Board Badger BB/JOB/01

Data Processing Agreement.

This Data Processing Agreement ("DPA") applies where the Operator, Dale Mooney, a sole trader based in the United Kingdom, trading as Board Badger ("Processor"), processes personal data on behalf of an account holder ("Controller") in order to provide the service. It supplements the Terms of Service and, for data protection matters, prevails in the event of conflict. Requests for a copy countersigned in a company's name, or for amendments, should be sent to legal@boardbadger.com.

1. Subject matter and duration

The Processor processes personal data only to provide the service to the Controller, for as long as the account is active, plus the retention period in section 8.

2. Nature and purpose

Storing and processing the boards, tasks, notes and comments entered by the Controller and by the people the Controller invites; issuing and ending those people's access; and sending the invitation and the notices that go with a board.

3. Types of personal data

The name and email address of each person the Controller invites to a board, the role they were given, the record of what they ticked off and commented on, any personal detail entered into a task title, a note or a comment, and the Controller's own account email address.

4. Categories of data subjects

The Controller's client contacts invited to a board, the Controller's own staff or contractors where invited, and any individual whose details are entered into a task or a comment.

5. The Processor's obligations

  1. Process on instruction: only on the Controller's documented instructions, use of the service being that instruction, unless the law requires otherwise.
  2. Confidentiality: anyone authorised by the Processor to process the data is bound by confidentiality.
  3. Security: appropriate technical and organisational measures, set out in section 6.
  4. Sub-processors: only those in section 7, on terms no less protective than this DPA, for which the Processor remains responsible.
  5. Assistance: help the Controller respond to data subject requests and meet their security, breach and impact assessment duties.
  6. Breach notice: notify the Controller without undue delay after becoming aware of a personal data breach affecting their data.
  7. Deletion or return: on termination, as set out in section 8.

6. Security measures

Data encrypted in transit with TLS and HSTS; passwords hashed with PBKDF2-HMAC-SHA256; per-board isolation enforced in the database query rather than in the interface; signed, HttpOnly, Secure sessions, with revocation that ends a session already issued; hosting on Cloudflare; rate limiting and bot protection; strict security headers with a per-request Content Security Policy nonce. Full detail on the Security page.

7. Authorised sub-processors

The Controller authorises these sub-processors. Reasonable notice is given on the Sub-processors page before one is added or replaced, so that the Controller may object.

  • Cloudflare, Inc.: hosting, database, OAuth storage, the MCP connection, and bot protection once switched on.
  • Resend, Inc.: transactional email delivery (United States).

8. Retention, return and deletion

While the account is active the data is kept in order to run the service. Closure is on the Controller's written request to privacy@boardbadger.com, there being no self-service closure in the product at the date of this DPA. On closure the Processor removes personal data from live systems within one month of the request and confirms it in writing. Residual copies persist in the hosting provider's automated backups and are removed on that provider's own retention schedule, which the Processor does not set. There is no export feature, so a Controller wanting a copy before closure should ask for one in writing.

9. Audit

The Processor responds to reasonable written requests for the information needed to demonstrate compliance, no more than once a year unless a supervisory authority or a breach requires otherwise, subject to reasonable confidentiality.

10. International transfers

Where a sub-processor processes data outside the UK or EEA, the Processor ensures an appropriate transfer mechanism is in place, such as the UK IDTA or an adequacy decision.

11. Liability and governing law

Liability under this DPA is subject to the limits in the Terms of Service. This DPA is governed by the laws of England and Wales.