Privacy Policy
Baselex sells verifiable compliance, so we hold our own data practices to the same standard: collect only what we need, say exactly why, and keep it inspectable. This notice explains how Baselex GmbH handles personal data through this website, with a focus on the “Book a demo” form. It is written to meet both the EU General Data Protection Regulation (GDPR) and the revised Swiss Federal Act on Data Protection (FADP).
1. Who we are
Baselex GmbH (“Baselex,” “we,” “us”) is the controller of the personal data described here.
- Registered office Metzerstrasse 19, 4056 Basel, Switzerland
- Commercial register UID CHE-447.173.650
- Data protection contact
2. Scope
This policy covers personal data we process as a controller through baselex.ai, including the “Book a demo” form and the sales or support correspondence that may follow.
It does not apply to data we process on behalf of a customer inside the Baselex platform. There, the customer is the controller, and their own privacy policy and our Data Processing Agreement govern that processing.
3. What we collect, and why
| You are… | What we collect | How we get it | Purpose & legal basis |
|---|---|---|---|
| Demo requester / prospective customer | Name, work email, company, role, and any optional message; later, our email and meeting correspondence. | You enter it in the form; through follow-up calls and emails. | To respond to your request and assess fit: steps taken at your request before a contract and our legitimate interest in answering B2B enquiries (GDPR Art. 6(1)(b) and (f)). If you tick the marketing box, we also contact you about products and updates on the basis of your consent (Art. 6(1)(a)), which you can withdraw at any time. |
| Website visitor | Standard request metadata (IP address, user-agent, timestamp) and strictly necessary cookies. | Automatically, when you load the site. | To deliver and secure the site and block automated abuse: our legitimate interest (Art. 6(1)(f)). See §4, Cookies. |
| Someone who contacts us | Your name, email, and the content of your message. | You email or message us. | To answer you: our legitimate interest (Art. 6(1)(f)). |
We do not sell your personal data, and we do not ask for special-category data through these channels, so please don’t include it in free-text fields.
Required fields, automated decisions, and children. Fields marked required are needed for us to act on your request; optional ones are labelled as such. We do not make decisions with legal or similarly significant effects about you by solely automated means, and we do not profile you through these channels. This website and our services are intended for businesses, not children.
4. Cookies
We use only strictly necessary cookies and similar storage: they keep the site working and secure and cannot be switched off. We use no advertising, analytics, or cross-site tracking cookies, and we load no third-party trackers, so this site does not need a cookie consent banner.
Our bot-protection provider, Cloudflare Turnstile, processes a limited set of signals to tell human visitors from automated traffic: your IP address, a TLS fingerprint, your browser user-agent, and the widget’s site key and origin. Cloudflare states these signals are strictly necessary for bot detection, that it cannot directly identify individuals from them, and that it does not use them for advertising or to train models; it may use them to improve Turnstile’s own bot detection. See the Cloudflare Turnstile Privacy Policy.
If we ever introduce analytics, we will use a privacy-first, cookieless tool and update this notice first.
5. How long we keep it
| You are… | Retention |
|---|---|
| Demo requester / prospective customer | Up to 36 months after your last active engagement, unless you become a customer (then per our customer agreement) or ask us to delete it sooner. |
| Marketing contact (you opted in) | Until you unsubscribe; we delete your details within 12 months afterwards. |
| Someone who contacts us | Up to 24 months after the enquiry is closed. |
| Website visitor | Short-lived operational and security logs kept by our infrastructure provider. |
After the period ends, we delete or irreversibly anonymise the data, unless a legal obligation requires us to keep it longer.
6. Who processes it, and where
We share personal data only with service providers (processors) that help us run the above. Our infrastructure provider is Cloudflare, which hosts this site, stores demo requests (Cloudflare D1), provides bot protection (Cloudflare Turnstile), and sends our internal lead-notification emails (Cloudflare Email Service). Cloudflare processes this data only to provide those services to us, under contract.
International transfers. We aim to keep personal data within Switzerland and the EU/EEA, and EU–Swiss transfers are permitted by mutual adequacy. Where a processor also processes data outside that area (for example, Cloudflare in the United States), we rely, where the provider is certified, on the EU–US Data Privacy Framework and its Swiss–US counterpart, and otherwise on the European Commission’s Standard Contractual Clauses together with the Swiss addendum recognised by the FDPIC. A copy of the safeguards is available on request.
7. How we protect your data
We apply appropriate technical and organisational measures, including encryption in transit and at rest, access on a need-to-know basis, and regular review of our providers. No method of transmission or storage is perfectly secure, but we work to protect your data against unauthorised access, alteration, disclosure, and loss.
8. Your rights
Under the GDPR and the Swiss FADP you can ask us to:
- access the personal data we hold about you;
- correct inaccurate or incomplete data;
- delete it, within legal limits;
- restrict or object to our processing, including direct marketing;
- receive it in a portable form, where applicable;
- withdraw consent at any time, without affecting processing already carried out.
To exercise any right, email privacy@baselex.ai. We may first ask you to confirm your identity, and we will respond within the time the law requires.
Complaints. If you believe we have mishandled your data, you may contact a supervisory authority: in Switzerland, the Federal Data Protection and Information Commissioner (FDPIC) in Bern; in the EU/EEA, your local data protection authority. We’d appreciate the chance to put things right first.
9. Changes to this policy
We may update this policy from time to time. The “Last updated” date above shows the current version, and we will take reasonable steps to flag material changes.
10. Contact
Questions, requests, or complaints about your personal data:
Baselex GmbH · privacy@baselex.ai · Metzerstrasse 19, 4056 Basel, Switzerland