Skip to content
BasinWright
Legal

Privacy Statement

How BasinWright handles personal data on this website, in the platform, and in the course of delivering an engagement.

Last updated 1 July 2026. This statement is provided as an example of the document structure this site's CMS produces and should be reviewed by your own counsel before publication.

Who we are

BasinWright is the controller for personal data described in the "This website" and "Recruitment" sections below. Where we operate a platform estate on behalf of a customer, that customer is the controller and BasinWright is the processor, acting on documented instructions under the data processing agreement between us.

This website

We process the following when you use basinwright.com.

Information you give us. Name, work email address, company, role, and anything you write in a contact form, a chat conversation or a demo configuration. We use it to respond to you and, where you have asked us to, to follow up about our services. Lawful basis: legitimate interests in responding to business enquiries, and consent where marketing follow-up applies.

Chat conversations. Messages exchanged with the assistant on this site are retained so we can answer follow-up questions and improve the assistant. Do not put confidential information or personal data about third parties into it.

Demo configurations. If you configure the interactive console — the industry, systems and decisions you select — that configuration is stored alongside your enquiry, because it is the most useful thing we have for preparing a relevant conversation.

Technical data. Standard server logs including IP address, user agent and requested paths, retained for security and diagnostics. We do not use advertising cookies or third-party analytics trackers on this site.

Retention: enquiry records for 24 months from last contact; chat conversations for 12 months; server logs for 90 days.

The platform

Where BasinWright operates an estate for a customer, personal data within that estate is processed on the customer's instructions under the data processing agreement.

  • Customer data is used to serve the customer's own workloads and to train the customer's own models. It is not used to train models for any other party and is not pooled across customers.
  • Sub-processing is limited to the published subprocessor register, with 30 days notice of change.
  • Data is processed in the regions the customer configures. Routes carrying a residency constraint fail rather than falling back to a non-compliant endpoint.
  • Retention within an estate is configured by the customer, and trace records are typically retained to match the underlying business record.

Data subject requests relating to platform data should be directed to the customer as controller. We support customers in fulfilling them within the timelines the agreement specifies.

Recruitment

Applications, CVs, interview notes and assessment results are processed to evaluate candidates. Lawful basis: steps prior to entering a contract, and legitimate interests in maintaining a record of hiring decisions.

Unsuccessful applicants' data is retained for 12 months so we can contact you about later roles, unless you ask us not to.

International transfers

Where personal data is transferred outside its country of origin, we rely on adequacy decisions where they exist and on standard contractual clauses otherwise, with a transfer impact assessment on file. Sovereign estates do not transfer data outside the host jurisdiction.

Your rights

Depending on your jurisdiction you may have the right to access, correct, delete, restrict or object to processing of your personal data, and to receive it in a portable form. Where we rely on consent you can withdraw it at any time.

To exercise a right, write to privacy@basinwright.com. We respond within one month and will tell you if we need longer. You also have the right to complain to your local data protection authority.

Security

Encryption in transit and at rest, role-based access control, and logged administrative access. We hold no third-party security certification at the time of writing — the Trust Centre sets out exactly which controls are implemented and where the audit programme stands.

Changes

Material changes to this statement are notified to customers in advance through the account contact, and the revision date above is updated on every change.

Contact

privacy@basinwright.com — or write to the data protection contact named in your agreement.