← Back to Board Box

Privacy Policy

Last Updated: February 4, 2026

This Privacy Policy explains how Board Box Inc ("Board Box," "we," "us") collects, uses, and shares information about individuals who interact with our websites and services (collectively, the "Service"). For terms governing use of the Service, see /terms.

If you use the Service under a contract with a Customer, that Customer controls the Personal Information it submits to the Service, and we process it as a service provider/processor. This Policy covers our role as a business/controller for our own sites and operations and describes our processing as a service provider/processor at a high level. If there is a conflict between this Policy and the Customer's agreement with us, the agreement controls.


Information We Collect

Account and contact information. Name, email address, organization, role/title, and authentication-related information.

Usage and device information. Log files, IP address, device identifiers, browser type, pages viewed, referring/exit pages, and date/time stamps.

Communications. Content of messages you send to us (for example, support requests and feedback).

Customer-submitted data. Information that Customers and their authorized users upload to the Service, including documents and information contained in those documents. We process this data on behalf of the Customer under our data processing terms.

Cookies and similar technologies. We use cookies and similar technologies to provide and improve the Service. You can control cookies through your browser settings; some features may not function properly without cookies.


How We Use Information

We use information to:


AI-Assisted Features

If Customers enable AI-assisted features, we may process relevant portions of Customer-submitted data (for example, document excerpts and user prompts) to generate responses, summaries, comparisons, or other outputs. This processing may involve trusted third-party service providers acting as subprocessors (see /subprocessors). We do not use Customer-submitted data to train our own foundation models.


How We Share Information

We may share information in the following circumstances:

Service providers and subprocessors. We use vendors to help provide the Service (for example, hosting, analytics, support tools, and AI service providers). They are contractually restricted in how they may use data.

Customer-directed sharing. The Service may allow Customers and their users to share specific content (such as documents) with others via sharing features (for example, share links). Sharing is controlled by the Customer and its users. People who receive shared content may be outside the Customer's organization, and we may log access to shared content for security and auditing.

Business transfers. In connection with a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets.

Legal and safety reasons. To comply with law, regulation, subpoena, or lawful request; or to protect rights, safety, and security.


No Sale or Sharing of Personal Information

We do not sell or share Personal Information as those terms are defined by the California Consumer Privacy Act (as amended by the CPRA).


Your Rights and Choices

Depending on your location, you may have rights to access, correct, delete, or receive a copy of your Personal Information, and to object to or restrict certain processing.

How to exercise rights. Email privacy@boardbox.ai. We may need to verify your identity before fulfilling a request.

If you are an end user of a Customer. If your account or data is managed by a Customer, please direct requests to that Customer. We will assist the Customer as required by our contract and applicable law.

California residents. You may have rights to know/access, delete, correct, and receive a portable copy of certain Personal Information, and to not receive discriminatory treatment for exercising these rights. You may also use an authorized agent to submit a request on your behalf, subject to verification.

EEA/UK residents. You may have the right to lodge a complaint with your local supervisory authority. Where required, we rely on legal bases such as performance of a contract, legitimate interests (for example, security and service improvement), consent (for certain cookies), and compliance with legal obligations.


Data Retention

We retain Personal Information for as long as necessary to provide the Service and for legitimate purposes such as complying with legal obligations, resolving disputes, and enforcing agreements.

Customer-submitted data. We retain and delete Customer-submitted data in accordance with the Customer's instructions and our agreement with the Customer (including applicable backup retention and deletion processes).

Operational and security records. We may retain logs and related records for security, fraud prevention, and reliability for a limited period consistent with our legitimate interests and legal obligations.


Security

We implement technical and organizational measures described at /security to protect Personal Information. No system is completely secure; please use strong passwords and safeguard account credentials.


International Data Transfers

If we transfer Personal Information internationally, we do so under appropriate safeguards such as Standard Contractual Clauses where applicable.


Children

The Service is not directed to children under 13, and we do not knowingly collect Personal Information from children under 13.


Changes to This Policy

We may update this Policy from time to time by posting the updated Policy and changing the "Last Updated" date. If you do not agree to the updated Policy, you should stop using the Service.


Contact

privacy@boardbox.ai (primary)
legal@boardbox.ai (back-up)