GDPR Compliance

Last updated: March 6, 2026

1. Scope

BaselineSentinel is based in the United States (State of Texas). This page describes how we address the EU General Data Protection Regulation (GDPR) and UK GDPR for individuals in the European Economic Area (EEA) and United Kingdom who use our Service. We process personal data as necessary to provide the Service and as set out in our Privacy Policy. Users in the United States and other jurisdictions are subject to our Privacy Policy and applicable local law; certain GDPR rights may not apply outside the EEA/UK.

2. Legal Basis

We process your data on the basis of: (a) contract—to perform our agreement with you (e.g., to provide the Service); (b) legitimate interests—to operate, secure, and improve the Service where not overridden by your rights; (c) consent—where we ask for your consent (e.g., marketing, non-essential cookies); and (d) legal obligation—where we must comply with law.

3. Your Rights (EEA/UK)

Subject to applicable law, you may have the right to:

  • Access: Request a copy of the personal data we hold about you.
  • Rectification: Request correction of inaccurate or incomplete data.
  • Erasure: Request deletion of your data (“right to be forgotten”) where the law allows.
  • Restriction: Request that we limit how we use your data in certain circumstances.
  • Portability: Receive your data in a structured, machine-readable format where technically feasible.
  • Object: Object to processing based on legitimate interests or for direct marketing.
  • Withdraw consent: Where processing is based on consent, you may withdraw it at any time.
  • Complain: Lodge a complaint with a supervisory authority in your country (e.g., in the UK, the ICO; in the EU, your member state’s data protection authority).

To exercise these rights, contact us at [email protected]. We will respond within the timeframes required by applicable law (e.g., one month under GDPR, subject to extensions where permitted).

4. Data Transfers

We are based in the United States. If we transfer personal data from the EEA/UK to countries outside the EEA/UK (including the United States), we ensure appropriate safeguards are in place as required by GDPR, such as adequacy decisions, standard contractual clauses (SCCs), or other approved mechanisms. Details are available on request.

5. Data Protection Contact

For questions about our data protection practices, to exercise your rights, or to contact a data protection officer if we have designated one: [email protected].

6. Updates

We may update this page to reflect changes in our practices or in the law. The “Last updated” date will be revised accordingly. Continued use of the Service after changes constitutes acceptance where permitted by law.