Privacy Notice
Effective 2026-09-23.
This notice explains what personal data BaseLoom handles, why, for how long, who else sees it, and the rights you have. It applies to the website and tools at https://app.baseloom.app, to support by email, to billing records, and to the email we send to advisors about our partner program.
1. Who we are and how to reach us
1.1 BaseLoom is a sole proprietorship based in India ("we", "us"). We are not a company. There is one person behind the service, the proprietor, supported by automated systems described in this notice. The proprietor's identity is verified by our payment and banking providers and is disclosed where the law requires, for example to a court, a regulator, or a customer who signs a BAA or needs it to enforce our Terms. The service is not anonymous.
1.2 Contacts:
| Purpose | Contact |
|---|---|
| Privacy questions and rights requests | privacy@baseloom.app |
| General support | support@baseloom.app |
| Legal notices | legal@baseloom.app |
| Grievance Officer (India) | Grievance Officer, BaseLoom, privacy@baseloom.app |
| EU representative (GDPR Article 27) | not yet appointed |
| UK representative (UK GDPR Article 27) | not yet appointed |
1.3 We have not appointed a data protection officer. We are not required to, given the size and nature of our processing. The proprietor handles privacy matters personally.
2. The short version
- Files you upload or text you paste into a tool are processed in server memory for your browser session and are not written to disk. When the session ends, they are gone. We cannot retrieve them later.
- Our tools run deterministic code. Your files are not sent to any AI model provider.
- We keep only what running and billing the service requires: subscription and billing records, a record that you accepted our terms, support emails, short-lived server logs, and a list of people who asked us not to email them.
- Dodo Payments is the seller of record. It takes payment under its own privacy policy. Card details never reach us.
- We do not sell personal data, share it for cross-context behavioral advertising, run advertising, or use analytics or tracking cookies.
- Support emails are answered first by an automated assistant that uses Anthropic's Claude to draft replies. You can ask for a human at any time.
3. Our role for each kind of data
3.1 Data inside your files. When your business uploads or pastes content into a tool, you decide what goes in and why. For personal data in that content (for example names of vendors, employees, patients or customers), you are the controller and we are your processor (GDPR), service provider (US state privacy laws) or data processor (India DPDP Act). Our Data Processing Addendum at https://app.baseloom.app/?view=legal&doc=dpa governs that processing and forms part of our Terms.
3.2 Everything else. For subscription, billing, support, website, legal acceptance and partner-outreach data, we are the controller (or data fiduciary in India) and this notice applies.
3.3 Payments. Dodo Payments acts as an independent controller for the payment data it collects at checkout. Its own privacy policy applies to that data.
4. What we process, why, on what legal basis, and for how long
4.1 The table below lists every category of personal data we handle as a controller. "Legal basis" refers to GDPR and UK GDPR Article 6. For other laws, see section 12.
| Data | Source | Purpose | Legal basis (Art 6) | Kept for |
|---|---|---|---|---|
| Uploaded files and pasted text | You, in a tool | To run the tool you chose (we act as your processor, see 3.1) | Processed on your instructions under the DPA | The browser session only; never written to disk |
| Name, email, billing country, company name, tax ID if given | Dodo Payments, when you subscribe | To issue and validate your license key, send service emails, answer support | 6(1)(b) contract | While subscribed, then as billing records below |
| Subscription and payment events (plan, tool, amounts, dates, status, partner referral code) | Dodo Payments webhooks | Accounting, tax records, partner commission, refunds | 6(1)(c) legal obligation (tax and accounting); 6(1)(b) contract; 6(1)(f) legitimate interest (paying partners correctly) | Up to 8 years after the end of the financial year they relate to, or longer if tax law requires |
| License-key validation result | Our license check | To confirm access to a paid tool | 6(1)(b) contract | Held in the browser session memory only |
| Terms acceptance record (time, document versions, tool id, one-way hash of the license key; no IP address) | Your click to accept | To prove what terms were agreed | 6(1)(f) legitimate interest (evidence of the contract); 6(1)(c) where law requires records | Up to the life of the subscription plus 8 years |
| Support emails, tickets and our replies | You | To answer questions, fix problems, handle refunds | 6(1)(b) contract; 6(1)(f) legitimate interest (answering non-customers) | Up to 2 years after the ticket closes |
| Attachment you choose to send with a bug report | You | To reproduce and fix the fault | 6(1)(b) contract; 6(1)(f) legitimate interest | Up to 7 days, then deleted |
| Server logs (IP address, time, page or endpoint, browser type, errors) | Your browser and our servers | Security, abuse prevention, capacity, fixing faults | 6(1)(f) legitimate interest (a secure, working service) | Up to 30 days |
| Error reports (stack trace, time, tool id, browser type; no file contents) | Our servers, if error reporting is enabled | Finding and fixing faults | 6(1)(f) legitimate interest | Up to 90 days |
| Partner referral code in a link you followed | The link | To credit the advisor who referred you | 6(1)(b) contract (with the partner); 6(1)(f) legitimate interest | With the subscription record |
| Partner (advisor) details: name, email, company, payout details held by the payout provider, commission history | The partner, the payout provider | To run the partner program and pay commission | 6(1)(b) contract; 6(1)(c) tax records | While a partner, then up to 8 years for payment records |
| Partner prospect data (see section 5) | A business contact data provider and public professional profiles | To invite advisors to the partner program | 6(1)(f) legitimate interest | See section 5 |
| Email suppression list (one-way hash of the address) | Your opt-out | To make sure we never email you again | 6(1)(c) and 6(1)(f) (honoring the opt-out) | Indefinitely, as long as we send email |
4.2 We do not ask for, and do not want, special category or sensitive personal data as a controller. If you include it in a support email, we use it only to answer you.
4.3 Where the legal basis is legitimate interest, we have weighed our interest against your rights and expectations. You can ask for a copy of that assessment and you can object (section 12).
4.4 Where the law requires a longer or shorter period than shown, we follow the law. When a period ends, we delete the data or reduce it to a form that no longer identifies you.
5. Partner prospects: people we email about the partner program
5.1 Who. We email advisors who serve businesses, such as fractional finance officers, virtual security officers, consultants, accountants and attorneys, to invite them to refer clients to our tools in return for a commission.
5.2 Source. We obtain business contact details from a business contact data provider and from public professional profiles and company websites.
5.3 What we hold. Name, business email address, job title, employer, business location (city, region, country), public professional profile link, and whether you opened, replied to or opted out of our email.
5.4 Legal basis and approach. Legitimate interest in offering a relevant business opportunity to professionals in their business capacity (GDPR 6(1)(f)). We send one invitation and at most a small number of follow-ups. Every email identifies us, gives our postal address, and has a one-click opt-out. We follow applicable email marketing law, including CAN-SPAM in the US, PECR in the UK, CASL in Canada and the Spam Act in Australia. Where a law requires prior consent for business email to your address or country, we do not email you without it.
5.5 Opting out. Use the link in any email, or reply "unsubscribe", or write to privacy@baseloom.app. We act on it promptly and in any case within 10 business days.
5.6 Retention. If you do not reply, we delete your prospect record within 6 months of the last email. If you opt out, we delete your record and keep only a one-way hash of your email address on a suppression list, so that we do not contact you again if your address appears in a future data set. The hash cannot be read back as your address, but because it can still be matched against your address we treat it as personal data and use it only for suppression.
5.7 Sending service. Outreach email is sent through Instantly, which handles prospect data only. See https://app.baseloom.app/?view=legal&doc=subprocessors.
5.8 Firm pages. Some invitations link to a page we prepare for your firm, showing which of our tools fit the clients your practice serves. The page names the firm, never a person, is kept out of search engines, and works without any cookie. We count how many times it is opened, as a number against the firm; we do not record who opened it, their IP address or their device.
5.9 Advertising to firms. We may show our partner program to a firm on LinkedIn by giving LinkedIn a list of firm names and websites. The list contains no names, email addresses or other details of people.
6. Automated support and AI
6.1 Support replies. An automated assistant reads incoming support emails and drafts replies. The drafts are written using Anthropic's Claude API. Every reply written this way says it was written by an automated assistant.
6.2 What is sent to Anthropic. The text of the support email thread, and the relevant parts of our own documentation. Your uploaded tool files are not sent. Attachments to support emails are not sent to Anthropic.
6.3 No training. We use Anthropic's commercial API. Anthropic's commercial terms state that content sent through it is not used to train its models.
6.4 A human is available. Ask for a human in your email and the proprietor will handle the matter personally.
6.5 No solely automated decisions with legal or similarly significant effects. Some refunds inside the refund window are approved automatically. That can only help you: a refund request is never refused by automation. Any refusal, and any decision about suspension or termination, is made by a person.
6.6 The tools themselves. The tools run deterministic rules and reference tables on your files. They do not use AI models and do not profile people. Their findings are for your review; you decide what to do with them.
7. Cookies
We use only strictly necessary cookies and session storage: the session state that keeps the tool working, and a session-affinity cookie set by our hosting provider so that your session stays on the same server. We use no analytics, advertising or third-party tracking cookies, and our fonts are served from our own servers. Details are at https://app.baseloom.app/?view=legal&doc=cookies.
8. Who else sees personal data
8.1 We use a small number of service providers (sub-processors) under written contracts. They may use the data only to provide their service to us. The full list, with what each receives and where, is at https://app.baseloom.app/?view=legal&doc=subprocessors. In summary:
- Microsoft Azure: hosting (the only provider that handles content of your files, in server memory).
- Dodo Payments: seller of record, checkout, invoices, tax, refunds, license keys.
- Rekomi: partner commission tracking and payouts.
- Zoho Mail: support mailbox.
- Anthropic: drafting support replies from support email text.
- Sentry: error reports without file contents, if enabled.
- Instantly and a business contact data provider: partner outreach only.
8.2 We disclose personal data to others only where the law requires it (for example a valid court order or a tax authority request), to protect our legal rights, or if the business is transferred to a new owner who takes on this notice. We will tell you about a transfer of the business in advance.
8.3 We do not sell personal data. We do not share it for cross-context behavioral advertising. We have not done so in the past 12 months.
9. International transfers
9.1 We are based in India. Our servers are in the United States (Microsoft Azure, East US 2 (United States)). Some service providers process data in the United States and other countries listed at https://app.baseloom.app/?view=legal&doc=subprocessors.
9.2 From the EU and EEA. We rely on the European Commission's Standard Contractual Clauses (Decision 2021/914), or on the EU-US Data Privacy Framework where the recipient is certified under it.
9.3 From the UK. We rely on the UK International Data Transfer Addendum to the Standard Contractual Clauses, or the UK Extension to the EU-US Data Privacy Framework where the recipient is certified.
9.4 From Switzerland. We rely on the Standard Contractual Clauses with the adjustments required under the Swiss Federal Act on Data Protection, or the Swiss-US Data Privacy Framework where the recipient is certified.
9.5 From India. Under the Digital Personal Data Protection Act 2023, personal data may be transferred outside India except to countries the Central Government restricts by notification. We do not transfer data to any restricted country.
9.6 Other countries. Where local law requires a transfer mechanism (for example Brazil, Japan, Singapore, the UAE), we rely on contractual safeguards with our providers or another basis the law allows. You can ask us for a copy of the relevant safeguards at privacy@baseloom.app.
10. Security
We protect personal data with measures suited to a small service that stores very little. Uploaded files stay in memory and are not written to disk. Traffic is encrypted in transit with TLS. Administrative accounts use multi-factor authentication and access is limited to the proprietor. Logs do not contain file contents. Payment card details never reach us. No system is perfectly secure; if a breach affects you, we will tell you and the authorities as the law requires. More at https://app.baseloom.app/?view=legal&doc=security.
11. Children
The service is for businesses and is not directed at anyone under 18. We do not knowingly collect personal data from children as a controller. If you believe we have, write to privacy@baseloom.app and we will delete it.
12. Your rights
12.1 Everyone. Whatever the law where you live, you can ask us what personal data we hold about you, ask for a copy, ask us to correct it, ask us to delete it, and ask us to stop emailing you. We honor these requests unless we must keep data by law (for example tax records) or need it to defend a legal claim. We will tell you if that is the reason.
12.2 Data in customer files. If your data was in a file a customer uploaded, that customer is the controller. We hold no copy after the session ends, so we normally have nothing to return or delete. Please contact the customer; we will help them respond.
12.3 EU and UK (GDPR, UK GDPR). You have the right of access, rectification, erasure, restriction of processing, data portability (for data you gave us under contract), and to object to processing based on legitimate interest, including an absolute right to object to direct marketing. You may withdraw consent at any time where we rely on it. You may complain to a supervisory authority, in particular in the country where you live or work. In the UK that is the Information Commissioner's Office. We ask that you contact us first so we can try to resolve the matter.
12.4 California and other US states. Residents of California (CCPA as amended by the CPRA) and of other states with comprehensive privacy laws (for example Colorado, Connecticut, Virginia, Utah, Texas, Oregon) may have the right to:
- know what personal information we collect, use and disclose, including the categories and specific pieces;
- delete personal information;
- correct inaccurate personal information;
- opt out of the sale or sharing of personal information, and of targeted advertising and profiling. We do not sell or share personal information, or use it for targeted advertising or profiling, so there is nothing to opt out of, but you may still ask;
- limit the use of sensitive personal information. We do not use sensitive personal information beyond the purposes the law permits;
- not be discriminated against for exercising these rights;
- appeal our decision on a request, by replying to our answer with "appeal". If we deny the appeal, you may contact your state attorney general.
Many of these laws apply only to businesses above revenue or volume thresholds that we may not meet yet. We honor these rights anyway.
Notice at collection (California). The categories of personal information we collect are those in section 4: identifiers (name, email, IP address), commercial information (subscriptions and payments), internet activity (server logs), professional information (job title and employer, for partner prospects), and, for customers who give it, a tax identifier. We collect them for the purposes in section 4, keep them for the periods in section 4, do not sell or share them, and disclose them to the service providers in section 8 for business purposes. We do not collect sensitive personal information as a controller except a tax identifier where a customer provides one for invoicing.
You may use an authorized agent to make a request. We may ask the agent for proof of authority and ask you to verify your identity directly.
12.5 India (DPDP Act 2023 and DPDP Rules 2025). You have the right to information about the personal data we process and with whom it is shared, correction, completion, updating and erasure, grievance redressal, and to nominate another person to exercise your rights if you die or become incapable. Where we rely on your consent, you may withdraw it as easily as you gave it. Write to our Grievance Officer (Grievance Officer, BaseLoom) at privacy@baseloom.app. We will respond within the period set by the DPDP Rules and in any case within 30 days. If you are not satisfied, you may complain to the Data Protection Board of India after using our grievance process.
12.6 Canada (PIPEDA). You may access and correct your personal information and withdraw consent, subject to legal and contractual limits. You may complain to the Office of the Privacy Commissioner of Canada.
12.7 Brazil (LGPD). You have the rights in Article 18 of the LGPD, including confirmation of processing, access, correction, anonymization or deletion of unnecessary data, portability, information about sharing, and review of consent. You may complain to the ANPD.
12.8 Australia (Privacy Act 1988). You may access and correct your personal information under the Australian Privacy Principles, and complain to the Office of the Australian Information Commissioner if we do not resolve your complaint.
12.9 Singapore (PDPA). You may access and correct your personal data and withdraw consent. You may complain to the Personal Data Protection Commission.
12.10 Japan (APPI). You may request disclosure, correction, suspension of use and deletion of retained personal data, and information about third-party provision and overseas transfers. You may contact the Personal Information Protection Commission.
12.11 UAE (PDPL). Where the UAE Federal Decree-Law No. 45 of 2021 applies to you, you have the rights of access, correction, erasure, restriction, portability and objection that it provides.
13. How to exercise your rights
13.1 Email privacy@baseloom.app and say which right you want to use. You do not need a special form.
13.2 Verification. We check your identity before acting, in proportion to the request. Usually we ask you to write from the email address we hold, or to confirm details that only you would know (such as the license key's last four characters or a recent invoice number). We do not ask for more information than we need, and we use what you send only to verify you.
13.3 Timing. We answer within 30 days. If a request is complex, we may extend this where the law allows (for example by up to two more months under GDPR, or 45 more days under CCPA) and will tell you why within the first 30 days.
13.4 Cost. Requests are free. We may charge a reasonable fee or decline a request that is manifestly unfounded or excessive, where the law allows, and will explain why.
14. Complaints
If you are unhappy with how we handled your data, please write to privacy@baseloom.app first. In India you can also write to our Grievance Officer. You always have the right to complain to the data protection authority where you live or work, or where the issue arose.
15. Changes to this notice
We post changes here with a new effective date. If a change materially affects how we use personal data, we email subscribers at least 30 days before it takes effect. Earlier versions are available on request.