Strictboard
UK flagENLog inRegister
Document Archive

Version-controlled archive with digital signing

Meetings & Minutes

Schedule meetings with agenda and minutes

Forum

Posts, decisions and discussions

Tasks

Assign tasks with deadlines

Contract GeneratorSnart

Generate contracts from templates

Share RegisterSnart

Digital share register with owners

New IssuanceSnart

Directed and rights issuances

Data protectionCompliance
Privacy policyCookie policySecurity policyTerms and Conditions
Board portalPricingAbout
Strictboard
UK flagEN
Strictboard

All board work in one system – secure, traceable and built for Swedish limited companies.

Product

  • Board portal
  • Overview
  • Pricing

Company

  • About
  • Contact
  • Careers

Security

  • Data protection
  • Compliance

© 2026 Strictboard. All rights reserved. Managed and hosted by Sitepulse.

Privacy policyCookie policySecurity policyTerms and Conditions
Security · Compliance

GDPR and regulatory compliance

Strictboard is built to meet requirements from GDPR and good industry practice.

We take responsibility for ensuring your data is handled lawfully, transparently, and securely — so you don't have to.

Read the privacy policy

Compliance built in

GDPR, data security, and traceability in one place.

Strictboard's architecture and procedures are designed to give you and your customers peace of mind.

GDPR compliance from the ground up
Data processing agreements provided
Data subject rights handled
Data deleted upon contract termination
Access logs and audit history
Data storage in the EU (GDPR-safe)
Clear privacy policy
Ongoing legal review
Contact us

GDPR in board work

A board archive contains personal data, more often than most people realise.

Directors' names and contact details, shareholders' identity numbers in the share register, personnel matters in the minutes and signing data from BankID. All of it is covered, and all of it is handled within the EU.

We are the processor, you are the controller. You determine the purposes; we process the data according to your instructions and the agreement governing it.

The purpose is bounded. The data is used to deliver the service — not to train models, profile or resell.

Deletion happens within 30 days of the contract ending, and you can export everything before then.

Data subject rights are handled through you as controller. We assist with extracts and deletion when you ask.

  • Processing within the EU
  • Data processing agreement
  • Bounded purpose
  • Deletion within 30 days
  • Export before cancellation
  • Audit trail over access

What Swedish company law requires of retention

Compliance for a board is not only about data protection. It is also about the documents still being there.

Minutes must be kept in numbered sequence and stored securely. An unbroken series is the simplest way to notice a missing set — and a gap shows up at review if it is not caught along the way.

The share register must be kept for as long as the company exists and at least ten years after dissolution. The retention duty outlives the company itself, which is hard to satisfy with a file on a laptop.

The auditor must be able to access the material. Role-based access with traceability is easier to stand behind than emailing a bundle once a year.

The board must continuously assess the company's financial position. That duty is hard to evidence without documentation, and it is exactly what gets examined when liability arises.

Questions to ask every vendor

Including us. The answers should be concrete, and an evasive answer is also an answer.

Where is data stored?

Ask for a region and a list of sub-processors with their locations.

How is access controlled?

Can the auditor be invited without seeing everything? What does adding a person cost? Does the tool distinguish director from deputy?

What is logged?

Can you see who opened a document, and when? Can the log be exported or reviewed by you?

What happens at cancellation?

In what format do you get the material, how quickly, and when is it deleted at the vendor?

How are incidents handled?

Who is notified, within what time, and how do you get what you need for your own reporting duty?

What is in the contract?

Is there a data processing agreement, and does it describe the processing you actually do in the tool?