Legal
Privacy Policy
Effective date: October 26, 2026
This Privacy Policy explains how BABA (“we,” “us,” or “our”) collects, uses, stores, and shares personal data when you use the BABA platform and related services (the “Service”). We are the data controller for the personal data described in this policy.
1. Who We Are
BABA is an HR (Human Resources) analytics platform operated by Elise Price Consulting, LLC. If you have questions about this policy or want to exercise your privacy rights, contact us at privacy@babamethod.com.
2. Data We Collect
We collect data in the following categories:
Account and profile data
Name, email address, and authentication credentials when you create an account. Profile settings and preferences you configure in the Service.
Workforce and HR (Human Resources) data
Information about employees, contractors, and team members entered by organization administrators, including names, job titles, departments, performance goals, project assignments, and compensation data. This data is entered by your organization; BABA processes it on behalf of your organization (which is the controller of that workforce data).
AI conversation data
Messages you send to the Ask Baba AI assistant (“conversation content”) are stored and processed to provide the Service. Conversation content may include names, HR (Human Resources) observations, or other personal details you type. Conversations are retained for 30 days and are then permanently deleted. (A longer retention window for our planned healthcare tier, Track 2, is not yet available.) You may delete a conversation at any time.
When Ask Baba answers a question that touches data from a connected accounting, payroll, or business integration (for example Xero, QuickBooks, or Square), the relevant figures from that connection are included in the request sent to our AI sub-processor for that answer, not just the text you typed. For a provider whose terms require your explicit consent before its data may be shared this way, we ask for that consent when you connect the integration, and you may withdraw it at any time from your integration settings; Ask Baba stops including that connection’s data in AI requests as soon as you do.
AI usage and feedback
We record which AI features you use, estimated compute costs per session, and optional feedback ratings or comments you submit on AI responses. Usage records are retained until your organization is deleted.
AI working-style memory
To behave like a consistent assistant across conversations, Ask Baba may remember short facts about how you prefer to work (for example, “prefers bullet-point summaries” or “reports figures in EUR”). These memories are tied to your individual user account and are not shared with your organization: your organization’s administrators and owners cannot see them. You can view, edit, and delete your remembered facts at any time from your account settings. They are retained until you delete them or close your account; they are not aged out on the conversation-retention schedule.
Conversation shares
If you share a conversation via a link, a snapshot or AI-generated summary of that conversation is stored and made accessible to anyone with the link until the share expires (default 90 days) or you revoke it. You can revoke a share at any time by deleting the link.
Consent records
When you choose to allow BABA staff to view a conversation to help you (for example, for support purposes), we record your explicit consent. That record is retained for compliance purposes.
Client and CRM (Customer Relationship Management) data
If your organization uses BABA’s CRM features, contact information for your clients (name, email, phone number) and revenue data synced from Stripe are stored on your behalf. Your organization is the controller of that client data; BABA processes it as a data processor.
Document uploads
If your organization uploads contract documents or other files, those files are stored in a private storage bucket. Parsed text extracted from those documents (for AI analysis) may be sent to our AI sub-processor. See Section 5.
Email you forward to your BABA inbox
If your organization uses the Universal Inbox feature, each org gets a dedicated inbound email address. Emails you forward there, including the sender and subject line, message body, and any attachments (receipts, invoices, documents, notes), are captured and routed to a review queue where a member of your organization classifies and approves where the content goes; BABA never files it automatically. The subject and message body are also indexed for search within your organization’s workspace, chunked and embedded by our Voyage AI sub-processor (see Section 5) so Ask Baba can search it. This happens automatically at capture, before anyone reviews or approves the item.
Attribution and analytics data
When you visit our website, we may collect UTM parameters and referral source information to understand how users find us. We also collect product-usage events (page views, feature interactions) using pseudonymous identifiers that do not directly identify you.
Technical data
IP addresses, browser type, and error reports collected automatically when you use the Service. Error reports may incidentally contain technical context; we take measures to minimize personal data in these reports (see Section 5: Sentry).
3. How We Use Your Data
We process personal data for the following purposes and legal bases:
- Providing the Service: to operate your account, process AI queries, surface workforce analytics, and fulfil your subscription (legal basis: contract performance, Art. 6(1)(b) GDPR).
- Improving the Service: to understand how features are used and improve them using aggregated, anonymized signals; individual message content is never used for model training without explicit consent (legal basis: legitimate interests, Art. 6(1)(f) GDPR).
- Security and fraud prevention:To detect abuse, prevent unauthorized access, and maintain audit logs (legal basis: legitimate interests, Art. 6(1)(f)).
- Legal and compliance obligations: to retain financial records, respond to data subject requests, and meet applicable legal requirements (legal basis: legal obligation, Art. 6(1)(c)).
- Communications: to send transactional notifications (account alerts, subscription updates) necessary for the Service (legal basis: contract performance).
No automated employment decisions. BABA informs human decisions; it does not make them. BABA does not make automated employment decisions; a human always reviews and acts on any insight BABA surfaces.
No use of protected-class data. BABA does not use or surface employee medical, disability, or other protected-class information for any recommendation.
4. Data Retention
We retain personal data for as long as needed to provide the Service or as required by law:
Backups. Our database is backed up daily and each backup is retained for up to 7 days. Deleted personal data may therefore persist in an encrypted backup for up to 7 days following deletion, after which it is permanently purged as that backup rotates out.
- AI conversations: retained for 30 days, then permanently deleted. (A longer retention window for our planned healthcare tier, Track 2, is not yet available.) You can delete conversations at any time.
- Conversation shares: expire and are permanently deleted after 90 days (default), or immediately when you revoke them.
- Account and profile data: retained while your account is active; deleted when your organization is removed from the Service.
- Contracts and financial records: may be retained beyond an account closure when required for legal record-keeping obligations.
- Access and compliance logs:Retained indefinitely as an audit trail; not subject to deletion on individual erasure requests.
- Forwarded email (Universal Inbox): the raw email is deleted from storage once your organization has routed it (filed it as a receipt, task, document, or note), or after 30 days if never routed, whichever happens first. The classified triage record (sender, subject, and where it was routed) is retained under the same soft-archive rules as the content it produced; forwarded content classified as financial (e.g. receipts) is retained for 7 years to meet financial record-keeping obligations, consistent with our other financial records above.
5. Sub-Processors and International Transfers
We share personal data with the following sub-processors to operate the Service. Where data is transferred outside the European Economic Area (EEA), we rely on Standard Contractual Clauses (SCCs) or adequacy decisions as the transfer mechanism.
- Anthropic (Claude API): US. Your AI conversation messages, parsed document content, and (when Ask Baba answers a data question) the relevant data pulled from your connected integrations are sent to Anthropic’s Claude API for inference. Anthropic processes this data under a Data Processing Agreement and Standard Contractual Clauses. Under our agreement with Anthropic, your data is not used to train Anthropic’s models. Anthropic retains this data for up to 30 days under its standard commercial retention policy; we do not currently have a zero-retention agreement with Anthropic in place.
- Voyage AI: US. Your conversation turn text (for cross-session memory) and reference document chunk text (for search) are sent to Voyage’s embeddings API to generate the vectors that power memory and document search. Voyage processes this data under a Data Processing Agreement and Standard Contractual Clauses. As of August 6, 2026, we opted out of Voyage’s default model-training use of submitted content. Data sent from that date onward is not used to train Voyage’s models and is deleted immediately after processing. Data sent before that date may remain subject to Voyage’s training use under its prior default terms.
- Supabase: EU (AWS eu-west-1 for production). Your database and file storage. Production data is hosted in Ireland, European Union.
- Sentry: EU (de.sentry.io). Error tracking. Session replays mask all on-screen text and form input before transmission. Error events use pseudonymous user IDs; no message content is included.
- Axiom: EU. Structured application logs. Logs contain pseudonymous UUIDs only; no message content is logged.
- PostHog: EU (eu.i.posthog.com). Product analytics. Events use pseudonymous identifiers; no message content is recorded.
- Amazon Web Services (SES + S3):Regional, matching your organization’s hosting region. If your organization uses the Universal Inbox feature, forwarded email is received via AWS Simple Email Service and the raw message is temporarily stored in a private Amazon S3 bucket before it is parsed and routed. AWS is already our infrastructure host; this uses the same provider for inbound email.
- Resend: US. We use Resend to send every outbound BABA email, including waitlist confirmations, sign-in links, and org invites. For a non-regulated-tier organization, this can also include invoice and proposal emails, and an internal notification to our staff when you submit product feedback, some of which carry a client’s name or other identifying content the sender places in the message. Resend processes this data under a Data Processing Agreement, incorporated automatically into its terms, and Standard Contractual Clauses, and is certified under the EU-U.S. Data Privacy Framework.
- Upstash Redis: US (development); production is provisioned in the EU alongside our database. We use Upstash to rate limit requests and to briefly cache Ask Baba tool results and accounting-integration reports, keyed to your organization. Cached data expires automatically and is not a durable store.
- Stripe (billing): US. If your organization subscribes to a paid BABA plan, we send the subscribing user’s email address (the first time we create a Stripe customer for your organization) and an opaque internal reference to that user, to Stripe to create and manage the subscription. We do not send the user’s name or your organization’s ID to Stripe. Stripe processes this data under a Data Processing Agreement, incorporated automatically into its terms, and Standard Contractual Clauses. This is separate from the Connected Account Data described in Section 6, which applies only if your organization separately connects its own Stripe account for revenue reporting.
6. Connected Integration Providers
When you connect one of the following third-party providers, that provider’s own terms require disclosures beyond what Sections 2 and 5 already describe. This section contains those disclosures.
Stripe
If your organization connects a Stripe account, BABA accesses and uses limited Connected Account Data (including historical charges, payouts, customer references, and invoice metadata) to power revenue reporting, CRM (Customer Relationship Management) invoicing, and related analytics features of the Service. By connecting your Stripe account, you authorize BABA to access, use, and store this Connected Account Data for these purposes for as long as the connection remains active, and you represent that you have the authority to grant this authorization for the connected business. This paragraph, together with our Terms of Service, is BABA’s Platform Provider Agreement with you under Stripe’s Connect Infrastructure Terms of Service.
Salesforce
If your organization connects Salesforce, BABA collects account, opportunity, contact, and pipeline records via the Salesforce APIs, under the authorization your administrator grants when connecting the integration. We use this data to power the CRM (Customer Relationship Management) and pipeline features you enable, store it in our production database (hosted in the EU, see Section 5), and share it only with the sub-processors listed in Section 5, including our AI sub-processor when Ask Baba answers a question that references it. We do not sell, rent, or otherwise share Salesforce-derived data with any other third party.
Google Workspace and Google Chat
If you connect Google Workspace (Drive, Sheets, Calendar) or Google Chat, BABA accesses only the specific files, spreadsheets, calendar events, or messages you authorize through Google’s consent screen, uses that content to power the feature you enabled (for example, importing data from a linked spreadsheet or summarizing a linked document), stores it as described in this Privacy Policy, and shares it only with the sub-processors listed in Section 5, including our AI sub-processor when Ask Baba answers a question that references it.
Limited Use disclosure: BABA’s use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Microsoft 365
If you connect Microsoft 365, BABA accesses only the data necessary for the features you enable, and deletes that data when you disconnect the integration, uninstall it, or close your account. You can review and revoke BABA’s access to your Microsoft account data at any time at account.live.com/consent/Manage or myapps.microsoft.com.
Asana
If you connect Asana, this Privacy Policy (together with our Terms of Service) is the user agreement and privacy policy governing BABA’s use of your Asana data.
Atlassian (Jira and Trello)
If you connect Jira or Trello, End User Data (as Atlassian’s Developer Terms define it) that BABA syncs is stored in Ireland, European Union, the same production hosting region described in Section 5.
7. Cookies and Tracking
BABA uses essential cookies required for authentication (session tokens) and user-preference storage. We do not use advertising or cross-site tracking cookies. Analytics events (PostHog) use pseudonymous identifiers stored in browser local storage.
8. Your Rights
Depending on where you are located, you may have the following rights regarding your personal data:
- Access (Art. 15 GDPR): request a copy of the personal data we hold about you.
- Rectification (Art. 16): ask us to correct inaccurate data.
- Erasure (Art. 17): ask us to delete your personal data, subject to legal retention obligations.
- Data portability (Art. 20):receive your data in a machine-readable format.
- Restriction (Art. 18): ask us to restrict processing in certain circumstances.
- Objection (Art. 21): object to processing based on legitimate interests.
To exercise any of these rights, email privacy@babamethod.com. We will respond within 30 days. At MVP, requests are handled by our team directly; a self-service portal is on our roadmap. You also have the right to lodge a complaint with your local data protection authority.
9. Data Security
We implement industry-standard security measures including encryption in transit (TLS), encryption at rest, row-level security policies in our database, and strict access controls. All data access by BABA staff to user conversations is logged and requires an explicit written justification.
10. Children
The Service is not directed at individuals under 16 years of age. We do not knowingly collect personal data from children.
11. Changes to This Policy
We may update this policy from time to time. Material changes will be notified by email or in-product notice at least 30 days before they take effect. The effective date at the top of this page reflects the most recent revision.
12. Contact
Questions about this policy or your personal data? Contact us at privacy@babamethod.com.