Privacy and Security Assurance
- 1Base does not sell client data or use project records for advertising resale.
- Financial and project activity is retained with traceability controls to support accountability.
- Security operations prioritize access control, encryption, and incident containment.
- Privacy requests are handled through verified workflows to protect against unauthorized disclosure.
1. Data Roles and Scope
1Base processes platform data to provide controlled financial workflows, governance oversight, and auditable records for professionals operating from personal to project-scale use cases.
Customer organizations control the project data they submit and manage user-level permissions within their workspace.
2. Data We Collect
- Account and identity details needed for secure access and collaboration.
- Financial workbook entries, currency totals, and sheet lifecycle actions.
- Milestone records, uploaded documents, and artifact metadata.
- Technical telemetry such as device, session, and event logs for security and reliability.
3. Why We Process Data
- Deliver and secure platform functionality requested by customers.
- Preserve auditability and accountability across project operations.
- Detect abuse, prevent fraud, and protect service integrity.
- Improve performance, reliability, and user experience.
4. Security Controls
Because 1Base handles financially sensitive workflows, security controls are applied across access, storage, and operational processes.
- Encryption in transit for network communication and encrypted storage controls.
- Role-based access boundaries and controlled administrative operations.
- Event logging, anomaly monitoring, and incident-response runbooks.
- Routine patching and security maintenance practices.
5. Data Sharing and Subprocessors
1Base does not sell customer data. Data is shared only with service providers required to operate the platform, under contractual confidentiality and security obligations.
Data may also be disclosed where legally required by valid law-enforcement or regulatory process.
6. Retention and Deletion
Data is retained for active service delivery and operational/legal obligations.
When accounts close, retention and deletion follow contractual commitments and documented lifecycle controls.
7. International Access and Transfers
Where cross-border processing is necessary, 1Base applies contractual and operational safeguards designed to protect personal and project data during transfer and access.
8. User Rights and Requests
Depending on jurisdiction, individuals may request access, correction, deletion, restriction, or export of personal data.
Identity verification is required before processing privacy requests to prevent unauthorized disclosure.
9. Policy Updates
This policy may be updated to reflect legal requirements and platform evolution. Updated versions are published with a revised effective date.