Privacy Policy
1. Who We Are
Basely Technologies Ltd is the data controller for personal data collected through the Basely platform (Connect, ContainerView, and Basely SSO). Our registered address is Durham Venture Lab, Durham University, Durham, DH1 3LE, United Kingdom.
Contact us regarding data protection at: privacy@basely.ai
This Privacy Policy is effective as of 1 January 2026 and applies to all users in the UK and European Economic Area (EEA). It is written to comply with the UK GDPR, the Data Protection Act 2018, and where applicable, the EU GDPR (Regulation 2016/679).
2. Personal Data We Collect
Account & Identity Data: Name, email address, Clerk authentication identifiers, and role (candidate or employer).
Profile Data: GitHub username and public repository data (repositories, languages, contributions, bio) retrieved via the GitHub API. LinkedIn profile URL (stored; full data extraction requires LinkedIn API access granted by you). Resume text parsed from documents you upload.
Assessment Data: Code written during ContainerView assessment sessions, execution logs, AI conversation transcripts, proctor logs (tab-switch events, idle periods), and quiz responses.
Usage & Technical Data: IP address, browser type, session identifiers, pages visited, time stamps, and error logs.
Payment Data: Subscription tier and billing history. Full payment card details are processed by Stripe and are never stored on Basely servers.
Communications Data: Emails you send to us and responses to in-platform notifications.
3. Legal Basis for Processing (UK GDPR Art. 6)
Contractual necessity (Art. 6(1)(b)): Profile creation, job matching, assessment delivery, and billing are necessary to perform our contract with you.
Legitimate interests (Art. 6(1)(f)): Platform security, fraud prevention, improving our AI matching algorithms (using aggregated and anonymised signals), and communicating product updates relevant to your use of the service.
Consent (Art. 6(1)(a)): Marketing emails and non-essential analytics cookies. You may withdraw consent at any time.
Legal obligation (Art. 6(1)(c)): Retaining financial records for HMRC compliance (6 years per UK tax law).
4. How We Use Your Data
We use your personal data to: create and maintain your account; generate AI-powered candidate-to-job matches; deliver and grade technical assessments; process subscription payments via Stripe; send transactional emails (application confirmations, invite acceptances, assessment results); improve our semantic matching models using anonymised aggregate data; detect and prevent fraud and abuse; comply with legal obligations.
We do not use your data to make solely automated decisions with legal or similarly significant effects without human review.
5. AI Processing & Third-Party Processors
Profile and assessment data is processed by AI models to generate skill verification, match scores, and feedback. We use:
Google Gemini (via Google Cloud): Text generation and embedding for skill analysis and matching. Data processed under Google's Data Processing Agreement. Google does not use API inputs to train its models.
OpenAI (fallback): Text generation where Gemini is unavailable. Data processed under OpenAI's API Data Processing Addendum. API data is not used for training.
Neon (PostgreSQL): Primary database hosting (EU/US). Data encrypted at rest and in transit.
Clerk: Authentication and identity management. Processes name, email, and session tokens.
Stripe: Payment processing. Subject to Stripe's own privacy policy and PCI-DSS compliance.
Resend: Transactional email delivery.
All third-party processors are bound by Data Processing Agreements and may not use your data for their own purposes.
6. International Data Transfers
Some processors (Google, OpenAI, Stripe) may transfer data outside the UK/EEA. Where this occurs, transfers are protected by UK International Data Transfer Agreements (IDTAs) or EU Standard Contractual Clauses (SCCs) as applicable under UK GDPR Chapter V.
7. Data Retention
Account data: Retained while your account is active and for 30 days after deletion request, then permanently erased.
Assessment data: Retained for 12 months after session completion, then deleted. Employers who commissioned the assessment retain anonymised scores for 24 months.
Financial records: Retained for 6 years per UK HMRC requirements.
AI conversation logs: Retained for 90 days for debugging, then deleted.
8. Your Rights Under UK GDPR
You have the right to: access your personal data (Art. 15); rectify inaccurate data (Art. 16); erase your data ("right to be forgotten", Art. 17); restrict processing (Art. 18); data portability in a machine-readable format (Art. 20); object to processing based on legitimate interests (Art. 21); and rights relating to automated decision-making (Art. 22).
To exercise any right, email privacy@basely.ai with your request. We will respond within 30 days (extendable by 2 months for complex requests). We may verify your identity before processing.
You have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk or call 0303 123 1113.
9. Cookies
We use essential cookies for authentication (Clerk session tokens) and preference storage. We use analytics cookies only with your consent. See our Cookie Policy for full details. You may manage cookie preferences at any time via the cookie banner.
10. Security
We implement appropriate technical and organisational measures including: TLS encryption in transit; AES-256 encryption at rest via Neon; JWT-based session authentication; role-based access controls; pgvector embeddings stored separately from raw PII; internal API secret headers on privileged endpoints.
11. Changes to This Policy
We will notify you by email and in-platform notice at least 14 days before material changes take effect. Continued use after the effective date constitutes acceptance. The current version is always available at basely.ai/privacy.