Where your call data lives and who can see it

Employee call monitoring in Australia is a trust decision as much as a software decision. This page says plainly what Callboard collects, where it is kept, how it is protected, and how you get it back. If a question is not answered here, ask us.

Call history, and nothing else

The app reads the phone's own call history. A persistent notification on the phone shows the rep it is running.

Collected

  • The phone's own call history: direction, start time, duration, and whether the call was answered, missed or declined
  • The phone number on each call, stored masked by default (a one-way hash plus the last three digits)
  • The phone's current call state: idle, ringing or on a call, so the live board is live
  • A check-in every five minutes so the board knows the phone is reachable
  • The phone model, the SIM slot used and the app version, for support

Not collected

  • No call audio. The app does not record calls.
  • No contacts, no SMS, no email, no photos, no files
  • No location
  • No microphone or camera access
  • No calls on a second personal SIM when you choose to track the first SIM only
  • Nothing from a personal phone: the app is deployed only to company-owned, fully managed Android phones

Your workspace is its own database

Most software puts every customer in one big database and relies on a filter to keep them apart. Callboard does not.

One database per customer
When you create a workspace, a separate database is created for it. Your calls, phones, users and settings live there and nowhere else.
Resolved from your address
Your workspace has its own web address. Every request, including the phones' and the API's, is tied to that address and answered only from your database.
Your own export
Ask for an export of your workspace at any time. It is your data, and you can take it with you.

Kept where your policy says

Employee call monitoring in Australia should keep the data in Australia. Callboard runs on dedicated infrastructure in multiple regions around the world, so your workspace lives where your policy says it must. Australian customers stay in Australia.

Dedicated infrastructure
The application and every customer database run on infrastructure we control, in multiple regions around the world. A workspace lives in the region that matches its country and is not moved without telling you.
Encrypted in transit
Every connection, from the phones, from your browser and from your CRM, uses TLS. Webhooks and CRM connections are HTTPS only.
Credentials encrypted at rest
CRM tokens, webhook secrets, mail and payment settings are encrypted before they are written to the database and decrypted only at the moment they are used.

Who can see what

Three roles, server-side sessions you can end, and a log of every change. Reps do not need accounts at all: their phones report on their behalf.

Owner, manager, viewer
Owners can do everything including billing. Managers run phones, leads, reports and settings. Viewers can only look. The last owner can never be removed by accident.
Sessions you can revoke
Sign-ins are held on the server, not in the browser, and can be ended at any time. Cookies are marked so scripts and other sites cannot read them.
Passwords handled properly
Passwords are stored with a slow, salted hash designed for passwords. Sign-in attempts are rate limited.
Audit log
Every change to phones, users, settings, integrations and billing is written to an audit log with who did it and when. Owners can read it.
Support access is logged
If you ask us to look inside your workspace, that access is short-lived, flagged as support access, and recorded in your audit log.

How a phone joins and leaves

A phone can only report to your workspace if it holds a token your workspace issued. Tokens are issued through enrolment codes you control.

Enrolment codes
Create a code for the whole fleet or a single-use code for a test handset. Revoke a code at any time; phones already enrolled keep working.
One token per phone
Each phone receives its own token at enrolment. Tokens are stored hashed on the server and are never shown again.
Revocation is immediate
Remove a phone on the Phones page and its token stops working on the next request. It cannot re-enrol with the fleet code until you restore it.
Rate limits on enrolment
Repeated enrolment attempts from one connection are throttled, so a leaked code cannot be brute-forced against your workspace.

Data leaving your workspace

Nothing leaves your workspace unless you switch it on. When you do, it goes only where you pointed it.

Signed webhooks
Each webhook request carries a timestamp and a signature computed with your endpoint's secret. Your receiver can check both and reject anything else. HTTPS only.
API keys you control
Keys are shown once, stored only as a hash, carry read or write scope, and can be revoked from the Integrations page. A key only ever reaches the workspace that issued it.
Credentials reported as set or not set
Once you enter a CRM credential, the interface only ever says whether it is set. It is never displayed again.

Card details never touch Callboard

Self-serve billing runs through Stripe. Larger customers on prepaid invoicing never enter a card at all.

Handled by Stripe
Your card is entered on a Stripe-hosted page and stored by Stripe. Callboard holds a customer reference, not a card number.
Verified events
Every message from Stripe about your subscription is checked for a valid signature before it changes anything in your workspace, and each one is processed once.
Phones keep reporting
If a payment fails, the workspace goes read-only while it is sorted out. Phones keep reporting so no call is lost during a billing dispute.

Leaving takes one request

There is no contract. When you are done, you can take your data with you and have the rest removed.

Export first
Ask for an export before you close. You receive your workspace data in a standard format.
Close the workspace
Closing stops enrolment, reporting and billing. The workspace and its phones stop immediately.
Database removed after 30 days
The workspace database is kept for 30 days after closure in case you change your mind, then removed.
Housekeeping
Expired sign-in sessions and completed integration jobs are pruned automatically after 30 days. Payment event records are pruned after 90 days.
Staff notices

The rules in your state, shown during setup

Monitoring calls on company phones is workplace surveillance. Some states require written notice to staff before it starts. Callboard shows the rule for your state when you set up the workspace and again when you add phones, so nobody finds out after the fact.

  • New South WalesWorkplace Surveillance Act 2005 (NSW): written notice to staff at least 14 days before monitoring starts.
  • Australian Capital TerritoryWorkplace Privacy Act 2011 (ACT): written notice to staff at least 14 days before monitoring starts.
  • Other states and territoriesNo specific notice period in law. Written notice before monitoring starts is still the norm for company-owned phones and supports your Privacy Act collection notice.
  • Customer numbersPhone numbers in a call log are personal information under the Privacy Act. Numbers are masked by default; switch on full numbers only once your notice covers it. This is a summary, not legal advice.

Who else touches your data

These are the providers Callboard relies on to run. Each one sees only what its job needs, and none of them sees your call history except the infrastructure that runs your database. We will tell you before adding one.

ProviderPurposeLocationNote
Dedicated infrastructureRuns the application and holds every customer databaseMultiple regions around the world, chosen to meet your data residency requirementsEncrypted disks, private network between the app and the databases, daily backups kept in the same region as the workspace.
StripeCard payments and subscription billing for self-serve customersGlobal, PCI DSS Level 1Sees your billing name, email and card. Never sees call data. Invoice customers do not touch Stripe at all.
Google (managed Google Play)Distributes the Android app to your managed phonesGlobalHandles the app package and your organisation ID. No call data is sent to Google by Callboard.

Responsible disclosure

Report a vulnerability to help@callboardmdm.com.

Tell us what you found, how to reproduce it, and how to reach you. We acknowledge reports within one business day, Sydney time, keep you informed while we fix it, and will not take action against anyone who reports in good faith and does not access or disturb other customers' data.

For a signed copy of this page, a security questionnaire, or a data processing addendum, contact us.

Try it on three phones

See what your data looks like inside

Start a trial, push the app to three phones, and open the audit log and the export yourself. Or send us your security questionnaire first.