S SanctumBoard
  • The platform
  • Pricing
  • Terms
See the demo

Legal

Privacy Policy

Version 1.0 · Effective 5 August 2026 · Australian Privacy Principles, Privacy Act 1988 (Cth)

Contents

  1. The short version
  2. Who we are
  3. What we collect
  4. Why we collect it
  5. Where it is stored
  6. AI and your board's content
  7. Who else touches it
  8. What leaves Australia
  9. How it is protected
  10. How long we keep it
  11. Your rights
  12. Cookies and tracking
  13. If something goes wrong
  14. Complaints
  15. Changes

1. The short version

Boards hand us the most sensitive documents their organisation produces — remuneration papers, legal advice, incident reports, matters discussed in camera. So the important answers come first, in full, rather than being assembled from fifteen clauses.

Your board's content stays in Australia. Papers, minutes, decisions, registers, board memory and every AI request Pam makes are stored and processed in Sydney. AI inference runs in ap-southeast-2 and Australian residency is enforced by our cloud permissions, not only by our code — the credential is scoped so an overseas region would be refused, not merely avoided.

We do not train AI on your content, ever. Not our own models, not anybody else's. Your papers are not training data, not a product input, and not shared with other customers.

We never sell personal information. There is no advertising on SanctumBoard, no advertising network, and no third party receives your information for its own purposes.

What does leave Australia is commercial contact information — the name, work email and organisation someone typed into a signup form, and billing details. That is set out precisely in clause 8, including exactly which fields.

2. Who we are

SanctumBoard is operated by 1Pacent Pty Ltd (ABN 79 678 368 306), an Australian private company. We are bound by the Australian Privacy Principles under the Privacy Act 1988 (Cth).

For most board content we act as a service provider to your organisation: your board decides what goes in and who may see it, and we hold it on your behalf. For your own account and billing details, we are the entity responsible.

3. What we collect

When you enquire or sign up

Your name, work email address, organisation name, country, the type of organisation, and which plan you were looking at. If you subscribe, your billing details — handled by Stripe, so we never see or store card numbers.

When you use SanctumBoard

  • Board content you provide — papers, agendas, minutes, resolutions, registers, attachments and anything else your board puts in. This may include personal information about directors, staff or others; your board decides what goes in.
  • Directors and users — name, email, role, and the register entries a board is required to keep, such as declared interests.
  • Authentication data — sign-in records and passkey public keys. A passkey's private key never leaves your device and we never receive it.
  • The audit trail — who did what, when, and what they approved. This is the product working, not surveillance: it is the record your board relies on to prove its own governance.
  • Technical logs — request timing, errors and IP addresses, kept to operate the service securely.

The content of AI prompts and responses is never written to our logs. We record that a request happened, what it cost in credits, and whether it succeeded — never what was in it. An engineer reading a log file cannot read your board's papers.

4. Why we collect it

To provide SanctumBoard and nothing else: running the governance cycle, keeping your records and audit trail, authenticating people, billing you, supporting you when you ask, keeping the service secure, and meeting our own legal obligations.

We do not use board content for product analytics, for benchmarking across customers, or for any marketing purpose.

5. Where it is stored

WhatWhereResidency
Board records and documents
papers, minutes, decisions, registers
Sydney, Australia
(ap-southeast-2)
Australia
AI inference
every request Pam makes
Sydney, Australia
AWS Bedrock, Australian inference profile
Australia
Board memory
what Pam remembers about your board
Sydney, AustraliaAustralia
Application computeSydney, Australia
(functions pinned to syd1)
Australia
Outbound emailSydney, AustraliaAustralia
BackupsSydney, AustraliaAustralia
Billing detailsStripeOverseas
Signup contact detailsHubSpotOverseas

Each board's data is separated from every other board's by the database itself, through row-level security — a query that forgets its boundary returns nothing rather than someone else's records. Professional and Enterprise subscriptions can be provisioned with a dedicated database and document store.

6. AI and your board's content

Pam runs on Anthropic's Claude models through AWS Bedrock in Sydney. Bedrock is a service of AWS: your content is sent to the model, the answer comes back, and it is not retained by the model provider or used to improve any model.

  • Australian residency is enforced by permissions. The credential the product uses is scoped to Australian inference profiles. A request to an overseas region fails; it is not merely discouraged.
  • There is no silent fallback. If our Australian AI provider is unavailable, Pam stops and says so. She will not quietly use a different provider in a different country to keep working.
  • You can turn AI off. Entirely, or function by function. SanctumBoard remains a complete governance system with it off.
  • Board memory is inspectable and erasable. What Pam remembers about your board can be viewed and deleted from within the product.

7. Who else touches it

We use a small number of providers. Each is bound to protect the information and to use it only to provide their service to us.

ProviderWhat forWhat they getWhere
Amazon Web ServicesAI inference, document storage, email delivery, backupsBoard content, at rest and in transitSydney
NeonManaged Postgres databaseBoard recordsSydney
VercelApplication hostingData in transit through functions pinned to SydneySydney · US company
StripePayments and subscriptionsBilling contact and payment details. No board content.Overseas
HubSpotEnquiries and customer recordsSignup contact details only. No board content.United States

We will update this table when it changes, and the version history of this page is the record of when it did.

8. What leaves Australia

Under Australian Privacy Principle 8 we must tell you if personal information is disclosed overseas, and to where. Two disclosures apply, and this is the whole of them.

HubSpot — United States

When you enquire or sign up, we send the following to our customer records system so that a person can respond to you and so we know who our customers are:

  • your name and work email address
  • your organisation's name, country and type
  • which plan you were looking at, and whether you started a trial, reached checkout, or asked us to be in touch

Nothing else is sent. No papers, no minutes, no decisions, no register entries, no AI output, no document content. The boundary is enforced in our code, and an automated test enumerates the permitted fields and fails if anything outside that list appears.

Stripe — overseas

If you subscribe, your billing contact details and payment information are handled by Stripe, which processes payments outside Australia. We never receive or store your card number. No board content is sent to Stripe.

Vercel — a note on the difference

Our application runs on Vercel with its compute pinned to Sydney, so your data is processed in Australia. Vercel is a US-incorporated company, and its personnel may access systems for support and operational purposes. We tell you this because "hosted in Australia" and "hosted by an Australian company" are different statements and it would be misleading to blur them.

9. How it is protected

  • Encryption in transit and at rest.
  • Isolation enforced by the database. Row-level security means one board cannot read another's records even if application code were wrong.
  • Passkeys for sealing decisions. The private key stays on your device, and a seal is cryptographically bound to the specific decision it approves — an approval cannot be moved to a different decision afterwards.
  • An append-only audit trail. Entries cannot be edited or deleted, by you or by us. A correction is made by adding an entry.
  • Least privilege. The application's database role cannot bypass tenant isolation, and the product refuses to start against a role that can.
  • Backups, held in Australia, with restores tested rather than assumed.

No system is perfectly secure, and we will not claim otherwise. What we will say is what we have actually built, which is above.

10. How long we keep it

  • Board records — for as long as your subscription runs, and for 90 days after it ends, during which you can still read and export everything.
  • Trials that end — the board becomes read-only. Nothing is deleted, so if you subscribe later you carry on where you stopped.
  • Audit trail and decision ledger — retained for the life of the board's account, and not editable. This is the record that makes your governance provable.
  • Financial records — retained as long as Australian tax and corporations law requires.
  • Enquiry records — kept while there is a genuine prospect of doing business, and removed on request.

11. Your rights

You may ask us to access the personal information we hold about you, correct it, export it in a usable format, or delete it. Email hello@sanctumboard.com and we will respond within 30 days.

Two honest limits, stated here rather than discovered later:

  • Board records belong to the board. If you are a director of a customer organisation, we will usually direct a request about board content to that organisation, because it is their record and not ours to release or erase.
  • The audit trail cannot be rewritten. When someone exercises a right to erasure we revoke their access and remove their personal details everywhere we can — but the fact that a named person approved a particular decision on a particular date remains, because that is the board's record of its own governance and erasing it would destroy the integrity every other board relies on. Where an entry must be corrected, a correcting entry is added.

12. Cookies and tracking

SanctumBoard uses cookies only to keep you signed in and to keep the session secure. There are no advertising cookies and no third-party tracking in the product.

This website carries no analytics, no advertising pixels and no third-party scripts of any kind. Reading this page tells us nothing about you.

13. If something goes wrong

We maintain a data breach response plan. If a breach is likely to cause you serious harm, we will notify you and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme — promptly, in plain language, and with what we know rather than what is comfortable.

Where the affected records belong to a customer organisation, we will notify that organisation so it can meet its own obligations.

14. Complaints

If you think we have mishandled your personal information, email hello@sanctumboard.com. We will acknowledge within 5 business days and respond substantively within 30 days.

If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner — oaic.gov.au, 1300 363 992.

15. Changes

We may update this policy. If a change materially affects how we handle your information, we will email you before it takes effect. Every version is dated, and we will provide an earlier version on request.

Contact

1Pacent Pty Ltd · ABN 79 678 368 306
Victoria, Australia
hello@sanctumboard.com

Version 1.0 · Effective 5 August 2026. See also our Terms of Service.

S SanctumBoard

Governance, with proof.

  • Home
  • Demo environment
  • AI governance assessment
  • Terms of Service
  • Privacy Policy

SanctumBoard is a product of 1Pacent Pty Ltd · ABN 79 678 368 306 · Victoria, Australia

© 2026 1Pacent Pty Ltd · Pam drafts; named humans approve; the board retains decision authority. SanctumBoard provides governance support and evidence — not legal advice or compliance determinations.