Privacy Policy

Last updated: September 2026

1. Scope and who is involved

This Privacy Policy explains how personal data is collected, used, disclosed, and protected in connection with BoardMeet. It applies to customer organisations, their Authorised Users, people whose information is included in customer governance records, and people who contact us. It should be read with our Terms of Use.

BoardMeet is a product brand, not a separate company. For Nigerian subscriptions, 618 Bees Limited, whose registered office is at No. 32, Providence Street, Lekki Phase 1, Lagos State, Nigeria, is the seller, invoice issuer, payment recipient, and first-line support provider. The App Brothers LLC owns and operates the hosted platform. Registration details and contact channels appear on our company-information page.

2. Controller and processor roles

Customer organisations normally determine why and how their board and governance Content is used and act as Data Controller for that Content.

The App Brothers LLC processes governance Content to operate, secure, and maintain the platform on the Customer's documented instructions. It separately determines limited processing required for platform security, abuse prevention, service administration, and reliability.

618 Bees Limited determines how it uses subscription, invoice, bank-transfer, contact, and support data to perform its contract and meet Nigerian legal obligations. When handling governance Content during a Customer-authorised support escalation, it processes that Content only for the authorised support purpose.

The applicable role depends on the data and purpose involved. Use of the BoardMeet brand does not merge the organisations into one legal entity.

3. Personal data we process

Account and membership information: name, email address, password hash, authentication and trusted-device data, roles, organisation, company access, and account status.

Governance Content: companies, meetings, agendas, notices, notice recipients and service evidence, minutes, resolutions, votes, signatures, board packs, tasks, committees, attendance, and messages.

Meeting media and transcripts: recordings, transcripts, speaker segments, and AI-assisted drafts where authorised meeting capture is enabled.

Billing and support data: plan requests, invoices, bank-transfer references and payment proofs, contact messages, and support correspondence.

Technical and security data: IP address, browser and device information, access logs, sign-in history, feature usage, error reports, and security events.

4. How we use personal data and our legal bases

Personal data is processed for the following purposes and, where applicable, on the following legal bases under the Nigeria Data Protection Act 2023:

To provide, operate, maintain, and support the Service: performance of contract for Account and billing data, or the Customer's documented instructions for governance Content.

To authenticate users and administer organisations, memberships, meetings, notices, and governance workflows: performance of contract and legitimate interests in operating the Service.

To issue invoices, record bank-transfer claims, confirm payments, and administer Subscriptions: performance of contract and legal obligations.

To investigate faults, prevent abuse, and protect the security, integrity, and availability of the Service: legitimate interests and legal obligations.

To send service messages and communicate material policy or product changes: performance of contract, legitimate interests, or legal obligations.

To send marketing communications where the recipient has consented or another lawful basis applies. Consent may be withdrawn at any time.

To comply with law, regulatory requests, and legal claims: legal obligations and legitimate interests.

5. Service providers, disclosures, and processing locations

The primary BoardMeet application, database, file storage, and transactional email delivery are hosted and processed through Amazon Web Services (AWS), Ireland region (eu-west-1), including Amazon S3 for storage and Amazon SES for email delivery. This is the primary storage location, not a statement that every processing operation occurs in Ireland.

Configured providers also include Recall in its Central Europe endpoint (eu-central-1) for authorised meeting capture, Daily for video, recording, and transcription functions, and OpenAI for authorised AI-assisted drafting. Each provider processes only the data needed for its function under applicable contractual and data-protection safeguards.

Personal data may also be disclosed to professional advisers under confidentiality obligations, regulators or law enforcement where required by valid legal process, or a successor entity in a merger, acquisition, or sale of substantially all of the relevant business, subject to continued protection of the data.

6. International transfers

Use of the Service involves transfers from Nigeria to the United States, Ireland, Germany, and other locations used by configured providers. Transfers are supported by contractual, organisational, and technical safeguards appropriate to the data and transfer, an applicable adequacy basis, or another lawful mechanism recognised under the Nigeria Data Protection Act 2023. We do not represent that all BoardMeet processing stays in Nigeria or in Ireland.

7. Access and sharing

We do not sell personal data. Access is limited by role and need. 618 Bees Limited's routine operational access is limited to Account, billing, contact, and support information; it does not receive routine access to customer governance records. Content access for support requires a Customer-authorised escalation. Data may also be disclosed where required by law or necessary to protect users, the Service, or legal rights.

8. Meeting capture

Meeting capture is optional and controlled by authorised Customer administrators. When enabled, a visible notetaking bot may record or transcribe the call and an authorised AI service may process the transcript to assist with a minutes draft. The Customer is responsible for informing participants and obtaining any consent required before capture starts.

9. Data retention

Account and governance records remain available while the Customer account is active.

When an organisation closes its Account, BoardMeet disables access. An authorised export may be requested before closure is confirmed. Data is retained in accordance with our data retention schedule at boardmeet.ng/data-retention. Each record class is held for its applicable minimum period from its applicable start event; account closure does not trigger immediate deletion of records within their minimum retention period. Active account and membership data is retained for the duration of the subscription and for 90 days from subscription end. Records not yet assigned a minimum period in the data retention schedule are retained for 90 days from account closure.

Most governance records are retained for a minimum of seven (7) years from their applicable start event: board and committee meeting papers from the meeting date; adopted minutes and resolutions from the date of creation or adoption; statutory notices and evidence-of-service records from the dispatch date. Billing and tax records are retained for a minimum of six (6) years from the end of the relevant tax year (31 December). Other record classes have shorter minimum periods as set out in the retention schedule.

Where the Service permits a Customer to configure retention periods for recordings, transcripts, and AI-generated outputs, the Customer's configured period applies. Where no preference has been set, the platform default period in the data retention schedule applies.

Residual provider copies and backups expire according to their own schedules. Records deleted from live storage are not restored from older backups.

10. Data security

Safeguards include encryption in transit and at rest, role-based access controls at Account and company level, multi-factor authentication controls, audit records for sensitive actions, network and infrastructure controls, and least-privilege operational access. Security practices are reviewed as the Service changes.

No system is completely secure. Customers should use strong, unique credentials and promptly report suspected incidents. Where required, affected organisations, individuals, and regulators will be notified of a qualifying personal-data breach.

11. Data-subject rights

Subject to applicable law, an individual may request access, correction, deletion, restriction, objection, portability, or withdrawal of consent. Requests concerning governance Content should generally be directed to the relevant Customer as Data Controller, which may instruct the operator as processor. Requests concerning Account, billing, support, or platform data may be sent to the privacy contact in Section 15 below. Identity may be verified before a request is fulfilled.

Individuals may also lodge a complaint with the Nigeria Data Protection Commission (NDPC):

Website www.ndpc.gov.ng
Email info@ndpc.gov.ng
Address No. 5 Donau Crescent, Off Amazon Street, Maitama, Abuja, Nigeria
Complaint form www.ndpc.gov.ng/complaints

12. Children's privacy

The Service is intended for business use by companies and their authorised personnel and is not directed at children. We do not knowingly collect personal data from children.

13. Cookies

We use cookies needed to operate and secure the Service, including session and trusted-device cookies. We do not use advertising or cross-site tracking cookies.

14. Changes to this Policy

We may update this Policy from time to time and will revise the date above. Material changes will be communicated to Customer administrators before they take effect.

15. Privacy and data-protection contact

618 Bees Limited has designated a Data Protection Officer (DPO) in accordance with the Nigeria Data Protection Act 2023:

Name Somto Madukosiri
Title Data Protection Officer
Email somto.madukosiri@618bees.com
Address 618 Bees Limited, No. 32, Providence Street, Lekki Phase 1, Lagos State, Nigeria
Response time We acknowledge within 48 hours and respond in full within 30 days.

Questions, rights requests, or concerns about personal data may be sent to the DPO at somto.madukosiri@618bees.com or to privacy@boardmeet.ng. Nigerian support and billing matters are handled through support@boardmeet.ng and billing@boardmeet.ng. Platform-operation matters may be escalated to The App Brothers LLC through the same privacy contact.

618 Bees Limited is registered with the Nigeria Data Protection Commission (NDPC) as a Data Controller and Data Processor of Major Importance. NDPC Registration Number: NDPC/DCP/14765.