Data Processing Agreement
Last updated: October 4, 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service or other written agreement (the "Agreement") between the customer named in that agreement ("Customer") and Basepoint Labs, Inc., a Delaware corporation ("Basepoint"). It applies wherever Basepoint processes Personal Data on Customer's behalf in providing the Basepoint platform (the "Service"). Customers who need a countersigned copy can request one at hello@getbasepoint.com.
1. Definitions
- "Personal Data" means any information relating to an identified or identifiable natural person that Basepoint processes on Customer's behalf under the Agreement.
- "Data Protection Laws" means all laws that apply to the processing of Personal Data under the Agreement, including the EU General Data Protection Regulation (GDPR), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, and the California Consumer Privacy Act as amended (CCPA).
- "Subprocessor" means a third party engaged by Basepoint to process Personal Data on Customer's behalf.
- "Security Incident" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data.
- "Standard Contractual Clauses" means the clauses approved by the European Commission in Decision 2021/914, and "UK Addendum" means the International Data Transfer Addendum issued by the UK Information Commissioner.
- "Controller", "Processor", "Data Subject", and "Processing" have the meanings given in the GDPR.
2. Roles and scope
Customer is the Controller of Personal Data, or, where Customer acts for its own clients, a Processor acting on their instructions. Basepoint is a Processor. Annex 1 describes the subject matter, duration, nature, and purpose of the processing and the categories of Data Subjects and Personal Data. Basepoint may also act as an independent Controller for account, billing, and usage data it collects for its own purposes, which is covered by the Privacy Policy rather than this DPA.
3. Processing on instructions
- Basepoint processes Personal Data only on Customer's documented instructions. The Agreement, Customer's use and configuration of the Service, and any further written instructions agreed between the parties are those instructions.
- Basepoint will tell Customer if, in its opinion, an instruction infringes Data Protection Laws, and may suspend the affected processing until the instruction is confirmed or changed.
- Basepoint does not sell Personal Data, share it for cross-context behavioural advertising, or use it to train machine learning models.
4. Confidentiality
Basepoint ensures that everyone it authorizes to process Personal Data is bound by a duty of confidentiality and has access only to the extent needed to provide and support the Service.
5. Security
Basepoint implements and maintains the technical and organizational measures described in Annex 2 and at getbasepoint.com/security. Basepoint may update those measures from time to time, provided the updates do not reduce the overall level of protection.
6. Subprocessors
- Customer gives general authorization for Basepoint to engage the Subprocessors listed at getbasepoint.com/legal/subprocessors.
- Basepoint will update that list before a new Subprocessor begins processing Personal Data. Customers who subscribe to notices by email will receive at least 30 days' notice of additions.
- Customer may object to a new Subprocessor on reasonable data protection grounds within 30 days of notice. The parties will work in good faith to resolve the objection. If they cannot, Customer may terminate the affected part of the Service and receive a pro-rata refund of prepaid fees for the remainder of the term.
- Basepoint imposes data protection obligations on each Subprocessor that are no less protective than those in this DPA, and remains responsible for each Subprocessor's performance.
7. Data Subject requests
The Service lets Customer export, correct, and delete Personal Data directly. Beyond that, Basepoint will assist Customer, by appropriate technical and organizational measures and to the extent reasonable, in responding to requests from Data Subjects to exercise their rights. If Basepoint receives such a request directly, it will forward it to Customer without undue delay and will not respond itself except to confirm that the request has been passed on.
8. Security Incidents
- Basepoint will notify Customer without undue delay, and in any event within 72 hours, after becoming aware of a Security Incident affecting Customer's Personal Data.
- The notice will describe the nature of the incident, the categories and approximate number of Data Subjects and records affected, the likely consequences, and the measures taken or proposed, to the extent known, with further detail provided as it becomes available.
- Basepoint will cooperate with Customer and take reasonable steps to contain, investigate, and remedy the incident. Notice of a Security Incident is not an admission of fault or liability.
9. Assistance
Taking into account the nature of the processing and the information available to it, Basepoint will provide reasonable assistance to Customer with data protection impact assessments and prior consultations with supervisory authorities required by Data Protection Laws.
10. Audits
- Basepoint will make available the information reasonably necessary to demonstrate compliance with this DPA, including its security documentation, completed security questionnaires, and any third-party assessment reports it holds.
- Where that information is not sufficient to demonstrate compliance, Customer, or an independent auditor it appoints and that is bound by confidentiality, may audit Basepoint's relevant controls no more than once in any 12-month period, on at least 30 days' written notice, during normal business hours, in a way that does not disrupt the Service, and at Customer's cost. An audit required by a supervisory authority or following a Security Incident is not subject to the once-per-year limit.
11. International transfers
- Basepoint processes Personal Data in the United States, as set out in the Subprocessor list.
- Where Data Protection Laws of the EEA, the UK, or Switzerland apply to a transfer of Personal Data to Basepoint, the Standard Contractual Clauses are incorporated into this DPA. Module Two (controller to processor) applies where Customer is a Controller, and Module Three (processor to processor) where Customer is a Processor. Clause 7 (docking) is included; Clause 9 Option 2 applies with the notice period in section 6; Clause 11 optional language is not included; Clause 13 and Annex I.C are completed with the competent supervisory authority determined under the GDPR; Clause 17 Option 1 and Clause 18 are completed with the law and courts of Ireland. Annexes I and II of the Standard Contractual Clauses are completed by Annexes 1 and 2 of this DPA.
- For transfers subject to UK law, the UK Addendum applies to the Standard Contractual Clauses, with the tables completed by the information in this DPA. For transfers subject to Swiss law, the Standard Contractual Clauses apply with the adjustments required by the Swiss Federal Data Protection and Information Commissioner.
- If a transfer mechanism relied on under this section is invalidated, the parties will cooperate in good faith to put an alternative lawful mechanism in place.
12. Return and deletion
Customer may export its data from the Service at any time. When the Agreement ends, Basepoint keeps Customer's Personal Data for 30 days so that Customer can complete its export, then deletes it, except where law requires longer retention. Customer may request earlier deletion in writing. Backups are overwritten in the ordinary course and are not used to restore deleted Customer data except to recover from a Security Incident or outage.
13. California
Where the CCPA applies, Basepoint acts as a Service Provider. Basepoint will not sell or share Personal Data, retain, use, or disclose it for any purpose other than the business purposes set out in the Agreement, or outside the direct business relationship with Customer, or combine it with Personal Data from other sources except as the CCPA permits. Basepoint certifies that it understands these restrictions and will notify Customer if it can no longer meet them. Customer may take reasonable steps to stop and remediate unauthorized use.
14. Liability
Each party's liability under this DPA, including the Standard Contractual Clauses, is subject to the limitations and exclusions of liability in the Agreement, except where Data Protection Laws do not allow such limits.
15. Term and precedence
This DPA applies for as long as Basepoint processes Personal Data on Customer's behalf. If this DPA conflicts with the Agreement on the processing of Personal Data, this DPA prevails. If this DPA conflicts with the Standard Contractual Clauses, the Standard Contractual Clauses prevail.
Annex 1. Details of processing
Subject matter and duration
Provision of the Service under the Agreement, for the term of the Agreement plus the deletion period in section 12.
Nature and purpose
Hosting, storing, organizing, analyzing, and displaying data that Customer puts into the Service to screen sites, assess grid and permitting conditions, design layouts, model project finance, manage documents, and coordinate with counterparties, including the use of AI features to extract, summarize, and draft content from that data.
Categories of Data Subjects
- Customer's employees, contractors, and other users of the Service.
- Landowners, counterparties, consultants, officials, and other contacts Customer records in the Service.
- External clients and partners Customer invites to the client portal.
Categories of Personal Data
- Names, business contact details, job titles, and organizations.
- Correspondence, meeting notes, and documents that Customer uploads or connects.
- Account identifiers and activity within the Service.
Special categories of data
None are intended to be processed. Customer agrees not to submit special category data unless the parties agree otherwise in writing.
Frequency
Continuous, for as long as Customer uses the Service.
Annex 2. Technical and organizational measures
The current measures are described in full at getbasepoint.com/security. In summary:
- Encryption of Personal Data at rest (AES-256) and in transit (TLS 1.3).
- Logical separation of each customer's data, enforced by row-level security in the database.
- Authenticated, role-based access to the Service, with named sharing and an isolated portal for external users.
- Private file storage reached only through expiring signed links.
- Backend services isolated in private networks, with secrets held in a managed secrets store and injected at run time.
- Monitoring and alerting on production services, and error tracking with sensitive data scrubbed.
- A documented process for notifying customers of Security Incidents.
- Written confidentiality and security obligations on every Subprocessor.
Annex 3. Subprocessors
The current list, including the location of processing, is maintained at getbasepoint.com/legal/subprocessors and forms part of this DPA.
