Legal
Baseworthy is a business tool bought by companies, so most of what we hold is commercial data rather than personal data. This policy covers the personal information we do handle: who signs in, who we correspond with, and what our servers log.
Effective 14 September 2026 · Further Theory, LLC, Boston, Massachusetts · legal@baseworthy.com
1.1Who this covers. This policy applies to baseworthy.com, the Baseworthy application, the waitlist, and our sales and support correspondence. It does not apply to any third-party site we link to.
1.2Controller. Baseworthy is a product of Further Theory, LLC, a Massachusetts limited liability company. For account, billing, marketing, support and website data, Further Theory is the controller (or, under United States law, the business). Contact: privacy@baseworthy.com, Further Theory, LLC, Boston, Massachusetts, United States.
1.3Processor. For the content a customer uploads into a workspace — parts, quotes, prices, suppliers, files and the analysis produced from them (“Customer Data”) — Further Theory acts as a processor (or service provider) on the customer’s instructions. The customer is the controller and decides what goes in. If you are an employee of a customer and want your data corrected or removed from a workspace, ask your workspace administrator; we will refer such requests to them. Our data processing addendum governs that processing. We provide it on request, and it forms part of any pilot or subscription agreement.
1.4Not for consumers. Baseworthy is sold to businesses and is not intended for personal, family or household use, and not for anyone under 18. We do not knowingly collect information from children and will delete it if we learn we have.
2.1Information you give us. Account and identity details (name, work email address, password credential handled by our authentication provider, company name, job title where volunteered), workspace membership and invitations, and the contents of messages you send us.
2.2Waitlist intake. When you join the waitlist we collect a work email address and whatever else you choose to send: your name, your company name, a description of what you need made, and the marketing source you arrived from. Only the email address is required. The form accepts text and nothing else, so no file or attachment reaches us through it.
2.3Customer Data. What you put into a workspace so that a request can be sourced: descriptions of what you need made, drawings, specifications, CAD files, photographs and links you upload or paste, quantities and target volumes, any existing quote you share, company context, and the correspondence and quotes that come back from suppliers. This is commercial data. It should not contain personal information beyond business-contact details, and our terms require customers not to send anything more sensitive.
2.4Usage and technical data. Server and application logs, including IP address, timestamps, pages and endpoints requested, browser and device characteristics, referring page, error traces, and records of analysis runs.
2.5Billing data. Where a subscription is paid, billing contact details and invoice records. Card details, if a card is ever used, are collected and stored by our payment processor, not by us.
2.6What we do not collect. The Service is not directed to consumers or to children, and is not designed to receive special-category data, health data, biometric data, government identifiers, financial account numbers or children’s data. Our terms require customers not to submit it, and submitting it breaches those terms. If such data reaches us it is processed only incidentally, as part of whatever a customer chose to upload, and we accept no obligation to identify or extract it beyond what the law requires.
2.7Selling and sharing. We do not sell personal information, and we do not share it for cross-context behavioural advertising, as those terms are used in United States state privacy laws. We do not buy personal information from data brokers, and we do not track you across other companies’ websites.
Where the GDPR or UK GDPR applies, our legal bases are shown in brackets.
3.1No automated decisions about you. Baseworthy uses automated processing to read sourcing requests, research manufacturers, draft and send RFQs, triage supplier replies and normalise quotes. It does not make automated decisions producing legal or similarly significant effects about individuals.
3.2Model training. We do not use Customer Data to train foundation models, and our agreements with the model providers listed on our subprocessor page prohibit them from using data we send through their business interfaces to train their models. We do use aggregated and de-identified material, as described in section 3, to improve our own prompts and methods and for the other purposes listed there.
4.1Subprocessors and vendors. We share what is necessary with the infrastructure, model, communications and business providers listed at /subprocessors, under contracts limiting them to processing on our instructions.
4.2Within your organisation. Anything you put into a workspace is visible to the other members of that workspace and to your workspace administrators. Workspaces are isolated from one another. We do not show one customer’s data to another, and we do not give any customer material from which another customer, its users, its suppliers or its prices can reasonably be identified. Aggregated and de-identified material created under section 3 identifies no one and is not restricted by this clause.
4.3Professional advisers. Lawyers, accountants, auditors and insurers, under duties of confidence.
4.4Legal and safety. Regulators, courts and law enforcement where we are legally required, or where disclosure is necessary to protect our rights, our users, or the public, or to investigate suspected fraud, abuse or a breach of our terms. Where we are legally permitted and it is reasonably practicable, we will try to notify the affected customer before responding to a request for their data; we are not obliged to challenge or delay a request, and we bear no liability for responding to one.
4.5Corporate transactions. A buyer, investor or successor in connection with a merger, financing, reorganisation, insolvency or sale of all or part of our business or assets, and their advisers, under a duty of confidence. This policy continues to apply to the transferred data until it becomes subject to a replacement policy, of which you will be given notice where the law requires it.
4.6No sale, no sharing for advertising. Further Theory does not sell personal information, does not share it for cross-context behavioural advertising, and has not done so in the preceding twelve months.
5.1The application uses strictly necessary cookies for sign-in and session security, and local storage for interface preferences. We do not run advertising cookies or third-party ad pixels. If we later add analytics, we will update this policy and, where required, ask for consent first.
5.2Do Not Track. Because we do not track users across third-party sites, we do not respond to browser Do Not Track signals. We honour opt-out preference signals such as Global Privacy Control where a state law requires it.
6.1Location. The Service is hosted on managed cloud infrastructure in the United States, and our model providers process data in the United States. If you are outside the United States, using Baseworthy involves transferring your data there.
6.2Transfer safeguards. For transfers of personal data from the European Economic Area, the United Kingdom or Switzerland, we rely on the European Commission’s Standard Contractual Clauses, with the UK Addendum where applicable, together with the technical and organisational measures described in our Data Processing Addendum. A copy is available on request.
6.3Retention. We keep personal information for as long as it is needed for the purposes described in section 3, and afterwards for as long as we require it to comply with law, to meet tax, accounting and audit obligations, to investigate or prevent abuse, and to establish, exercise or defend legal claims. Customer Data is kept while the workspace is active and deleted within thirty days of a verified deletion request or of account closure, save for backups that expire on their ordinary cycle, normally within thirty-five days. Waitlist requests are deleted on request and otherwise kept no longer than twenty-four months. Billing and tax records are kept for seven years. Aggregated and de-identified material created under section 3 is not personal information, is not subject to these periods, and may be retained indefinitely.
In plain English
Email privacy@baseworthy.com and ask us to delete your data. We will verify the request, act on it within the period the law gives us, and tell you if an exemption means we have to keep something. Where the data sits in a customer’s workspace we are only the processor, so we pass the request to that customer.
7.1We encrypt data in transit and at rest, keep each customer’s workspace separate from every other, restrict staff access to the people who need it for support and operations, require multi-factor authentication for that access, log it, and review security-relevant changes before they ship. We describe our measures in more detail to a customer’s security reviewer on request, under confidence. This description is a summary of our current measures, not a warranty, a service level or a contractual commitment; measures change as the Service and the threats to it change.
7.2No system is perfectly secure. You are responsible for your credentials and for the devices and accounts your people use. Report a suspected vulnerability or compromise to security@baseworthy.com. We aim to acknowledge good-faith reports. Testing the Service without our prior written authorisation breaches our terms; where a researcher stays within a scope we have agreed in writing beforehand, we do not intend to pursue them, but nothing here is a waiver of any right or a licence to test.
7.3Incidents. If a breach affecting personal data occurs, we will notify affected customers without undue delay and within the timeframe applicable law requires, with what we then know and what we are doing about it. Where we act as a processor, notice to a customer is notice to that customer’s users, the customer is responsible for any further notification its own obligations require, and we have no obligation to notify its users, its regulators or the public directly. Notice is not an acknowledgement of fault or liability.
8.1Everyone. Where applicable data-protection law gives you the right, you may ask us for a copy of the personal information we hold about you as a controller, ask us to correct or delete it, or object to marketing. We will consider a request from anyone else, and will always honour a request to stop marketing, but we are not obliged to grant rights that the law applicable to you does not give. Write to privacy@baseworthy.com.
8.2Europe and the United Kingdom. You have rights of access, rectification, erasure, restriction, portability and objection, and the right to withdraw consent where we rely on it. You may complain to your supervisory authority, though we would rather you came to us first.
8.3California and other United States states. Depending on your state, you may have rights to know, access, correct, delete, obtain a portable copy, opt out of sale, sharing or targeted advertising, limit use of sensitive information, and appeal a refusal. We do not sell or share personal information or use it for targeted advertising, and we do not use sensitive personal information for inferring characteristics. We will not discriminate against you for exercising a right. An authorised agent may act for you with written proof of authority. To appeal a decision, reply to our response and mark it “appeal”.
8.4How we handle requests. We verify requests against information we already hold, respond within the period the applicable law requires (generally 30 or 45 days, extendable where permitted), and may decline where an exemption applies, telling you why. For Customer Data we are only a processor: we will refer your request to the customer whose workspace holds it, and assist them in answering it.
9.1Changes. We may update this policy at any time. The effective date at the top changes with it. Where a change materially reduces your rights we will take reasonable steps to give notice by email or in the application before it takes effect, except where the change is required by law or to address a security or legal risk, in which case it takes effect immediately. Continued use after the effective date means the updated policy applies.
9.2Contact. Privacy questions and rights requests: privacy@baseworthy.com. Security: security@baseworthy.com. Everything else: hello@baseworthy.com. Postal mail reaches us at Further Theory, LLC, Boston, Massachusetts, United States.
See also our Terms of Service, the subprocessor list. For a plain-language account of how what you send us is handled, write to hello@baseworthy.com.