bastios.ai License Agreement (EULA)
Bastios

Privacy Policy

Bastios AI LLC · Version 1.3 · Effective August 14, 2026 · Supersedes Version 1.2 (August 11, 2026) prospectively, on acceptance
Plain-language summary: Bastios is an AI assistant installed on a Mac mini that you own, at your premises unless you elect a Bastios-hosted deployment. Your financial records, books, transactions, documents, and linked-account content live on your own Box. Bastios does not host, collect, copy, or retain your books and records on Bastios servers, and each client runs an isolated, single-tenant instance — your data is never shown to or accessible by any other client. What changed in this version: we simplified how AI-model data retention is described — the product itself shows each model's retention status where you choose it; connector language is now vendor-neutral, so adding or changing an integration never changes this Policy; the current list of third-party providers now lives at bastios.ai/subprocessors, with a written copy available on request; and we clarified that only an affirmative act — never silence or continued use — accepts a new version of this Policy.
Contents:
1. Who We Are & Scope 2. The Core Model 3. Our Roles 4. What We Collect Off the Box 4A. Cookies & Tracking 5. What Stays on the Box 6. Linked Third-Party Accounts 7. How We Use Information 8. Legal Bases (GDPR) 9. Cloud AI, Inference Modes & No-Training 9A. Managed Services — the Full Data Flow 9B. Dedicated Compute & Private Models 10. No Sale or Sharing 11. Subprocessors 12. Data Retention 12A. Deletion & Written Certification 13. Security Measures 14. Your Privacy Rights 15. Exercising Your Rights 16. Children's Privacy 17. International Transfers 18. Data Breach Notification 19. Changes 20. Contact Us

1. Who We Are & Scope Revised in 1.2

This Privacy Policy explains how Bastios ("Bastios," "we," "us," or "our") handles personal information in connection with the Bastios product and related websites and services. Bastios is a Texas limited liability company.

Registered legal name: Bastios AI LLC
Governing law / venue: State of Texas

What this policy covers

This policy covers (a) the limited personal information Bastios collects as a company — visitors to our marketing websites (bastios.ai, bastios.net), people who contact us for sales or support, the contacts on a client's license and billing records, and the health/telemetry metadata our update agent reports about a deployed Box (Section 4); and (b) New in 1.2 the client content and usage records Bastios handles when a client enables Managed Services (Sections 9A and 9B).

What this policy does NOT cover

This policy does not govern the data that lives on a client's own Box. That on-box data (your books, records, transactions, documents, emails, and linked-account content) is controlled by the Client, stays on the Client's hardware, and is governed by the Client's own privacy practices. It also does not govern the independent terms and privacy policies of the third-party services a Client chooses to link (see Sections 6 and 11).

Definitions

Box
the client-owned Mac mini (or other Client-owned hardware approved by Bastios) on which Bastios is installed and runs, at the Client's premises unless the Client has elected a Bastios-hosted deployment.
Instance
the single, isolated deployment of Bastios running on one Client's Box. One instance per Client.
Client
the business that owns the Box and licenses Bastios.
AI Coordinator
the Client's own employee who oversees the assistant day-to-day, grants approvals, and handles exceptions.
Linked accounts
the Client's own third-party accounts (e.g., QuickBooks Online, Gmail/Microsoft 365, a bank feed) that the Client connects to its Box.
On-box data
any data that resides on the Box: financial records, documents, the local registry/event log/audit log, caches, and linked-account content pulled for a task.
Egress
sending data from the Box to a third party outside the Box.
Client Content New
the prompts, documents, business context, and responses that pass through a Managed Service on the Client's instruction.
Managed Services New
services in which Bastios acts as the Client's provider of a metered third-party capability — principally Managed Inference (Bastios is the AI model/inference provider), and, where elected, managed web search.
Direct Mode New
operation in which the Box calls an AI model provider on the Client's own account, with Bastios not in the path.
Local Mode New
operation with no cloud model connected; nothing is sent.
Usage Metering Records New
the non-content records Bastios creates to bill and support Managed Services (Section 9A.3).
Derived Artifacts New
embeddings, vector stores, indices, caches, fine-tuning corpora, adapters, and prompt-and-response logs generated from Client Content.

2. The Core Model: Your Data Lives on Your Own Hardware Revised in 1.2

Bastios is a local, on-box, default-deny AI assistant delivered as a service and installed on a client-owned Mac mini (or other Client-owned hardware approved by Bastios). It is not a cloud SaaS that ingests your data. Stated plainly:

An honest note on what "on-box" does and does not mean Revised in 1.2

The assistant works by sending relevant business context to an AI model — that is its intended function. "On-box" is a statement about where your data lives and who holds it, not a claim that nothing ever leaves the Box. What leaves, and who is in the path, depends on the mode you choose:

ModeWhat leaves the BoxIs Bastios in the path?What Bastios stores
LocalNothing.No.Nothing.
Direct (your own AI account)The request and selected business context, sent from your Box directly to your AI provider.No. Bastios never sees it.Nothing about the request.
Managed (Bastios is your AI provider)The request and selected business context, sent to Bastios, then relayed to an AI model provider — or served from compute dedicated to you.Yes, in transit (Section 9A).Usage Metering Records only — volume, model, timestamp, cost. Not your prompts or responses.

What never goes to the Portal as stored data, in any mode: your books, ledgers, documents, or linked-account content. Outside Managed Mode, Box-to-Portal traffic is limited to outbound requests for updates, skills, and verified data (such as the AI-model list and API pricing), plus account and non-content billing metadata.

The finance/PII hard-block, in every mode. Content the software has detected, or a user has tagged, as financial data or personal information is blocked from outbound AI-model calls at the code level — including in Managed Mode — and the block is not overridden by a human approval unless that specific capability is explicitly opted in. Honest limitation: this control operates on content that is tagged or detected as such. It substantially reduces, but cannot eliminate, the possibility that personal or financial information appears in a prompt a user writes.

3. Our Roles: Controller, Processor, and What That Means Here Revised in 1.2

For the limited off-box data we collect (marketing, support, license/subscription/billing, and update-agent health metadata), Bastios acts as an independent data controller and is responsible for that data under this policy.

For all data on the Box, the Client is the controller. The Client decides what data lives on its Box, what accounts to link, and how that data is used. Bastios does not control on-box data.

For Client Content processed through a Managed Service, the Client is the controller and Bastios is a processor and service provider acting solely on the Client's instructions. New in 1.2 Bastios does not determine the purposes of that processing, does not process Client Content for its own purposes, does not sell or share it, and does not combine it with data from any other source. The AI model providers and infrastructure providers identified in the subprocessor list referenced in Section 11 act as Bastios's subprocessors for that processing. Bastios remains an independent controller for the account, billing, security, and fraud-prevention records generated alongside it.

Bastios does not process the Client's books on any third party's behalf. Where a Client links any of its own third-party accounts, that provider and Bastios act as independent data controllers (not joint controllers); each is responsible for its own privacy compliance. This applies to every connector, including ones we release in the future.

Because the Client controls on-box data, requests from individuals about data residing on a Box (for example, a Client's customer or employee) are directed to the Client as controller. Bastios will reasonably assist the Client where required.

4. What We Collect Off the Box Revised in 1.2

The following is the personal information Bastios collects and holds. Categories, sources, and purposes are presented in the notice format used under the California CPRA, the Colorado Privacy Act, and the Texas Data Privacy and Security Act.

CategoryExamplesSourcePurpose
Website visitor dataIP address, device/browser type, pages viewed, referring URL, essential cookie/analytics identifiersDirectly from your browser when you visit bastios.ai / bastios.netOperate and secure the site; understand interest; respond to inquiries
Prospect & contact dataName, business name, email, phone, role, message contentDirectly from you (forms, email, calls)Respond to sales and informational requests
Support communicationsSupport tickets, emails, the contents of your requestsDirectly from you (the Client / AI Coordinator)Provide and document support
License, subscription & billing recordsClient legal/business name, billing contact, plan/tier, subscription status, invoices, payment status (card data handled by our payment processor, not stored by Bastios)Directly from the Client; from our payment processorProvision and bill the service; manage the subscription
Portal account & authentication recordsOrganization and member identifiers, Box identifiers, sign-in and device-authorization records, API key hashes, and any client-supplied provider credentials the client asks us to hold (encrypted)From the Client when a Portal account is createdAuthenticate the Client's Box and users; operate the Portal
Usage Metering Records (Managed Services) NewOrganization and Box identifier, timestamp, provider and model selected, input/output token counts, request status, request identifier, vendor cost and amount charged. No prompt or response content.Generated by the Bastios relay when the Client uses a Managed ServiceBill the Client; support and dispute resolution; capacity planning; security and abuse prevention — and nothing else (Section 9A.3)
Client Content in transit (Managed Services) NewThe prompt, the business context selected for the request, and the model's responseSent by the Client's Box when the Client uses a Managed ServiceRelayed to the AI model provider to generate the requested response. Passes through; not stored by Bastios (Section 9A.2)
Update-agent health / telemetry metadataBox online/offline status, software version, update success/failure, health-check and crash signals, non-content diagnostic metadataFrom the deployed Box's update agent (subscription clients)Keep the Box reliable: monitoring, patching, post-update health checks, auto-rollback
Website voice-assistant conversationsThe content of what you say to the voice assistant on our website — your questions, any business details you choose to share, and a summary of the conversationDirectly from you, through the voice assistant on bastios.aiRespond to your inquiry; sales and business development

The update agent does not send your books, records, documents, or linked-account content to Bastios. Updates are pull-based: the Box phones home and applies updates only if the subscription is active; no Client data is ever pushed to or pulled from clients. Telemetry is operational metadata, not content.

Website voice assistant. If you use the voice assistant on the Bastios website, we collect the information you choose to share during that conversation, including a summary we retain with your inquiry. We use it to respond to you and for our sales and business-development purposes. This applies only to what you explicitly say to the voice assistant, which is part of our marketing website and is entirely separate from the on-box product and from Managed Services.

4A. Cookies & Tracking Technologies (Marketing Site Only)

This section applies only to the Bastios marketing websites (bastios.ai, bastios.net), which are hosted on Cloudflare. The on-box product itself uses no third-party tracking, advertising, or analytics cookies — it runs locally on the Client's Box and does not load third-party trackers.

On our marketing site we use a limited set of cookies and similar technologies:

Consent. Where required by law, non-essential analytics cookies are set only after you consent through our cookie banner, and you may decline or withdraw consent at any time. We honor browser-level signals (such as Global Privacy Control) where applicable.

How to manage cookies. You can manage or delete cookies through our cookie-preference control on bastios.ai and through your browser settings. Disabling non-essential cookies does not affect the Bastios appliance, which uses no such cookies.

5. What Stays on the Box and We Do NOT Collect Revised in 1.2

The following remains on the Client's Box and does not flow to Bastios as stored data, in any mode:

Bastios neither receives nor retains this data as a stored copy. We have no copy of your books on our servers.

The one honest qualification. New in 1.2 In Managed Mode, the portion of the above that the assistant selects as context for a particular request passes through Bastios in transit to reach the model — subject to the finance/PII hard-block and your privacy mode, both applied on your Box before anything is sent. Passing through is not storing: Bastios does not write that content to its database, and its metering schema has no field for it (Section 9A).

6. How the Box Uses Linked Third-Party Accounts (Client-Owned, Gated) Revised in 1.2

The Client may link its own third-party accounts to the Box. Everything the assistant can do is governed by a default-deny permission broker on the Box:

Each linked third party is the Client's own account, white-glove provisioned in the Client's name. Bastios is not a money transmitter and takes no custody of funds.

7. How We Use the Information We Collect Revised in 1.2

We use the off-box information from Section 4 to:

What we never do with it. We do not use this information to build advertising profiles, to build usage or productivity profiles of individual users, or to make decisions producing legal or similarly significant effects about individuals. We do not use Client Content, Usage Metering Records, or Derived Artifacts to train, fine-tune, evaluate, benchmark, or improve any model, product, or service (Section 9).

8. Legal Bases for Processing (GDPR / UK GDPR)

Where the EU or UK GDPR applies to off-box personal data we collect, we rely on:

Where Bastios processes Client Content as a processor (Section 3), it does so on the Client's documented instructions and the Client is responsible for the legal basis for that processing.

9. Cloud AI Processing, Inference Modes, and the No-Training Commitment Revised in 1.2

9.1 What the model does

Bastios is model-agnostic. Within the assistant, the AI model is used for narration, classification, drafting, and routing; deterministic code does the bookkeeping judgment — a guided procedure, not an unguided agent, decides how items are coded.

9.2 Whose account, and who governs the provider Revised in 1.2

In Direct Mode, the assistant runs on your AI provider account. Bastios does not select or control that provider and is not in the path; what the provider does with data sent to it is governed by your agreement with it.

In Managed Mode, Bastios selects and contracts with the model provider under Bastios's own commercial terms, and Section 9A governs.

9.3 No training on your data — what we promise, precisely Revised in 1.2

About ourselves, without qualification: Bastios does not use your data to train, fine-tune, evaluate, benchmark, or improve any model, product, or service. Not your documents, not your prompts, not the model's outputs, not embeddings or indices built from them, not data you license from someone else. This is a promise about our own conduct and it is absolute. We may build features you ask for — and we own that software — but requirements and feedback are ours; your content is never training material.

About the AI model providers, stated precisely rather than broadly:

9.4 Credentials are designed not to enter a prompt

Stored credentials and API keys live in the macOS Keychain (or a 0600-permission file fallback) and travel only in HTTP headers; the system is designed so that they do not enter a model's system prompt, messages, or tool definitions. This has been examined in internal credential-isolation reviews covering the Box and the Portal, most recently completed in 2026, which found no leak path in the paths examined. Where Bastios holds a client-supplied provider credential in the Portal at the client's request, it is encrypted at the application layer (Section 13).

9.5 Privacy modes applied before anything leaves your Box Revised in 1.2

Every cloud call — Direct or Managed — passes through one outbound boundary on your Box that writes a metadata-only audit event (provider, model, counts, tags — never raw content), applies the finance/PII hard-block, and applies your selected privacy mode:

An unknown or mistyped policy value resolves to Pseudonymized (fail-closed). With no key connected, a keyless local response is used and nothing is sent to a cloud model.

9.6 NIST alignment

Our AI handling is aligned to the NIST AI Risk Management Framework and mapped against the current OWASP Agentic AI Top 10 in our internal security posture. These are internal alignment exercises, not third-party certifications (Section 13).

9A. Managed Services — the Full Data Flow New in 1.2

This section applies only if you turn on a Managed Service. Managed Services are off by default and are not enabled for a paying client until that client affirmatively accepts this policy and the Bastios EULA of the same version (Section 19; EULA Section 0.4).

9A.1 What Bastios is doing

In Managed Mode, Bastios AI LLC is your AI model and inference provider. We accept your Box's request at our Portal, select the configured model, and either relay the request to a model provider using our own commercial account, or serve it from compute dedicated to you alone (Section 9B) — in which case no third-party model provider receives your content at all. We return the response to your Box. We act in this role solely as your processor, on your instruction.

The same structure applies to any other metered third-party service we offer this way — for example, managed web search, where your search query is relayed to a search provider under our account. Every such provider is named in the published subprocessor list referenced in Section 11 before it can be used.

9A.2 The data flow, step by step

  1. On your Box. The request is assembled. The permission broker checks the capability. The outbound boundary applies the finance/PII hard-block and your privacy mode (Section 9.5) and writes a metadata-only audit entry. Redaction and blocking happen before anything leaves your hardware.
  2. In transit to us. The request travels over TLS to portal.bastios.ai. The Box connects only over HTTPS and only to that allowed host.
  3. At Bastios. We authenticate your Box, check your balance and limits, attach our provider credential, and stream the request to the model provider and the response back to your Box. We do not write the request or response body to storage. Our metering database has no field for prompt or response content. We write one Usage Metering Record per request.
  4. At the model provider. The provider processes the request under our commercial agreement with it (Section 9.3) and returns a response. Or, with a dedicated environment, no model provider is involved.
  5. Back on your Box. Pseudonyms are restored, the response is delivered, and the transaction is recorded in your on-box audit log, which you own and control.

9A.3 Metering, not monitoring

What we record for each request, and nothing more: your organization and Box identifier; the date and time; the model provider and model selected; input and output token counts (or the equivalent unit for a non-inference Managed Service); the request status; a request identifier; and the resulting cost and charge.

What we do not do. We do not read, review, store, index, analyze, or train on the content of your prompts, responses, documents, or work product. We do not build usage, behavioral, or productivity profiles of your business or of any individual user. We do not inspect what you are working on. We do not use Usage Metering Records for any purpose other than billing, support and dispute resolution, capacity planning, security, and abuse prevention, and we do not sell, share, or disclose them except as needed to bill you through our payment processor or as required by law.

The honest limitation. Your prompt and response content necessarily passes through our infrastructure in transit so that we can relay it — that is what the service is. Our commitment is that we do not persist, inspect, or analyze it, and that our systems are built not to: the relay streams request and response bodies without writing them to storage, and our metering schema contains no content fields. We do not claim that we are technically incapable of seeing content in transit. If you need an architecture in which Bastios cannot see your content, use Direct Mode — we are not in the path at all.

How long we keep metering records. For the life of your account and 24 months after, except that records forming part of an invoice, tax, or accounting record are kept 7 years as law requires, and records under legal hold are kept until the hold lifts. Automated enforcement of this schedule is being implemented; until it is, deletion is performed on request and on this schedule as a documented manual procedure.

9A.4 Who at Bastios can see what

9B. Dedicated Compute and Private Models New in 1.2

What it is. Where your order form provides for it, Bastios provisions and operates computing capacity — for example, dedicated GPU capacity with a cloud infrastructure provider — for your exclusive benefit. A model running there serves only your requests. No other client's requests are served by it and no other client's data enters it. Where your workload runs entirely in that environment, no third-party AI model provider receives your content at all; the only third party in the path is the named infrastructure provider.

Your private AI is yours. Where we facilitate training, tuning, grounding, or indexing on your data: as between you and Bastios, you own the resulting model — its weights, adapters, embeddings, indices, and outputs — and we claim no ownership. It is not shared with, offered to, merged into, pooled with, benchmarked against, or used to serve any other client, and it is not merged into any Bastios base model or product. No other Bastios client benefits from it. It is not our model that you use; it is your model that we run for you. Section 9.3 applies in full: we do not use it, your corpora, or its outputs to improve anything of ours.

The necessary limit. That ownership is ownership as between you and Bastios. It is subject to the terms of any third-party license governing data used to create or ground the model, and it conveys no right you do not already hold in that data — we cannot give away a data vendor's rights, because we do not have them. You are responsible for holding the rights to any data you direct us to process. Be aware that a data licensor may take the position that model weights, embeddings, indices, caches, and prompt-and-response logs derived from its licensed data remain its property and are subject to its confidentiality and destruction obligations. Where that is so, Section 12A is the mechanism that meets it.

On termination, you elect export, destruction, or both (Section 12A).

10. No Sale for Money; Consent-Based Advertising; Opt-Out Signals Revised in 1.2

We do not sell your personal information for money. We do not sell, share, rent, or disclose Client Content or Usage Metering Records to anyone, other than to the subprocessors in Section 11 strictly to deliver the service you requested, or as required by law.

Advertising cookies, only with your consent. We use Google's advertising tag (see Section 4A) to measure the performance of our own advertising. These advertising cookies are non-essential and are set only after you opt in through our cookie banner. To the extent this use is a "sale" or "share" for cross-context behavioral advertising, or "targeted advertising," as those terms are defined under the California CPRA, the Texas Data Privacy and Security Act, or similar state laws, it occurs only with your consent and you may opt out at any time. If you do not consent, we do not set these cookies and no such sharing occurs.

Honoring opt-out signals. We honor browser-level universal opt-out preference signals, such as Global Privacy Control. When your browser sends such a signal, we treat advertising and analytics cookies as declined and do not set them, regardless of the banner.

We do not use personal information for profiling that produces legal or similarly significant effects about individuals.

11. Subprocessors and Third-Party Services Revised in 1.2

(a) Bastios's subprocessors — where the current list lives

These are the third parties Bastios engages to operate the Portal, the Managed Services, and its own company systems. The current list of Bastios's third-party providers and subprocessors — each one's purpose, the data categories it receives, and its location — is published at bastios.ai/subprocessors. We will provide a written copy of the complete current list on request to privacy@bastios.ai. That list may be updated only in accordance with the change-notice and objection rules below, which are part of this policy and are not changed by an update to the list. Each version of the list carries its own date. We may change providers; a change of provider does not amend this policy, and the protections of this policy apply regardless of provider.

Provider-side retention posture for AI model providers. Under our commercial or enterprise account terms with each model provider: no training on inputs or outputs. Limited provider-side retention for abuse monitoring may apply, except for models covered by a zero-data-retention configuration we hold — stated per model in the software (Section 9.3), not here.

We do not use consumer, free-tier, or trial services in the Managed Services path. Managed Inference runs on our commercial/enterprise accounts under agreements prohibiting training on inputs.

Change notice. New in 1.2 We will give at least 30 days' written notice before adding or replacing a subprocessor that will process Client Content, except where a shorter period is necessary to maintain the service or address a security issue, in which case we give notice as promptly as practicable. You may object within the notice period; if we cannot agree on an alternative, you may terminate the affected Managed Service without penalty and continue in Direct or Local Mode. Where your own data-license obligations require prior written consent to each subprocessor, we will not route your content through one that has not been consented to.

(b) Client-linked third parties on the Box

A Client may connect its own third-party accounts to the Box — accounting, email and calendar, bank-transaction data, payments, electronic signature, messaging, and AI-model providers. Each linked service is the Client's own account, white-glove provisioned in the Client's name, and data shared with it is governed by that party's own terms and privacy policy, not by Bastios. These are not Bastios subprocessors. Connectors read only what a task needs through sanctioned APIs — no bulk extraction, warehousing, scraping, or cross-client aggregation. You can request the current list of supported connections at hello@bastios.ai. New connectors are added as an ordinary product improvement. A new connector adds no Bastios subprocessor and does not change this policy.

12. Data Retention Revised in 1.2

On-box data is Client-controlled and Client-deletable. Because Bastios does not hold your books and records, Bastios sets no retention period for them. The Client controls how long on-box data is kept and can delete it. The on-box audit log is append-only and stays on the Box.

Client Content in Managed Services: not retained. New in 1.2 Bastios does not store the prompts, business context, or responses relayed through a Managed Service. There is no retention period because there is no retained copy. Provider-side retention at a model provider is a separate matter, addressed in Sections 9.3 and 11.

Usage Metering Records: life of the account plus 24 months; invoice/tax/accounting records 7 years; anything under legal hold, until the hold lifts. Automated enforcement of this schedule is being implemented; until it is, deletion is performed on request and on this schedule as a documented manual procedure (Section 9A.3).

Securely delete on consent revocation. Where a Client revokes a connector's consent, the Box securely deletes the affected connector-sourced data consistent with that provider's own requirements, which differ by provider and which Bastios meets for each connector it supports.

Other off-box data. Bastios retains the off-box data in Section 4 only as long as necessary for the purposes it was collected, including providing and supporting the services, administering accounts and subscriptions, complying with legal obligations, resolving disputes, protecting security, and enforcing our rights. As general guidance: license, subscription, and billing records for the life of the account and seven (7) years thereafter for tax and accounting; support communications up to three (3) years; website analytics up to twenty-six (26) months; update-agent health/telemetry metadata up to twenty-four (24) months; website voice-assistant records and inquiry summaries up to twenty-four (24) months. When retention is no longer necessary, Bastios securely deletes or irreversibly de-identifies the information. Certain records may be kept longer where law requires or to establish, exercise, or defend legal claims.

12A. Deletion and Written Certification New in 1.2

What you can ask for. On your written request, on expiry or termination of a Managed Service, or on termination of your agreement, Bastios will delete or irreversibly destroy all Client Content and Derived Artifacts in our possession or control, including: prompt and response content and any log containing it; corpora, training and grounding datasets; embeddings, vector stores, and indices; caches; adapters and fine-tuned weights; and copies held by our subprocessors, to the extent we or they hold them.

Written certification, within 7 business days. We will provide written certification of deletion, signed by an officer of Bastios, within seven (7) business days of the request or of termination, identifying what was deleted, from which systems, and when. Where your data licensor requires certification directly, we will provide it to that licensor at your direction.

Narrow exceptions, stated up front. We may retain (a) Usage Metering Records and invoice, tax, and accounting records as law requires and on the schedule in Section 12 — these contain no Client Content; (b) material subject to a legal hold, for the duration of the hold; and (c) content in routine encrypted backups of Bastios systems, which cycle out on their ordinary schedule and are not restored for any other purpose. We will identify any such retained material in the certification.

On termination you choose: export (we make your corpora, derived artifacts, and any private-model weights available in a reasonable machine-readable form), destruction (we delete and certify), or both. If you make no election within thirty (30) days, we proceed with destruction and certification — unless your data licensor requires earlier destruction, in which case that controls and we act on it promptly.

Remote support access, and Bastios-hosted Boxes New in 1.2

We have no standing remote access to your Box. We do not connect to it, log into it, or operate it as a matter of course, and accepting this policy or the EULA does not give us that right.

When we do connect, it is because you asked us to, in writing, separately. Remote support requires a specific written authorization outside the EULA that names the purpose, the scope, and an expiry. It does not renew on its own, and you can revoke it at any time, for any reason, and we stop. A support ticket or a verbal go-ahead is not an authorization.

What we do while connected. We look at what the stated purpose requires and nothing else. We do not use remote access to browse, collect, index, copy, or keep your data, and we do not use it to get around any control described here — the finance/PII hard-block, the no-training promise, and the rule that we keep no client data on Bastios servers all apply in full during a support session. Being honest about the limit: fixing a system that holds your data can expose our people to that data while they work. That exposure is limited to the purpose, is covered by our confidentiality obligations, and gives us no right to keep, reuse, or disclose what was seen. Every session is written to your Box's append-only audit log, which you can read.

If you choose to have us host your Box. Where your order form provides for it, you may elect to have Bastios host your Box at a facility we operate or contract for, instead of at your own premises. It is your election — we do not relocate or host a Box without it. What does not change: the Box stays single-tenant to you, your data is not commingled with any other client's, and every commitment in this policy continues to apply. What does change, plainly: physical custody. We and our facility provider can physically reach the hardware, and our staff hold the administrative access needed to run and maintain it. For a hosted deployment we will not describe your data as residing on your own premises, because it does not. The facility, its country and region, and the operator are named in your order form, and that provider is a subprocessor with the change-notice rights described in the subprocessor section. On termination or on request we return or migrate your data — and your hardware where you own it — and then delete what remains in our custody, certifying that deletion on request.

13. Security Measures Revised in 1.2

Bastios maintains administrative, technical, and organizational safeguards designed to protect the information it holds and to secure the software it delivers. Our program follows a default-deny, human-in-the-loop model: sensitive actions require human approval, credentials and secrets are kept in protected storage, network exposure is restricted, and access is controlled and logged. Each release is reviewed for security issues before delivery, and we review and update these measures over time. No security program eliminates all risk.

For Bastios-operated infrastructure (the Portal and Managed Services): New in 1.2

Honest statement on certifications. Bastios does not currently hold SOC 2, ISO 27001, PCI DSS, HIPAA, or any other security certification or attestation, and has not undergone an accredited external audit or formal third-party penetration test. Our security reviews to date are internal reviews; we conduct them on the deployed product and remediate findings on a risk-ranked basis. We describe our security posture honestly and do not overstate it.

14. Your Privacy Rights

Depending on where you live, you may have some or all of the following rights regarding the off-box personal information Bastios controls:

Requests about on-box data, and about Client Content processed through a Managed Service, are directed to the Client as the controller of that data; Bastios will reasonably assist the Client as required, including by executing deletion and certification under Section 12A on the Client's instruction.

15. How to Exercise Your Rights

Submission methods. You may submit a request by emailing privacy@bastios.ai or by using our online Privacy Request Form at bastios.ai/privacy-request. At least two methods are provided where California law requires.

Identity verification. We will take reasonable steps to verify your identity before acting, which may require matching information we already hold.

Authorized agents. An authorized agent may submit a request on your behalf with proof of authorization; we may still verify your identity directly.

Timelines. We respond within the timeframes required by applicable law (generally within 45 days under US state laws, extendable as permitted; within one month under the GDPR/UK GDPR). Deletion requests under Section 12A are certified within seven (7) business days.

Right to appeal. If we deny your request, you may appeal by emailing privacy@bastios.ai with "Appeal" in the subject line. We will respond within the period required by Colorado, Texas, and Virginia law and, where applicable, tell you how to contact your state attorney general.

16. Children's Privacy

The Bastios product and websites are intended for businesses and are not directed to children. We do not knowingly collect personal information from anyone under 13 (or under 16 where applicable law sets that threshold). If we learn that we have collected such information, we will delete it. If you believe a child has provided us information, contact privacy@bastios.ai.

17. International Data Transfers and Data Residency Revised in 1.2

International transfers. Bastios is headquartered in the United States, and the off-box data described in this Policy — including Usage Metering Records — is processed in the United States. Managed Service requests are relayed to model providers whose processing locations are described in the subprocessor list referenced in Section 11. Where Bastios transfers personal data subject to the laws of the European Economic Area or the United Kingdom, we use appropriate safeguards recognized under applicable law, including the EU Standard Contractual Clauses and, where applicable, the UK International Data Transfer Addendum (IDTA) or other lawful transfer mechanisms.

On-box data does not transfer. A Client's on-box data physically remains on the Client's premises, on the Client-owned Box. Bastios does not move that data to its own infrastructure. In Managed Mode, the context selected for a given request transits Bastios's infrastructure to reach the model and is not stored there (Section 9A).

Data residency for dedicated environments. Where an order form provides for a dedicated compute environment, the region is stated in that order form and the workload runs there.

18. Data Breach Notification Revised in 1.2

Off-box data. If a security incident affects the off-box personal data Bastios controls, we will notify affected individuals and authorities as required by law — including, where applicable, notifying the relevant EU/UK supervisory authority within 72 hours under the GDPR, and notifying Texas residents without unreasonable delay and no later than 60 days, and the Texas Attorney General within 30 days where a breach affects at least 250 Texans, alongside other applicable state and federal requirements.

Client Content in Managed Services. New in 1.2 We will notify the affected Client promptly, and in any event without undue delay, of any unauthorized access to or disclosure of Client Content in our possession or control, and will cooperate with that Client's obligations to notify its own licensors, regulators, or customers — including on shorter timelines those obligations impose.

Connector passthrough deadlines. Where a connector provider's own terms impose a shorter notification deadline than the periods above, Bastios meets that deadline for data sourced from that connector. These vary by provider and Bastios tracks them per connector rather than listing them here (for example, one major accounting provider requires notice within 24 hours of discovery).

On-box incidents. Because the Client controls the Box, the Client is the controller for any incident affecting on-box data and leads notification to its own affected individuals; Bastios will reasonably assist and will report any connector-specific obligations that apply.

19. Changes to This Policy Revised in 1.2

Ordinary changes. We may update this Privacy Policy from time to time. When we do, we revise the version number and effective date above and, for material changes, provide notice as required by applicable law — by email, through the website, or through the Portal.

Changes we will not make quietly. New in 1.2 Continued use is not acceptance of, and we will not implement without your affirmative acceptance:

Why. Version 1.1 of this policy does not accurately describe Managed Services. Rather than rely on a general "we may update this policy" clause to bring anyone within materially different data handling, we require fresh affirmative acceptance. Managed Services stay off for a paying client until that client's authorized representative accepts this policy and the Bastios EULA of the same version, and we hold that acceptance record. Acceptance is captured by execution of an order form or addendum identifying the version, or by an in-product click-through that records the version, a hash of the accepted text, the timestamp, the accepting user, and the organization. Both methods produce the same record.

20. Contact Us / Privacy & Data Protection Contact

General: hello@bastios.ai
Privacy requests, current subprocessor list, deletion & certification: privacy@bastios.ai
Legal: legal@bastios.ai
Privacy Officer: Bastios Privacy Team (privacy@bastios.ai)
EU / UK representative: Not applicable — Bastios does not offer goods or services to, or monitor the behavior of, individuals in the EEA or UK. If that changes, Bastios will appoint an Article 27 representative and update this Policy.
Websites: bastios.ai, bastios.net