BoardConfidential workflows
POPIAAligned posture
GDPRAligned posture
150+Organisations
17Countries
Privacy principles

The privacy page should feel practical, credible, and proportionate.

This page is part of the trust architecture around BoardEvaluator™. It should reassure governance buyers and participants that privacy is handled with the seriousness expected in a board-evaluation environment.

Confidential by context

Board evaluation data is sensitive because it can reflect boardroom dynamics, governance weaknesses, independence concerns, and strategic oversight quality.

Purpose-led handling

Information should be collected and used for defined purposes such as responding to enquiries, operating evaluations, supporting reporting, and maintaining the service.

Data minimisation

Only the information reasonably required for the product, support, commercial process, or compliance need should be processed.

Rights and accountability

Privacy should not be hidden. Users and stakeholders need a clear route to understand handling practices and make requests where applicable.

Information types

What kinds of information may be handled.

The privacy model spans both the public website and the BoardEvaluator™ platform environment.

Common categories

Contact details submitted through Contact or Book a Demo
Organisation and role information needed to scope a board evaluation conversation
Platform account and participation data used to administer evaluation cycles
Board-evaluation responses, comments, and workflow activity where the product is in use
Technical and website usage data needed for platform operation, analytics, and security monitoring
Contact data Organisation data Evaluation data Usage data

How that information is commonly used

To respond to enquiries, demos, pricing, and support requests
To configure and run evaluation cycles across boards, committees, and modules
To create outputs, reports, and disclosure-oriented material where relevant
To maintain service quality, platform security, and lawful business operations
To meet contractual, governance, legal, and regulatory obligations where applicable
Service delivery Reporting Support Compliance
Privacy workflow

How privacy fits into the operating model.

The point of this section is to show that privacy is not a disconnected policy page. It follows the real BoardEvaluator™ journey from enquiry to evaluation delivery and ongoing governance support.

01

Collect

Gather only the information needed to support an enquiry, a demo request, or an evaluation workflow.

02

Scope

Match data use to a legitimate product, advisory, contractual, or governance purpose before broader processing happens.

03

Control

Apply role-based access, administrative boundaries, and workflow controls appropriate to a board context.

04

Protect

Use security measures, including the posture described on Security, to safeguard information in use and at rest.

05

Retain

Keep information for a justified period based on service delivery, evidence needs, legal obligations, and contract terms.

06

Respond

Provide a route for privacy requests, questions, corrections, or other lawful data-subject interactions through Contact.

Sharing, storage, and retention

What buyers usually want clarified before they move forward.

A strong privacy page anticipates the practical questions that legal, company secretariat, procurement, and risk stakeholders will ask.

Sharing and disclosure

Information may be shared with trusted service providers, hosting infrastructure, implementation or support personnel, and other parties where that is necessary to operate the service, meet contractual commitments, or comply with law. Information is not treated as an open commercial asset simply because it is available to the business.

Storage and access control

Privacy and security work together. Hosting, encryption, role-based access, and audit-aware administration support more controlled handling of evaluation-related data in sensitive governance workflows.

See the security posture

Retention and deletion

Retention depends on the nature of the engagement, governance evidence needs, legal requirements, and operational necessity. When information is no longer reasonably required, deletion or de-identification should follow the applicable process and obligations.

Data-subject and stakeholder rights

Request access to personal information where applicable
Request correction of inaccurate or incomplete information
Request deletion where lawful and operationally appropriate
Object to certain processing or request restriction where applicable
Ask questions about privacy, retention, or evaluation-data handling

Submit a privacy enquiry

Policy routes connected to this page

Security for technical and control posture
Methodology for how sensitive evaluation data becomes board-ready output
POPIA for South African privacy relevance
Cookies for site-level cookie disclosure
Terms for broader legal framing
Privacy in product context

The privacy page should connect clearly to what the product actually does.

Privacy matters more when it is linked to the platform, the module architecture, and the real board processes behind the data.

Platform

See the end-to-end workflow

Privacy becomes more understandable when the evaluation process itself is clear.

Modules

Understand what may be assessed

Module scope affects the nature and sensitivity of the information being processed.

Trust

Review the wider trust layer

Privacy is stronger when read together with company, methodology, and security context.

FAQs

Questions this privacy page should answer directly.

The goal is clarity for governance teams, participants, and stakeholders reviewing trust, compliance, or procurement fit.

Depending on the interaction, BoardEvaluator™ may handle contact information, organisation information, platform account data, board-evaluation participation data, evaluation responses, and technical usage data needed to operate, support, and protect the service.
Because board evaluations can surface sensitive information about board dynamics, oversight quality, independence, governance gaps, and strategy execution. The privacy posture therefore needs to match the seriousness of the context.
Privacy explains why and how information is handled. Security explains the controls used to protect that information, including hosting, encryption, access control, and audit-aware administration.
Use Contact if you need to raise a privacy request, ask a data-handling question, or escalate a concern relating to personal information or evaluation-data handling.
The strongest trust path is usually Security, Methodology, POPIA, Cookies, and Terms, together with the product pages like Platform and Modules.
Next step

If the privacy posture looks right, the next move is to test fit in your governance context.

Privacy is one part of the buyer-confidence journey. The commercial decision still depends on platform fit, module scope, reporting needs, security expectations, and the right delivery model.