Legal
Privacy Policy
Effective date: September 5, 2026
This Privacy Policy explains how BABA(“we,” “us,” or “our”) collects, uses, stores, and shares personal data when you use the BABA platform and related services (the “Service”). We are the data controller for the personal data described in this policy.
1. Who We Are
BABA is an HR analytics platform operated by Elise Price Consulting, LLC. If you have questions about this policy or want to exercise your privacy rights, contact us at privacy@babamethod.com.
2. Data We Collect
We collect data in the following categories:
Account and profile data
Name, email address, and authentication credentials when you create an account. Profile settings and preferences you configure in the Service.
Workforce and HR data
Information about employees, contractors, and team members entered by organization administrators — including names, job titles, departments, performance goals, project assignments, and compensation data. This data is entered by your organization; BABA processes it on behalf of your organization (which is the controller of that workforce data).
AI conversation data
Messages you send to the Ask Baba AI assistant (“conversation content”) are stored and processed to provide the Service. Conversation content may include names, HR observations, or other personal details you type. Conversations are retained for 30 days (standard plans) or up to 6 years (HIPAA plans) and are then permanently deleted. You may delete a conversation at any time.
When Ask Baba answers a question that touches data from a connected accounting, payroll, or business integration (for example Xero, QuickBooks, or Square), the relevant figures from that connection are included in the request sent to our AI sub-processor for that answer — not just the text you typed. For a provider whose terms require your explicit consent before its data may be shared this way, we ask for that consent when you connect the integration, and you may withdraw it at any time from your integration settings; Ask Baba stops including that connection’s data in AI requests as soon as you do.
AI usage and feedback
We record which AI features you use, estimated compute costs per session, and optional feedback ratings or comments you submit on AI responses. Usage records are retained until your organization is deleted.
AI working-style memory
To behave like a consistent assistant across conversations, Ask Baba may remember short facts about how you prefer to work (for example, “prefers bullet-point summaries” or “reports figures in EUR”). These memories are tied to your individual user account and are not shared with your organization — your organization’s administrators and owners cannot see them. You can view, edit, and delete your remembered facts at any time from your account settings. They are retained until you delete them or close your account; they are not aged out on the conversation-retention schedule.
Conversation shares
If you share a conversation via a link, a snapshot or AI-generated summary of that conversation is stored and made accessible to anyone with the link until the share expires (default 90 days) or you revoke it. You can revoke a share at any time by deleting the link.
Consent records
When you choose to allow BABA staff to view a conversation to help you (for example, for support purposes), we record your explicit consent. That record is retained for compliance purposes.
Client and CRM data
If your organization uses BABA’s CRM features, contact information for your clients (name, email, phone number) and revenue data synced from Stripe are stored on your behalf. Your organization is the controller of that client data; BABA processes it as a data processor.
Document uploads
If your organization uploads contract documents or other files, those files are stored in a private storage bucket. Parsed text extracted from those documents (for AI analysis) may be sent to our AI sub-processor — see Section 5.
Email you forward to your BABA inbox
If your organization uses the Universal Inbox feature, each org gets a dedicated inbound email address. Emails you forward there — sender and subject line, message body, and any attachments (receipts, invoices, documents, notes) — are captured and routed to a review queue where a member of your organization classifies and approves where the content goes; BABA never files it automatically. Forwarded content is stored as sent — we do not open or read it beyond what our automated classifier needs to propose a destination.
Attribution and analytics data
When you visit our website, we may collect UTM parameters and referral source information to understand how users find us. We also collect product-usage events (page views, feature interactions) using pseudonymous identifiers that do not directly identify you.
Technical data
IP addresses, browser type, and error reports collected automatically when you use the Service. Error reports may incidentally contain technical context; we take measures to minimize personal data in these reports (see Section 5 — Sentry).
3. How We Use Your Data
We process personal data for the following purposes and legal bases:
- Providing the Service — to operate your account, process AI queries, surface workforce analytics, and fulfil your subscription (legal basis: contract performance, Art. 6(1)(b) GDPR).
- Improving the Service — to understand how features are used and improve them using aggregated, anonymized signals; individual message content is never used for model training without explicit consent (legal basis: legitimate interests, Art. 6(1)(f) GDPR).
- Security and fraud prevention — to detect abuse, prevent unauthorized access, and maintain audit logs (legal basis: legitimate interests, Art. 6(1)(f)).
- Legal and compliance obligations — to retain financial records, respond to data subject requests, and meet applicable legal requirements (legal basis: legal obligation, Art. 6(1)(c)).
- Communications — to send transactional notifications (account alerts, subscription updates) necessary for the Service (legal basis: contract performance).
No automated employment decisions. BABA informs human decisions — it does not make them. BABA does not make automated employment decisions; a human always reviews and acts on any insight BABA surfaces.
No use of protected-class data. BABA does not use or surface employee medical, disability, or other protected-class information for any recommendation.
4. Data Retention
We retain personal data for as long as needed to provide the Service or as required by law:
- AI conversations — retained for 30 days (standard plan) or up to 6 years (HIPAA plan), then permanently deleted. You can delete conversations at any time.
- Conversation shares — expire and are permanently deleted after 90 days (default), or immediately when you revoke them.
- Account and profile data — retained while your account is active; deleted when your organization is removed from the Service.
- Contracts and financial records — may be retained beyond an account closure when required for legal record-keeping obligations.
- Access and compliance logs — retained indefinitely as an audit trail; not subject to deletion on individual erasure requests.
- Forwarded email (Universal Inbox) — the raw email is deleted from storage once your organization has routed it (filed it as a receipt, task, document, or note), or after 30 days if never routed, whichever happens first. The classified triage record (sender, subject, and where it was routed) is retained under the same soft-archive rules as the content it produced; forwarded content classified as financial (e.g. receipts) is retained for 7 years to meet financial record-keeping obligations, consistent with our other financial records above.
5. Sub-Processors and International Transfers
We share personal data with the following sub-processors to operate the Service. Where data is transferred outside the European Economic Area (EEA), we rely on Standard Contractual Clauses (SCCs) or adequacy decisions as the transfer mechanism.
- Anthropic (Claude API)— US. Your AI conversation messages, parsed document content, and — when Ask Baba answers a data question — the relevant data pulled from your connected integrations are sent to Anthropic’s Claude API for inference. Anthropic processes this data under a Data Processing Agreement and Standard Contractual Clauses. Under our zero-retention agreement, Anthropic does not retain or train on your data beyond the duration of the request.
- Voyage AI— US. Your conversation turn text (for cross-session memory) and reference document chunk text (for search) are sent to Voyage’s embeddings API to generate the vectors that power memory and document search. Voyage processes this data under a Data Processing Agreement and Standard Contractual Clauses. As of August 6, 2026, we opted out of Voyage’s default model-training use of submitted content — data sent from that date onward is not used to train Voyage’s models and is deleted immediately after processing. Data sent before that date may remain subject to Voyage’s training use under its prior default terms.
- Supabase — EU (AWS eu-west-1 for production). Your database and file storage. Production data is hosted in Ireland, European Union.
- Sentry — EU (de.sentry.io). Error tracking. Session replays mask all on-screen text and form input before transmission. Error events use pseudonymous user IDs; no message content is included.
- Axiom — EU. Structured application logs. Logs contain pseudonymous UUIDs only; no message content is logged.
- PostHog — EU (eu.i.posthog.com). Product analytics. Events use pseudonymous identifiers; no message content is recorded.
- Amazon Web Services (SES + S3)— regional, matching your organization’s hosting region. If your organization uses the Universal Inbox feature, forwarded email is received via AWS Simple Email Service and the raw message is temporarily stored in a private Amazon S3 bucket before it is parsed and routed. AWS is already our infrastructure host; this uses the same provider for inbound email.
6. Connected Integration Providers
When you connect one of the following third-party providers, that provider’s own terms require disclosures beyond what Sections 2 and 5 already describe. This section contains those disclosures.
Stripe
If your organization connects a Stripe account, BABA accesses and uses limited Connected Account Data — including historical charges, payouts, customer references, and invoice metadata — to power revenue reporting, CRM invoicing, and related analytics features of the Service. By connecting your Stripe account, you authorize BABA to access, use, and store this Connected Account Data for these purposes for as long as the connection remains active, and you represent that you have the authority to grant this authorization for the connected business. This paragraph, together with our Terms of Service, is BABA’s Platform Provider Agreement with you under Stripe’s Connect Infrastructure Terms of Service.
Salesforce
If your organization connects Salesforce, BABA collects account, opportunity, contact, and pipeline records via the Salesforce APIs, under the authorization your administrator grants when connecting the integration. We use this data to power the CRM and pipeline features you enable, store it in our production database — hosted in the EU, see Section 5 — and share it only with the sub-processors listed in Section 5, including our AI sub-processor when Ask Baba answers a question that references it. We do not sell, rent, or otherwise share Salesforce-derived data with any other third party.
Google Workspace and Google Chat
If you connect Google Workspace (Drive, Sheets, Calendar) or Google Chat, BABA accesses only the specific files, spreadsheets, calendar events, or messages you authorize through Google’s consent screen, uses that content to power the feature you enabled (for example, importing data from a linked spreadsheet or summarizing a linked document), stores it as described in this Privacy Policy, and shares it only with the sub-processors listed in Section 5, including our AI sub-processor when Ask Baba answers a question that references it.
Limited Use disclosure: BABA’s use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Microsoft 365
If you connect Microsoft 365, BABA accesses only the data necessary for the features you enable, and deletes that data when you disconnect the integration, uninstall it, or close your account. You can review and revoke BABA’s access to your Microsoft account data at any time at account.live.com/consent/Manage or myapps.microsoft.com.
Asana
If you connect Asana, this Privacy Policy — together with our Terms of Service — is the user agreement and privacy policy governing BABA’s use of your Asana data.
Atlassian (Jira and Trello)
If you connect Jira or Trello, End User Data (as Atlassian’s Developer Terms define it) that BABA syncs is stored in Ireland, European Union — the same production hosting region described in Section 5.
7. Cookies and Tracking
BABA uses essential cookies required for authentication (session tokens) and user-preference storage. We do not use advertising or cross-site tracking cookies. Analytics events (PostHog) use pseudonymous identifiers stored in browser local storage.
8. Your Rights
Depending on where you are located, you may have the following rights regarding your personal data:
- Access (Art. 15 GDPR) — request a copy of the personal data we hold about you.
- Rectification (Art. 16) — ask us to correct inaccurate data.
- Erasure (Art. 17) — ask us to delete your personal data, subject to legal retention obligations.
- Data portability (Art. 20) — receive your data in a machine-readable format.
- Restriction (Art. 18) — ask us to restrict processing in certain circumstances.
- Objection (Art. 21) — object to processing based on legitimate interests.
To exercise any of these rights, email privacy@babamethod.com. We will respond within 30 days. At MVP, requests are handled by our team directly; a self-service portal is on our roadmap. You also have the right to lodge a complaint with your local data protection authority.
9. Data Security
We implement industry-standard security measures including encryption in transit (TLS), encryption at rest, row-level security policies in our database, and strict access controls. All data access by BABA staff to user conversations is logged and requires an explicit written justification.
10. Children
The Service is not directed at individuals under 16 years of age. We do not knowingly collect personal data from children.
11. Changes to This Policy
We may update this policy from time to time. Material changes will be notified by email or in-product notice at least 30 days before they take effect. The effective date at the top of this page reflects the most recent revision.
12. Contact
Questions about this policy or your personal data? Contact us at privacy@babamethod.com.