging

We do not collect special-category data deliberately, we do not buy data about you from third parties, and we do not build advertising profiles.

Data we receive from Meta

When a customer connects their Instagram professional account or Facebook Page, they sign in to their own Meta account and grant the permissions themselves. We never ask for, see, or store a Meta password. With that grant we receive:

We request the narrowest permission set that makes two-way messaging work: instagram_basic, instagram_manage_messages, pages_messaging, pages_manage_metadata, pages_show_list, pages_read_engagement and business_management. We do not request permissions for content publishing, advertising audiences, or friend lists through this integration.

Data received from Meta is used only to deliver the messaging feature to the customer whose account it came from. We do not sell it, do not share it with data brokers, do not use it for advertising, and do not use it to train general-purpose AI models.

Data we receive from Kommo

When a customer connects Kommo, they sign in to their own account and authorise the connection themselves. We never ask for, see, or store their Kommo password. With that authorisation we receive their pipeline, stage, lead and contact data, and access tokens scoped to that account, so the assistant can read and, where the customer enables it, update their own CRM. This data is used only to deliver the integration to the customer whose account it came from — never sold, never shared with data brokers, never used for advertising.

Google user data

A customer can connect a Google account to their workspace. The workspace owner or admin signs in on Google's own consent screen and grants the permissions there; we never ask for, see, or store a Google password. The connection is made in two separate steps, and each step asks only for the permissions it names. The second step is optional.

Google permissionWhat we access, and why
Step 1 — the Google connection
calendar.events
View and edit events on your calendars
Events on the connected calendar. We create an event when the customer's AI agent or team books a meeting (title, time, the guest email the customer's contact supplied, and a Google Meet link), and read upcoming events to show the customer their own agenda in the app.
calendar.freebusy
See the availability on your calendars
Free/busy time of the connected calendar — and, when a colleague is responsible for a customer, of that colleague's calendar if it is shared with the connected account — so the agent only offers meeting slots that are actually free. Only busy/free blocks are read, not event details; we do not change calendar settings or sharing.
drive.file
Files this app creates
Only the files Boardroom itself creates in the customer's Google Drive — the accounting export spreadsheet. We cannot see or open any other file in the customer's Drive.
gmail.send
Send email on your behalf
Sending email from the customer's own address when the customer instructs it: a reply a team member approved, or a letter composed in the app. This permission cannot read any message.
openid, email
Your Google account address
To show the customer which Google account is connected, and to make sure a later step is granted by the same account.
Step 2 — optional: «Allow reading incoming mail»
gmail.readonly
Read your email
Requested only if the customer presses «Allow reading incoming mail» in the app and approves it on a separate Google screen. We read new messages in the inbox so the customer's AI agent can answer enquiries in the same conversation (from the customer's address, using gmail.send), and so invoices and receipts that arrive as attachments can be taken into the customer's own accounting. Newsletters and automated mail are recorded for the customer but never answered. Without this step Boardroom reads no email at all.

How we use Google user data.

Limited Use. Boardroom's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Storage. The long-lived Google token is stored encrypted in a dedicated secret store and is never sent to a browser. Short-lived access tokens are created for a single request and discarded. Transport is TLS throughout.

Retention and deletion. The stored Google token and the list of granted permissions are kept while the connection exists. Emails the agent answered, meetings it booked and documents taken into accounting are kept as part of the customer's workspace for the life of the account, unless the customer deletes them sooner. The workspace owner or admin can disconnect Google at any time in the app: open Settings → Integrations, press Disconnect on the Google Calendar or Email (Google) card, and press it again to confirm. We then ask Google to revoke Boardroom's access, and immediately delete the stored Google token and the connection record; the app reports both results separately — whether Google confirmed the revocation, and that the stored token was deleted. If Google does not confirm, the token is still deleted, and the app asks the customer to remove Boardroom in their Google Account as well. The customer can also revoke Boardroom's access directly in their Google Account at myaccount.google.com/permissions; from that moment the stored token no longer works and we can no longer reach any Google data. Disconnecting does not delete the emails, meetings and documents already in the workspace; to have that Google-derived data deleted too, email us at the address below or follow the data deletion instructions; we complete it within 30 days. When a workspace is closed, its Google token and Google-derived data are deleted with it.

Advertising measurement on our public website

Our public pages (the home page, pricing, this policy, terms and support) use the Meta Pixel to measure whether our own advertising works: a page view, and clicks on «Book a demo», «Experience Boardroom AI», WhatsApp and the voice orb. Meta may set cookies for this. We also keep the advertising tags a visitor arrived with (utm parameters, ad, ad set and campaign ids, fbclid) in the browser's local storage, so a demo booked later can be matched to the ad that brought it. The pixel is not loaded inside the Boardroom cabinet after sign-in, and no customer, conversation or CRM data is sent to Meta by it. You can block it with your browser's tracking protection or an ad blocker; the site keeps working.

AI processing

Message content is sent to our AI provider (Anthropic) to generate a reply for the customer's team. It is processed to answer that conversation and is not used by us or by the provider to train foundation models. Where a customer has not enabled outbound sending, the generated reply is stored as a draft for a human to review and is never delivered to the end user. The same applies to Google user data, as described in Google user data.

Storage, security and location

Data is held in managed infrastructure (Supabase and Netlify). Access tokens are stored encrypted at rest in a dedicated secret store and are never exposed to a browser. Each workspace's data is isolated at the database level, and access is limited to the roles the customer assigns. Transport is TLS throughout.

How long we keep it

When an account is closed we delete customer data within 30 days, except records we are legally required to retain.

Sharing

We share data only with the infrastructure and AI providers needed to run the service, each under contract and only for that purpose, and where the law compels disclosure. We do not sell personal data.

Your rights

You may ask us to access, correct, export or delete your data, or to restrict how it is used. If you contacted a business that uses Boardroom, please contact that business first — they control the conversation. If that is not practical, write to us and we will route the request.

Deletion is documented separately, including the one-click route: Data deletion instructions.

Children

The service is for businesses and is not directed at anyone under 16.

Changes

If this policy changes materially we will update the date above and notify account owners by email.

Contact

Boardroom Digital Intelligence, United Arab Emirates
boardroom.gen@gmail.com

Boardroom Revenue Control OS · Обновлено 14 сентября 2026

Политика конфиденциальности

Boardroom Revenue Control OS («Boardroom», «мы») — сервис бизнес-программного обеспечения. Компании («клиенты») используют его для управления своими продажами: данными CRM, маркетинговыми каналами и ИИ-ассистентом, который помогает отвечать людям, обратившимся к ним.

Эта политика объясняет, что мы собираем, зачем, как долго храним и как удалить данные. Она охватывает весь сервис, включая части, подключённые к платформам Meta (Instagram и Facebook), к Kommo, а также к Google (Календарь, Диск и Gmail) — см. Данные пользователей Google.

Кто контролирует данные

В отношении данных наших собственных клиентов — компаний, которые регистрируются в сервисе — контролёром данных является Boardroom. В отношении данных конечных пользователей, с которыми общаются эти компании (например, человека, написавшего в Instagram аккаунту клиента), контролёром является клиент, а Boardroom выступает обработчиком по его поручению.

Что мы собираем

ДанныеЗачем
Данные аккаунта наших клиентов — имя, рабочий email, компания, роль в рабочем пространствеДля создания и защиты аккаунта, а также для выставления счетов
Сообщения из подключённых каналов, а также ID и имя отправителя в рамках платформыЧтобы ИИ-ассистент мог читать переписку, отвечать по контексту и показывать команде клиента общий инбокс
Токены доступа, выданные подключённой платформой (CRM, Meta, Google, Telegram, телефония)Чтобы читать собственные данные клиента с этой платформы и, если клиент это включил, отвечать от его имени
Агрегированные метрики — количество сообщений, время ответа, эффективность кампанийДля дашбордов, на которые подписан клиент
Технические логи — время запросов, коды статуса, типы ошибокБезопасность, защита от злоупотреблений и отладка

Мы намеренно не собираем данные особых категорий, не покупаем данные о вас у третьих лиц и не строим рекламные профили.

Данные, которые мы получаем от Meta

Когда клиент подключает свой профессиональный аккаунт Instagram или Facebook Page, он сам входит в свой аккаунт Meta и сам предоставляет разрешения. Мы никогда не запрашиваем, не видим и не храним пароль от Meta. С этим разрешением мы получаем:

Мы запрашиваем минимальный набор разрешений, необходимый для двусторонней переписки: instagram_basic, instagram_manage_messages, pages_messaging, pages_manage_metadata, pages_show_list, pages_read_engagement и business_management. Мы не запрашиваем разрешения на публикацию контента, рекламные аудитории или списки друзей через эту интеграцию.

Данные, полученные от Meta, используются только для предоставления функции переписки клиенту, чей это аккаунт. Мы их не продаём, не передаём брокерам данных, не используем для рекламы и не используем для обучения универсальных ИИ-моделей.

Данные, которые мы получаем от Kommo

Когда клиент подключает Kommo, он сам входит в свой аккаунт и сам авторизует подключение. Мы никогда не запрашиваем, не видим и не храним его пароль от Kommo. С этой авторизацией мы получаем данные его воронки, этапов, лидов и контактов, а также токены доступа, ограниченные этим аккаунтом, — чтобы ассистент мог читать и, если клиент это включил, обновлять его собственную CRM. Эти данные используются только для предоставления интеграции клиенту, чей это аккаунт, — никогда не продаются, не передаются брокерам данных, не используются для рекламы.

Данные пользователей Google

Клиент может подключить к своему рабочему пространству аккаунт Google. Владелец или администратор пространства входит на экране согласия самого Google и выдаёт разрешения там; мы никогда не запрашиваем, не видим и не храним пароль от Google. Подключение делается в два отдельных шага, и каждый шаг запрашивает только названные в нём разрешения. Второй шаг — по желанию.

Разрешение GoogleК чему мы получаем доступ и зачем
Шаг 1 — подключение Google
calendar.events
Просмотр и изменение событий календаря
События подключённого календаря. Мы создаём событие, когда ИИ-агент или команда клиента назначает встречу (название, время, адрес гостя, который сообщил сам контакт клиента, и ссылка Google Meet), и читаем ближайшие события, чтобы показать клиенту его собственное расписание в приложении.
calendar.freebusy
Просмотр занятости в календарях
Занятость (свободно/занято) подключённого календаря — а если за клиента отвечает коллега, то и календаря этого коллеги, если он открыт подключённому аккаунту, — чтобы агент предлагал только действительно свободное время. Читаются только интервалы занятости, без содержания событий; настройки календаря и доступ к нему мы не меняем.
drive.file
Файлы, созданные этим приложением
Только файлы, которые Boardroom сам создаёт на Google Диске клиента, — таблица выгрузки бухгалтерии. Никакие другие файлы на Диске клиента мы не видим и открыть не можем.
gmail.send
Отправка писем от вашего имени
Отправка писем с собственного адреса клиента по его указанию: ответ, одобренный сотрудником, или письмо, составленное в приложении. Это разрешение не позволяет прочитать ни одного письма.
openid, email
Адрес вашего аккаунта Google
Чтобы показать клиенту, какой аккаунт Google подключён, и убедиться, что следующий шаг разрешает тот же аккаунт.
Шаг 2 — по желанию: «Разрешить читать входящие письма»
gmail.readonly
Чтение писем
Запрашивается, только если клиент сам нажал в приложении «Разрешить читать входящие письма» и подтвердил это на отдельном экране Google. Мы читаем новые письма во входящих, чтобы ИИ-агент клиента мог отвечать на обращения в той же переписке (с адреса клиента, через gmail.send), и чтобы счета и чеки, приходящие вложениями, попадали в собственную бухгалтерию клиента. Рассылки и автоматические письма записываются для клиента, но на них никогда не отвечают. Без этого шага Boardroom не читает почту вообще.

Как мы используем данные пользователей Google.

Ограниченное использование (Limited Use). Использование и передача Boardroom информации, полученной через API Google, любому другому приложению соответствуют Правилам в отношении данных пользователей сервисов Google API (Google API Services User Data Policy), включая требования ограниченного использования (Limited Use). Boardroom's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Хранение. Долгоживущий токен Google хранится зашифрованным в выделенном хранилище секретов и никогда не передаётся в браузер. Краткоживущие токены доступа создаются на один запрос и сразу отбрасываются. Передача данных всегда идёт по TLS.

Срок хранения и удаление. Сохранённый токен Google и список выданных разрешений хранятся, пока существует подключение. Письма, на которые ответил агент, назначенные им встречи и документы, принятые в бухгалтерию, хранятся в пространстве клиента в течение срока действия аккаунта, если клиент не удалит их раньше. Владелец или администратор пространства может в любой момент отключить Google в самом приложении: откройте Настройки → Интеграции, нажмите Отключить на карточке Google Calendar или «Почта (Google)» и нажмите ещё раз для подтверждения. Тогда мы просим Google отозвать доступ Boardroom и сразу удаляем сохранённый токен Google и запись о подключении; приложение сообщает оба результата по отдельности — подтвердил ли Google отзыв доступа и удалён ли сохранённый токен. Если Google отзыв не подтвердил, токен всё равно удаляется, а приложение просит клиента дополнительно удалить Boardroom в своём аккаунте Google. Клиент также может отозвать доступ Boardroom напрямую в своём аккаунте Google на странице myaccount.google.com/permissions; с этого момента сохранённый токен перестаёт работать, и доступа к данным Google у нас больше нет. Отключение не удаляет письма, встречи и документы, уже находящиеся в пространстве; чтобы удалить и эти полученные из Google данные, напишите нам по адресу ниже или воспользуйтесь инструкцией по удалению данных; мы выполняем это в течение 30 дней. При закрытии пространства его токен Google и полученные из Google данные удаляются вместе с ним.

Измерение рекламы на публичном сайте

На публичных страницах (главная, цены, эта политика, условия и поддержка) стоит пиксель Meta — чтобы понимать, работает ли наша собственная реклама: просмотр страницы и нажатия «Записаться на демо», «Попробовать Boardroom AI», WhatsApp и голосового шара. Meta может ставить для этого cookie. Метки рекламы, с которыми пришёл посетитель (utm-параметры, id объявления, группы и кампании, fbclid), мы храним в локальном хранилище браузера, чтобы связать записанное позже демо с объявлением. Внутри кабинета Boardroom после входа пиксель не загружается, и никакие данные клиентов, переписки и CRM через него в Meta не уходят. Его можно заблокировать защитой от отслеживания в браузере или блокировщиком рекламы — сайт продолжит работать.

Обработка ИИ

Содержание сообщений отправляется нашему ИИ-провайдеру (Anthropic) для генерации ответа команде клиента. Оно обрабатывается только для ответа на эту переписку и не используется нами или провайдером для обучения базовых моделей. Если клиент не включил исходящую отправку, сгенерированный ответ сохраняется как черновик для проверки человеком и никогда не доставляется конечному пользователю. То же относится к данным пользователей Google — см. Данные пользователей Google.

Хранение, безопасность и расположение

Данные хранятся на управляемой инфраструктуре (Supabase и Netlify). Токены доступа хранятся зашифрованными в выделенном хранилище секретов и никогда не раскрываются браузеру. Данные каждого рабочего пространства изолированы на уровне базы данных, доступ ограничен ролями, назначенными клиентом. Передача данных всегда идёт по TLS.

Сколько мы храним данные

При закрытии аккаунта мы удаляем данные клиента в течение 30 дней, за исключением записей, которые обязаны хранить по закону.

Передача данных

Мы передаём данные только инфраструктурным и ИИ-провайдерам, необходимым для работы сервиса, каждому по договору и только для этой цели, а также когда этого требует закон. Мы не продаём персональные данные.

Ваши права

Вы можете запросить у нас доступ, исправление, экспорт или удаление ваших данных, либо ограничение их использования. Если вы обращались к компании, использующей Boardroom, пожалуйста, сначала свяжитесь с ней — переписку контролирует она. Если это невозможно, напишите нам, и мы направим запрос по назначению.

Удаление описано отдельно, включая способ в один клик: Инструкция по удалению данных.

Дети

Сервис предназначен для бизнеса и не рассчитан на лиц младше 16 лет.

Изменения

При существенном изменении этой политики мы обновим дату выше и уведомим владельцев аккаунтов по email.

Контакты

Boardroom Digital Intelligence, Объединённые Арабские Эмираты
boardroom.gen@gmail.com