BoardWalk

Strategy, delivery, and proof.

Privacy notice

This notice explains how BoardWalk handles account information, organization membership, workspace content, billing details, and service records. BoardWalk is business software licensed to organizations for use by their teams.

Effective 2026-08-15Published by LockedIn LabsMechanism detail on the security page

Roles and responsibilities

When an organization uses BoardWalk, that organization decides what goes into its register and how long it is kept. We store and process it on their instructions and for no purpose of our own. In the vocabulary of data protection law, the customer organization is the controller of its register content and we are its processor. If you are an employee of a customer and want your record changed or removed, your own administrator can act faster than we can, and they are the correct first stop.

For the small amount of data that is genuinely ours to decide about — the email address of someone who signs up before any organization exists, and the billing contact on a paid plan — we are the controller.

Information we process

  • Account identity. An email address, the sign-in credential itself, and a display name if one is given. Passwords are never stored by this application; authentication is handled by Supabase Auth.
  • Organization membership. Which workspaces an account belongs to and what role it holds in each.
  • Register content. Whatever the customer records: project and program titles and summaries, objectives, requirement statements and citations, risks, dependencies, findings and reviewer notes, capacity and financial figures, test identifiers and failure messages, environment labels and addresses, and uploaded documents. This is business content, and it contains personal data only where the customer puts a person’s name in it — an owner, an approver, an author.
  • The decision trail. An append-only record of every act that changes what the register claims: what changed, when, and which signed-in person did it. The actor is taken from the authenticated session by the database rather than supplied by the client, so an entry cannot name somebody else.
  • Billing details. On a paid plan, a billing contact and subscription state. Card numbers are entered on Stripe’s own page and never reach this application.
  • Ordinary request data. The logs a hosting platform keeps to serve and secure a website.

Sensitive data

A portfolio governance register does not need protected health information to do its job, and this one does not ask for any. There is no field for a member, a claim, a diagnosis or a card number, no import path that expects one, and no feature that would work better with one.

Customers must not submit clinical, payment-card, government identifier, or comparable sensitive data. BoardWalk does not currently screen every ingestion path automatically, so customers remain responsible for the content they provide. See the security page and terms of service for the applicable controls and restrictions.

Where it is stored

Customer data is stored by Supabase, a managed Postgres platform, in a single United States region. It is encrypted at rest by that platform, and every connection — browser to application, application to database — runs over TLS. The application itself is delivered by Netlify.

Self-service plans do not include a regional data-residency commitment. Data is currently stored in the United States. Customers with specific residency requirements should confirm them before use.

Who else sees it

The full subprocessor list is published on the security page rather than assembled when someone asks. In summary: Supabase holds the database, the authentication identities and file storage; Netlify receives request metadata and serves the rendered pages; Resend receives the email address of anyone invited to a workspace; Stripe receives billing contact and payment details on a paid plan.

If a workspace turns on the optional voice assistant, Google Gemini receives a brief scoped by the same row-level policies the workspace uses — the workspace name and slug, selected project keys, titles and states, aggregate counts — together with the live conversation’s audio and transcriptions. When the assistant is not enabled, it receives nothing at all.

Beyond those, nothing. We do not sell personal information, do not share it with advertising networks, do not disclose it to data brokers, and do not train any model of our own on customer content.

Cookies and tracking

The only cookie this product sets is the session cookie that keeps a signed-in person signed in. It is marked Secure, restricted to same-site requests, and it exists for authentication. There is no advertising cookie, analytics cookie or cross-site tracking identifier.

The public pages do not embed third-party advertising or analytics scripts.

Retention and deletion

Register content is kept for as long as the customer keeps it; they can edit and delete it from inside the product. Decision-trail records follow a different retention model.

The trail refuses deletion to everybody — to the organization’s owner, to us, and to the database superuser. This is enforced in the database. Within an active tenancy, an entry recording that a named person accepted something on a date cannot be selectively removed. It is retained for the life of the tenancy. Deleting a tenancy removes the tenancy and its trail together.

Self-service plans do not currently include certified deletion on termination or a complete machine-readable tenant export. Customers that require either service should address it in their agreement.

Your choices

An employee of a customer organization should ask their own workspace administrator, who can see and change their membership and most of their record directly. For anything an administrator cannot resolve, or if you are not a member of a workspace, the contact page sets out the routes that exist. We will not ask for more information to verify a request than is needed to be sure the request is genuinely yours.

Security

Security architecture, tenant-isolation controls, operational safeguards, subprocessors, and current assurance materials are described on the security page.

Children

This is business software licensed to organizations for use by their staff. It is not directed at children, and we do not knowingly create accounts for them.

Changes

This notice carries an effective date and changes will move it. A change that materially alters what is held, where it is stored, or who processes it will be communicated to customers.