Privacy Policy
Last updated: 20 August 2026
This policy explains what personal data BaseData collects when you use this website or deal with us, why we collect it, and the rights and choices you have. We keep data collection to a minimum and we never sell it.
- We are a business-to-business consultancy for UK social housing. We process contact enquiries and, if you sign in, account, members-area activity and optional Academy records as described below.
- We use privacy-friendly, cookieless analytics (aggregated visit and page-speed counts) and no advertising or cross-site tracking cookies.
- The NEC tools in the members area run in your browser; the files you open are not uploaded to us.
- The members area needs an account: you sign in with Google or Microsoft, and we store your name, email and an account status. That status is not a vetting step: it exists so we can withdraw access from an account if we ever need to, not to decide who gets in.
- If you use the Academy, we store your course progress, notes, test results and any certificate files you choose to upload. They are private to your account. For account deletion, an operator-controlled Academy purge prevents new Academy uploads until cleanup succeeds and the account is removed. A failed storage or provider operation leaves retry inventory and delays completion until it is resolved.
- If you use CodePad, we store your private notes and code, folder and chat structure, preferences, and attachments you choose to upload. These records are restricted to the signed-in member. Deletions can remain in retry inventory until storage-provider cleanup completes.
1. Who we are
BaseData ("we", "us", "our") is BaseData Business Intelligence Ltd, a company registered in England and Wales under company number 11751494, with its registered office at The Barn, 31 Bridge Street, Hitchin, SG5 2DF. We are the data controller for the personal data described in this policy. We are registered with the UK Information Commissioner's Office (ICO) under registration number ZC169576.
If you have any questions about this policy or your data, contact us at privacy@basedatabi.com.
2. The data we collect, and why
Contact enquiries
When you use our contact form we collect your name, email address, your organisation (optional) and the message you send. We use this only to read and respond to your enquiry and, where relevant, to take steps toward providing services you have asked about. Our lawful basis is our legitimate interest in responding to enquiries, and, where you are asking about engaging us, taking steps at your request before entering a contract. Your message reaches us as an email through Microsoft 365; it is not stored in any separate database on this site.
Calls and meetings
If we have a call or meeting with you, we may record and transcribe it, for example to capture notes, actions and an accurate record of what was discussed. We use Microsoft Teams and its Copilot assistant for this, so the recording and transcript are processed by Microsoft. We will tell you before we record and only do so with your agreement; let us know at any time if you would prefer that we did not.
NEC Housing tools (members area)
Our schema tools (the Wiki, Explorer, Path-to-SQL finder and the Business Objects extractor) run in your web
browser. When you open a Business Objects .rep or .wid file in the extractor, the file
is read and processed on your own device and is not uploaded to us. If, and only if, you choose the optional
"AI clean-up" button, the extracted SQL text (not the original file) is sent to our server and on to Anthropic's
API to be reformatted, then returned to you. We do not store it. Please do not paste confidential personal data
into that feature.
Members accounts
The members area requires an account. You sign in with Google or Microsoft, and we receive your name, email address and a provider account identifier from them. We store these, along with an account status, in our database (hosted by Neon). That status is not a vetting step: anyone who signs in gets access immediately, and we keep the status only so we can withdraw access from an account if we ever need to. The first time you sign in, we send you one welcome email introducing the tools; that is not the start of a mailing list, and we do not send you anything further of that kind. We do not store the passwords for, or long-lived access tokens from, your Google or Microsoft account. Our lawful basis is our legitimate interest in operating a restricted tool for fellow practitioners. You can ask us to delete your account at any time. This is an operator-handled request, not an automatic sign-in deletion hook. If you have Academy or CodePad data, we complete their operator-controlled purges first. Those purges prevent new writes while cleanup is in progress, and we remove the account only after their cleanup is complete. Removing the account also removes the temporary purge markers.
CodePad (private notes, code and attachments)
If you use CodePad, we store the notes and code you write, your folder and chat structure, presentation preferences, and any attachments you choose to upload. Database records are hosted by Neon and attachments are held in private Vercel Blob storage. CodePad data is restricted to the signed-in member who owns it. Other members cannot list, search, read, change, download or delete it. We use the data only to provide your private workspace. Our lawful basis is our legitimate interest in providing this members tool.
You can ask us to delete CodePad data. Deletion first moves attachment records into recoverable retry inventory, then removes the underlying private objects through a leased cleanup process. A provider failure leaves that inventory in place, so the request remains incomplete until a retry or manual resolution confirms cleanup. For a CodePad-only request, the temporary mutation marker is removed only after no inventory remains. For account deletion, an operator-controlled CodePad purge runs before the account is removed and the marker remains until that separate account removal.
Academy (course progress and evidence)
If you use the Academy, we store what you record there against your member account: which course items you have marked in progress or complete, the notes you write, the test and quiz results you log, and any certificate files you choose to upload (PDF, PNG or JPG, up to 4 MB each). The records sit in our database (hosted by Neon) and the files in private storage (Vercel Blob); the files are never public, and are served back only to you, through a signed-in request. Nobody else can see them, and we do not use them to monitor you: they are your own record of your learning. Our lawful basis is our legitimate interest in providing the course. Ask us to delete your Academy data. An operator-controlled purge runs before account removal; it does not happen automatically when an account is deleted. For an Academy-only request, the temporary upload lock is released after cleanup succeeds so the account can remain active. For account deletion, the lock remains until the account is removed. If a Blob or other provider operation fails, retry inventory remains and the deletion request stays incomplete until retry or manual resolution succeeds.
Members area activity
While you are signed in, we record which of our members tools you open, and when, against your account. We keep a daily count per tool rather than a log of every click, and we do not track you on the public site or anywhere else on the web. Unlike the website analytics below, this is tied to your name: it tells us that you, specifically, opened the Wiki on a given day. We use it to see which tools are worth building on, and to notice when someone looks stuck and could use a hand. It does not include your Academy records, which stay private as described above. Our lawful basis is our legitimate interest in running and improving a restricted tool for fellow practitioners. We keep it for 12 months. A daily scheduled cleanup removes older records. If a cleanup run fails, the records may remain until the next successful run or manual intervention, and the failure is reported for investigation. The records also go when your account is deleted.
Website analytics
We use Vercel Web Analytics and Speed Insights to understand, in aggregate, how many people visit the site and how quickly pages load. These are privacy-friendly and cookieless: they do not set tracking cookies, do not build a profile of you, and do not follow you across other websites. Our lawful basis is our legitimate interest in maintaining and improving the site.
Technical and security data
Like any website, our hosting provider automatically logs technical information when you visit, which may include your IP address, user agent, request path and response details. This is used to operate the site securely and reliably and to diagnose problems. To protect the contact form and member-access decisions from abuse, we also apply rate limits that store a keyed pseudonymous fingerprint derived from your IP address; the raw IP address is not stored in these database counters. Someone who holds the secret can reproduce the fingerprint for a candidate IP address, so the fingerprint is still treated as personal data. Expired limiter records are scheduled for daily cleanup and may remain until a failed cleanup is successfully retried or resolved manually.
Your preferences
We store your light/dark theme choice in your browser's local storage so the site remembers it between visits. This stays on your device and is not used to identify or track you.
3. Cookies and local storage
We do not use advertising or cross-site tracking cookies. The client-side storage we use is strictly functional: your theme preference (local storage) and, if you sign in to the members area, a session cookie that keeps you signed in plus a small local-storage note of your display name so the header can show you as signed in. Our analytics are cookieless. We keep these uses under review and will update this policy and our consent approach if the technologies or purposes change.
4. Who we share data with
We do not sell your personal data or share it for marketing. We rely on a small number of trusted service providers ("processors") to run the site and work with you:
- Microsoft 365 (Microsoft) - delivers the email sent from our contact form and the email we send to members, and provides Microsoft Teams and Copilot for recording and transcribing calls and meetings.
- Anthropic - reformats SQL only when you choose the optional AI clean-up in the Business Objects extractor.
- Vercel - hosts the website, private Academy certificate files and private CodePad attachments, processes server logs, and provides cookieless Web Analytics and Speed Insights.
- Neon - hosts the database that stores member accounts, daily members-area activity, Academy records, CodePad records, pseudonymous rate-limit counters and recoverable cleanup inventory.
- Google and Microsoft - provide sign-in for the members area; when you choose to sign in, they confirm your identity and share your name and email with us.
- Google Fonts (Google) - serves the site's fonts to your browser.
- jsDelivr - serves one interactive-graph script used on the home and Explorer pages.
When the fonts or that script load, your browser contacts Google and jsDelivr directly, and those providers may receive your IP address as part of the request. We may update this list as our setup changes.
5. Marketing
We do not currently send marketing emails or run a newsletter. If we introduce one in future it will be opt-in only, you will be able to unsubscribe at any time, and we will update this policy before we start.
6. International transfers
Some of these providers (for example Microsoft, Vercel, Anthropic and Google) operate outside the UK, including in the United States. Where personal data is transferred outside the UK, we rely on appropriate safeguards, such as the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or an adequacy decision where one applies.
7. How long we keep it
- Contact enquiries: 24 months after our last correspondence, unless we need them longer for a legal or contractual reason.
- Call and meeting recordings or transcripts: six months by default in Microsoft Teams.
- Member account and sign-in records: while the account remains active, then deleted on request after any Academy and CodePad purge has completed, unless we have a legal reason to keep a limited record.
- Members-area activity: 12 months, enforced by scheduled daily cleanup. A failed run is retried or resolved manually, so deletion may occur shortly after the 12-month point rather than at an exact instant.
- Academy progress, notes, tests and certificates: while you keep them or your account remains active. On deletion, an operator-controlled purge moves database records and private Blob files through a recoverable cleanup process. An Academy-only request releases its temporary upload lock after cleanup; an account-deletion request keeps the lock until account removal. If a provider operation fails, retry inventory remains and completion is delayed until retry or manual resolution confirms deletion.
- CodePad notes, code, folders, chats, preferences and attachments: while you keep them or your account remains active. On deletion, an operator-controlled purge hands attachments to recoverable cleanup inventory before removing visible records. A CodePad-only request releases its mutation marker only after cleanup; an account-deletion request keeps it until account removal. Provider failures retain retry inventory and delay completion until retry or manual resolution confirms deletion.
- Rate-limit fingerprints: through the relevant abuse-prevention window and until the next successful scheduled cleanup.
- Vercel analytics and technical logs: for the reporting or log-retention window configured under the Vercel products and account plan in use. Because those windows can vary, contact us if you need the current operational detail.
Data processed only by the in-browser NEC tools is not retained by us. We review these periods and delete or anonymise data earlier when it is no longer needed.
8. Your rights
Under UK data protection law you have the right to access the personal data we hold about you, to have it corrected or deleted, to restrict or object to how we use it, and to ask for a copy in a portable format. To exercise any of these, email us at privacy@basedatabi.com. You also have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk, though we would appreciate the chance to put things right first.
9. Changes to this policy
We may update this policy from time to time. The "last updated" date at the top of the page shows when it last changed.