Last updated: September 7, 2026
Effective date: September 7, 2026
BasilAI Ltd., or the ShieldON service provider identified in your order or signed agreement (ShieldON, we, us or our), respects your privacy. This policy explains how we collect, use, disclose and protect personal information when you visit our website, request a demonstration or pilot, create an account, or use our hosted services, APIs, console, documentation or support (the Services).
Read this policy together with the ShieldON Terms of Service, your applicable order and any data processing agreement (DPA).
1. Scope and our roles
For website visitors, prospective customers, customer contacts and account users, we generally act as a controller or equivalent under applicable law, determining the purposes and means of processing.
For personal information customers submit through hosted Services, customers generally determine those purposes and means. We process it on their behalf as a processor or service provider under the relevant DPA or commercial agreement.
Your organization may manage your account and access work-related data. It is responsible for its own processing. For private or offline deployments, data generally remains in the customer's environment. We generally do not receive business data unless the customer supplies support materials, enables a feature connected to us, or agrees otherwise in a commercial agreement.
For requests concerning data controlled by your employer or another ShieldON customer, contact that organization's administrator first. We will assist the customer as required by law and our agreement.
This policy does not govern independent processing by third-party AI providers, customer-connected systems or third-party websites and services. Their own policies apply.
2. Information we collect or process
2.1 Information you provide
- Identity and contact information: name, work email, role, company, country or region and other contact details you provide.
- Account and organization information: display name, login identifiers, securely hashed passwords, organization and workspace membership, roles, permissions and preferences.
- Sales, pilot and support information: requests, correspondence, tickets, feedback, meeting records and diagnostic materials you voluntarily supply.
- Transaction and contract information: orders, plans, billing contacts, payment status, tax and contract records. Payment providers generally process card details directly; any provider we introduce will be identified in the relevant interface or subprocessor information.
- Service configuration: organizations, workspaces, model catalogs, provider integrations, routing, limits, budgets, versions, releases, safeguards, IP allowlists and metadata rules.
2.2 AI gateway content
Depending on customer use and configuration, request processing may involve prompts, system messages, conversations, files, images, audio and other inputs; model outputs, streamed responses, embedding vectors and tool-call data; customer-defined application, environment, team, project, customer, user, feature or session metadata; and provider, model, routing, retry, fallback and policy-decision information.
Default content retention: ShieldON's default product design does not persist prompts, model outputs or embedding vectors. Unless the customer expressly enables retention, requests handling of support materials, a commercial agreement provides otherwise or law requires otherwise, content is processed temporarily to complete requests, apply security checks and return results.
Administrators should assess actual data flows and retention against their configuration, deployment and selected providers. This default applies only to ShieldON's own processing; it does not determine third-party providers' retention, training or other data-use rules.
2.3 Usage, audit and technical information
To operate and protect the Services, we may process:
- Request identifiers, API key prefixes or internal identifiers, organizations, workspaces, configurations, releases, models, providers, status codes and error categories.
- Timestamps, token counts, credits or costs, latency, routing chains, attempts, and limit or budget decisions.
- Non-sensitive metadata the customer permits us to index, and safeguard match categories and outcomes.
- IP addresses, browser or client types, operating systems, device details, access times, request paths, session events, diagnostic logs and security events.
- Audit records of logins and changes to membership, credentials, configurations, policies, releases, rollbacks and other governance actions.
By default, ordinary logs and audit summaries are designed not to contain provider secrets, plaintext API keys, prompts, model outputs, embedding vectors or metadata marked sensitive. Credentials may be stored encrypted where necessary to provide the Services, or only as irreversible hashes, salts and prefixes, as appropriate.
2.4 Cookies and similar technologies
We use cookies or similar technologies necessary for login sessions, security and language or interface preferences. The current product design gives console session cookies a maximum life of seven days; logout, administrator action or security events may invalidate them earlier.
Where we use non-essential analytics, personalization or advertising cookies, we will provide the notices and choices required by applicable law before setting them. You can manage cookies through browser settings and the preference controls we provide when using optional cookies. Blocking necessary cookies may prevent login or impair functionality.
We do not sell personal information or share it for cross-context behavioral advertising. If this changes, we will update this policy and provide legally required opt-out choices before the change.
3. Information sources
We may receive information from you; your organization, administrators, colleagues or authorized partners; configured applications, API clients, identity systems, AI providers or integrations; service operation, security, audit and diagnostic processes; and public sources or business partners lawfully supplying information.
4. Purposes and legal bases
When acting as controller, we rely on the following bases where recognized by applicable law. Contractual necessity applies only where processing is necessary for a contract with the individual, or steps they request before entering one. For business contacts and users, we may instead rely on legitimate interests in operating and supporting enterprise services. Legitimate interests apply only where the relevant law recognizes that basis. When processing for a customer, we follow its lawful instructions and DPA; the customer determines its own legal basis.
| Purpose | Typical information | Basis or processing role, where applicable |
|---|---|---|
| Provide, configure and maintain Services | Account, organization, configuration, AI requests, usage | Contract; legitimate interests in enterprise service provision; lawful customer instructions when acting as processor |
| Authenticate and manage access | Login identifiers, password hashes, sessions, roles, key identifiers, IP addresses | Contract; legitimate interests in account administration and security |
| Route requests to selected providers | Inputs, outputs, configuration, necessary metadata | Contract; legitimate interests in enterprise service provision; lawful customer instructions when acting as processor |
| Metering, budgets, analytics and reporting | Tokens, costs, models, providers, permitted metadata | Contract; legitimate interests in improving Services |
| Security, abuse prevention, diagnostics and auditing | IP addresses, logs, policy decisions, audit events, support materials | Legitimate interests in security and reliable operation; legal obligations |
| Support and business communications | Contacts, tickets, feedback, pilot and contract information | Contract or pre-contractual steps; legitimate interests in responding to inquiries and managing customer relationships |
| Product improvement and development | De-identified or aggregated usage, feedback, diagnostics | Legitimate interests in improving Services; consent where required |
| Legal compliance and protection of rights | Relevant account, log and contract records | Legal obligations; establishment, exercise or defense of legal claims |
When relying on legitimate interests, we consider necessity, effects on individuals and reasonable expectations. We do not use customer prompts, model outputs or other Customer Data to train our or third parties' general-purpose AI models unless the customer separately and expressly opts in in writing and has the necessary rights.
We do not make decisions solely through ShieldON's automated processing that have legal or similarly significant effects on individuals. Customers configuring automated workflows must assess and meet their own notice, lawful-basis and human-review obligations.
5. Disclosure
We may disclose information as necessary to:
- Customers and authorized users: relevant administrators, workspace members and authorized personnel receiving account, usage, log or audit information.
- Customer-selected providers and integrations: AI requests and necessary metadata sent, and outputs received, under customer instructions.
- Service providers and subprocessors: suppliers of hosting, networking, databases, object storage, email, support, security monitoring, diagnostics and other operational services.
- Professional advisers: lawyers, auditors, insurers, banks and other advisers subject to confidentiality obligations.
- Authorities or others: where we believe in good faith disclosure is necessary to comply with legal process, protect rights or safety, investigate fraud or prevent abuse.
- Business transaction participants: potential or actual parties to financing, mergers, acquisitions, reorganizations, insolvency or business or asset sales, subject to appropriate confidentiality safeguards.
Providers processing on our behalf must follow our instructions and apply appropriate safeguards. You may request subprocessor information relevant to your Services using our contact email. Any notice, authorization or objection requirements under applicable law or a DPA apply.
6. International transfers
Depending on hosting regions, configuration, providers and support arrangements, information may be transferred outside your country to countries with different privacy laws.
Where required, we use recognized mechanisms and supplementary safeguards, such as adequacy decisions, EU standard contractual clauses, the UK international data transfer addendum or agreement, and necessary technical and organizational measures. Hosting regions and data residency commitments are governed by the commercial agreement.
Customers with private or offline deployments are responsible for assessing transfers caused by their configured providers, integrations, remote support and other outbound connections.
7. Security
We apply risk-appropriate technical and organizational measures, including access controls, least privilege, encryption in transit, credential protection, auditing, tenant isolation, log minimization, vulnerability management and incident response.
Product design includes encrypted provider credentials; plaintext API keys shown only at creation or rotation; storage of necessary hashes or prefixes for API keys; HttpOnly and SameSite attributes for session cookies; and restrictions on sensitive fields in ordinary logs. Availability of controls and allocation of responsibilities depend on the version, deployment and commercial agreement.
No transmission or storage system is absolutely secure. If you suspect account or data exposure, contact us promptly and revoke or rotate potentially affected credentials.
8. Retention and deletion
We retain information only as necessary for the purposes described, contractual performance, security and auditing, dispute resolution and legal obligations. Retention depends on the information, configuration, deployment, risks and legal requirements.
| Information | Retention criteria |
|---|---|
| Website inquiries, demonstrations and pilot communications | As needed to respond, follow up on pilots or maintain the relevant business contact; then deleted or anonymized unless legal or dispute needs require retention |
| Account, membership and organization information | During the account or business relationship; afterward, deleted or anonymized when closure, data return and necessary security and legal matters are completed |
| Console sessions | Up to seven days, or earlier on logout, revocation or security invalidation |
| Prompts, model outputs and embeddings | Not persisted by default; if retention is expressly enabled, the configured, ordered or DPA-agreed period applies |
| Usage and request logs | Determined by configuration or agreement and the period needed for usage reconciliation, troubleshooting and security investigation; deleted or anonymized when no longer needed |
| Governance and security audit records | Determined by agreement, statutory retention duties and the period needed for related incidents, audits or disputes |
| Provider credentials and API keys | Necessary encrypted values, hashes or prefixes while the integration or key is active; secure deletion procedures apply after revocation or deletion |
| Support materials | As needed to resolve tickets, verify fixes and address related issues; customers may request earlier deletion of unnecessary attachments |
| Contract, billing and tax records | For the period required by applicable law |
| Backups | Overwritten or securely deleted through applicable backup rotation and disaster recovery procedures after deletion from active systems; pending backups are protected and isolated from ordinary business processing |
When information is no longer needed, we delete or irreversibly anonymize it, or isolate it while a legal retention period or backup cycle runs its course. Legally retained information is used only for the required purposes and duration. Customers control deletion and backup cycles in private deployments unless otherwise agreed.
9. Your privacy rights
Depending on applicable law, you may have rights to information, access and copies; correction; deletion; restriction or objection; portability; withdrawal of consent without affecting earlier lawful processing; objection to solely automated decisions with significant effects; non-discrimination for exercising rights; and complaints to a competent privacy authority.
Direct marketing: You may object to processing for direct marketing at any time, using an unsubscribe option in the message or contacting us below.
Send requests to hello@shieldon.ai. We may verify your identity and authority. Authorized agents may need to provide proof of authorization.
Where we act for a customer, we may refer your request to it or ask you to contact it. We respond within applicable legal deadlines. Where law permits, we may limit or refuse manifestly unfounded or excessive requests, or requests subject to an exception, and explain why.
10. California and certain other US states
Where state privacy laws apply, Section 2 may cover identifiers, customer records, internet or electronic network activity, commercial information, professional information, approximate location inferred from IP addresses and inferences from these categories.
We collect, use and disclose these categories for the purposes in Section 4 to the recipients in Section 5. We do not sell personal information or share it for cross-context behavioral advertising, and do not knowingly sell or share information about people under 16.
Eligible residents may request information, access, correction, deletion or a copy, and appeal a refusal where applicable. Use the contact in Section 9. Before any future practice constituting a legally defined sale or sharing begins, we will provide required notices and opt-out mechanisms.
11. Mainland China
Where the Personal Information Protection Law of the People's Republic of China or related rules apply:
- We follow principles of lawfulness, fairness, necessity, good faith and minimum necessary retention, and explain purposes, methods, categories, retention and rights channels clearly.
- Consent may be withdrawn. Processing requiring separate or written consent will occur only after that consent is obtained.
- Where we determine the processing of sensitive personal information, we explain its necessity and effects on individual rights and apply strict safeguards.
- For transfers outside mainland China, we complete applicable security assessments, certifications, standard contracts or other required procedures, provide required overseas-recipient information and obtain separate consent where necessary.
- You may exercise applicable rights of access, copying, correction, supplementation, deletion, restriction or refusal, explanation of processing rules, withdrawal of consent and account closure.
- Where law requires a mainland institution or representative, we will publish and submit the required details.
Customers generally determine the purposes and means of their processing. They are responsible for notices, identification of sensitive information and information about children under 14, required consent, personal information protection impact assessments, and lawful provider, location and transfer choices. We provide reasonable assistance under the DPA and lawful instructions.
12. Children
The Services are intended for businesses and professional users, not people under 18. We do not knowingly collect children's personal information. Contact us if you believe a child has supplied it; we will investigate and take appropriate deletion measures.
Customers must not process children's personal information through the Services without the required lawful basis, notices, consent and safeguards.
13. Third-party links and services
Links or integrations may lead to independent websites, AI providers or services. We do not control, or take responsibility for, their independent privacy practices. Review their terms and privacy policies before enabling integrations or sending data.
14. Changes to this policy
We may update this policy to reflect changes in the Services, law or processing. We will update the dates above and give reasonable notice before material changes take effect through the website, in-service notices or account contact details. Where consent is required, we will obtain it before the new processing begins.
15. Contact
For privacy questions, rights requests or concerns, contact:
BasilAI Ltd. / ShieldON
Privacy email: hello@shieldon.ai
You may complain to the competent data protection or privacy authority in your jurisdiction if you are dissatisfied with our response.