Skip to main content
Platform Review
PricingSign in
Baseten assessment

Baseten procurement policy evidence

Only topics backed by verified findings appear below. Each row preserves the platform's exact policy words and capture provenance.

Verified procurement policy findings for Baseten
TopicPlan or tierRiskTheir wordsSource
DPA, audit rights & data residencyAll applicable tiersmediumThe proposed audit plan must describe the proposed scope, duration, and start date of the audit. Baseten will review the proposed audit plan and provide Customer with any concerns or questions (for example, any request for information that could compromise Baseten’s security, privacy, employment or other relevant policies). Baseten will work cooperatively with Customer to agree on a final audit plan. If the controls or measures to be assessed in the requested audit are addressed in a SOC 2 Type 2, ISO, NIST or similar audit report performed by a qualified third-party auditor within twelve (12) months of Customer’s audit request (“ Audit Report ”) and Baseten has confirmed in writing that there are no known material changes in the controls audited and covered by such Audit Report(s), Customer agrees to accept provision of such Audit Report(s) in lieu of requesting an audit of such controls or measures. Baseten need not give access to its premises for the purposes of such an audit or inspection: ‍ where an Audit Report is accepted in lieu of such controls or measures in accordance with Section 10.6; to any individual unless they produce reasonable evidence of their identity; to any auditor whom Baseten has not approved in advance (acting reasonably); to any individual who has not entered into a non-disclosure agreement with Baseten on terms acceptable to Baseten; outside normal business hours at those premises; or on more than one occasion in any calendar year during the term of the Agreement, except for any audits or inspections which Customer is required to carry out under Applicable Data Protection Laws or by a Supervisory Authority. Captured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow Where Customer is not established in an EU Member State, Article 3(2) of the GDPR applies and Customer has appointed an EU representative under Article 27 of the GDPR: the competent supervisory authority shall be the supervisory authority of the EU Member State in which Customer’s EU representative relevant to the processing hereunder is based (from time-to-time).Captured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow Where Customer is not established in an EU Member State, Article 3(2) of the GDPR applies, but Customer has not appointed an EU representative under Article 27 of the GDPR: the competent supervisory authority shall be the supervisory authority of the EU Member State notified in writing to Baseten’s contact point for data protection identified in Attachment 1 to Annex 2 (European Annex) to the DPA, which must be an EU Member State in which the data subjects whose personal data is transferred under these Clauses in relation to the offering of goods or services to them, or whose behavior is monitored, are located.Captured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow Name: The entity or other person who is a counterparty to the Agreement Address: Customer’s address is the address shown in the Agreement entered into by and between the Customer and Baseten; or if the Agreement does not include the address, the Customer’s principal business trading address unless otherwise notified to privacy@baseten.co . Contact Details for Data Protection: Customer’s contact details are: the contact details shown in the Agreement; orCaptured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tiersmedium Baseten, taking into account the nature of the Processing and the information available to Baseten, shall provide reasonable assistance to Customer, at Customer’s cost, with any data protection impact assessments and prior consultations with Supervisory Authorities which Customer reasonably considers to be required of it by Article 35 or Article 36 of the GDPR, in each case solely in relation to Processing of Customer Personal Data by Baseten. ‍ Except to the extent prohibited by applicable law, Customer shall be fully responsible for all time spent by Baseten (at Baseten’s then-current professional services rates) in Baseten’s provision of any cooperation and assistance provided to Customer under Paragraph 2.1, and shall on demand reimburse Baseten any such costs incurred by Baseten.Captured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow Duration of Processing / Retention Period: For the period determined in accordance with the Agreement and DPA, including Section 9 of the DPA. Transfers to (sub)processors: Transfers to Sub-Processors are as, and for the purposes, described from time to time in the Sub-Processor List.Captured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow “ Services ” means those services and activities to be supplied to or carried out by or on behalf of Baseten for Customer pursuant to the Agreement. “ Sub-Processor ” means any third party appointed by or on behalf of Baseten to Process Customer Personal Data. “ Supervisory Authority ” means any entity with the authority to enforce Applicable Data Protection Laws, including, (i) in the context of the EEA and the EU GDPR, shall have the meaning given to that term in the EU GDPR; and (ii) in the context of the UK and the UK GDPR, means the UK Information Commissioner’s Office. “ UK Transfer Addendum ” means the template Addendum B.1.0 issued by the ICO and laid before Parliament in accordance with s119A of the Data Protection Act 2018 on 2 February 2022, as it is revised under Section 18 of the Mandatory Clauses included in Part 2 thereof. Unless otherwise defined in this DPA, all capitalized terms in this DPA shall have the meaning given to them in the Agreement.Captured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow Customer Activities: Customer’s activities relevant to this DPA are the use and receipt of the Services under and in accordance with, and for the purposes anticipated and permitted in, the Agreement as part of its ongoing business operations. Role: Controller  – in respect of any Processing of Customer Personal Data in respect of which Customer is a Controller in its own right; andCaptured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow Organizational management and staff responsible for the development, implementation and maintenance of Baseten’s information security program. Captured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow The following modules of the SCCs apply in the manner set out below (having regard to the role(s) of Customer set out in Attachment 1 to Annex 2 (European Annex) to the DPA): Module Two of the SCCs applies to any EU Restricted Transfer involving Processing of Customer Personal Data in respect of which Customer is a Controller in its own right; and/or Module Three of the SCCs applies to any EU Restricted Transfer involving Processing of Customer Personal Data in respect of which Customer is itself acting as a Processor on behalf of any other person.Captured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow Baseten being ‘data importer’. Part C of Annex I to the Appendix to the SCCs is populated as below: The competent supervisory authority shall be determined as follows: Where Customer is established in an EU Member State: the competent supervisory authority shall be the supervisory authority of that EU Member State in which Customer is established.Captured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tiersmedium For the avoidance of doubt, this DPA shall not apply to Baseten’s collection, use, disclosure or other Processing of Service Data, and Service Data does not constitute Customer Personal Data.Captured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow Customer agrees that, without limiting Baseten’s obligations under Section 5 (Security), Customer is solely responsible for its use of the Services, including (a) making appropriate use of the Services to maintain a level of security appropriate to the risk in respect of the Customer Personal Data; (b) securing the account authentication credentials, systems and devices Customer uses to access the Services; (c) securing Customer’s systems and devices that Baseten uses to provide the Services; and (d) backing up Customer Personal Data. Customer shall ensure: that there is, and will be throughout the term of the Agreement, a valid legal basis for the Processing by Baseten of Customer Personal Data in accordance with this DPA and the Agreement (including, any and all instructions issued by Customer from time to time in respect of such Processing) for the purposes of all Applicable Data Protection Laws (including Article 6, Article 9(2) and/or Article 10 of the GDPR (where applicable)); and that all Data Subjects have (i) been presented with all required notices and statements (including as required by Article 12-14 of the GDPR (where applicable)); and (ii) provided all required consents, in each case (i) and (ii) relating to the Processing by Baseten of Customer Personal Data. ‍ Customer agrees that the Service, the Security Measures, and Baseten’s commitments under this DPA are adequate to meet Customer’s needs, including with respect to any security obligations of Customer under Applicable Data Protection Laws, and provide a level of security appropriate to the risk in respect of the Customer Personal Data. Captured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow Baseten shall not Process Customer Personal Data other than on Customer’s instructions or as required by applicable laws. Customer instructs Baseten to Process Customer Personal Data as necessary to provide the Services to Customer under and in accordance with the Agreement. The Parties acknowledge and agree that the details of Baseten’s Processing of Customer Personal Data (including the respective roles of the Parties relating to such Processing) are as described in Annex 1 (Data Processing Details) to the DPA.Captured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow To the extent that any Processing of Customer Personal Data under this DPA involves a UK Restricted Transfer from Customer to Baseten, the Parties shall comply with their respective obligations set out in the SCCs, which are hereby deemed to be: varied to address the requirements of the UK GDPR in accordance with UK Transfer Addendum and populated in accordance with Part 2 of Attachment 1 to Annex 2 (European Annex); and entered into by the Parties and incorporated by reference into this DPA. ‍Adoption of new transfer mechanism Baseten may on notice vary this DPA and replace the relevant SCCs with: any new form of the relevant SCCs or any replacement therefor prepared and populated accordingly (e.g., standard data protection clauses adopted by the European Commission for use specifically in respect of transfers to data importers subject to Article 3(2) of the EU GDPR); or another transfer mechanism, other than the SCCs, that enables the lawful transfer of Customer Personal Data to Baseten under this DPA in compliance with Chapter V of the GDPR. ‍Provision of full-form SCCs In respect of any given Restricted Transfer, if requested of Customer by a Supervisory Authority, Data Subject or further Controller (where applicable) – on specific written request (made to the contact details set out in Annex 1 (Data Processing Details); accompanied by suitable supporting evidence of the relevant request), Baseten shall provide Customer with an executed version of the relevant set(s) of SCCs responsive to the request made of Customer (amended and populated in accordance with Attachment 1 to Annex 2 (European Annex) in respect of the relevant Restricted Transfer) for countersignature by Customer, onward provision to the relevant requestor and/or storage to evidenceCaptured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow Sub-Processors:  When Baseten engages a Sub-Processor under these Clauses, Baseten shall enter into a binding contractual arrangement with such Sub-Processor that imposes upon them data protection obligations which, in substance, meet or exceed the relevant standards required under these Clauses and the DPA – including in respect of: applicable information security measures;Captured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tiersmedium Baseten may on notice vary this DPA to the extent that (acting reasonably) it considers necessary to address the requirements of Applicable Data Protection Laws from time to time, including by varying or replacing the SCCs in the manner described in Paragraph 3.3 of Annex 2 (European Annex).Captured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow Baseten shall make available to Customer on request, such information as Baseten (acting reasonably) considers appropriate in the circumstances to demonstrate its compliance with Applicable Data Protection Laws. Subject to Sections 10.3 to 10.8, in the event that Customer (acting reasonably) is able to provide documentary evidence that the information made available by Baseten pursuant to Section 10.1 is not sufficient in the circumstances to demonstrate Baseten’s compliance with this DPA, Baseten shall allow for and contribute to audits, including on-premise inspections, by Customer or an auditor mandated by Customer in relation to the Processing of Customer Personal Data by Baseten. Customer shall give Baseten reasonable notice of any audit or inspection to be conducted under Section 10.2 (which shall in no event be less than fourteen (14) days’ notice) and shall use its best efforts (and ensure that each of its mandated auditors uses its best efforts) to avoid causing any destruction, damage, injury or disruption to Baseten’s premises, equipment, Personnel, data, and business (including any interference with the confidentiality or security of the data of Baseten’s other customers or the availability of Baseten’s services to such other customers). Prior to conducting any audit, Customer must submit a detailed proposed audit plan providing for the confidential treatment of all information exchanged in connection with the audit and any reports regarding the results or findings thereof. Captured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow In the context of any EU Restricted Transfer, the SCCs populated in accordance with Part 1 of this Attachment 1 are incorporated by reference into and form an effective part of the DPA (if and where applicable in accordance with Paragraph 3.1 of Annex 2 (European Annex) to the DPA).Captured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow For each Module of the SCCs, the following applies as and where applicable to that Module and the Clauses thereof: The optional ‘Docking Clause’ in Clause 7 is not used and the body of that Clause 7 is left intentionally blank. In Clause 9: OPTION 2: GENERAL WRITTEN AUTHORISATION applies, and the minimum time period for advance notice of the addition or replacement of Sub-Processors shall be the advance notice period set out in Section 6.3 of the DPA; and OPTION 1: SPECIFIC PRIOR AUTHORISATION is not used and that optional language is deleted; as is, therefore, Annex III to the Appendix to the SCCs. In Clause 11, the optional language is not used and is deleted. In Clause 13, all square brackets are removed and all text therein is retained. In Clause 17: OPTION 1 applies, and the Parties agree that the SCCs shall be governed by the law of Ireland in relation to any EU Restricted Transfer; and OPTION 2 is not used and that optional language is deleted. For the purposes of Clause 18, the Parties agree that any dispute arising from the SCCs in relation to any EU Restricted Transfer shall be resolved by the courts of Ireland, and Clause 18(b) is populated accordingly. In this Paragraph 3, references to “ Clauses ” are references to the Clauses of the SCCs.Captured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow The DPA applies only applies to Baseten’s Processing of Customer Personal Data under the Agreement to the extent such Customer Personal Data is subject to Applicable Data Protection Laws. Annex 2 (European Annex) to this DPA applies only if and to the extent Baseten’s Processing of Customer Personal Data under the Agreement is subject to the GDPR. Annex 3 (California Annex) to this DPA applies only if and to the extent Baseten’s Processing of Customer Personal Data under the Agreement is subject to the CCPA with respect to which Customer is a “business” (as defined in the CCPA).Captured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow Audit and risk assessment procedures designed for the purposes of periodic review and assessment of risks to Baseten.Captured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tiersmedium Nothing in this DPA shall require Baseten to furnish more information about its Sub-Processors in connection with such audits than such Sub-Processors make generally available to their customers. Nothing in this Section 10 shall be construed to obligate Baseten to breach any duty of confidentiality. Except to the extent prohibited by applicable law, Customer shall be fully responsible for all time spent by Baseten (at Baseten’s then-current professional services rates) in Baseten’s provision of any cooperation and assistance provided to Customer under this Section 10 (excluding any costs incurred in the procurement, preparation or delivery of Audit Reports to Customer), and shall on demand reimburse Baseten any such costs incurred.Captured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow Baseten, taking into account the nature of the Processing of Customer Personal Data, shall provide Customer with such assistance as may be reasonably necessary and technically feasible to assist Customer in fulfilling its obligations to respond to Data Subject Requests, to the extent required by Applicable Data Protection Laws. If Baseten receives a Data Subject Request, Customer will be responsible for responding to any such request. If required by Applicable Data Protection Laws, Baseten shall: promptly notify Customer if it receives a Data Subject Request; and not respond to any Data Subject Request, other than to advise the Data Subject to submit the request to Customer, except on the written instructions of Customer or as required by Applicable Data Protection Laws. Except to the extent prohibited by applicable law, Customer shall be fully responsible for all time spent by Baseten (at Baseten’s then-current professional services rates) for Baseten’s cooperation and assistance provided to Customer under this Section 7, and shall on demand reimburse Baseten any such costs incurred.Captured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow 2.4 Security Measures .  Baseten will implement and maintain technical and organizational measures designed to protect Customer Content in the possession or under the control of Baseten against accidental or unlawful destruction, loss, alteration, unauthorized disclosure of or access thereto as described in Annex I (the “ Security Measures ”). Baseten may update the Security Measures from time to time, so long as the updated measures do not materially decrease the overall protection of Customer Content in the possession or under the control of Baseten.  With respect to any Baseten Products & Services for which the Customer is the Hosting Party, the Customer will be solely responsible for implementing and maintaining (i) technical and organizational measures designed to prevent accidental or unlawful destruction, loss, alteration, unauthorized disclosure of or access to the Baseten Products & Services hosted by Customer; and (ii) egress for the Baseten Products & Services hosted by Customer necessary for Baseten to provide the Services. 2.5 Personal Data .  To the extent that Baseten “Processes” “Customer Personal Data” as part of the Services, the Parties shall comply with their respective obligations under the DPA (incorporated herein). The terms Processes and Customer Personal Data shall have the meanings set forth in the DPA.Captured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow (ii)  to comply with any other reasonable instructions provided by Customer in accordance with the terms of this DPA.Captured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow In the event that Customer receives a Data Subject Request under the EU GDPR and requires assistance from Baseten, Customer should email Baseten’s contact point for data protection identified in Annex 1 (Data Processing Details) to the DPA.Captured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow THIS DATA PROCESSING ADDENDUM (“DPA”)  is entered into as of the Addendum Effective Date by and between: (1) Baseten Labs, Inc., a U.S. corporation with its principal business address at 201 Spear Street, Suite 1600, San Francisco, CA 94105 (“ Baseten ”); and (2) the entity or other person (“ Customer ”) who is a counterparty to the Agreement (as defined below) into which this DPA is incorporated and forms a part, together the “ Parties ” and each a “ Party ”.Captured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow Annex I to the Appendix to the SCCs is populated with the corresponding information detailed in Annex 1 (Data Processing Details) to the DPA, with:Captured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow Where Baseten receives an instruction from Customer that, in its reasonable opinion, infringes the GDPR, Baseten shall inform Customer. Customer acknowledges and agrees that any instructions issued by Customer with regards to the Processing of Customer Personal Data by or on behalf of Baseten pursuant to or in connection with the Agreement shall be in strict compliance with the GDPR and all other applicable laws.Captured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow When complying with its transparency obligations under Clause 8.3 of the SCCs, Customer agrees that it shall not provide or otherwise make available, and shall take all appropriate steps to protect, Baseten’s and its licensors’ trade secrets, business secrets, confidential information and/or other commercially sensitive information. Where applicable, for the purposes of Clause 10(a) of Module Three of the SCCs, Customer acknowledges and agrees that there are no circumstances in which it would be appropriate for Baseten to notify any third-party controller of any Data Subject Request and that any such notification shall be the sole responsibility of Customer. For the purposes of Clause 15.1(a) of the SCCs, except to the extent prohibited by applicable law and/ or the relevant public authority, as between the Parties, Customer agrees that it shall be solely responsible for making any notifications to relevant Data Subject(s) if and as required. The terms and conditions of Section 6 of the DPA apply in relation to Baseten’s appointment and use of Sub-Processors under the SCCs. Any approval by Customer of Baseten’s appointment of a Sub- Processor that is given expressly or deemed given pursuant to that Section 6 constitutes Customer’s documented instructions to effect disclosures and onward transfers to any relevant Sub-Processors if and as required under Clause 8.8 of the SCCs. The audits described in Clauses 8.9(c) and 8.9(d) of the SCCs shall be subject to any relevant terms and conditions detailed in Section 10 of the DPA. Certification of deletion of Personal Data as described in Clauses 8.5 and 16(d) of the SCCs shall be provided only upon Customer’s written request.Captured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow Change management procedures and tracking mechanisms designed to test, approve and monitor material changes to Baseten’s technology and information assets.Captured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow In this DPA the following terms shall have the meanings set out in this Section 1, unless expressly stated otherwise: “ Addendum Effective Date ” means the effective date of the Agreement. “ Agreement ” means the Customer Agreement under which Baseten has agreed to provide services to Customer entered into by and between the Parties. “ Applicable Data Protection Laws ” means the privacy, data protection and data security laws and regulations of any jurisdiction applicable to the Processing of the relevant Customer Personal Data under the Agreement, including, without limitation, GDPR and the CCPA (as and where applicable). “ CCPA ” means the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 (“CPRA”), and any binding regulations promulgated thereunder. “ Controller ” means the entity that, alone or jointly with others, determines the purposes and means of the Processing of Personal Data, including, as applicable, any “business” as that term is defined by the CCPA. “ Customer Personal Data ” means any Personal Data comprised within Customer Content and Processed by Baseten or its Sub- Processors on behalf of Customer to perform the Services under the Agreement. “ Data Subject Request ” means the exercise by a Data Subject of its rights in accordance with Applicable Data Protection Laws in respect of Customer Personal Data and the Processing thereof. “ Data Subject ” means the identified or identifiable natural person to whom Customer Personal Data relates. Captured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow Customer’s compliance with Applicable Data Protection Laws.Captured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow System audit or event logging.Captured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow This DPA shall be incorporated into and form part of the Agreement with effect from the Addendum Effective Date. In the event of any conflict or inconsistency between: this DPA and the Agreement, this DPA shall prevail; or any SCCs entered into pursuant to Paragraph 2 of Annex 2 (European Annex) and this DPA and/or the Agreement, the SCCs shall prevail in respect of the Restricted Transfer to which they apply.Captured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow Processor  – in respect of any Processing of Customer Personal Data in respect of which Customer is itself acting as a Processor on behalf of any other person (including its affiliates if and where applicable).Captured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow In the context of any UK Restricted Transfer, the SCCs as varied by the UK Transfer Addendum and populated in accordance with Part 2 of this Attachment 1 are incorporated by reference into and form an effective part of the DPA (if and where applicable in accordance with Paragraph 3.2 of Annex 2 (European Annex) to the DPA).Captured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow 1.6 “ Customer Model Output ” means the output of any query received by the Customer Model through the Baseten Products & Services. 1.7 “Documentation” means the technical materials provided by Baseten to Customer in hard copy or electronic form describing the use and operation of the Baseten Products & Services. 1.8 “ DPA ” means the Data Processing Addendum attached hereto at Annex II. 1.9 “ Effective Date ” means the date you accept this Agreement, as set forth in the second paragraph of these Terms. 1.10 “ End User ” means a third-party that accesses or uses the Customer Model deployed through the Baseten Products & Services. 1.11 “Error” means a reproducible failure of the Baseten Products & Services to substantially conform to the Documentation. 1.12 “ Hosting Party ” means, for a particular Baseten Product & Service, the party responsible for hosting such Baseten Product & Service. 1.13 “Intellectual Property Rights” means any and all now known or hereafter existing (a) rights associated with works of authorship, including copyrights, mask work rights, and moral rights; (b) trademark or service mark rights; (c) trade secret rights; (d) patents, patent rights, and industrial property rights; (e) layout design rights, design rights, and other proprietary rights of every kind and nature other than trademarks, service marks, trade dress, and similar rights; and (f) all registrations, applications, renewals, extensions, or reissues of the foregoing, in each case in any jurisdiction throughout the world. Captured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow Change management procedures and tracking mechanisms designed to test, approve and monitor all material changes to Baseten’s technology and information assets.Captured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow Where the SCCs apply in accordance with Paragraph 3.1 of Annex 2 (European Annex) to the DPA each of the Parties is hereby deemed to have signed the SCCs at the relevant signature block in Annex I to the Appendix to the SCCs.Captured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow As from the Addendum Effective Date, Baseten will implement and maintain the Security Measures as set out in this Annex 4. Data security controls which may include segregation of data, restricted (e.g. role-based) access and monitoring, and utilization of commercially available encryption for Customer Personal Data.Captured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow To the extent that any Processing of Customer Personal Data under this DPA involves an EU Restricted Transfer from Customer to Baseten, the Parties shall comply with their respective obligations set out in the SCCs, which are hereby deemed to be: populated in accordance with Part 1 of Attachment 1 to Annex 2 (European Annex); and ‍entered into by the Parties and incorporated by reference into this DPA.Captured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow Annex II to the Appendix to the SCCs is populated as below: General: Please refer to Section 5 of the DPA and Annex 4 (Security Measures) to the DPA.Captured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow Sensitive Categories of Data, and associated additional restrictions/safeguards: Categories of sensitive data: None – as noted in Section 11.4 of the DPA, Customer agrees that Restricted Data, which includes ‘sensitive data’ (as defined in Clause 8.7 of the SCCs), must  not  be submitted to the Services. Additional safeguards for sensitive data: Captured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow Where relevant in accordance with Paragraph 3.2 of Annex 2 (European Annex) to the DPA, the SCCs also apply in the context of UK Restricted Transfers as varied by the UK Transfer Addendum in the manner described below – Part 1 to the UK Transfer Addendum. As permitted by Section 17 of the UK Transfer Addendum, the Parties agree: Tables 1, 2 and 3 to the UK Transfer Addendum are deemed populated with the corresponding details set out in Annex 1 (Data Processing Details) and the foregoing provisions of this Attachment 1 (subject to the variations effected by the Mandatory Clauses described in (b) below); and ‍ Table 4 to the UK Transfer Addendum is completed by the box labelled ‘Data Importer’ being deemed to have been ticked. Part 2 to the UK Transfer Addendum. The Parties agreed to be bound by the Mandatory Clauses of the UK Transfer Addendum. ‍ In relation to any UK Restricted Transfer to which they apply, where the context permits and requires, any reference in the DPA to the SCCs, shall be read as a reference to those SCCs as varied in the manner set out in Paragraph 1.1 of this Part 2.Captured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow shall comply with Applicable Data Protection Laws (if and as applicable in the context);  Captured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow “ Personnel ” means a person’s employees, agents, consultants or contractors. “ Process ” and inflection thereof means any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction. “ Processor ” means the entity that Processes Personal Data on behalf of the Controller, including, as applicable, any “service provider” as that term is defined by the CCPA. “ Restricted Transfer ” means the disclosure, grant of access or other transfer of Customer Personal Data to any person located in: (i) in the context of the EEA, any country or territory outside the EEA which does not benefit from an adequacy decision from the European Commission (an “ EU Restricted Transfer ”); and (ii) in the context of the UK, any country or territory outside the UK, which does not benefit from an adequacy decision from the UK Government (a “ UK Restricted Transfer ”), which would be prohibited without a legal basis under Chapter V of the GDPR. “ SCCs ” means the standard contractual clauses approved by the European Commission pursuant to implementing Decision (EU) 2021/914. “ Service Data ” means any data relating to the use, support and/or operation of the Services, which is collected directly by Baseten from and/or about users of the Services and/or Customer’s use of the Service for use for its own purposes (certain of which may constitute Personal Data). Captured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow Frequency of transfer: Ongoing – as initiated by Customer in and through its use, or use on its behalf, of the Services. Nature of the Processing: Processing operations required in order to provide the Services in accordance with the Agreement. Purpose of the Processing: Customer Personal Data will be processed:Captured 2026-06-08Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow 1. Definitions . In this Annex, the terms “business purpose”, “commercial purpose”, “personal information”, “sell”, “service provider” and “share” shall have the respective meanings given thereto in the CCPA. CCPA and other capitalized terms not defined in this Schedule are defined in the DPA.Captured 2026-06-08Open source →Finding permalink →
Data retentionAll applicable tiersmediumBaseten is not obligated to back up any Customer Content; the Customer is solely responsible for creating backup copies of any Customer Content at Customer’s sole cost and expense. If Customer processes the personal data of any third party in Customer’s use of the Services, Customer is responsible for providing legally adequate privacy notices and obtaining necessary consents for processing, storage, use and transfer of such data, and, without limitation to any other terms of this Agreement, Customer represents and warrants that Customer has provided all necessary privacy notices and obtained all necessary consents in connection with the foregoing.  Customer agrees that any use of the Baseten Products & Services contrary to or in violation of the representations and warranties of Customer in this Section 5.2 (Customer Warranty) constitutes unauthorized and improper use of the Baseten Products & Services. 5.3 Customer Responsibility for Data and Security. Customer and its Authorized Users will have access to the Customer Content and will be responsible for all changes to and/or deletions of Customer Content and the security of all passwords and other Access Protocols required in order to access the Baseten Products & Services. Customer will have the ability to export Customer Content out of the Baseten Products & Services and is encouraged to make its own back-ups of the Customer Content. Customer has the sole responsibility for the accuracy, quality, integrity, legality, reliability, and appropriateness of all Customer Content and for obtaining and maintaining the required Supported Environment. Captured 2026-06-08Open source →Finding permalink →
Data retentionAll applicable tierslow return or deletion of Customer Personal Data as and where required; and engagement of further Sub-Processors.Captured 2026-06-08Open source →Finding permalink →
Data retentionAll applicable tiersunknown Duration of Processing / Retention Period: For the period determined in accordance with the Agreement and DPA, including Section 9 of the DPA. Transfers to (sub)processors: Transfers to Sub-Processors are as, and for the purposes, described from time to time in the Sub-Processor List.Captured 2026-07-19Open source →Finding permalink →
Data retentionAll applicable tiersunknown The right to delete Personal Data.  You have the right to request the deletion of Your Personal Data, subject to certain exceptions. Once We receive and confirm Your request, We will delete (and direct Our Service Providers to delete) Your personal information from our records, unless an exception applies. We may deny Your deletion request if retaining the information is necessary for Us or Our Service Providers to:Captured 2026-07-19Open source →Finding permalink →
Data retentionAll applicable tiersunknown 11.1 Term. This Agreement will begin on the Effective Date and continue in full force and effect as long as any Order remains in effect, unless earlier terminated in accordance with the Agreement (the “Term” ). Unless otherwise stated in the applicable Order, (a) the term of an Order will begin on the Effective Date and continue in full force and effect for one (1) year, unless earlier terminated in accordance with the Agreement; and (b) the Order will automatically renew for additional terms of one (1) year unless either party gives written notice of non-renewal to the other party at least sixty (60) days prior to the expiration of the then-current term. 11.2 Termination for Breach. Either party may terminate this Agreement immediately upon notice to the other party if the other party materially breaches this Agreement, and such breach remains uncured more than thirty (30) days after receipt of written notice of such breach.  11.3 Effect of Termination. Upon termination or expiration of this Agreement for any reason: (a) all licenses granted hereunder will immediately terminate and, to the extent Customer is the Hosting Party, for the avoidance of doubt Customer shall cease hosting such Baseten Products & Services under this Agreement; (b) promptly after the effective date of termination or expiration, each party will comply with the obligations to return all Confidential Information of the other party, as set forth in Section 9 (Confidentiality); and (c) any amounts owed to Baseten under this Agreement will become immediately due and payable. Captured 2026-07-19Open source →Finding permalink →
Data retentionAll applicable tierslow Subject to Sections 9.2 and 9.3, upon the date of cessation of any Services involving the Processing of Customer Personal Data (the “ Cessation Date ”), Baseten shall promptly cease all Processing of Customer Personal Data for any purpose other than for storage or as otherwise permitted or required under this DPA. Subject to Section 9.4, to the extent technically possible in the circumstances (as determined in Baseten’s sole discretion), on written request to Baseten (to be made no later than fourteen (14) days after the Cessation Date (“ Post-cessation Storage Period ”)), Baseten shall within thirty (30) days of such request: return a complete copy of all Customer Personal Data within Baseten’s possession to Customer by secure file transfer, promptly following which Baseten shall delete or anonymize all other copies of such Customer Personal Data; or either (at its option) delete or anonymize all Customer Personal Data within Baseten’s possession. In the event that during the Post-cessation Storage Period, Customer does not instruct Baseten in writing to either delete or return Customer Personal Data pursuant to Section 9.2, Baseten shall promptly after the expiry of the Post-cessation Storage Period either (at its option) delete; or render anonymous, all Customer Personal Data then within Baseten’s possession to the fullest extent technically possible in the circumstances. Baseten may retain Customer Personal Data where permitted or required by applicable law, for such period as may be required by such applicable law, provided that Baseten shall: maintain the confidentiality of all such Customer Personal Data; and Process the Customer Personal Data only as necessary for the purpose(s) specified in the applicable law permitting or requiring such retention.  Captured 2026-06-08Open source →Finding permalink →
Data retentionAll applicable tiersunknown The Company will retain Your Personal Data only for as long as is necessary for the purposes set out in this Privacy Policy. We will retain and use Your Personal Data to the extent necessary to comply with our legal obligations (for example, if we are required to retain your data to comply with applicable laws), resolve disputes, and enforce our legal agreements and policies. The Company will also retain Usage Data for internal analysis purposes. Usage Data is generally retained for a shorter period of time, except when this data is used to strengthen the security or to improve the functionality of Our Service, or We are legally obligated to retain this data for longer time periods.Captured 2026-07-19Open source →Finding permalink →
Data retentionAll applicable tierslowSections 1 (Definitions), 3.2 (Restrictions), 3.3 (Ownership), 3.4 (Open Source Software), 3.5 (Feedback), 4 (Fees and Expenses; Payments), 5.2 (Customer Warranty), 7.2 (Disclaimer), 8 (Limitation of Liability), 9 (Confidentiality), 10 (Indemnification), 11.3 (Effect of Termination), and 12 (Miscellaneous) will survive expiration or termination of this Agreement for any reason. 11.4 Data Extraction.  For twenty (20) days after the end of the Term, as applicable, Baseten will make Customer Content available to Customer through the Baseten Products & Services on a limited basis solely for purposes of Customer retrieving Customer Content, unless Baseten is instructed by Customer to delete such data before that period expires. After such period, Baseten will discontinue all use of Customer Content and destroy all copies of Customer Content in its possession.Captured 2026-06-08Open source →Finding permalink →
Data retentionAll applicable tiersunknown Complete the transaction for which We collected the personal information, provide a good or service that You requested, take actions reasonably anticipated within the context of our ongoing business relationship with You, or otherwise perform our contract with You.Captured 2026-07-19Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersmedium With business partners:  We may share Your information with Our business partners to offer You certain products, services or promotions.Captured 2026-07-19Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersunknown If the Company is involved in a merger, acquisition or asset sale, Your Personal Data may be transferred. We will provide notice before Your Personal Data is transferred and becomes subject to a different Privacy Policy.Captured 2026-07-19Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersunknown Where relevant in accordance with Paragraph 3.2 of Annex 2 (European Annex) to the DPA, the SCCs also apply in the context of UK Restricted Transfers as varied by the UK Transfer Addendum in the manner described below – Part 1 to the UK Transfer Addendum. As permitted by Section 17 of the UK Transfer Addendum, the Parties agree: Tables 1, 2 and 3 to the UK Transfer Addendum are deemed populated with the corresponding details set out in Annex 1 (Data Processing Details) and the foregoing provisions of this Attachment 1 (subject to the variations effected by the Mandatory Clauses described in (b) below); and ‍ Table 4 to the UK Transfer Addendum is completed by the box labelled ‘Data Importer’ being deemed to have been ticked. Part 2 to the UK Transfer Addendum. The Parties agreed to be bound by the Mandatory Clauses of the UK Transfer Addendum. ‍ In relation to any UK Restricted Transfer to which they apply, where the context permits and requires, any reference in the DPA to the SCCs, shall be read as a reference to those SCCs as varied in the manner set out in Paragraph 1.1 of this Part 2.Captured 2026-07-19Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersunknown We may use or disclose and may have used or disclosed in the last twelve (12) months the following categories of personal information for business or commercial purposes:Captured 2026-07-19Open source →Finding permalink →
Subprocessors & data sharingAll applicable tierslow change, then either Party may by written notice to the other Party with immediate effect terminate the Agreement, either in whole or to the extent that it relates to the Services which require the use of the proposed Sub-Processor, as its sole and exclusive remedy. Captured 2026-06-08Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersunknown Please note that the categories listed above are those defined in the CCPA. This does not mean that all examples of that category of personal information were in fact disclosed, but reflects our good faith belief to the best of our knowledge that some of that information from the applicable category may be and may have been disclosed. When We disclose personal information for a business purpose or a commercial purpose, We enter a contract that describes the purpose and requires the recipient to both keep that personal information confidential and not use it for any purpose except performing the contract.Captured 2026-07-19Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersmedium We may share Your personal information in the following situations: With Service Providers:  We may share Your personal information with Service Providers to monitor and analyze the use of our Service, for payment processing, to contact You.Captured 2026-07-19Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersmedium Service Provider  means any natural or legal person who processes the data on behalf of the Company. It refers to third-party companies or individuals employed by the Company to facilitate the Service, to provide the Service on behalf of the Company, to perform services related to the Service or to assist the Company in analyzing how the Service is used.Captured 2026-07-19Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersmedium If Customer does not object to Baseten’s appointment of a Sub-Processor during the objection period referred to in Section 6.4, Customer shall be deemed to have approved the engagement and ongoing use of that Sub-Processor. ‍‍ Captured 2026-06-08Open source →Finding permalink →
Subprocessors & data sharingAll applicable tierslow Customer generally authorizes Baseten to appoint Sub-Processors, including the Sub-Processors listed at https://trust.baseten.co/ (or such other successor URL as may be notified to Customer from time to time) (“ Sub-Processor List”) . Baseten will ensure that each Sub-Processor shall be bound by a written agreement that includes terms which offer at least a level of protection for Customer Personal Data substantially similar to those set out in this DPA (including the Security Measures). Baseten will be liable for any breach of this DPA caused by a Sub-Processor to the extent Baseten would have been liable had such breach been caused by Baseten. Baseten shall notify Customer if it engages a new Sub-Processor at least fifteen (15) days prior to the date on which the new Sub-Processor will commence processing Customer Personal Data by updating the Sub-Processor List or by sending Customer a notification if Customer opts-in to receive such notifications in the manner made available on the Sub-processor List. Customer may object in writing to Baseten's appointment of a new Sub-Processor based on reasonable data protection concerns by emailing  privacy@baseten.co within five (5) calendar days of notice of the new Sub-Processor and the parties will discuss such concerns in good faith. If the parties are unable to reach a mutually agreeable solution, Baseten will either (a) use reasonable efforts to make available a commercially reasonable change in the provision of the Services, which avoids the use of that proposed Sub-Processor; or (b) where: (i) such a change cannot be made within thirty (30) days from Baseten’s receipt of Customer’s objection; (ii) no commercially reasonable change is available; and/or (iii) Customer declines to bear the cost of the proposedCaptured 2026-06-08Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersunknown We may use Your Personal Data to contact You with newsletters, marketing or promotional materials and other information that may be of interest to You. You may opt-out of receiving any, or all, of these communications from Us by following the unsubscribe link or instructions provided in any email We send or by contacting Us. We may use Email Marketing Service Providers to manage and send emails to You.Captured 2026-07-19Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersmedium We may share Your personal information identified in the above categories with the following categories of third parties:Captured 2026-07-19Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersunknown For business transfers:  We may share or transfer Your personal information in connection with, or during negotiations of, any merger, sale of Company assets, financing, or acquisition of all or a portion of Our business to another company.Captured 2026-07-19Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersunknown From Service Providers . For example, third-party vendors to monitor and analyze the use of our Service, third-party vendors for payment processing, or other third-party vendors that We use to provide the Service to You.Captured 2026-07-19Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersunknown Their Privacy Policy can be viewed at  https://segment.com/legal/privacy/ Captured 2026-07-19Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersunknown “ Personnel ” means a person’s employees, agents, consultants or contractors. “ Process ” and inflection thereof means any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction. “ Processor ” means the entity that Processes Personal Data on behalf of the Controller, including, as applicable, any “service provider” as that term is defined by the CCPA. “ Restricted Transfer ” means the disclosure, grant of access or other transfer of Customer Personal Data to any person located in: (i) in the context of the EEA, any country or territory outside the EEA which does not benefit from an adequacy decision from the European Commission (an “ EU Restricted Transfer ”); and (ii) in the context of the UK, any country or territory outside the UK, which does not benefit from an adequacy decision from the UK Government (a “ UK Restricted Transfer ”), which would be prohibited without a legal basis under Chapter V of the GDPR. “ SCCs ” means the standard contractual clauses approved by the European Commission pursuant to implementing Decision (EU) 2021/914. “ Service Data ” means any data relating to the use, support and/or operation of the Services, which is collected directly by Baseten from and/or about users of the Services and/or Customer’s use of the Service for use for its own purposes (certain of which may constitute Personal Data). Captured 2026-07-19Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersunknown  3.4 Open Source Software. Certain items of software may be provided to Customer with the Baseten Products & Services and are subject to “open source” or “free software” licenses ( “Open Source Software” ). Some of the Open Source Software is owned by third parties. The Open Source Software is not subject to the terms and conditions of Sections 3.1 (Baseten License Grant) or 10 (Indemnification). Instead, each item of Open Source Software is licensed under the terms of the end-user license that accompanies such Open Source Software. Nothing in this Agreement limits Customer’s rights under, or grants Customer rights that supersede, the terms and conditions of any applicable end user license for the Open Source Software. If required by any license for particular Open Source Software, Baseten makes such Open Source Software, and Baseten’s modifications to that Open Source Software, available by written request at the notice address specified below.  3.5 Feedback. Customer hereby grants to Baseten a royalty-free, worldwide, transferable, sublicensable, irrevocable, perpetual license to use or incorporate into the Services any suggestions, enhancement requests, recommendations or other feedback provided by Customer, including Authorized Users, relating to the Services. Baseten will not identify Customer as the source of any such feedback.Captured 2026-07-19Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersunknown Sub-Processors:  When Baseten engages a Sub-Processor under these Clauses, Baseten shall enter into a binding contractual arrangement with such Sub-Processor that imposes upon them data protection obligations which, in substance, meet or exceed the relevant standards required under these Clauses and the DPA – including in respect of: applicable information security measures;Captured 2026-07-19Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersunknown Their Privacy Policy can be viewed at  https://www.twilio.com/legal/privacy Captured 2026-07-19Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersunknown The security of Your Personal Data is important to Us, but remember that no method of transmission over the Internet, or method of electronic storage is 100% secure. While We strive to use commercially acceptable means to protect Your Personal Data, We cannot guarantee its absolute security.Captured 2026-07-19Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersunknown For each Module of the SCCs, the following applies as and where applicable to that Module and the Clauses thereof: The optional ‘Docking Clause’ in Clause 7 is not used and the body of that Clause 7 is left intentionally blank. In Clause 9: OPTION 2: GENERAL WRITTEN AUTHORISATION applies, and the minimum time period for advance notice of the addition or replacement of Sub-Processors shall be the advance notice period set out in Section 6.3 of the DPA; and OPTION 1: SPECIFIC PRIOR AUTHORISATION is not used and that optional language is deleted; as is, therefore, Annex III to the Appendix to the SCCs. In Clause 11, the optional language is not used and is deleted. In Clause 13, all square brackets are removed and all text therein is retained. In Clause 17: OPTION 1 applies, and the Parties agree that the SCCs shall be governed by the law of Ireland in relation to any EU Restricted Transfer; and OPTION 2 is not used and that optional language is deleted. For the purposes of Clause 18, the Parties agree that any dispute arising from the SCCs in relation to any EU Restricted Transfer shall be resolved by the courts of Ireland, and Clause 18(b) is populated accordingly. In this Paragraph 3, references to “ Clauses ” are references to the Clauses of the SCCs.Captured 2026-07-19Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersmedium The Service Providers We use may have access to Your Personal Data. These third-party vendors collect, store, use, process and transfer information about Your activity on Our Service in accordance with their Privacy Policies.Captured 2026-07-19Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersmedium Third party vendors to whom You or Your agents authorize Us to disclose Your personal information in connection with products or services We provide to YouCaptured 2026-07-19Open source →Finding permalink →
Subprocessors & data sharingAll applicable tierslow Baseten’s Obligations.‍ The business purposes and services for which Baseten is Processing personal information are for Baseten to provide the services to and on behalf of Customer as set forth in the Agreement. It is the Parties’ intent that with respect to any personal information, Baseten is a service provider. Baseten (a) acknowledges that personal information is disclosed by Customer only for the limited and specific purposes described in the Agreement; (b) shall comply with applicable obligations under the CCPA and shall provide the same level of privacy protection to personal information as is required by the CCPA; (c) agrees that Customer has the right to take reasonable and appropriate steps under Section 10 (Audit Rights) of this DPA to help ensure that Baseten’s use of personal information is consistent with Customer’s obligations under the CCPA; (d) shall notify Customer in writing of any determination made by Baseten that it can no longer meet its obligations under the CCPA; and (e) agrees that Customer has the right, upon notice, including pursuant to the preceding clause, to take reasonable and appropriate steps to stop and remediate unauthorized use of personal information. Baseten shall not (a) sell or share any personal information; (b) retain, use or disclose any personal information for any purpose other than for the business purposes specified in the Agreement, including retaining, using or disclosing the personal information for a commercial purpose other than the business purpose specified in the Agreement, or as otherwise permitted by CCPA; (c) retain, use or disclose the personal information outside of the direct business relationship between Baseten and Customer; or (d) combine personal information received pursuant to the Agreement withCaptured 2026-06-08Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersmedium With Affiliates:  We may share Your information with Our affiliates, in which case we will require those affiliates to honor this Privacy Policy. Affiliates include Our parent company and any other subsidiaries, joint venture partners or other companies that We control or that are under common control with Us.Captured 2026-07-19Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersunknown notification of Personal Data Breaches to Baseten;Captured 2026-07-19Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersunknown return or deletion of Customer Personal Data as and where required; and engagement of further Sub-Processors.Captured 2026-07-19Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersunknown This DPA shall be incorporated into and form part of the Agreement with effect from the Addendum Effective Date. In the event of any conflict or inconsistency between: this DPA and the Agreement, this DPA shall prevail; or any SCCs entered into pursuant to Paragraph 2 of Annex 2 (European Annex) and this DPA and/or the Agreement, the SCCs shall prevail in respect of the Restricted Transfer to which they apply.Captured 2026-07-19Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersunknown Name: The entity or other person who is a counterparty to the Agreement Address: Customer’s address is the address shown in the Agreement entered into by and between the Customer and Baseten; or if the Agreement does not include the address, the Customer’s principal business trading address unless otherwise notified to privacy@baseten.co . Contact Details for Data Protection: Customer’s contact details are: the contact details shown in the Agreement; orCaptured 2026-07-19Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersunknown Google Analytics is a web analytics service offered by Google that tracks and reports website traffic. Google uses the data collected to track and monitor the use of our Service. This data is shared with other Google services. Google may use the collected data to contextualize and personalize the ads of its own advertising network.Captured 2026-07-19Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersunknown You can opt-out of having made your activity on the Service available to Google Analytics by installing the Google Analytics opt-out browser add-on. The add-on prevents the Google Analytics JavaScript (ga.js, analytics.js and dc.js) from sharing information with Google Analytics about visits activity.Captured 2026-07-19Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersmedium Under California Civil Code Section 1798 (California's Shine the Light law), California residents with an established business relationship with us can request information once a year about sharing their Personal Data with third parties for the third parties' direct marketing purposes. If you'd like to request more information under the California Shine the Light law, and if You are a California resident, You can contact Us using the contact information provided below.Captured 2026-07-19Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersunknown We may use third-party Service providers to monitor and analyze the use of our Service.Captured 2026-07-19Open source →Finding permalink →

Informational only, not legal advice. Terms can change; verify every cited source and capture date during procurement review.

📢 POLICY UPDATES ALERT

AIRIN Brief

Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.