Baseten Data Request Policy
Like other technology companies, Baseten Labs, Inc. ("Baseten") may receive requests from individuals, courts, government agencies, and litigants to disclose, preserve, or delete data other than in the ordinary operation and provision of the Services. This Data Request Policy describes Baseten's policies and procedures for responding to such requests for Customer Content (the “Policy”). Capitalized terms used but not defined in this Policy have the meanings given in the Baseten Terms and Conditions available at [https://www.baseten.co/legal/terms] or other written agreement between Baseten and the applicable customer ("Customer") governing use of the Services (the "Agreement"). In the event of any inconsistency between this Policy and the Agreement (including the Data Processing Addendum available at https://www.baseten.co/dpa (the "DPA")), the Agreement controls.
Baseten's role is that of an infrastructure and platform services provider. Customer Content belongs to the Customer, and Baseten processes it on the Customer's behalf and at the Customer's direction, as described in the Agreement and the DPA. That role shapes how Baseten responds to every category of request below.
1. Requests by Individuals
Individuals who want to access, correct, delete, or exercise other rights with respect to Customer Content, including personal data contained in Customer Content, should direct their request to the applicable Customer. The Customer controls its Customer Content and decides what is submitted to, retained in, and removed from the Services. Where Baseten receives a request from an individual relating to Customer Content and can reasonably identify the relevant Customer, Baseten will refer the individual to that Customer and, consistent with the DPA, will provide the Customer with reasonable assistance in responding to data subject requests. Requests relating to personal data that Baseten processes for its own purposes (for example, website visitor or marketing data) are addressed in the Baseten Privacy Policy available at https://www.baseten.co/privacy-policy.
While Baseten defers to the Customer for decisions regarding Customer Content, Baseten reserves the right, as described in the Agreement, to require removal of, or to remove, Customer Content that violates applicable law, the Agreement, or the rights of a third party.
2. Requests by Courts, Government Agencies, and Litigants
All requests by courts, government agencies, law enforcement, or parties involved in litigation for the disclosure of Customer Content should be sent to legal@baseten.co and must include: (a) the identity of the requesting party or agency; (b) the relevant criminal or civil matter; and (c) a specific description of the Customer Content requested, including the relevant Customer's name and, if applicable, the relevant user's name. Requests must be prepared and served in accordance with applicable law. All requests should be narrow and focused on the specific Customer Content sought, and Baseten will construe all requests narrowly. Please do not submit unnecessarily broad requests.
Except as expressly permitted by the Agreement, or in an emergency involving danger of death or serious physical injury to a person that requires disclosure without delay, Baseten will not disclose Customer Content unless it is compelled to do so by valid and binding legal process or an order of a court or governmental or regulatory body of competent jurisdiction, in each case issued in accordance with applicable law, including, where applicable, the Stored Communications Act, 18 U.S.C. Section 2701 et seq.
Baseten will notify the Customer before disclosing any of that Customer's Customer Content so that the Customer may seek to contest or limit the disclosure, unless Baseten is legally prohibited from providing notice (for example, by a nondisclosure order issued under 18 U.S.C. Section 2705) or there is a clear indication of illegal conduct or risk of harm to persons or property associated with the use of such Customer Content. Where a nondisclosure obligation is time limited, Baseten will provide notice to the Customer once the obligation expires. If legally permitted, the requesting party or the Customer, as applicable, will be responsible for Baseten's reasonable costs of responding to the request.
Baseten will honor valid preservation requests issued under 18 U.S.C. Section 2703(f). A preservation request does not compel disclosure; disclosure requires the legal process described above.
3. Service and Jurisdiction
Baseten Labs, Inc. is a Delaware corporation headquartered at 560 Davis St., Suite 250, San Francisco, CA 94111. Any party issuing legal process or legal information requests to Baseten (for example, discovery requests, warrants, or subpoenas) must properly issue or domesticate the process in the United States and serve Baseten in a jurisdiction where it is resident or has a registered agent authorized to accept service on its behalf. Foreign courts and law enforcement agencies should proceed through a Mutual Legal Assistance Treaty, letters rogatory, or other applicable diplomatic or legal means to obtain data through a court of competent jurisdiction in the United States.
4. A Note on Data Retention
Where the Services or a product operate under a Zero Data Retention posture as described in the Baseten Security Practices available at https://www.baseten.co/security-practices, Baseten does not log, record, or save Customer Content contained in inference inputs or outputs to persistent storage after real-time processing, subject to the limited exceptions described in the Security Practices. As a result, requested Customer Content may not exist in Baseten's systems. Baseten cannot produce data it does not retain, and this Policy does not obligate Baseten to begin retaining data in the absence of valid legal process requiring preservation.
Questions about this Policy? Contact legal@baseten.co.