Privacy Policy
Version: 3.0
Effective Date: 28 September 2026
Replaces: Privacy Policy version 2.0 of 30 April 2026
1. Who we are
WASH AI is operated by Baobab Tech, a trading name of Mills IT Consulting Ltd., a company incorporated in Alberta, Canada under Corporate Access Number 2019455316, whose registered office is at 2836 29 St SW, Calgary, Alberta, Canada ("Baobab Tech", "we", "us", "our").
This policy covers all WASH AI interfaces: the web application and WhatsApp.
Contact:
General queries and security reports: support@washai.org
Privacy and data-subject requests: privacy@washai.org
EU representative under Article 27 GDPR: to be appointed. Until one is appointed, EU data subjects can send GDPR enquiries to privacy@washai.org.
2. Tenants and our role
WASH AI is organised into tenants. Each tenant is a space with its own users, documents and settings.
- Public tenant. Free and open to any individual. Baobab Tech runs it and is the controller of its users' personal data.
- Open tenants. Spaces run with partner organisations that any WASH AI user can access. Baobab Tech is the controller of users' personal data in open tenants.
- Private tenants. Spaces for organisations that hold an institutional subscription. Only users the organisation authorises can access them. The organisation is the controller of its users' personal data, and Baobab Tech is its processor under the Data Processing Agreement. If you use a private tenant, direct privacy requests to your organisation; we forward any request we receive to it.
Private-tenant users can also query the public knowledge base. Documents marked private in a private tenant are used only within that tenant.
Baobab Tech is also the controller of business contact and billing data about the staff of subscribing organisations.
3. Personal data we collect
3.1 Account data. Name, email address, organisation, role, country office and preferred language. On WhatsApp, your phone number.
3.2 Authentication data. You sign in to the web application with a one-time passcode sent to your email, or with Google or LinkedIn. We do not store passwords. With Google or LinkedIn, we receive only the identity attributes that provider releases to us (usually name, email and profile picture).
3.3 Conversation data. Your prompts, the responses, the AI model that served each request, conversation titles, timestamps, and any feedback you give (ratings and comments).
3.4 Uploaded documents. Documents that you or your tenant administrators upload, including any personal data they contain.
3.5 Technical data. Truncated IP address, device and browser type, session identifiers, error logs, performance metrics and feature-usage events.
3.6 Communications. Correspondence with our support and privacy mailboxes.
Do not submit special category data (such as health, ethnicity or religious belief), criminal offence data, or personal data about children. We do not filter input for this data. If we learn that it has been submitted, we delete it unless the law requires us to keep it.
4. How we use personal data and lawful bases
This table covers processing for which Baobab Tech is the controller. In private tenants, we process personal data only on the organisation's instructions.
| Purpose | Lawful basis (Article 6 GDPR) |
|---|---|
| Creating and managing your account | Contract (Art. 6(1)(b)) |
| Answering your queries, including AI inference, document retrieval, web search and translation | Contract (Art. 6(1)(b)) |
| Securing the service and preventing abuse | Legitimate interests (Art. 6(1)(f)) |
| Diagnosing errors and monitoring quality through observability traces | Legitimate interests (Art. 6(1)(f)) |
| Product analytics and anonymised, aggregated sector-level reporting | Legitimate interests (Art. 6(1)(f)), or consent where required |
| Operational emails (one-time passcodes, service notices, breach notifications) | Contract / legal obligation (Art. 6(1)(c)) |
| Product-update emails | Consent (Art. 6(1)(a)) |
| Complying with legal obligations | Legal obligation (Art. 6(1)(c)) |
We do not sell personal data, use it for advertising, or use your prompts, outputs or uploaded documents to train or fine-tune AI models.
5. AI models and data flow
5.1 Public and open tenants. You choose a response mode: Fast, Smart or Deep. Baobab Tech chooses the model and provider behind each mode and changes them over time, weighing carbon footprint, data protection and cost. Inference runs through Google Cloud Vertex AI or the Vercel AI Gateway, which forwards requests to the model's provider. Depending on the model, inference may be processed outside the EU and UK, including in the United States. We keep a record of the model that served each request.
5.2 Private tenants. The organisation's Order Form sets which models, providers and processing regions its inference may use (its Model Configuration). We enforce this server-side, and users in the tenant cannot select a model. An organisation can require all inference to stay in the EU.
5.3 Commitments for every model. We contract with model providers on terms that exclude training on your data and, where the provider offers it, exclude data retention (zero data retention).
5.4 Other processing steps.
- Supporting tasks. Conversation titles, expert-request extraction and query embeddings are processed by EU-owned providers through EUrouter, or, for tenants that do not require EU or UK processing, by Voyage AI in the United States.
- Web search. Where a tenant enables it and no relevant document is found in the knowledge base, your query is sent to Tavily (United States).
- WhatsApp. Messages pass through Meta's WhatsApp Cloud API. Machine translation on WhatsApp is performed by Lara (Translated S.r.l., Italy).
- Document ingest. Uploaded documents are converted on servers Baobab Tech owns and operates in Canada. These servers hold temporary copies and delete them when each ingest job completes.
6. Sharing and subprocessors
We share personal data only with:
- Subprocessors that operate parts of the service, bound by data protection terms (listed below);
- The organisation that runs your tenant, where you use a private tenant;
- Professional advisers (lawyers, auditors, accountants) bound by confidentiality;
- Authorities and courts where the law requires it;
- A successor in a merger, reorganisation or sale of assets, under equivalent protections.
6.1 Subprocessors
This list applies to all tenants.
Last updated: 25 September 2026.
| Subprocessor | Service | Processing location | Transfer mechanism |
|---|---|---|---|
| Vercel Inc. | Application hosting and serverless functions | EU (Frankfurt) | SCCs and UK Addendum, for incidental control-plane access |
| Neon Inc. | Primary database and text search index, and Supplier document pipeline database | EU (Frankfurt) | SCCs and UK Addendum, for incidental control-plane access |
| Cloudflare Inc. (R2) | Document storage | EU jurisdiction | SCCs and UK Addendum, for incidental control-plane access |
| Google Cloud (Vertex AI) | Chat inference; optical character recognition fallback during document ingest | EU (europe-west4, Netherlands) | Not required |
| EUrouter B.V. | Conversation titles, expert-request extraction, and query embedding (bge-m3). Constrained per request to EU-owned providers with no retention and no training. Routes to Mistral AI, Scaleway, IONOS, OVHcloud and GreenPT | EU (Netherlands) | Not required |
| Translated S.r.l. (Lara) | Machine translation on the WhatsApp channel | EU (Italy) | Not required |
| Langfuse (EU cloud) | Observability traces, including prompts and outputs, retained up to 90 days | EU | Not required |
| Tavily | Web search, where the Tenant enables it and where no relevant document is found in the knowledge base | United States | SCCs and UK Addendum |
| Postmark | One-time passcodes and notification emails with minimal content | United States | SCCs and UK Addendum |
| Meta Platforms Ireland / Meta Platforms Inc. (WhatsApp Cloud API) | WhatsApp messaging, where the Tenant enables it | United States | SCCs and UK Addendum |
| Vercel Inc. (analytics and monitoring) | Product analytics and error monitoring | Multi-region | SCCs and UK Addendum |
| Voyage AI (MongoDB, Inc.) | Query embedding for Tenants not requiring EU or UK data processing | United States | SCCs and UK Addendum |
6.2 Additional subprocessors for public and open tenants
| Subprocessor | Service | Processing location | Transfer mechanism |
|---|---|---|---|
| Vercel Inc. (AI Gateway) | Routing inference requests to model providers | Multi-region | SCCs and UK Addendum |
| Model providers reached through Google Cloud Vertex AI or the Vercel AI Gateway | Chat inference for the Fast, Smart and Deep modes | Varies by model; may include the United States | SCCs and UK Addendum where the provider is outside the EU/UK |
Subscribing organisations receive notice of subprocessor changes under paragraph 5 of the Data Processing Agreement.
7. Location and international transfers
We store conversation data, account data and documents at rest in the European Union (primary database in Frankfurt; document storage under EU jurisdiction).
Personal data is processed outside the UK and the EEA:
- during document ingest on our servers in Canada (temporary copies only);
- by our personnel and contractors in Canada and elsewhere, for support and maintenance;
- by the subprocessors in section 6 located outside the UK and the EEA.
Transfers to Canada and the UK rely on adequacy decisions. Other transfers rely on the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) and the UK International Data Transfer Addendum. A summary of our transfer impact assessments is available from privacy@washai.org.
8. Retention
| Category | Retention period |
|---|---|
| Conversation history, public and open tenants | Until you delete it or close your account |
| Conversation history, private tenants | Until the user or the organisation deletes it, or for the retention period the organisation sets in its Order Form. Deleted within 30 days after the organisation's 30-day exit period ends |
| Observability traces (include prompts and outputs) | Up to 90 days |
| Temporary document copies on ingest servers | Deleted when each ingest job completes |
| Account data | Duration of the account, plus 12 months after closure |
| Security and audit logs | Up to 12 months |
| Support correspondence | Up to 24 months from last contact |
| Billing records for subscribing organisations | As required by tax and accounting law |
| Database point-in-time recovery history | 24 hours, then overwritten |
9. Your rights
Subject to the GDPR, the UK GDPR, Canadian privacy law and equivalent regimes, you have the right to:
- access the personal data we hold about you;
- rectify inaccurate or incomplete data;
- erase your data, subject to legal retention requirements;
- restrict processing in certain circumstances;
- data portability for data you provided that we process by automated means on the basis of contract or consent;
- object to processing based on legitimate interests;
- withdraw consent at any time, without affecting earlier processing;
- not be subject to solely automated decisions with legal or similarly significant effects;
- lodge a complaint with a supervisory authority, in particular where you live or work, or where the alleged infringement took place.
Write to privacy@washai.org to exercise these rights. We respond within one month, extendable by two months for complex requests. If you use a private tenant, we forward your request to the organisation that runs it within five business days.
10. Security
We apply the following technical and organisational measures:
- Encryption in transit (TLS 1.2 or higher) and at rest (AES-256)
- Logical separation of each tenant's data by tenant identifier
- Email one-time passcode login and social login (Google, LinkedIn) for Authorised Users; role-based access control
- Multi-factor authentication for all staff and contractors with production access
- Database network access controls
- Audit logging of administrative actions, including a record of the AI model that served each request
- Server-side enforcement of each Tenant's Model Configuration, with model selection not exposed to that Tenant's Authorised Users
- Vulnerability management and weekly security patching
- Secure development practices, including code review
- Primary database and text search index hosted in the European Union, with point-in-time recovery history retained for 24 hours
- External uptime monitoring
- Document ingest servers operated by the Supplier, with temporary copies deleted after each job
- Confidentiality obligations for all staff and contractors
- Data protection due diligence on Subprocessors
We notify personal data breaches that present a risk to individuals to the relevant supervisory authority within 72 hours of becoming aware of them, and to affected users without undue delay where the risk is high. Organisations with private tenants are notified within 48 hours.
Report a suspected security issue to support@washai.org.
11. Cookies
- Strictly necessary: authentication, session management and security. These do not require consent.
- Functional: remembering your language and interface preferences.
- Analytics: measuring feature usage to improve the service.
We use no advertising or cross-site tracking cookies. Non-essential cookies are set only after you opt in.
12. Age
WASH AI is for professional and academic use by adults. You must be 18 or older to use it. If we learn that a child has provided personal data, we delete it.
13. EU AI Act transparency
WASH AI is an AI system under Regulation (EU) 2024/1689 (the EU AI Act). You are told that you are interacting with an AI, and AI-generated content is labelled as such, in line with Article 50. WASH AI is not deployed for any high-risk use listed in Annex III. An organisation that intends to use WASH AI in a high-risk workflow must agree governance arrangements with us in advance.
14. Digital Services Act
Where WASH AI falls within Regulation (EU) 2022/2065 (the Digital Services Act), we maintain:
- a single point of contact for authorities and users (Articles 11 and 12): support@washai.org;
- a notice-and-action mechanism for illegal content (Article 16): support@washai.org;
- internal complaint handling (Article 20);
- transparency reporting where applicable (Article 15);
- measures to protect minors (Article 28), by restricting use to adults.
WASH AI is not a Very Large Online Platform under Article 33.
15. Automated decision-making
WASH AI generates answers to your queries. It makes no automated decisions with legal or similarly significant effects on you under Article 22 GDPR. It is a decision-support tool, and you remain responsible for decisions you take based on its outputs.
16. Changes to this policy
We notify material changes through the WASH AI interface or by email at least 30 days before they take effect, unless the law requires a shorter period. Earlier versions are available on request.
17. Contact
Baobab Tech (Mills IT Consulting Ltd.)
2836 29 St SW, Calgary, Alberta, Canada
General queries and security reports: support@washai.org
Privacy and data-subject requests: privacy@washai.org
You can lodge a complaint with your local data protection supervisory authority at any time.
© 2026 Baobab Tech (Mills IT Consulting Ltd.). All rights reserved.