Legal

Privacy Policy

Privacy Policy

Last updated /

Effective date: 25 August 2026
Version: 1.0

This Privacy Policy explains how Basilai Limited (“Basil,” “we,” “us,” or “our”) collects, uses, discloses, stores, and protects personal data in connection with Basil’s hosted software-as-a-service products, websites, applications, and related services made available through aos.work, basilos.ai, and any other location that links to this Policy (collectively, the “Service”).

This Policy is the Privacy Notice referred to in the Basil Terms of Service. It does not form part of those Terms and does not limit any right that applicable data protection law gives you. If a separate written agreement, data processing addendum, or other mandatory legal requirement applies to a particular processing activity, that document or requirement controls to the extent of any conflict.

1. Personal data we collect

Depending on how you use the Service, we may collect the following categories of personal data:

1.1 Account and organisation data

We may collect your name, email address, authentication and account details, organisation or workspace information, role, seat assignment, account preferences, and related registration information.

If you use an organisation workspace, we may also receive information about your organisation, workspace administrators, invitations, access permissions, and membership status.

1.2 User Content and instructions

We process the prompts, messages, files, instructions, configurations, connector settings, schedules, and other material that you submit to or create through the Service (“User Content”) in order to provide the requested Service.

User Content may contain personal data about you or other people. You are responsible for ensuring that you have the authority and lawful basis required to submit that personal data and instruct us to process it. Unless the Service expressly supports and appropriately protects the information, do not submit government identification numbers, payment card data, passwords, authentication secrets, health records, highly sensitive personal data, or information subject to professional secrecy or special regulatory restrictions.

1.3 Usage, technical, and security data

We may collect information generated when you access or use the Service, including device and browser information, IP address, timestamps, feature interactions, performance and error logs, service telemetry, diagnostic information, and security signals or events. We use this information to operate, secure, troubleshoot, measure, and improve the Service.

1.4 Billing and transaction data

We may collect subscription, plan, seat, invoice, transaction, payment status, tax, and billing contact information. Payments are processed by Stripe or its affiliates. Basil does not store complete payment card details; Stripe’s own terms and privacy notice apply to its processing of payment information.

1.5 Connectors and third-party services

If you connect a third-party account or service, we may process the account identifiers, permissions, authorisation information, tokens, content, and execution results necessary to establish and operate that connection, as configured or authorised by you.

The relevant third-party provider may separately collect and process personal data under its own terms and privacy notice. We do not control the processing carried out independently by that provider.

1.6 Communications and support

We may collect information you provide when you contact us, request support, submit feedback, report a security issue, exercise a privacy right, or otherwise communicate with us.

1.7 Cookies and similar technologies

We may use cookies and similar technologies necessary to provide, secure, remember, and measure the Service. Information about non-essential cookies and any consent choices is presented through the applicable cookie notice or consent interface. Where consent is required, we will not use non-essential cookies unless and until you make the appropriate choice.

2. How we use personal data

We may use personal data to:

  1. create and administer accounts, organisation workspaces, roles, invitations, and access;

  2. provide, personalise, maintain, troubleshoot, and improve the Service, including processing User Content to generate Outputs and perform requested tasks;

  3. provide Memory features, Skills, Connectors, scheduled tasks, file operations, and other features you request or enable;

  4. measure Credits, plan limits, usage, capacity, performance, and service reliability;

  5. process subscriptions, seats, invoices, refunds, taxes, fraud checks, and payment-related administration;

  6. communicate with you about the Service, your account, transactions, security, changes, and support;

  7. prevent, detect, investigate, and respond to fraud, abuse, unlawful activity, security incidents, and violations of the Terms;

  8. protect the rights, property, safety, and operations of Basil, our users, and others;

  9. comply with legal obligations, lawful requests, court orders, and regulatory requirements; and

  10. create and use aggregated, statistical, or de-identified information that does not reasonably identify you or reveal your User Content, including to analyse, maintain, secure, and improve the Service.

We will not use your User Content to train a general-purpose AI model unless you separately and expressly opt in. This does not prevent the uses of service telemetry, security signals, feedback, or aggregated or de-identified information described above.

3. Legal bases where required

Where applicable law requires a legal basis, we may process personal data on one or more of the following bases:

  • performance of a contract or steps taken at your request before entering into a contract;

  • our legitimate interests, including operating, securing, supporting, improving, and defending the Service, provided those interests are not overridden by your rights;

  • your consent, where consent is required or requested;

  • compliance with a legal obligation; or

  • protection of vital interests or another legal basis permitted by applicable law.

Where we rely on consent, you may withdraw it as permitted by law. Withdrawal does not affect processing that occurred before withdrawal or processing that can continue on another lawful basis.

4. Organisation workspaces

If you use the Service through an organisation, that organisation may control your account, workspace access, User Content, configuration, and retention settings. Organisation administrators may be able to view, manage, export, restrict, or delete workspace content and account information, subject to the organisation’s configuration and applicable law.

For organisation workspaces, Basil’s role may depend on the processing activity and the applicable agreement or law. Basil may process data to provide and secure the Service, while the organisation may independently determine how its workspace and User Content are used. Requests concerning organisation-controlled data may need to be directed first to the relevant organisation administrator.

Unless a separate written agreement states otherwise, you and the organisation are responsible for giving appropriate notices, obtaining required permissions, and ensuring that data submitted to the Service may lawfully be processed for the requested purpose.

5. When we disclose personal data

We may disclose personal data as reasonably necessary for the purposes described in this Policy:

5.1 Service providers

We may disclose personal data to vendors and service providers that help us host, store, secure, support, analyse, communicate about, bill, or otherwise operate the Service. They may process personal data only as reasonably necessary for their services and subject to appropriate contractual or legal restrictions.

5.2 Models, Skills, Connectors, and requested actions

When you request a feature that relies on a model, Skill, Connector, or other third-party service, we may send the relevant data needed to perform that request. You are responsible for reviewing permissions, recipients, configuration, scope, and consequences before authorising a Connector or automated action.

5.3 Organisation administrators and other users

We may disclose or make available workspace information to organisation administrators, invited users, recipients, or other people according to the applicable workspace settings, permissions, instructions, and actions. You are responsible for confirming that the people and destinations you select are authorised to receive the relevant data.

5.4 Corporate transactions

We may disclose personal data in connection with a merger, reorganisation, financing, acquisition, sale of assets or business, transfer to an affiliate, or similar corporate transaction, subject to applicable law.

5.5 Legal, safety, and protection purposes

We may disclose personal data where we reasonably believe it is necessary to comply with law or legal process, enforce the Terms, investigate suspected misuse, protect the Service, or protect the rights, safety, and property of Basil, our users, or others.

5.6 Aggregated or de-identified information

We may disclose information that has been aggregated or de-identified so that it does not reasonably identify you or reveal your User Content. We will not attempt to re-identify such information except where necessary to test the effectiveness of our de-identification process or where permitted by law.

6. International processing and transfers

Basil and the service providers described in this Policy may process personal data in countries other than the country in which you live or use the Service. Where applicable law requires safeguards for an international transfer, we will use a lawful transfer mechanism or another permitted safeguard. By using the Service, you acknowledge that international processing may be necessary to provide the Service, subject to those legal requirements.

7. Retention and deletion

We retain personal data only for as long as reasonably necessary for the purposes described in this Policy, including to provide the Service, maintain security, resolve disputes, enforce agreements, comply with legal obligations, and maintain reliable backups.

Retention periods vary by the type of data, the feature used, account and subscription status, legal requirements, security needs, and the settings or instructions of an organisation workspace. We do not promise indefinite storage.

Following termination, Basil will ordinarily provide up to 30 days for you to retrieve exportable User Content, subject to the exceptions and conditions in the Terms. After that period, we may delete or de-identify User Content, subject to legal retention duties, security needs, and backup cycles. Third-party providers may retain information already processed under their own notices and retention rules.

We may retain aggregated or de-identified information after deletion where it no longer reasonably identifies you or reveals your User Content.

8. Security

We use reasonable technical and organisational measures designed to protect personal data against unauthorised access, loss, misuse, alteration, and disclosure. No method of transmission, storage, or processing is completely secure, and we cannot guarantee that the Service or personal data will always be uninterrupted, error-free, or completely secure.

You are responsible for maintaining the confidentiality of your credentials, using appropriate permissions, reviewing Connector authorisations, and notifying us promptly at security@basilos.ai if you suspect unauthorised access or a security issue.

9. Your rights and choices

Depending on your location and applicable law, you may have the right to request access to, correction of, deletion of, restriction of, or portability of your personal data, or to object to particular processing. You may also have the right to withdraw consent where processing is based on consent and to lodge a complaint with a relevant data protection authority.

To exercise an applicable right, contact privacy@basilos.ai. We may need to verify your identity and may request additional information needed to locate or evaluate the request. Some rights are subject to legal exceptions, technical limitations, the rights of other people, security requirements, or the terms of an organisation workspace.

If your data is controlled by an organisation, we may refer your request to that organisation or ask you to contact its administrator first. We may retain a record of your request and its resolution as necessary to comply with law and protect our rights.

10. Children

The Service is not directed to children. You must be at least 18 years old and legally capable of entering into a binding contract to use the Service. We do not knowingly request or intentionally enable a person under 18 to create an account or use the Service.

11. Third-party services and links

The Service may contain links to or integrations with third-party products and services, including payment services, models, Skills, Connectors, and content sources. Those third parties may collect and process personal data under their own terms and privacy notices. This Policy does not govern independent third-party processing, and Basil is not responsible for third-party practices outside Basil’s reasonable control.

12. Changes to this Policy

We may update this Policy to reflect changes to the Service, law, regulation, security, third-party services, or our business. We will publish the current version through the Service or our websites and will provide additional notice where required by law. The effective date and current version will appear at the beginning of the Policy.

13. Contact us

Basilai Limited
Unit D, 12/F Seabright Plaza
9–23 Shell Street
North Point, Hong Kong

Privacy requests: privacy@basilos.ai
General support: support@basilos.ai
Security reports: security@basilos.ai

Company number: 79082001
Business registration number: 79082001

Jump to

Move enterprise AI from pilots into production.

Move enterprise AI from pilots into production.

Move enterprise AI from pilots into production.