Skip to main content
Legal

Privacy Policy

Last updated 1 September 2026

Baseline Telemetry Advisory is the trading name of the practice.

This Privacy Policy explains how Baseline Telemetry Advisory ("we", "us") collects and processes personal data when you visit our website, engage us for advisory services, or use the Baseline Telemetry Advisory delivery workspace (Mode A). Where an engagement is delivered directly inside your own platforms (Mode B, for example Jira, Linear, Vanta, Drata, or Secureframe), those platforms remain under your control and their processing is governed by your own agreements with them. We comply with Regulation (EU) 2016/679 (GDPR), the UK GDPR where applicable, and the Irish Data Protection Act 2018.

Data controller

The data controller is Baseline Telemetry Advisory. Privacy contact: privacy@btadvisory.io.

When we act as processor

For engagement data that our clients upload into the Baseline Telemetry Advisory delivery workspace (risk registers, controls, evidence, policies, incidents, vendor records, planner tasks, reports), the client is the controller and Baseline Telemetry Advisory is the processor. Those processing activities are governed by our Data Processing Agreement (DPA), available at /dpa.

Personal data we process

Category
Account data
What it contains
Name, work email, job title, company, authentication credentials, TOTP factor metadata.
Lawful basis
Art. 6(1)(b)
Category
Engagement data
What it contains
Content clients or their team members upload into the workspace. Categories are defined per engagement.
Lawful basis
Art. 6(1)(b)
Category
Usage and security logs
What it contains
IP address, user agent, sign-in timestamps, MFA events, audit trail of workspace actions and of actions blocked by role or tenant permissions.
Lawful basis
Art. 6(1)(f)
Category
Correspondence
What it contains
Email and messages you send us.
Lawful basis
Art. 6(1)(f)
Category
Push notification subscriptions
What it contains
Browser push endpoint and public keys, stored only if you turn on workspace notifications.
Lawful basis
Art. 6(1)(a)

Web push notifications

If you enable notifications in the workspace, your browser issues a push subscription (an endpoint URL and two public keys) that we store against your account so we can deliver workspace alerts such as a published deliverable or an assigned control. We never use push for marketing. Turning notifications off in the workspace or in your browser revokes the subscription and we delete the stored record.

Lawful bases

Basis
Contract, 6(1)(b)
Applies to
Delivering the advisory services and operating the workspace.
Notes
Primary basis for account and engagement data.
Basis
Legitimate interests, 6(1)(f)
Applies to
Security logging, fraud prevention, running our business, and low-volume B2B outreach to work email addresses.
Notes
B2B email marketing is sent under the "existing customer / similar services" grounds permitted by S.I. 336 of 2011 (ePrivacy Regulations, Ireland) with a clear opt-out in every message.
Basis
Legal obligation, 6(1)(c)
Applies to
Tax records and regulatory retention.
Notes
Six years for invoicing under Irish Revenue rules.
Basis
Consent, 6(1)(a)
Applies to
Feature or communication opt-ins, including analytics and marketing cookies.
Notes
Withdraw at any time by emailing privacy@btadvisory.io.

Where your data lives

Primary application data is stored in a managed Postgres service hosted in eu-west-2 (London, United Kingdom). Backups remain in the same region. Static frontend assets are served through a managed edge network; those edges hold metadata and cached static assets only, not primary personal data. The providers are named on /subprocessors.

International transfers

We are established in Ireland and our primary storage is in the United Kingdom. Transfers from Baseline Telemetry Advisory (EEA, Ireland) to the United Kingdom rely on the European Commission's UK adequacy decision (2021).

Where an engagement uses AI features that route to model providers in the United States through the managed AI gateway, those transfers rely on the Standard Contractual Clauses set out in Commission Implementing Decision (EU) 2021/914 (module 2, controller-to-processor). AI features are only invoked when the client opts in. Our full sub-processor list is at /subprocessors.

For personal data that originates in the United Kingdom and is transferred to a country without UK adequacy (for example the United States), we use the SCCs together with the UK International Data Transfer Addendum (version B1.0, issued under section 119A of the Data Protection Act 2018). The Addendum is incorporated into our DPA. We have carried out transfer impact assessments for every transfer path, covering the destination country's law, the safeguards applied, and the fallback if a transfer mechanism is invalidated. A summary is available to clients on request.

Retention

Data set
Engagement data
Retention window
engagement duration plus 24 months by default
Ground
Contract; MSA may specify otherwise.
Data set
Handover exports (PDF, XLSX, DOCX, ZIP)
Retention window
Client-owned; retained on the same schedule as engagement data (above), then deleted, subject to any legal or regulatory hold.
Ground
Contract; same schedule as engagement data.
Data set
Audit trail
Retention window
24 months
Ground
GDPR art. 5(2) accountability, lawful ground to refuse erasure of the log entries themselves.
Data set
Marketing / prospect data
Retention window
Until you unsubscribe or 24 months of inactivity.
Ground
Consent or legitimate interests.
Data set
Push notification subscriptions
Retention window
Browser push endpoint and keys, kept until you disable notifications or the subscription expires.
Ground
Consent; deleted when the browser subscription is revoked.
Data set
Privacy request submissions
Retention window
Name, email, request type, and free text, retained for 24 months.
Ground
GDPR art. 5(2) accountability, proof that the request was handled.
Data set
Records under legal or regulatory hold
Retention window
Duration of the obligation or claim, then deleted.
Ground
GDPR art. 17(3)(b) and 17(3)(e).
Data set
Tax and invoicing records
Retention window
Six years
Ground
Irish Revenue statutory retention.

Your rights

You have the right to access, rectify, erase, restrict, port, and object to processing of your personal data, and to withdraw consent where processing is based on consent. Audit trail entries are immutable at the database level and are not pseudonymised or otherwise altered in response to an erasure request; they stay in full for accountability under art. 5(2). Submit a request through the privacy request form or email privacy@btadvisory.io. We respond within one calendar month under GDPR art. 12(3).

When we cannot delete

We honour deletion requests except where we are required to keep records by law (for example tax and invoicing records for six years), for accountability under GDPR art. 5(2), or where the records are needed to establish, exercise, or defend a legal claim, including under a litigation or regulatory hold. Anything outside that scope is deleted or pseudonymised, the retained records are restricted to storage and not used for anything else, and we delete them once the ground expires.

Typical examples: invoicing and tax records (six years under Irish Revenue rules), audit trail entries kept for accountability, and any records covered by an open dispute, insurance claim, or regulator query. For invoicing, tax, and dispute-related records, we delete or pseudonymise everything outside the exception, restrict the remainder to storage under art. 18, and write back to you setting out which categories we kept, on what ground, and for how long. Audit trail entries are kept in full and never pseudonymised, since the log is immutable by design.

Where the data sits in a client workspace and Baseline Telemetry Advisory acts as processor, deletion follows the controller's instruction. If that instruction conflicts with a legal requirement we are subject to, we inform the controller before acting, as set out in the DPA.

Supervisory authority

Our lead supervisory authority is the Data Protection Commission (DPC), Ireland: https://www.dataprotection.ie/. If you are located in the United Kingdom, you can also lodge a complaint with the Information Commissioner's Office (ICO), United Kingdom: https://ico.org.uk/.

Automated decision-making and AI (art. 22)

We do not make decisions about you by solely automated means that produce legal effects or otherwise significantly affect you. We do not profile or score individuals. Where AI assistance is used in delivery work, it drafts and summarises material; a Baseline Telemetry Advisory advisor reviews and is accountable for every output before it reaches a client. AI features in the workspace are off by default and enabled per engagement only when the client opts in. Client personal data is not used to train or fine-tune models. If that position ever changes, we will update this notice, complete a data protection impact assessment, and tell affected clients in writing before the change takes effect.

Data protection officer and representative

Baseline Telemetry Advisory is established in Ireland and processes personal data in the European Economic Area, so no representative under GDPR art. 27 is required. For the United Kingdom we monitor the UK GDPR art. 27 position and will appoint a UK representative if our processing of UK data subjects moves beyond occasional, low-risk activity.

We have not appointed a statutory Data Protection Officer. The tests in GDPR art. 37(1) are not met: we are not a public authority, we do not carry out large-scale systematic monitoring of individuals, and we do not process special-category data at scale. The Founder and Principal owns data protection accountability, and privacy questions go to privacy@btadvisory.io. We review this position annually and will appoint a DPO if the tests are met or a client contract requires one.

Children's data

Our services are sold to businesses and are not directed to children. We do not knowingly collect personal data from anyone under 16, and the delivery workspace is not intended for use by children. If you believe a child has given us personal data, email privacy@btadvisory.io and we will delete it.

Security and breach notification

Technical and organisational measures include row-level security on all workspace tables, mandatory multi-factor authentication, leaked-password screening against Have I Been Pwned, encryption in transit (TLS 1.2+) and at rest, least-privilege advisor access, and an append-only audit trail. Details on /trust.

Where Baseline Telemetry Advisory acts as controller and a Personal Data Breach is likely to result in a risk to individuals, we notify the Data Protection Commission (and the ICO for UK data subjects) within 72 hours of becoming aware, in line with GDPR art. 33. Where Baseline Telemetry Advisory acts as processor, we notify the client controller without undue delay and in any event within 72 hours, so they can meet their own art. 33 obligation.

Cookies and analytics

The website uses strictly necessary cookies always, and (with your consent) analytics cookies. Analytics loads only after you consent and is configured with IP anonymisation on, advertising features off, and consent-mode defaults set to denied until you opt in. No advertising or marketing tags are deployed. Consent is the lawful basis (art. 6(1)(a)) for analytics cookies; you can give, change, or withdraw consent at any time from /cookies. The authenticated delivery workspace does not run advertising or cross-site tracking.

Your current cookie state

Reading your saved choice.

Withdrawing clears the record and deletes analytics and marketing cookies already stored on this browser. Both buttons carry equal weight.

AI and managed services

Some workspace features use managed AI services when enabled for an engagement. They process only the content a user submits to that feature. The providers, processing locations, and transfer safeguards are listed in our Sub-processors notice. AI features can be disabled per engagement, and AI-assisted outputs are reviewed by Baseline Telemetry Advisory before delivery.

AI in our delivery work

Baseline Telemetry Advisory may use managed AI and coding assistants for limited internal research, drafting, coding, and analysis. They are not a routine route for client workspace content, and we do not intentionally submit client secrets, credentials, raw evidence, sensitive personal data, or confidential engagement material. Clients may request that AI-assisted processing be excluded from their engagement.

A separate, disclosed process, Drift Watch, uses Anthropic's Claude to read Baseline Telemetry Advisory's own source code and a dedicated internal reference tenant (a permanent fixture we maintain for exactly this purpose, never a real client engagement) to verify the platform's own behaviour against the live database on a recurring schedule. It is not authorised to query any other tenant, and it never processes a client's engagement data. Every tenant runs on the same underlying structure, so a fix that comes out of this audit applies across the board rather than to one client's workspace.

Baseline Telemetry Advisory uses a managed business productivity suite for email, bookings, documents, and administration. A managed transactional email provider sends authentication messages, invitations, booking confirmations, reminders, and operational notifications.

Changes

We will update the "Last updated" date at the top of this page when the policy changes. Material changes to processing that affect existing clients will be notified in writing.

Legal / last updated 1 September 2026