Skip to the content
The operating system for desk work that lives in files
Try a sample
Legal · effective 2026-09-23

Data Processing Addendum

Effective 2026-09-23.

This Data Processing Addendum ("DPA") is between the customer that accepts our Terms of Service ("Customer", "you") and BaseLoom, a sole proprietorship based in India ("BaseLoom", "we").

It forms part of the Terms of Service at https://app.baseloom.app/?view=legal&doc=terms and applies automatically, without a separate signature, whenever you use a BaseLoom tool to process personal data. If you need a countersigned copy, email legal@baseloom.app.

1. Definitions

1.1 Data Protection Law means all laws on personal data that apply to the processing under this DPA, including, where applicable: the EU General Data Protection Regulation 2016/679 ("GDPR"); the UK GDPR and Data Protection Act 2018 ("UK Data Protection Law"); the Swiss Federal Act on Data Protection ("FADP"); the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA") and other US state comprehensive privacy laws; India's Digital Personal Data Protection Act 2023 and Rules 2025 ("DPDP Act"); and equivalent laws elsewhere.

1.2 Customer Personal Data means personal data contained in files, text or data that you or your users upload or paste into a tool.

1.3 Session means a single browser session in which a tool is used. It ends when the browser tab is closed, the session times out, or the server process holding it restarts.

1.4 Sub-processor means a third party we engage that processes Customer Personal Data.

1.5 Security Incident means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data.

1.6 Terms such as controller, processor, data subject, personal data, processing, supervisory authority, business, service provider, data fiduciary and data processor have the meanings given in the applicable Data Protection Law.

2. Roles and scope

2.1 You are the controller (or business, or data fiduciary) of Customer Personal Data. We are your processor (or service provider, or data processor). Where you are yourself a processor acting for another controller, we are your sub-processor, and you confirm your controller has authorized our engagement.

2.2 This DPA covers Customer Personal Data only. For personal data we handle as a controller (subscription, billing, support, website and partner-outreach data), our Privacy Notice at https://app.baseloom.app/?view=legal&doc=privacy applies.

2.3 The subject matter, nature, purpose, duration, types of data and categories of data subjects are set out in Annex I.

3. Your responsibilities

3.1 You are responsible for having a lawful basis to process Customer Personal Data and to have us process it, and for giving any notices and obtaining any consents required.

3.2 You will upload only the personal data a tool needs. The tools are designed to work on business documents and, where possible, on redacted or de-identified data.

3.3 You will not upload protected health information unless a Business Associate Agreement is signed by both parties (see https://app.baseloom.app/?view=legal&doc=baa). You will not upload ITAR technical data, EAR-controlled technology or Controlled Unclassified Information, as set out in our Acceptable Use Policy at https://app.baseloom.app/?view=legal&doc=aup.

4. Processing on documented instructions

4.1 We process Customer Personal Data only on your documented instructions, including with regard to international transfers, unless required to do otherwise by law. If so, we will tell you of that legal requirement before processing, unless the law forbids it on important grounds of public interest.

4.2 Your instructions are: the Terms, this DPA, and your use of a tool (choosing it, loading files, running it, and exporting results). Any further instruction must be in writing and consistent with the nature of the service.

4.3 We will tell you promptly if, in our opinion, an instruction infringes Data Protection Law. We are not obliged to carry out a legal review of your instructions.

5. Ephemeral processing: the core technical measure

5.1 Uploaded files and pasted text are processed in the memory of the server handling your Session. They are not written to disk, not saved to a database, not included in backups and not used for any other purpose.

5.2 When the Session ends, the data is released from memory. We do not keep a copy and cannot recover it.

5.3 The tools run deterministic code and reference tables. Customer Personal Data is not sent to any AI model provider or other third party, other than the hosting provider whose servers hold the memory.

5.4 Results (findings, draft letters, converted files) are shown in your browser and delivered to you as downloads. Once you download them, they are under your control.

5.5 Server logs and error reports are configured not to record file contents.

6. Confidentiality

6.1 We ensure that every person authorized to process Customer Personal Data is bound by confidentiality. Today the only such person is the proprietor.

6.2 We do not access Customer Personal Data except as needed to provide the service in the Session, or to investigate a problem at your request with data you choose to share.

7. Security

7.1 We implement the technical and organizational measures in Annex II, which are designed to ensure a level of security appropriate to the risk, as required by GDPR Article 32.

7.2 We may update those measures, provided the overall level of protection does not decrease.

8. Sub-processors

8.1 General authorization. You give us general written authorization to engage Sub-processors. The current list is at https://app.baseloom.app/?view=legal&doc=subprocessors (Annex III).

8.2 Notice of changes. We will give at least 30 days' notice before a new Sub-processor starts processing Customer Personal Data, by email to your billing contact and by updating the list.

8.3 Objection. You may object on reasonable data protection grounds within those 30 days by writing to legal@baseloom.app. We will try in good faith to resolve the objection. If we cannot, you may terminate the affected subscription before the change takes effect and receive a pro-rata refund of any prepaid unused period.

8.4 Flow-down. We impose on each Sub-processor, by written contract, data protection obligations that provide at least the same level of protection as this DPA, in particular sufficient guarantees of appropriate technical and organizational measures.

8.5 Liability. We remain liable to you for the performance of each Sub-processor's obligations, as required by Data Protection Law.

9. Assistance with data subject requests

9.1 Taking into account the nature of the processing, we will assist you by appropriate technical and organizational measures in responding to requests from data subjects to exercise their rights.

9.2 Because Customer Personal Data exists only for the Session, in most cases we hold nothing to access, correct, delete or port once the Session ends. On request we will confirm this in writing.

9.3 If a data subject contacts us directly about Customer Personal Data, we will not respond on the merits (other than to redirect them) and will tell you without undue delay, if we can identify you.

10. Assistance with security, impact assessments and consultation

10.1 Taking into account the nature of processing and the information available to us, we will help you meet your obligations under GDPR Articles 32 to 36: security, notification of personal data breaches, data protection impact assessments and prior consultation with supervisory authorities.

10.2 We do this mainly by providing this DPA, the Security Overview at https://app.baseloom.app/?view=legal&doc=security, the Sub-processor list, and written answers to reasonable questions.

11. Security Incidents

11.1 We will notify you without undue delay, and in any case within 72 hours, after becoming aware of a Security Incident affecting Customer Personal Data.

11.2 The notice will include, as far as then known: the nature of the incident, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point. Where not all information is available at once, we will provide it in phases without further undue delay.

11.3 We will take reasonable steps to contain the incident and reduce its effects, and will cooperate with you.

11.4 Notification is not an admission of fault or liability.

11.5 You are responsible for notifying supervisory authorities and data subjects where you are the controller, unless we agree otherwise in writing.

12. Deletion and return

12.1 Customer Personal Data is deleted automatically at the end of each Session (section 5). Return of data is performed during the Session, through the tool's results and downloads.

12.2 On termination of the Terms, no Customer Personal Data remains with us to return or delete, other than any attachment you chose to send to support, which is deleted within 7 days of receipt. On request we will confirm deletion in writing.

12.3 If a law requires us to keep any Customer Personal Data, we will protect it under this DPA and process it only for that legal purpose.

13. Information and audits

13.1 We will make available the information necessary to demonstrate compliance with this DPA and GDPR Article 28, and will allow for and contribute to audits, including inspections, by you or an independent auditor you appoint, under this section.

13.2 Documentation first. You agree to first request written information: this DPA, the Security Overview, the Sub-processor list, and answers to a reasonable security questionnaire. Most questions can be settled this way.

13.3 Further audit. If that information is not enough to show compliance, or a supervisory authority requires it, you may conduct an audit:

  • (a) on at least 30 days' written notice;
  • (b) no more than once in any 12 months, unless following a Security Incident or required by a supervisory authority;
  • (c) during normal business hours in India, remotely where practical, without disrupting the service;
  • (d) by you or an independent auditor bound by confidentiality who is not our competitor;
  • (e) at your cost, including our reasonable time at rates agreed in advance.

13.4 Audits of Sub-processors are satisfied by the Sub-processors' own published certifications and audit reports, where available.

13.5 We do not hold any security certification (such as ISO 27001 or SOC 2). We will not claim one until it is obtained.

14. International transfers

14.1 Customer Personal Data is processed in the United States (Microsoft Azure, East US 2 (United States)). The proprietor, who can administer the servers, is in India.

14.2 EU Standard Contractual Clauses. Where a transfer of Customer Personal Data from the European Economic Area to us is a restricted transfer under GDPR, the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914 ("EU SCCs") are incorporated by reference and form part of this DPA, as follows:

  • (a) Module Two (controller to processor) applies where you are a controller; Module Three (processor to processor) applies where you are a processor.
  • (b) Clause 7 (docking clause) is included.
  • (c) Clause 9: Option 2 (general written authorization) applies, with a notice period of 30 days, as set out in section 8.
  • (d) Clause 11: the optional language on independent dispute resolution bodies is not included.
  • (e) Clause 13: the competent supervisory authority is the one of the member state where you are established; if you are not established in the EEA, the one of the member state where your Article 27 representative is established; if you have none, the one of the member state where the data subjects concerned are located (and if several, the one indicated by you or, failing that, the Irish Data Protection Commission).
  • (f) Clause 17: Option 1 applies; the EU SCCs are governed by the law of Ireland.
  • (g) Clause 18: disputes are resolved by the courts of Ireland.
  • (h) Annexes I, II and III of the EU SCCs are completed by Annexes I, II and III of this DPA.
  • (i) For Module Three, you will pass on to your controller any information we provide under the EU SCCs.

14.3 UK. Where a transfer from the UK is a restricted transfer under UK Data Protection Law, the International Data Transfer Addendum to the EU SCCs issued by the Information Commissioner (version B1.0, in force 21 March 2022, as revised under Section 18 of its Mandatory Clauses) ("UK Addendum") is incorporated. Table 1 is completed with the parties' details in Annex I; Table 2 with the modules and clauses in section 14.2; Table 3 with Annexes I to III of this DPA; and in Table 4, either party may end the UK Addendum as set out in its Section 19.

14.4 Switzerland. Where a transfer from Switzerland is subject to the FADP, the EU SCCs apply with these adjustments: the Swiss Federal Data Protection and Information Commissioner is the competent supervisory authority for such transfers; references to the GDPR are read as references to the FADP where relevant; references to member states do not prevent data subjects in Switzerland from suing in their place of habitual residence; and the EU SCCs protect data of legal entities to the extent the FADP does.

14.5 Onward transfers. Our Sub-processors are bound by the EU SCCs, the UK Addendum, or another valid transfer mechanism (such as certification under the EU-US Data Privacy Framework) as listed in Annex III.

14.6 Government access. As of the effective date of this DPA, we have not received any request from a public authority for Customer Personal Data. If we do, we will act as required by Clause 15 of the EU SCCs, including notifying you where legally permitted and challenging a request we consider unlawful.

14.7 Other laws. Where another jurisdiction requires a transfer mechanism, the parties agree that this DPA serves as that mechanism to the extent the law allows, and will cooperate in good faith to put any additional required terms in place.

14.8 Precedence. If the EU SCCs or the UK Addendum conflict with this DPA or the Terms, the EU SCCs or the UK Addendum prevail.

15. US state privacy laws (CCPA and similar)

15.1 We are your service provider (and, where applicable, processor or contractor). We process Customer Personal Data only for the limited and specified business purpose of providing the tools you use, as described in Annex I.

15.2 We will not:

  • (a) sell or share Customer Personal Data (including for cross-context behavioral advertising);
  • (b) retain, use or disclose it for any purpose other than the business purpose, including any commercial purpose, or outside the direct business relationship with you;
  • (c) combine it with personal information we receive from others or collect ourselves, except as the CCPA permits for service providers.

15.3 We will comply with the CCPA and provide the same level of privacy protection it requires. We will tell you if we can no longer meet our obligations.

15.4 You may take reasonable and appropriate steps to ensure we use Customer Personal Data consistently with your obligations, and to stop and remediate unauthorized use, including through section 13.

15.5 We certify that we understand and will comply with the restrictions in this section 15.

16. India (DPDP Act)

16.1 Where the DPDP Act applies, you are the data fiduciary and we are your data processor. We process Customer Personal Data only under this DPA, which is the valid contract required by section 8(2) of the DPDP Act.

16.2 We maintain reasonable security safeguards (Annex II) to prevent personal data breaches, and will notify you of any breach under section 11 so that you can inform the Data Protection Board and affected data principals.

16.3 We erase Customer Personal Data as set out in section 12, and will erase any personal data on your instruction when you are required to erase it.

17. Liability

17.1 Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Terms, except where Data Protection Law or the EU SCCs do not permit such a limitation (including liability to data subjects under Clause 12 of the EU SCCs).

18. Duration, changes and precedence

18.1 This DPA lasts for as long as we process Customer Personal Data for you, and ends automatically when the Terms end and no Customer Personal Data remains with us.

18.2 We may update this DPA to reflect changes in law or in our service, with at least 30 days' notice for any change that reduces your protection. We will not reduce the protection of Customer Personal Data below what Data Protection Law requires.

18.3 If this DPA conflicts with the Terms, this DPA prevails for the processing of Customer Personal Data. Section 14.8 applies to the EU SCCs and UK Addendum.

18.4 Governing law and jurisdiction follow the Terms, except that the EU SCCs are governed as set out in section 14.2.

Annex I: Description of processing

A. Parties

Data exporterData importer
NameThe Customer named in the subscription recordBaseLoom, a sole proprietorship based in India
AddressAs in the subscription recordIndia; notices by email to legal@baseloom.app
ContactThe billing contactlegal@baseloom.app
RoleController (Module Two) or processor (Module Three)Processor
ActivitiesUse of BaseLoom toolsProviding the tools
Signature and dateBy accepting the TermsBy making the service available under the Terms

B. Description of the transfer and processing

ItemDescription
Categories of data subjectsDepend on the tool and on what you upload. Typically: your vendors, suppliers and their staff; your employees and contractors; your customers and their contacts; counterparties named in contracts; claimants, applicants and account holders named in regulated records; patients only where a BAA is signed.
Categories of personal dataDepend on the tool. Typically: names, business contact details, job titles, identifiers and account numbers, invoice and payment details, contract terms, employment records such as job category or injury log entries, and transaction records.
Sensitive dataNot required by any tool. Health data may appear in healthcare tools only under a signed BAA. Other special category data may be present only if you choose to upload it. Safeguard: in-memory processing with no storage (Annex II).
FrequencyContinuous, each time you use a tool.
Nature of processingReading, parsing, checking against rules and reference tables, and producing findings, draft documents and converted files, all in server memory.
PurposeTo provide the tools you subscribe to, as described in the Terms.
Duration and retentionThe Session only. Nothing is stored after the Session ends.
Transfers to Sub-processorsHosting only, for the duration of the Session. See Annex III.
Competent supervisory authorityAs set out in section 14.2(e).

Annex II: Technical and organizational measures

These are the measures in place today. We list only measures that exist.

  1. Ephemeral processing. Uploaded files and pasted text are held in server memory for the Session only. They are not written to disk, databases or backups.
  2. No third-party analysis. Customer Personal Data is not sent to AI model providers or any third party other than the hosting provider.
  3. Encryption in transit. All traffic between your browser and our servers uses TLS.
  4. Least privilege. Only the proprietor has administrative access. Automated components have only the permissions they need. Service credentials are held in the hosting provider's secret store, not in code.
  5. Multi-factor authentication on all administrative accounts (hosting, payments, email, code repository).
  6. Logging without contents. Server logs record requests and errors, not file contents. Logs are kept for up to 30 days. Error reports, where enabled, exclude file contents.
  7. Isolation. The service runs in containers on managed cloud infrastructure. Each Session's data is held in that Session's memory and is not shared with other Sessions.
  8. Dependency updates. We track and apply security updates to the software libraries and base images we use.
  9. Backups. Backups cover only billing, subscription, acceptance-log and support records. They do not contain Customer Personal Data.
  10. Physical security. Provided by Microsoft Azure data centers under Microsoft's own certified controls. We do not operate our own data centers.
  11. Incident response. A written procedure to contain, assess and notify within the time in section 11.
  12. Payment data. Card details are handled only by Dodo Payments and never reach our systems.

Annex III: Sub-processors

The current list of Sub-processors, with purpose, location and transfer mechanism, is at https://app.baseloom.app/?view=legal&doc=subprocessors. For Customer Personal Data in the tools, the only Sub-processor is Microsoft Azure (hosting, server memory, Microsoft Azure, East US 2 (United States)). If you choose to send an attachment to support, it is also held by our support mailbox provider (Zoho Mail) until it is deleted, within 7 days of receipt. Please do not include personal data in support attachments unless it is needed to reproduce a fault.