New: Your Basalt workspace for Odoo. MCP, proactive agents, visualisation. Learn more

Basalt

Legal

Privacy

A clear account of what the Basalt website collects, why we use it, who receives it and how you can exercise your rights.

Last updated : 31 August 2026

01

Who is responsible

For website visitors, prospects, applicants and business contacts, BSLT Systems OÜ, trading as Basalt, is the data controller. Write to hello@usebasalt.com for any privacy request.

When Basalt processes personal data inside a client system during a mission, the client is normally the controller and Basalt is its processor. That processing is governed by the signed services agreement and data-processing agreement, not by this website notice alone.

Trading name
Basalt
Legal entity
BSLT Systems OÜ
Legal form
Osaühing, Estonian private limited company
Registry code
17472884
Register
Estonian Commercial Register
Registered office
Ahtri tn 12, 15551 Tallinn, Estonia
Email
hello@usebasalt.com
02

What we collect and why

Please do not place sensitive personal data or confidential client information in a free-text booking answer or first contact message.

Website requests
IP address, browser and request data needed to deliver, secure and diagnose the site. Basis: our legitimate interest in operating a reliable and secure website.
Contact and applications
Your name, professional details, email address, message and attachments. Basis: steps requested before a contract and our legitimate interest in responding to business enquiries or recruitment.
Call booking
Your contact details, selected time and answers to the booking questions. Basis: steps requested before a contract and our legitimate interest in organising the conversation.
Client administration
Contact, proposal, contract and billing information. Basis: contract, legitimate interests and legal accounting or tax obligations.
03

Cookies and measurement

The Basalt marketing site does not currently use advertising cookies, behavioural tracking or a third-party analytics product. We therefore do not display a consent banner that would offer choices for tools that are not present.

Technical infrastructure may use strictly necessary mechanisms for security and service delivery. Cal.com is loaded only after you choose to open the calendar. Its own service may use cookies needed to operate the booking interface. If analytics or advertising tools are added later, this notice and the consent mechanism will be updated before they are enabled.

04

Who receives data

A WhatsApp button is an external link. If you choose it, WhatsApp and Meta process the interaction under their own terms. Basalt does not load WhatsApp tracking code on the website. We do not sell personal data and do not share it for cross-context behavioural advertising.

  • Vercel, for website hosting, content delivery, media and technical logs.
  • Neon, for the database that supports site content and settings where applicable.
  • Cal.com, when you open the calendar or make a booking.
  • Our business email provider, when you write to us or receive a reply.
  • Professional advisers or public authorities where access is required by law or necessary to establish or defend legal rights.
05

International transfers

Some suppliers process data outside the European Economic Area, particularly in the United States. Where required, transfers are covered by an adequacy decision, the EU-US Data Privacy Framework for a certified recipient, Standard Contractual Clauses or another lawful safeguard. You may ask us for information about the safeguard used for a specific transfer.

06

How long we keep it

  • Unsuccessful prospect and general contact records are normally removed or anonymised within 24 months after the last meaningful exchange.
  • Recruitment records are normally kept for up to 24 months after the last exchange, unless you ask us to delete them sooner or a legal claim requires longer retention.
  • Client, contract and billing records are kept for the relationship and then for the period required by applicable accounting, tax and limitation rules.
  • Security and technical logs are kept for the shortest period supported by the relevant infrastructure configuration and then deleted or aggregated.
07

Your rights

Depending on the processing and your location, you may ask for access, correction, deletion, restriction, portability or object to processing based on legitimate interests. You may withdraw consent where consent is the basis. We normally answer within one month and may need to verify your identity.

Write to hello@usebasalt.com. You may also complain to the Estonian Data Protection Inspectorate or to the supervisory authority where you live or work.

08

Security and automated decisions

We use access controls, encryption in transit, managed infrastructure and least-privilege access appropriate to the data and the service. No internet service can promise absolute security.

The website does not make a decision about you solely by automated means that produces legal or similarly significant effects. Booking answers are used to prepare a human conversation.

09

Changes to this notice

We update this page when the website, our suppliers or the law changes. The date at the top shows the current version. A material change affecting an existing relationship will also be communicated directly where required.