Privacy
Workspace data is scoped to your tenant. Biometric templates are site-local special-category data that we cannot decrypt. This page states the position publicly; the architecture is what enforces it.
Controller and processor
For employee, asset, and access records held in a workspace, the customer organisation is the data controller. Baselivery processes that data on their instructions in order to provide the service, under a data processing agreement that forms part of the order form.
For the marketing website and enquiries submitted through the contact form, Baselivery is the controller. That is limited to the contact details and message you choose to send us.
Biometric data
A gait or face template capable of identifying a person is special-category data under European data protection law. We treat every embedding as special-category data, including where it only corroborates a claim already made by a credential.
Templates are generated and stored on the edge node at the site where they were enrolled. They are encrypted with a key sealed to that node's hardware root of trust. Escrow shares are held by customer custodians. Baselivery staff hold no shares and cannot decrypt a template.
A lawful basis must be recorded for the workspace before any policy carrying gait or face weight will compile. There is no configuration path that enables biometric processing without that record existing first.
- Raw video is held in a short in-memory buffer and never written to disk.
- Skeleton keypoints exist only for the duration of a gait window.
- Plaintext templates are explicitly overwritten in memory after encryption.
- Bystanders who present no credential are never embedded.
- No template, and no encrypted template, is replicated to the hosted control plane.
- Customer templates are never used to train models shipped to other customers.
What the hosted service holds
The hosted control plane holds the operational records a workspace needs: directory-sourced identities and group memberships, asset records, tickets, knowledge pages, approval history, and audit events.
For access decisions it holds session metadata, the resulting score, the matched rule, the policy revision, and the epochs in force. It does not hold images, keypoints, or templates.
Individual rights
Where your employer is the controller, requests are normally made through them, and we support them in responding. You may also use the contact form with the privacy topic and we will route the request appropriately.
- Access: an export of template metadata and full decision history. The template itself is not returned, because disclosing a raw embedding would create the risk this design exists to prevent.
- Erasure: the wrapping key for that person's templates is destroyed, rendering the stored ciphertext permanently unreadable, and the metadata record is tombstoned.
- Portability: metadata in a structured format. Templates are not portable between model versions and are not exported.
- Objection: a recorded objection forces credential-only operation where the tenant floor permits it. Where it does not, access is refused and the employer is notified, because overriding a floor is a legal decision rather than an engineering one.
- Rectification: re-enrollment creates a new template set, and the previous set is tombstoned for a dispute window before destruction.
Retention
Biometric templates are retained until offboarding plus thirty days by default. That window is configurable by the customer within a hard maximum, and exists so that a disputed decision can still be investigated.
Decision records and audit events are retained for the period the customer configures for their compliance obligations. Incident footage is not retained at all unless a hold has been authorised by a person, in which case it is stored as an encrypted clip for the duration of that hold.
Location and transfers
Where you run a dedicated single-tenant deployment, operational data resides wherever you deploy it, and residency is a property of your own infrastructure.
For the hosted service, the region is stated on your order form. Biometric templates never transfer anywhere: they stay on the edge node at the site of enrollment regardless of where the control plane runs.
Contacting us
Data protection questions and subject rights requests go through the contact form on the privacy topic. Suspected vulnerabilities go through the security topic rather than a public ticket.
Every claim here corresponds to a mechanism we will walk a security or privacy team through in detail. If something on this page does not match what you are shown, we would rather hear about it than have you assume the page was right.