1INTRODUCTION
1.1 BoardPAC Inc. (“BoardPAC”, “we”, “us” or “our”) is committed to protecting the privacy and security of personal information entrusted to us.
1.2 This Privacy Policy explains how BoardPAC collects, uses, processes, stores, discloses and protects personal information through:
- the BoardPAC website, currently available at www.boardpac.co (the “Website”);
- the BoardPAC software and cloud-based platform (the “Platform”);
- BoardPAC mobile applications, where applicable;
- communications and interactions with BoardPAC, including requests for information, demonstrations, support and customer service; and
- other services or interactions that expressly refer to this Privacy Policy.
1.3 BoardPAC provides its services to customers and users located in multiple countries and jurisdictions. Accordingly, personal information may be subject to different privacy and data protection laws depending on the location of the individual, the applicable customer relationship and the nature of the processing.
1.4 This Privacy Policy is intended to provide transparency regarding our privacy practices. Where a customer has entered into a separate agreement with BoardPAC governing the processing of personal data, including a Data Processing Agreement or other applicable data protection terms, those contractual terms shall apply to the extent they govern the relevant processing.
2INFORMATION WE COLLECT
2.1 Information You Provide
2.1.1 Depending on how you interact with BoardPAC, we may collect personal information including:
- name;
- employer, organization or company;
- job title or designation;
- country or general business location;
- email address;
- telephone number;
- account and authentication information;
- information provided when requesting a demonstration, quotation or information about our services;
- information provided to our support or customer service teams;
- communications and correspondence with BoardPAC;
- professional information and profile information; and
- any other information that you voluntarily provide to us.
2.1.2 Where appropriate, we may also collect information concerning an organization, such as the number of board members, committee members, organizational requirements or other information necessary to understand the organization’s requirements.
2.2 Information Collected Through the Platform
2.2.1 Where you use the BoardPAC Platform on behalf of a customer organization, BoardPAC may process personal information contained within the data uploaded or submitted to the Platform by or on behalf of that customer.
2.2.2 Such information may include board and committee information, names, designations, contact information, meeting-related information, documents, communications and other information determined by the relevant customer.
2.2.3 In these circumstances, BoardPAC generally processes such information on behalf of the customer in accordance with the applicable customer agreement and data protection terms.
2.3 Information Collected Through Mobile Applications
2.3.1 When you download or use a BoardPAC mobile application, we may collect technical information necessary to operate, secure and optimize the application, including device type, operating system version, application version, device identifiers and related technical information.
2.3.2 BoardPAC does not intentionally request or track precise location information through its mobile applications unless specifically stated otherwise at the relevant time and permitted by applicable law.
2.4 Automatically Collected Information
2.4.1 When you visit our Website or use our Platform, we may automatically collect certain technical and usage information, including:
- Internet Protocol (“IP”) address;
- browser type;
- operating system;
- internet service provider;
- referring and exit pages;
- date and time information;
- clickstream and usage information;
- device information; and
- other technical information reasonably necessary for security, analytics and service operation.
3HOW WE USE PERSONAL INFORMATION
3.1 BoardPAC may use personal information for legitimate and disclosed purposes, including:
- providing, operating and maintaining the Website and Platform;
- creating and administering user accounts;
- authenticating users and maintaining account security;
- providing customer support and responding to enquiries;
- responding to requests for demonstrations, information or services;
- communicating with customers and users regarding services, updates and relevant information;
- monitoring, maintaining and improving the performance, security and functionality of our services;
- detecting, preventing and investigating fraud, security incidents, unauthorized access and other misuse;
- complying with applicable legal, regulatory and contractual obligations;
- enforcing our agreements and protecting our legal rights;
- conducting analytics and improving our products and services; and
- carrying out other purposes disclosed at the point of collection or otherwise permitted by applicable law.
3.2 BoardPAC will not use personal information for purposes materially incompatible with the purposes for which it was collected unless the individual has provided the required authorization or the processing is otherwise permitted by applicable law.
4LEGAL BASES FOR PROCESSING
4.1 Where required by applicable law, BoardPAC will process personal information on an appropriate legal basis, which may include:
- the individual’s consent;
- performance of a contract or steps taken at the individual’s request prior to entering into a contract;
- compliance with a legal obligation;
- protection of legitimate interests, where permitted by applicable law; or
- another lawful basis recognized by applicable law.
4.2 Where processing is based on consent, the individual may withdraw that consent in accordance with applicable law.
4.3 Withdrawal of consent will not affect the lawfulness of processing undertaken before withdrawal.
5CUSTOMER DATA
5.1 Where BoardPAC processes personal information contained in customer data as a service provider or processor on behalf of a customer, the relevant customer generally determines the purposes and means of processing.
5.2 BoardPAC will process such customer data in accordance with the applicable customer agreement, data protection terms and lawful instructions of the customer, subject to applicable law.
5.3 BoardPAC’s Data Protection Policy establishes controls relating to data security, data subject rights, data retention, deletion, cross-border transfers, breach management and compliance.
5.4 The Data Protection Policy provides for the secure deletion or return of Client Data following termination, subject to applicable law and agreed retention requirements.
6DISCLOSURE OF PERSONAL INFORMATION
6.1 BoardPAC may disclose personal information where reasonably necessary for the purposes described in this Privacy Policy, including to:
- employees and authorized personnel who require access for legitimate business purposes;
- service providers, hosting providers, cloud infrastructure providers and other technology providers that provide services to BoardPAC;
- professional advisers, auditors and consultants;
- competent governmental, regulatory, law enforcement or judicial authorities where required or permitted by law;
- entities involved in a corporate transaction, such as a merger, acquisition, financing, restructuring or sale of assets, subject to appropriate confidentiality and legal requirements; and
- other parties where the individual has provided authorization or disclosure is otherwise permitted or required by applicable law.
6.2 BoardPAC requires relevant third-party service providers that process personal information on its behalf to maintain appropriate confidentiality, security and data protection obligations.
6.3 Where personal information is transferred to third-party agents for processing, BoardPAC remains responsible for such onward transfers to the extent required by applicable law or the applicable data protection framework.
7INTERNATIONAL AND CROSS-BORDER DATA TRANSFERS
7.1 Because BoardPAC Inc. is based in the United States and provides services to customers and users internationally, personal information may be processed, stored or accessed in countries other than the country in which it was originally collected.
7.2 Where personal information is transferred across borders, BoardPAC will implement appropriate safeguards as required by applicable data protection laws.
7.3 Depending on the applicable jurisdiction and circumstances, such safeguards may include contractual protections, adequacy mechanisms, standard contractual clauses, recognized certification mechanisms or other lawful transfer mechanisms.
7.4 Individuals should be aware that the data protection laws of the country to which information is transferred may differ from those of their home jurisdiction.
8EU-U.S. DATA PRIVACY FRAMEWORK
8.1 BoardPAC Inc. complies with the EU-U.S. Data Privacy Framework (EU-U.S. DPF) as set forth by the U.S. Department of Commerce.
8.2 BoardPAC Inc. has certified to the U.S. Department of Commerce that it adheres to the EU-U.S. Data Privacy Framework Principles (EU-U.S. DPF Principles) with regard to the processing of personal data received from the European Union in reliance on the EU-U.S. DPF.
8.3 If there is any conflict between the terms in this Privacy Policy and the EU-U.S. DPF Principles, the Principles shall govern.
8.4 To learn more about the Data Privacy Framework Program and to view our certification, please visit: https://www.dataprivacyframework.gov/
8.5 In compliance with the EU-U.S. DPF, BoardPAC Inc. commits to resolve DPF Principles-related complaints about our collection and use of personal information.
8.6 EU individuals with inquiries or complaints regarding our handling of personal data received in reliance on the EU-U.S. DPF should first contact BoardPAC Inc. at: webmaster@boardpac.co
8.7 The Federal Trade Commission has jurisdiction over BoardPAC Inc.’s compliance with the EU-U.S. Data Privacy Framework (EU-U.S. DPF).
8.8 BoardPAC remains liable under the DPF Principles for the onward transfer of personal data to third-party agents that process such data on BoardPAC’s behalf, in cases where those agents process the data in a manner inconsistent with the DPF Principles, unless BoardPAC proves it is not responsible for the event giving rise to the damage.
8.9 Where an unresolved DPF complaint cannot be resolved through the applicable mechanisms, individuals may have additional rights and recourse under the EU-U.S. DPF, including, where applicable, binding arbitration in accordance with the DPF Principles and procedures.
9GOVERNMENT AND LAW ENFORCEMENT REQUESTS
9.1 BoardPAC may be required to disclose personal information in response to lawful requests by public authorities, including requests made to satisfy applicable legal, regulatory, national security or law enforcement requirements.
9.2 Where legally permitted, BoardPAC will take reasonable steps to ensure that disclosures are limited to the information legally required or otherwise reasonably necessary for the relevant purpose.
10CHOICES AND CONTROL OVER PERSONAL INFORMATION
10.1 Subject to applicable law, BoardPAC offers individuals the ability to choose, or opt out, of:
10.1.1 disclosure of their personal information to a third party; or
10.1.2 use of their personal information for a materially different purpose from the purpose for which it was originally collected or subsequently authorized.
10.2 Individuals may exercise applicable choices by contacting: webmaster@boardpac.co
10.3 Where processing is necessary to provide a requested service, comply with a legal obligation or otherwise process information on another lawful basis, withdrawal or restriction of consent may affect BoardPAC’s ability to provide certain services.
12ANALYTICS AND LOG FILES
12.1 BoardPAC may automatically collect information through log files and analytics technologies.
12.2 This information may include IP addresses, browser type, internet service provider, referring and exit pages, operating system, date/time information and clickstream data.
12.3 BoardPAC may combine automatically collected information with other information where reasonably necessary to improve services, security, analytics, Website functionality or user experience.
14INFORMATION SECURITY
14.1 BoardPAC maintains administrative, technical and organizational safeguards designed to protect personal information against unauthorized access, disclosure, alteration, loss, misuse or destruction.
14.2 Our security measures may include:
- database-level security controls;
- system-level access controls;
- network security controls;
- firewalls;
- intrusion detection and monitoring mechanisms;
- physical security controls;
- encryption of information in transit using appropriate transport-layer security technologies;
- encryption and other safeguards for information at rest, where applicable;
- access controls based on business need and authorization;
- confidentiality obligations applicable to personnel;
- vulnerability management and security assessments; and
- business continuity, backup and disaster recovery controls.
14.3 BoardPAC’s Information Security Program is based on the ISO/IEC 27001 framework and is designed to identify, assess and treat information security risks in accordance with BoardPAC’s applicable risk management processes.
14.4 BoardPAC classifies customer information as confidential and applies appropriate confidentiality, integrity and availability controls to such information.
14.5 Customer data is not knowingly shared with unrelated entities except as authorized by the customer, required to provide the services, or otherwise permitted or required by applicable law.
14.6 No method of transmission over the Internet or method of electronic storage is completely secure.
14.7 Accordingly, while BoardPAC takes reasonable measures to protect personal information, BoardPAC cannot guarantee absolute security.
15DATA BREACH AND INCIDENT RESPONSE
15.1 BoardPAC maintains incident management procedures designed to identify, assess, contain, investigate and remediate data security incidents.
15.2 Where BoardPAC processes personal information on behalf of a customer and a Data Breach occurs, BoardPAC will notify the relevant customer in accordance with the applicable contractual requirements and applicable law.
15.3 BoardPAC’s Data Protection Policy provides for notification to the relevant Client without undue delay and, for specified breaches affecting Client Confidential Information, Client Data or Personal Data processed on behalf of a Client, within the contractual four-hour notification period specified in that Policy.
15.4 BoardPAC will take appropriate steps to investigate and mitigate security incidents, which may include:
- isolating affected systems;
- revoking compromised credentials;
- restoring information from secure backups; and
- implementing appropriate security patches or corrective measures.
16DATA RETENTION
16.1 BoardPAC retains personal information only for as long as reasonably necessary for the purposes for which it was collected, to provide services, comply with contractual and legal obligations, resolve disputes, enforce agreements and protect BoardPAC’s legitimate interests.
16.2 Retention periods may vary depending on:
- the nature and sensitivity of the information;
- the purpose for which it was collected;
- the applicable customer relationship;
- applicable legal and regulatory requirements; and
- the need to establish, exercise or defend legal claims.
16.3 Where customer data is subject to a separate agreement, the applicable contractual retention and deletion provisions will apply.
17DATA DELETION AND RETURN
17.1 Subject to applicable law and contractual requirements, individuals may request deletion of their personal information.
17.2 Where a customer agreement requires the return or deletion of customer data following termination, BoardPAC will comply with the applicable contractual requirements.
17.3 BoardPAC’s Data Protection Policy provides for secure deletion or permanent overwriting of Client Data from backup media in accordance with BoardPAC’s standard backup retention and rotation schedule, unless earlier deletion is technically feasible or required by law.
17.4 Where applicable, customers may request written confirmation of deletion from active production systems.
17.5 BoardPAC may retain information where retention is required by law or reasonably necessary to establish, exercise or defend legal claims.
18YOUR PRIVACY RIGHTS
18.1 Depending on your location and applicable law, you may have rights relating to your personal information, including:
- the right to request access to personal information;
- the right to request correction of inaccurate or incomplete information;
- the right to request deletion or erasure;
- the right to request restriction of processing;
- the right to object to certain processing;
- the right to data portability, where applicable;
- the right to withdraw consent where processing is based on consent; and
- the right to lodge a complaint with a competent data protection authority.
18.2 The rights available to you may vary depending on your jurisdiction and the applicable legal basis for processing.
18.3 BoardPAC’s Data Protection Policy also recognizes applicable rights relating to access, rectification, erasure, restriction, portability and secure return or deletion of data.
18.4 To exercise your rights, please contact: webmaster@boardpac.co
18.5 BoardPAC will respond within the timeframe required by applicable law.
19CHILDREN’S INFORMATION
19.1 Our services are intended primarily for business and professional use and are not directed toward children.
19.2 BoardPAC does not knowingly collect personal information from children where such collection is prohibited by applicable law.
19.3 If you believe that a child has provided personal information to BoardPAC in circumstances where such collection was not authorized, please contact us so that we can take appropriate action.
20THIRD-PARTY WEBSITES AND SERVICES
20.1 The Website may contain links to third-party websites, applications or services.
20.2 BoardPAC does not control and is not responsible for the privacy practices, security or content of third-party websites or services.
20.3 We encourage you to review the privacy policies of any third-party website or service before providing personal information.
21MARKETING COMMUNICATIONS
21.1 Where permitted by applicable law, BoardPAC may use contact information to provide information regarding BoardPAC products, services, events, updates or other relevant business communications.
21.2 Where required, BoardPAC will provide appropriate consent or opt-out mechanisms.
21.3 You may request to stop receiving marketing communications by following the unsubscribe instructions contained in the relevant communication or by contacting: webmaster@boardpac.co
21.4 Withdrawal from marketing communications will not necessarily prevent BoardPAC from sending non-marketing communications relating to your account, contractual relationship, security, transactions or other necessary service matters.
22PROCESSING BY SERVICE PROVIDERS
22.1 BoardPAC may engage third-party service providers to support its operations and services, including cloud hosting, infrastructure, security, analytics, communications, customer support and other technology services.
22.2 BoardPAC requires relevant service providers that process personal information on its behalf to implement appropriate confidentiality, security and data protection measures.
22.3 BoardPAC will maintain appropriate oversight of such service providers in accordance with applicable law and contractual requirements.
23COMPLIANCE AND AUDIT
23.1 BoardPAC maintains processes for demonstrating compliance with applicable data protection and information security requirements.
23.2 Where required under an applicable customer agreement, BoardPAC may provide appropriate evidence of compliance, which may include relevant security certifications, independent audit reports, vulnerability assessments or penetration testing results.
23.3 BoardPAC’s Data Protection Policy provides for compliance verification and audit mechanisms, subject to applicable contractual conditions, confidentiality requirements and reasonable limitations designed to avoid disruption to BoardPAC’s operations.
24CONFIDENTIALITY
24.1 BoardPAC treats customer information and personal information as confidential and limits access to authorized personnel who require such access for legitimate business purposes.
24.2 BoardPAC personnel and relevant service providers are subject to applicable confidentiality obligations.
25LEGAL AND REGULATORY DISCLOSURES
25.1 BoardPAC may collect, use, retain or disclose personal information where reasonably necessary to:
- comply with applicable law, regulation or legal process;
- respond to lawful requests from governmental, regulatory, judicial or law enforcement authorities;
- protect the rights, property or safety of BoardPAC, its customers, users or other persons;
- investigate fraud, security incidents or other unlawful activity;
- enforce contractual terms; or
- establish, exercise or defend legal claims.
26CHANGES TO THIS PRIVACY POLICY
26.1 BoardPAC may update this Privacy Policy from time to time to reflect changes in our services, information practices, legal requirements or regulatory obligations.
26.2 Where required by applicable law, BoardPAC will provide notice of material changes through appropriate means, which may include email, Website notification or other legally permitted methods.
26.3 The revised Privacy Policy will indicate the applicable “Last Updated” date.
26.4 We encourage you to periodically review this Privacy Policy for the latest information regarding our privacy practices.
27CONTACT US
27.1 If you have questions, concerns, requests or complaints regarding this Privacy Policy or BoardPAC’s processing of personal information, please contact:
BoardPAC Inc.
9600 Great Hills Trail, Suite 150W
Austin, Texas 78759
USA
Email: webmaster@boardpac.co
27.2 Where applicable, individuals may also contact their relevant data protection or privacy supervisory authority regarding concerns about the processing of their personal information.
28APPLICABLE PRIVACY RIGHTS BY JURISDICTION
28.1 BoardPAC recognizes that individuals may have additional rights under the privacy laws applicable in their jurisdiction.
28.2 Where a particular jurisdiction grants additional rights or imposes additional requirements, BoardPAC will apply such requirements to the extent legally applicable to the relevant processing activity.
28.3 Nothing in this Privacy Policy is intended to restrict or remove any mandatory rights available to individuals under applicable privacy or data protection legislation.
29DISPUTE RESOLUTION MECHANISM
29.1 Without prejudice to Clause 8.7, which provides that the Federal Trade Commission has jurisdiction over BoardPAC Inc.’s compliance with the EU-U.S. Data Privacy Framework (EU-U.S. DPF), any dispute arising between an individual and BoardPAC Inc. in relation to the collection, use, or processing of personal data under the EU-U.S. DPF shall, where applicable, be referred to JAMS (Judicial Arbitration and Mediation Services) for resolution in accordance with the applicable JAMS rules and procedures.
29.2 The dispute resolution mechanism under this Clause 29 shall be subject to any rights, remedies, or requirements applicable under the EU-U.S. DPF and applicable law.

