Legal
Privacy Policy
Effective date: July 15, 2026 · Last updated: July 15, 2026
1. Who we are
Basient ("we") provides an LLM gateway service. For customer workload data we act as processor (GDPR) / operador (LGPD); the customer is the controller. For website and billing data we act as controller.
2. Data we process
| Category | Examples | Role |
|---|---|---|
| Workload data | prompts, completions, embeddings | Processor — only in transit; persisted only if customer disables zero-retention |
| Usage metadata | tokens, model, cost, latency, tenant id | Processor |
| Account data | name, work email, billing | Controller |
| Website data | analytics (cookieless), contact forms | Controller |
3. Why we process it (legal bases)
- Contract performance — service delivery, billing
- Legitimate interest — security, abuse prevention, product analytics
- Consent — marketing communications only
4. Retention
Zero-retention mode: workload content is never persisted. Usage metadata: 13 months. Account data: life of contract + 5 years (tax/legal).
5. International transfers
EU data stays in the EU by default (residency pinning). Where a transfer occurs: Standard Contractual Clauses (EU) / contractual safeguards per LGPD art. 33.
6. Your rights
GDPR arts. 15–22 and LGPD art. 18: access, correction, deletion, portability, objection. Write to privacy@basient.com — response within 30 days (GDPR) / 15 days (LGPD).
7. Security
See the Trust Center. Encryption in transit (TLS 1.3) and at rest (AES-256); SOC 2 Type II audited controls.
8. Subprocessors
Current list at /legal/subprocessors; 30-day advance notice of changes.
9. Contact & DPO
DPO / Encarregado: Basient Privacy Office — dpo@basient.com. Supervisory authority complaints: your local DPA / ANPD (Brazil).