Privacy Policy
Last updated: 8 October 2026
This policy explains what personal data baseray processes, why, on what legal basis, who receives it, how long we keep it and how you can use your rights. It covers baseray.ai, app.baseray.ai and api.baseray.ai, our API, our MCP server and the emails we send.
baseray is a business-to-business data service. It describes every building in Romania and Czechia and the registered businesses whose registered office is at a building’s address. It is built for companies, not for consumers.
1. Who we are
The controller of your personal data is the provider of the baseray service (“baseray”, “we”, “us”).
- Privacy questions and requests: [email protected]
- General contact: [email protected]
2. Summary
- We collect what we need to run your account, bill you and keep the service secure.
- Product analytics is pseudonymous and runs on servers in the EU. We do not record sessions. We use no advertising cookies and no ad pixels.
- Building data describes buildings, not people. We do not link buildings to private individuals. We do not show who lives in a building or who holds title to it.
- Business data comes from public company registers. For sole traders this is personal data. Section 7 explains their rights, including how to remove a business from baseray.
- You can access, correct, export or delete your data. Write to [email protected]. We answer within one month.
3. Our role: controller or processor
We are the controller for:
- account, workspace, billing, analytics, log and email data about our customers and visitors;
- the building and business data we compile and publish in the app, the API, exports and public pages.
We are a processor under Article 28 GDPR only for personal data that customers put into the service themselves, such as notes, the content of lead lists and the email addresses of people they invite. For that data the customer is the controller and we act on the customer’s instructions. A Data Processing Agreement is available on request at [email protected].
4. Data we process about customers and visitors
4.1 Account
When you create an account we process your first and last name, email address, password (stored only as a one-way hash), optional phone number, language, two-factor authentication settings, and a record of your consents (terms, privacy policy, and marketing emails if you opt in). We record whether your email address is verified. For each browser session we keep the IP address, user agent and time of last activity, so you can see and end your sessions.
During onboarding we ask for your job function, how you heard about us, company size, industry, use cases and target countries. We use the answers to set up your workspace and to understand who uses baseray.
Legal basis: performing our contract with you or your company (Article 6(1)(b) GDPR). Onboarding answers and session records also rest on our legitimate interest in tailoring and securing the service (Article 6(1)(f)).
4.2 Workspace
A workspace holds its name, the company name and website, members and their roles, invitation emails, lead lists and saved buildings, API keys (stored only as hashes, so we cannot read them back), daily API usage counts, the credit ledger (which buildings were opened in full or exported, and when), and connected AI assistants (OAuth clients and tokens).
Legal basis: performing the contract (Article 6(1)(b)); enforcing plan limits and preventing abuse (Article 6(1)(f)).
4.3 Billing
Payments run through Stripe. We store your Stripe customer id, subscription, plan, invoices and, if you give it, your tax or VAT id. You enter card data directly with Stripe. It never reaches our servers.
Legal basis: performing the contract (Article 6(1)(b)) and keeping accounting and tax records as the law requires (Article 6(1)(c)).
4.4 Sign-up attribution
When you sign up we store with your account the campaign parameters of the link you arrived with (utm_source, utm_medium, utm_campaign, utm_content, utm_term), the referring website and the first page you landed on. This tells us which channels bring customers.
Legal basis: our legitimate interest in measuring our marketing (Article 6(1)(f)). You can object at any time (section 14).
4.5 Product analytics
We use PostHog Cloud EU, hosted in Frankfurt, Germany, to understand how baseray is used and what to improve. Analytics runs only once we have configured it.
What we collect: a pseudonymous user id (a one-way hash, never your email address), page views, referrer, campaign parameters, product events (for example sign-up completed, onboarding completed, list, export and credit events; checkout, trial and subscription events are sent from our servers), browser and device type, and an approximate location that PostHog derives from your IP address.
What we do not do: we do not record sessions, we do not use analytics for advertising and we do not sell analytics data.
On baseray.ai, analytics is cookieless. It sets no analytics cookies and writes nothing to your browser’s local storage. In the app, the analytics library can keep a pseudonymous identifier in your browser for signed-in use. If we switch that on, we will update this policy and ask for your consent first where the law requires it.
Legal basis: our legitimate interest in measuring and improving the service (Article 6(1)(f)). We weighed this against your interests: the data is pseudonymous, limited to how the product is used, stored in the EU and never used to make decisions about you. To object, write to [email protected] and we will exclude your account from analytics. Browser settings or extensions that block tracking scripts also stop it.
4.6 Server logs and security
Our servers log the IP address, user agent, requested path and time of each request. We use logs to run the service, find faults, enforce API limits and detect attacks.
Legal basis: our legitimate interest in a secure, working service (Article 6(1)(f)).
4.7 Emails and correspondence
We send transactional emails (email verification, password reset, invitations, billing notices) through Resend. They are part of the service. We send marketing emails only if you opted in. Every marketing email has an unsubscribe link, and you can opt out at any time in your settings. We keep sales and support correspondence to answer you and to keep a record of what was agreed.
Legal basis: contract for transactional emails (Article 6(1)(b)); consent for marketing emails (Article 6(1)(a)), which you can withdraw at any time without affecting earlier processing; legitimate interest for correspondence (Article 6(1)(f)).
5. Cookies and similar technologies
We use only cookies that are strictly necessary to provide the service. The law does not require consent for them.
| Cookie or storage | Purpose | Duration |
|---|---|---|
| Session cookie | Keeps you signed in | Until you sign out or the session expires |
| CSRF/XSRF token | Protects forms against cross-site request forgery | Browser session |
| Remember me | Keeps you signed in on this device, if you choose it | Up to 400 days |
| Selected workspace | Opens the workspace you used last | Until changed |
| Theme and language | Remembers your display preferences | Until changed |
We use no advertising cookies and no third-party ad pixels. If we add them, we will update this policy and ask for your consent before they are set.
The map in the app comes from Google Maps Platform. To show map imagery, the 3D view and address suggestions, your browser connects to Google, which receives your IP address and the addresses you type.
6. Building and address data in the product
baseray describes buildings: footprint, height and volume (each marked as measured or estimated), floors, dwellings and entrances where on record, construction year where on record, category, existing solar panels with the date of the check, roof solar potential, and climate and hazard facts. We compile this from public building and land registers, official statistics, and open map and aerial data.
This data is about buildings, not people. We do not link buildings to private individuals. We do not show who lives in a building or who holds title to it.
An address, especially that of a family house, can still relate to an identifiable person. We treat addresses with care. We process them on the basis of our legitimate interest, and that of our customers, in understanding buildings for energy, solar, insurance, construction and sales work (Article 6(1)(f)). If you believe a building record relates to you and you want to object, write to [email protected] with the address. We will assess the request and, where your interests prevail, remove or limit the record in the product and on public pages.
7. Notice to sole traders and self-employed persons
This section is our information notice under Article 14 GDPR for natural persons whose business appears in a public company register: in Romania, for example, a PFA, II or IF; in Czechia, an OSVČ or other self-employed natural person (fyzická osoba podnikající). The name of such a business often contains the person’s name and its registered office may be their home, so this data is personal data.
7.1 What data we process
Business name, registration number (CUI in Romania, IČO in Czechia), country, registered office address, legal status, registered activity, and employee range and turnover where published. We add no private phone numbers, private email addresses or other contact data. We process no special categories of data.
7.2 Source
Public company registers and public tax records, where this data is published by law: in Romania, the trade register and public fiscal records; in Czechia, the public registers of economic subjects.
7.3 Purposes
- Letting our customers find businesses for business-to-business prospecting.
- Market analysis.
- Risk and insurance assessment of buildings.
- Showing what is registered at an address, in the app and on public pages on baseray.ai, including the public company directory by address.
A registered office shows where a business is registered. It does not mean the business occupies the building or holds title to it, and we do not present it that way.
7.4 Legal basis and balancing
We rely on legitimate interest (Article 6(1)(f) GDPR): ours in offering a business information service, and our customers’ in finding and assessing businesses. We balanced these interests against yours:
- the data is already public, published by law so that others can know who trades and where;
- it concerns you only in your business capacity;
- we add no private contact data;
- we do not profile you in a way that produces legal or similarly significant effects;
- we process no special categories of data;
- you can object at any time and we will remove your business (section 7.7).
7.5 Recipients
Our customers, through the app, the API and exports; visitors to public pages on baseray.ai; and our sub-processors (section 9).
7.6 Retention
We keep the data while it is published in the register. We remove it within 30 days after it leaves the register or after a successful objection.
7.7 Your rights and how to opt out
You have the rights listed in section 14, including the right to object under Article 21 GDPR. To remove your business from baseray, email [email protected] with its registration number (CUI or IČO). We will exclude the business from the app, the API, exports and public pages. We keep a minimal suppression record (the registration number and the date) so the business is not imported again at the next register update. We answer within one month.
7.8 Why you did not receive an individual notice
We hold data on a very large number of businesses taken from public registers, and we do not hold their contact details. Writing to each person would involve disproportionate effort, so under Article 14(5)(b) GDPR we publish this notice instead.
7.9 Customers who contact you
A customer who uses baseray to contact a business is an independent controller for its own outreach. Our terms require customers to comply with the GDPR and the laws on unsolicited communications, including Romanian Law No. 506/2004 and Czech Act No. 480/2004 Coll. If a customer contacts you, you can exercise your rights directly with that customer.
8. Legal bases at a glance
| Purpose | Legal basis (GDPR) |
|---|---|
| Creating and running your account and workspace, the API and the MCP server | Contract, Art. 6(1)(b) |
| Billing, invoices, tax and accounting records | Contract, Art. 6(1)(b); legal obligation, Art. 6(1)(c) |
| Security, logs, rate limits, abuse prevention | Legitimate interest, Art. 6(1)(f) |
| Product analytics, sign-up attribution, onboarding answers | Legitimate interest, Art. 6(1)(f) |
| Marketing emails | Consent, Art. 6(1)(a) |
| Building and business register data in the product and on public pages | Legitimate interest, Art. 6(1)(f) |
| Handling legal claims and requests from authorities | Legal obligation, Art. 6(1)(c); legitimate interest, Art. 6(1)(f) |
9. Sub-processors and other recipients
We use these sub-processors. Each processes personal data only on our instructions and under a data processing agreement.
| Sub-processor | Purpose | Location | Transfer safeguard |
|---|---|---|---|
| Microsoft Azure | Hosting: application cluster, databases, backups | Poland Central region, EU | Data stays in the EU |
| Cloudflare | Hosting of baseray.ai, content delivery, DNS, edge functions | Global network | EU-US Data Privacy Framework; Standard Contractual Clauses |
| Stripe (Stripe Payments Europe Ltd.) | Payments and invoicing | Ireland, EU | EU entity |
| PostHog (EU Cloud) | Product analytics, when enabled | Germany, EU | Data stays in the EU |
| Resend | Transactional email | USA | EU-US Data Privacy Framework; Standard Contractual Clauses |
| Google (Google Maps Platform) | Map imagery, 3D view and address autocomplete in the app | USA | EU-US Data Privacy Framework; Standard Contractual Clauses |
Stripe is also an independent controller for its own fraud prevention and regulatory compliance processing, under its own privacy policy.
We also disclose personal data when the law requires it (for example to tax authorities or courts), to professional advisers bound by confidentiality, and to a buyer or successor if our business is transferred, who must then honour this policy. We do not sell personal data.
10. Transfers outside the EU
Our main hosting is in the EU. Some providers are based in the USA or run global networks. Where personal data leaves the European Economic Area, we rely on the EU-US Data Privacy Framework for certified providers and on Standard Contractual Clauses approved by the European Commission. You can ask for a copy of these safeguards at [email protected].
11. AI assistants you connect
Through our MCP server you can connect an AI assistant, such as Claude or ChatGPT, after signing in with OAuth. The assistant acts with your account and receives the data you ask it to fetch. You choose the assistant. Its provider handles that data under its own terms and privacy policy, and it is not our sub-processor. You can disconnect an assistant at any time in your settings; we then revoke its tokens.
12. How long we keep data
| Data | Retention |
|---|---|
| Account data | While the account exists; deleted within 30 days after you delete the account |
| Workspace data (members, lists, API key hashes, usage, credit ledger) | Until the workspace is deleted |
| Billing records and invoices | As long as tax and accounting law requires, up to 10 years |
| Sign-up attribution | As long as the account exists |
| Analytics events | 24 months |
| Server logs | 30 days |
| Business register data | While published in the register; removed within 30 days after it leaves the register |
| Suppression records | As long as needed to honour the objection |
| Backups | Overwritten within 35 days |
You can delete your account in Settings at any time.
13. Security
- All connections to our sites and API are encrypted in transit (HTTPS/TLS).
- Passwords and API keys are stored only as one-way hashes.
- Access to production systems is limited to staff who need it, with individual accounts.
- Two-factor authentication is available for every account.
- Hosting and backups are in EU data centres.
If a personal data breach is likely to put your rights at risk, we will notify the competent supervisory authority within 72 hours of becoming aware of it and inform you where the law requires.
14. Your rights
Under the GDPR you have the right to:
- access your personal data and receive a copy;
- have inaccurate data corrected;
- have your data erased;
- restrict processing;
- receive the data you gave us in a structured, machine-readable format (portability);
- object to processing based on legitimate interest, and at any time to direct marketing;
- withdraw consent at any time, without affecting processing before the withdrawal;
- lodge a complaint with a supervisory authority (section 15).
To exercise a right, email [email protected]. We may ask you to confirm your identity, for example by writing from the email address of your account. We answer within one month. For complex or numerous requests we may extend this by two further months and will tell you why. Requests are free unless they are manifestly unfounded or excessive.
We make no decisions about you based solely on automated processing that produce legal or similarly significant effects.
15. Complaints
You can complain to the supervisory authority of the EU member state where you live, where you work or where the alleged infringement took place. For example:
- Romania: Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP), www.dataprotection.ro
- Czechia: Úřad pro ochranu osobních údajů (ÚOOÚ), www.uoou.gov.cz
We would appreciate the chance to resolve your concern first at [email protected].
16. Children
baseray is a business service and is not meant for anyone under 18. We do not knowingly collect personal data of children.
17. Changes to this policy
We will update this policy when our processing changes. For material changes we will notify customers by email or in the app before they take effect. The date at the top shows the latest version.
18. Contact
- Privacy: [email protected]
- Everything else: [email protected]