1. Key Terms

BAO Systems defines several important roles in its services framework. “Customers” are parties contracting for Services. “Users” are individuals authorized by Customers to use the platform. “Subjects” refers to third parties whose data is collected through the Services, with their information called “Subject Data.”

The company operates multiple websites and services collectively referred to as “Services” in this policy.

2. Policy Application

This Privacy Policy describes BAO Systems’ handling of personal information where the company acts as a controller — including Customer account information and usage data. The policy states: “If you do not agree with this policy, do not access or use our Services.”

When BAO Systems hosts Subject Data and User information for Customers, those Customers act as controllers under GDPR, and the company serves as their processor. Users and Subjects should consult their Customer’s privacy policy for information about how their data is handled.

Customers in the EEA, UK, or Switzerland should review BAO Systems’ Data Processing Agreement.

3. Personal Information Collected

BAO Systems collects:

4. How Personal Information Is Collected

Information You Provide

Users supply information directly when registering accounts, communicating support inquiries, responding to surveys, and participating in events.

Information Collected Automatically

The company collects data about device usage, including browser type, pages visited, interaction time, and location information when permitted. For Users, BAO Systems states it collects “information about your interactions with the Customer’s account” in “anonymous, aggregated or pseudonymized form.”

Information From Third Parties

Information arrives via Customers, third-party service integrations, and payment processors. The policy notes: “The information we receive when you link or integrate our Services with a third-party service depends on the settings, permissions and privacy policy controlled by that third-party service.”

5. How Personal Information Is Used

BAO Systems uses collected information for:

Legal Bases for Processing

The company processes information based on:

For EEA residents, BAO Systems collects information only where legal bases exist under EU law.

6. How Personal Information Is Shared

BAO Systems shares information with:

7. Your Rights and Choices

Users may access, update, change, or delete personal information by contacting security@baosystems.com or through their account. Users can opt out of marketing communications via unsubscribe links.

The policy notes: “there is likely to be a delay in deleting your personal information from our systems when you ask us to delete it.”

Applicable rights include restricting processing, exercising data portability, and lodging complaints with supervisory authorities. EEA residents may withdraw consent at any time.

Users and Subjects should contact their Customer to exercise rights regarding information held by that Customer.

8. Data Protection Measures

BAO Systems uses data hosting providers in the EEA and implements technical security measures. The company maintains “administrative, technical and physical safeguards” to protect against unauthorized access and unlawful processing.

9. Data Retention

BAO Systems retains personal information while accounts remain active and as long as necessary to provide Services. The company considers minimum retention periods, claim periods, and whether information is aggregated or pseudonymized.

Notably: “As Customers may have seasonal projects or come back to us after an account becomes inactive, we don’t immediately delete your personal information when your trial expires, or you cancel all paid or subscription Services.”

Aggregated and anonymized information may be retained indefinitely. Users can request account deletion by contacting security@baosystems.com.

10. Data Privacy Framework

BAO Systems complies with the EU-U.S., UK Extension, and Swiss-U.S. Data Privacy Frameworks. The company has certified adherence to the corresponding principles with the U.S. Department of Commerce.

Unresolved DPF complaints may be directed to JAMS. The company commits to cooperating with EU, UK, and Swiss data protection authorities regarding human resources data complaints.

BAO Systems notes: “BAO Systems shall remain liable under the EU-U.S. DPF, the UK-U.S. DPF, and Swiss-U.S. DPF if a third party processes your information in a manner inconsistent” with framework requirements, except where proven otherwise.

The company is subject to U.S. Federal Trade Commission oversight.

11. Users’ Personal Information

Customer Relationship with Users

Customers collecting User information bear sole responsibility for compliance with applicable laws. BAO Systems provides no legal advice regarding these relationships.

Customer Relationship with Subjects

Customers control all individual Subject Data. BAO Systems is not responsible for Customers’ privacy and security practices.

12. Policy Toward Children

The Services are not directed at individuals under 13. BAO Systems states it does “not knowingly collect personal information from children under 13” and will delete such information if discovered. Questions should be directed to security@baosystems.com.

13. Policy Updates

BAO Systems updates the Privacy Policy periodically. The company updates the “Effective Date” and notifies users of material changes through site notices or direct communication.

14. Contact Information

BAO Systems, LLC 2900 K St. NW Suite 506 Washington, DC 20007, USA Email: security@baosystems.com

EU Representative: BAO Systems LLC – Sucursal em Portugal R. Gregório Lopes Lote 1639, Loja 1400-414 Lisboa Portugal Email: security@baosystems.com