Legal · Data Protection
BASTYN Privacy Policy
Version 1.0 · Last updated: 19 June 2026 · Effective from: 20 June 2026
This Privacy Policy explains how Rooted Logic LDA (“BASTYN”, “we”, “us”, “our”) collects, uses, shares and protects personal data when you visit our websites at bastyn.io and bastyn.com (the “Site”), use our services as a registered customer, partner or end user, communicate with us, attend our events, or otherwise interact with us.
This Policy is written to comply with the General Data Protection Regulation (Regulation (EU) 2016/679) (“EU GDPR”), the United Kingdom General Data Protection Regulation as it forms part of the law of England and Wales, Scotland and Northern Ireland by virtue of the European Union (Withdrawal) Act 2018 (“UK GDPR”), the Data Protection Act 2018, the Portuguese General Data Protection Implementation Law (Lei n.º 58/2019, de 8 de agosto), and where applicable — the Brazilian General Data Protection Law (Lei n.º 13.709/2018, “LGPD”) and applicable United States state privacy laws.
1. Who is the controller of your personal data
The data controller is:
Rooted Logic LDA, a sociedade por quotas incorporated in Portugal under NIPC 519106822, with its registered office at Casal Sao Rafael, Setubal, Portugal.
Rooted Logic LDA operates internationally through branch establishments in United Kingdom and United States of America.
The branches are operational establishments of the same legal person. Rooted Logic LDA is the controller in respect of all processing described in this Policy regardless of which branch handles the day-to-day interaction.
Lead supervisory authority. Our lead supervisory authority for cross-border processing under the EU GDPR is the Comissão Nacional de Proteção de Dados (CNPD), Portugal — www.cnpd.pt.
Data Protection Officer. Our Data Protection Officer can be contacted at dpo@bastyn.io or by post at the registered office, marked for the attention of the DPO.
EU representative under EU GDPR Art. 27. Not applicable; the controller is established in the European Union.
UK representative under UK GDPR Art. 27. Not applicable; the controller has a UK establishment.
2. Whose personal data this Policy covers
This Policy covers personal data of:
- Site visitors — anyone who accesses the Site;
- Customers and prospective customers — individuals representing organisations that purchase or evaluate BASTYN services (typically procurement, security, compliance, engineering and legal staff);
- Partners and prospective partners — individuals representing resellers, referral partners, OEM embedders, marketplace operators and certification bodies;
- End users of partner-deployed deployments — only where data subjects’ personal data is processed by BASTYN as a processor on behalf of a customer or partner (see clause 11);
- Event attendees, newsletter subscribers and content recipients;
- Job applicants and candidates (covered separately by our Recruitment Privacy Notice provided at point of application);
- Visitors to our offices (covered separately by signage at the relevant location).
This Policy does not cover personal data we process as a processor on behalf of a customer or partner, for example, where a customer submits test corpora that contain personal data. That processing is governed by the data processing terms incorporated into our Online Purchase Terms & Conditions (Document 3) or the relevant Partnership / Platform Agreement (Document 4).
3. The personal data we collect
| Category | Examples | Source |
|---|---|---|
| Identity & contact | Name, business email, business phone, job title, employer, country | You; LinkedIn; lawfully accessible business directories |
| Account & authentication | Username, hashed password, multi-factor authentication factors, API keys | You; generated on registration |
| Commercial relationship | Company size, role, AI use cases described, procurement stage, contract terms | You; CRM activity |
| Billing | Billing name, billing address, VAT/tax identifiers, last four digits of payment card; full payment card data is processed by our payment service provider and not stored by us | You; payment service provider |
| Usage and technical | IP address, device type, browser, pages viewed, referrer, session timestamps, API call metadata, error logs | Automatically collected via Site, application and API |
| Cookies and similar | See clause 14 | Automatically collected via Site |
| Communications | Emails, support tickets, chat transcripts, call recordings (where you have been informed and lawful basis exists), webinar registrations | You; our communications platforms |
| Event participation | Registration data, attendance data, dietary requirements (where supplied) | You; event platforms |
| Marketing preferences | Subscription status, opt-in records, opt-out timestamps, click and open behaviour | You; marketing platform |
We do not routinely collect special categories of personal data under EU/UK GDPR Art. 9, criminal-conviction data under Art. 10, or sensitive personal data under the LGPD. If you provide such data unsolicited, we will not act upon it and will delete it as soon as practicable unless retention is required for the establishment, exercise or defence of legal claims.
4. Why we process personal data and the lawful basis for doing so
| Purpose | Categories used | EU/UK GDPR lawful basis | Legitimate interests where applicable |
|---|---|---|---|
| Operating the Site and ensuring its security | Usage and technical; cookies | Legitimate interests (Art. 6(1)(f)) | Maintaining a secure, available website for prospective and current customers |
| Responding to enquiries and pre-sale conversations | Identity & contact; commercial relationship; communications | Legitimate interests; pre-contractual steps (Art. 6(1)(b)) | Engaging with potential customers who have approached us |
| Providing the BASTYN service to a registered customer | Identity & contact; account & authentication; commercial relationship; billing; usage | Performance of contract (Art. 6(1)(b)) | — |
| Billing, payment processing, fraud prevention and tax | Billing; identity & contact; usage | Performance of contract; legal obligation (Art. 6(1)(c)) | — |
| Direct marketing of BASTYN services to existing customers and to business contacts | Identity & contact; marketing preferences | Legitimate interests; consent (Art. 6(1)(a)) where required by ePrivacy or LGPD | Promoting our services to professional contacts who have an established commercial interest |
| Newsletter and gated content | Identity & contact; marketing preferences | Consent (Art. 6(1)(a)) | — |
| Events, webinars and conferences | Identity & contact; event participation | Performance of contract for the event; consent for marketing follow-up | — |
| Improving and developing our services and methodology | Aggregated and pseudonymised usage and technical only | Legitimate interests (Art. 6(1)(f)) | Continuous improvement of a security-critical product |
| Internal security, audit, compliance, financial controls | All categories as needed for the specific incident | Legitimate interests; legal obligation | Operating a secure business and meeting regulatory obligations |
| Establishment, exercise or defence of legal claims | All categories as relevant | Legitimate interests; legal obligation | Protecting the rights of BASTYN, customers, partners and data subjects |
| Compliance with legal obligations including sanctions screening, anti-money-laundering, tax, accounting | Identity & contact; billing; commercial relationship | Legal obligation (Art. 6(1)(c)) | — |
No automated decision-making producing legal or similarly significant effects. We do not use your personal data to make decisions about you that produce legal effects concerning you or that similarly significantly affect you within the meaning of EU/UK GDPR Art. 22. Where BASTYN technology evaluates AI systems on behalf of customers, those evaluations relate to AI systems and not to natural persons.
No training of AI models on personal data. We do not use personal data of Site visitors, customer contacts or end users to train, fine-tune, evaluate or benchmark any AI model, our own or any third party’s. Customer-supplied data submitted under Document 3 is governed by the contractual terms there, which prohibit training use without separate written consent.
5. With whom we share personal data
We share personal data with the following categories of recipient, only where strictly necessary for the purposes set out above and under appropriate contractual safeguards (typically EU GDPR Art. 28 processing terms, EU Standard Contractual Clauses 2021/914, the UK International Data Transfer Agreement or Addendum, and equivalent LGPD safeguards):
| Recipient category | Purpose |
|---|---|
| Cloud hosting and infrastructure providers | Operating the Site, application and database. Google Cloud Platform |
| Email and communication providers | Transactional email, support ticketing, calendar, document storage |
| CRM and marketing platforms | Sales pipeline management and email campaigns |
| Payment service providers | Card payment processing is handled by Stripe — full card data not received by us |
| Analytics and product telemetry | Aggregated and pseudonymised usage analytics |
| Identity and authentication providers | Single sign-on, multi-factor authentication |
| Professional advisers | Legal, accounting, tax, insurance, audit |
| Sanctions and compliance screening | Sanctions, politically-exposed-person and adverse-media screening |
| Public authorities | Where compelled by valid legal process or required by law |
| Acquirers in a corporate transaction | Subject to confidentiality and data protection commitments |
A current list of sub-processors used in delivery of the BASTYN service is maintained and updated on changes.
We do not sell personal data, share it for cross-context behavioural advertising, or rent or trade contact lists.
6. International transfers
Personal data may be transferred to recipients located outside the European Economic Area, the United Kingdom or Brazil — in particular to our UK and US branches, and to cloud and software providers based in the United States.
Where we transfer personal data outside the EEA, we rely on:
- adequacy decisions where available (for example, the EU–US Data Privacy Framework where the US recipient is certified, or the UK Extension to the same);
- the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) or the UK International Data Transfer Agreement / Addendum, supplemented by transfer impact assessments and supplementary technical and organisational measures where required following Schrems II;
- equivalent safeguards under Lei 58/2019 and LGPD where those regimes apply.
Where the transfer is to our UK or US branch, the receiving branch is part of the same legal person as the controller; we nonetheless apply equivalent technical and organisational protections to those used for transfers between separate legal entities.
7. How long we keep personal data
We keep personal data for no longer than is necessary for the purposes for which it is processed, taking into account our contractual obligations, legitimate interests and legal duties.
| Category | Typical retention |
|---|---|
| Site logs and security telemetry | 12 months from collection, save where retained longer for active investigation |
| Pre-sale enquiry records | 24 months from last contact unless converted to a customer relationship |
| Customer account, billing and contract records | Term of the contract plus 7 years (statutory tax and accounting retention; longer if litigation is reasonably anticipated) |
| Marketing preferences and opt-out records | Indefinitely, to honour the opt-out |
| Recruitment data | 12 months from end of process unless candidate consents to longer retention |
| Cookies | See cookie notice; typically 13 months maximum for analytics cookies |
After the applicable retention period the data is deleted, anonymised or where deletion would be disproportionately burdensome placed beyond use and retained only for the establishment, exercise or defence of legal claims.
8. Your rights
Subject to the conditions in the EU/UK GDPR, Lei 58/2019 or the LGPD as applicable to you, you have the right to:
- access the personal data we hold about you and to receive a copy;
- rectification of inaccurate or incomplete data;
- erasure in the circumstances set out in Art. 17 GDPR;
- restriction of processing in the circumstances set out in Art. 18 GDPR;
- portability of personal data you have provided to us, where processing is by automated means and based on consent or contract performance (Art. 20 GDPR);
- object to processing based on legitimate interests, including direct marketing (Art. 21 GDPR);
- withdraw consent at any time where processing is based on consent, without affecting the lawfulness of processing before withdrawal;
- lodge a complaint with a supervisory authority — in the first instance the CNPD (Portugal), the Information Commissioner’s Office (United Kingdom) at ico.org.uk, the Autoridade Nacional de Proteção de Dados (Brazil) under LGPD, or the supervisory authority in your habitual residence or place of alleged infringement.
To exercise any of these rights, contact dpo@bastyn.io. We will respond within one month of receipt of a verifiable request, or two months where the request is complex (with notice within the first month).
We may need to verify your identity before responding. We will not charge a fee unless the request is manifestly unfounded or excessive.
9. Security
We maintain technical and organisational measures appropriate to the risk, taking into account the state of the art, the costs of implementation, the nature and scope of processing, and the likelihood and severity of risks to data subjects. These measures include encryption in transit and at rest, role-based access control, multi-factor authentication, security monitoring and alerting, vulnerability management, secure software development practices, supplier due diligence, business continuity and incident response procedures, and staff training.
We are working towards ISO/IEC 27001 certification and aligning with SOC 2 Type II controls.
If we become aware of a personal data breach which is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours where required, and will notify you directly without undue delay where the breach is likely to result in a high risk to your rights and freedoms, in each case in accordance with our statutory obligations.
10. Direct marketing
We send marketing communications about BASTYN services to existing customers and to business contacts who have a relevant professional interest, and to subscribers to our newsletter or gated content. You can opt out of marketing at any time using the unsubscribe link in any marketing email or by contacting contact@rootedlogic.ai. Opting out of marketing does not affect transactional or service communications relating to a contract you have with us.
11. When BASTYN acts as a processor
Where BASTYN provides services to a customer or partner, the customer or partner is typically the controller of personal data they submit to BASTYN, and BASTYN is the processor. In that role, BASTYN processes that personal data only on the documented instructions of the customer, under the data processing terms incorporated into the Online Purchase Terms & Conditions (Document 3) or the Partnership / Platform Agreement (Document 4). If you are a data subject whose personal data has been submitted to BASTYN by such a customer, you should direct your data subject rights requests in the first instance to that customer; we will assist the customer in responding.
12. Changes to this Policy
We may update this Policy from time to time to reflect changes to our practices, our services or the law. The version published on the Site at the time of access governs the processing of your personal data. Where the changes are material we will provide additional notice — for example, by email to registered customers or by prominent notice on the Site.
13. Children
The Site and the BASTYN service are not directed to and not intended for use by children. We do not knowingly collect personal data of children under 16. If you believe we hold personal data of a child without appropriate authority, please contact contact@rootedlogic.ai.
14. Cookies and similar technologies
The Site uses cookies and similar technologies. A cookie is a small text file placed on your device when you visit a website. Categories used:
| Category | Purpose | Lawful basis |
|---|---|---|
| Strictly necessary | Session management, security, load balancing, authentication | Legitimate interests; not subject to consent under PECR / EU ePrivacy |
| Functional | Remembering preferences (language, region) | Consent |
| Analytics | Pseudonymised usage analytics for product improvement | Consent |
| Marketing / measurement | Conversion measurement and pseudonymous attribution where used | Consent |
You can manage non-essential cookies through the cookie banner shown on first visit and via the cookie preferences link in the Site footer. You can also configure your browser to refuse cookies. Doing so may degrade some features of the Site.
15. Contact
For any privacy-related question, complaint, or to exercise your rights:
- Email: contact@rootedlogic.ai
- Post: Data Protection Officer, Rooted Logic LDA, Casal Sao Rafael, Setubal, 2925-384 Portugal
