WASH AI Logo

Privacy Policy

Version: 3.0
Effective Date: 28 September 2026
Replaces: Privacy Policy version 2.0 of 30 April 2026


1. Who we are

WASH AI is operated by Baobab Tech, a trading name of Mills IT Consulting Ltd., a company incorporated in Alberta, Canada under Corporate Access Number 2019455316, whose registered office is at 2836 29 St SW, Calgary, Alberta, Canada ("Baobab Tech", "we", "us", "our").

This policy covers all WASH AI interfaces: the web application and WhatsApp.

Contact:
General queries and security reports: support@washai.org
Privacy and data-subject requests: privacy@washai.org
EU representative under Article 27 GDPR: to be appointed. Until one is appointed, EU data subjects can send GDPR enquiries to privacy@washai.org.


2. Tenants and our role

WASH AI is organised into tenants. Each tenant is a space with its own users, documents and settings.

  • Public tenant. Free and open to any individual. Baobab Tech runs it and is the controller of its users' personal data.
  • Open tenants. Spaces run with partner organisations that any WASH AI user can access. Baobab Tech is the controller of users' personal data in open tenants.
  • Private tenants. Spaces for organisations that hold an institutional subscription. Only users the organisation authorises can access them. The organisation is the controller of its users' personal data, and Baobab Tech is its processor under the Data Processing Agreement. If you use a private tenant, direct privacy requests to your organisation; we forward any request we receive to it.

Private-tenant users can also query the public knowledge base. Documents marked private in a private tenant are used only within that tenant.

Baobab Tech is also the controller of business contact and billing data about the staff of subscribing organisations.


3. Personal data we collect

3.1 Account data. Name, email address, organisation, role, country office and preferred language. On WhatsApp, your phone number.

3.2 Authentication data. You sign in to the web application with a one-time passcode sent to your email, or with Google or LinkedIn. We do not store passwords. With Google or LinkedIn, we receive only the identity attributes that provider releases to us (usually name, email and profile picture).

3.3 Conversation data. Your prompts, the responses, the AI model that served each request, conversation titles, timestamps, and any feedback you give (ratings and comments).

3.4 Uploaded documents. Documents that you or your tenant administrators upload, including any personal data they contain.

3.5 Technical data. Truncated IP address, device and browser type, session identifiers, error logs, performance metrics and feature-usage events.

3.6 Communications. Correspondence with our support and privacy mailboxes.

Do not submit special category data (such as health, ethnicity or religious belief), criminal offence data, or personal data about children. We do not filter input for this data. If we learn that it has been submitted, we delete it unless the law requires us to keep it.


4. How we use personal data and lawful bases

This table covers processing for which Baobab Tech is the controller. In private tenants, we process personal data only on the organisation's instructions.

PurposeLawful basis (Article 6 GDPR)
Creating and managing your accountContract (Art. 6(1)(b))
Answering your queries, including AI inference, document retrieval, web search and translationContract (Art. 6(1)(b))
Securing the service and preventing abuseLegitimate interests (Art. 6(1)(f))
Diagnosing errors and monitoring quality through observability tracesLegitimate interests (Art. 6(1)(f))
Product analytics and anonymised, aggregated sector-level reportingLegitimate interests (Art. 6(1)(f)), or consent where required
Operational emails (one-time passcodes, service notices, breach notifications)Contract / legal obligation (Art. 6(1)(c))
Product-update emailsConsent (Art. 6(1)(a))
Complying with legal obligationsLegal obligation (Art. 6(1)(c))

We do not sell personal data, use it for advertising, or use your prompts, outputs or uploaded documents to train or fine-tune AI models.


5. AI models and data flow

5.1 Public and open tenants. You choose a response mode: Fast, Smart or Deep. Baobab Tech chooses the model and provider behind each mode and changes them over time, weighing carbon footprint, data protection and cost. Inference runs through Google Cloud Vertex AI or the Vercel AI Gateway, which forwards requests to the model's provider. Depending on the model, inference may be processed outside the EU and UK, including in the United States. We keep a record of the model that served each request.

5.2 Private tenants. The organisation's Order Form sets which models, providers and processing regions its inference may use (its Model Configuration). We enforce this server-side, and users in the tenant cannot select a model. An organisation can require all inference to stay in the EU.

5.3 Commitments for every model. We contract with model providers on terms that exclude training on your data and, where the provider offers it, exclude data retention (zero data retention).

5.4 Other processing steps.

  • Supporting tasks. Conversation titles, expert-request extraction and query embeddings are processed by EU-owned providers through EUrouter, or, for tenants that do not require EU or UK processing, by Voyage AI in the United States.
  • Web search. Where a tenant enables it and no relevant document is found in the knowledge base, your query is sent to Tavily (United States).
  • WhatsApp. Messages pass through Meta's WhatsApp Cloud API. Machine translation on WhatsApp is performed by Lara (Translated S.r.l., Italy).
  • Document ingest. Uploaded documents are converted on servers Baobab Tech owns and operates in Canada. These servers hold temporary copies and delete them when each ingest job completes.

6. Sharing and subprocessors

We share personal data only with:

  • Subprocessors that operate parts of the service, bound by data protection terms (listed below);
  • The organisation that runs your tenant, where you use a private tenant;
  • Professional advisers (lawyers, auditors, accountants) bound by confidentiality;
  • Authorities and courts where the law requires it;
  • A successor in a merger, reorganisation or sale of assets, under equivalent protections.

6.1 Subprocessors

This list applies to all tenants.

Last updated: 25 September 2026.

SubprocessorServiceProcessing locationTransfer mechanism
Vercel Inc.Application hosting and serverless functionsEU (Frankfurt)SCCs and UK Addendum, for incidental control-plane access
Neon Inc.Primary database and text search index, and Supplier document pipeline databaseEU (Frankfurt)SCCs and UK Addendum, for incidental control-plane access
Cloudflare Inc. (R2)Document storageEU jurisdictionSCCs and UK Addendum, for incidental control-plane access
Google Cloud (Vertex AI)Chat inference; optical character recognition fallback during document ingestEU (europe-west4, Netherlands)Not required
EUrouter B.V.Conversation titles, expert-request extraction, and query embedding (bge-m3). Constrained per request to EU-owned providers with no retention and no training. Routes to Mistral AI, Scaleway, IONOS, OVHcloud and GreenPTEU (Netherlands)Not required
Translated S.r.l. (Lara)Machine translation on the WhatsApp channelEU (Italy)Not required
Langfuse (EU cloud)Observability traces, including prompts and outputs, retained up to 90 daysEUNot required
TavilyWeb search, where the Tenant enables it and where no relevant document is found in the knowledge baseUnited StatesSCCs and UK Addendum
PostmarkOne-time passcodes and notification emails with minimal contentUnited StatesSCCs and UK Addendum
Meta Platforms Ireland / Meta Platforms Inc. (WhatsApp Cloud API)WhatsApp messaging, where the Tenant enables itUnited StatesSCCs and UK Addendum
Vercel Inc. (analytics and monitoring)Product analytics and error monitoringMulti-regionSCCs and UK Addendum
Voyage AI (MongoDB, Inc.)Query embedding for Tenants not requiring EU or UK data processingUnited StatesSCCs and UK Addendum

6.2 Additional subprocessors for public and open tenants

SubprocessorServiceProcessing locationTransfer mechanism
Vercel Inc. (AI Gateway)Routing inference requests to model providersMulti-regionSCCs and UK Addendum
Model providers reached through Google Cloud Vertex AI or the Vercel AI GatewayChat inference for the Fast, Smart and Deep modesVaries by model; may include the United StatesSCCs and UK Addendum where the provider is outside the EU/UK

Subscribing organisations receive notice of subprocessor changes under paragraph 5 of the Data Processing Agreement.


7. Location and international transfers

We store conversation data, account data and documents at rest in the European Union (primary database in Frankfurt; document storage under EU jurisdiction).

Personal data is processed outside the UK and the EEA:

  • during document ingest on our servers in Canada (temporary copies only);
  • by our personnel and contractors in Canada and elsewhere, for support and maintenance;
  • by the subprocessors in section 6 located outside the UK and the EEA.

Transfers to Canada and the UK rely on adequacy decisions. Other transfers rely on the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) and the UK International Data Transfer Addendum. A summary of our transfer impact assessments is available from privacy@washai.org.


8. Retention

CategoryRetention period
Conversation history, public and open tenantsUntil you delete it or close your account
Conversation history, private tenantsUntil the user or the organisation deletes it, or for the retention period the organisation sets in its Order Form. Deleted within 30 days after the organisation's 30-day exit period ends
Observability traces (include prompts and outputs)Up to 90 days
Temporary document copies on ingest serversDeleted when each ingest job completes
Account dataDuration of the account, plus 12 months after closure
Security and audit logsUp to 12 months
Support correspondenceUp to 24 months from last contact
Billing records for subscribing organisationsAs required by tax and accounting law
Database point-in-time recovery history24 hours, then overwritten

9. Your rights

Subject to the GDPR, the UK GDPR, Canadian privacy law and equivalent regimes, you have the right to:

  • access the personal data we hold about you;
  • rectify inaccurate or incomplete data;
  • erase your data, subject to legal retention requirements;
  • restrict processing in certain circumstances;
  • data portability for data you provided that we process by automated means on the basis of contract or consent;
  • object to processing based on legitimate interests;
  • withdraw consent at any time, without affecting earlier processing;
  • not be subject to solely automated decisions with legal or similarly significant effects;
  • lodge a complaint with a supervisory authority, in particular where you live or work, or where the alleged infringement took place.

Write to privacy@washai.org to exercise these rights. We respond within one month, extendable by two months for complex requests. If you use a private tenant, we forward your request to the organisation that runs it within five business days.


10. Security

We apply the following technical and organisational measures:

  • Encryption in transit (TLS 1.2 or higher) and at rest (AES-256)
  • Logical separation of each tenant's data by tenant identifier
  • Email one-time passcode login and social login (Google, LinkedIn) for Authorised Users; role-based access control
  • Multi-factor authentication for all staff and contractors with production access
  • Database network access controls
  • Audit logging of administrative actions, including a record of the AI model that served each request
  • Server-side enforcement of each Tenant's Model Configuration, with model selection not exposed to that Tenant's Authorised Users
  • Vulnerability management and weekly security patching
  • Secure development practices, including code review
  • Primary database and text search index hosted in the European Union, with point-in-time recovery history retained for 24 hours
  • External uptime monitoring
  • Document ingest servers operated by the Supplier, with temporary copies deleted after each job
  • Confidentiality obligations for all staff and contractors
  • Data protection due diligence on Subprocessors

We notify personal data breaches that present a risk to individuals to the relevant supervisory authority within 72 hours of becoming aware of them, and to affected users without undue delay where the risk is high. Organisations with private tenants are notified within 48 hours.

Report a suspected security issue to support@washai.org.


11. Cookies

  • Strictly necessary: authentication, session management and security. These do not require consent.
  • Functional: remembering your language and interface preferences.
  • Analytics: measuring feature usage to improve the service.

We use no advertising or cross-site tracking cookies. Non-essential cookies are set only after you opt in.


12. Age

WASH AI is for professional and academic use by adults. You must be 18 or older to use it. If we learn that a child has provided personal data, we delete it.


13. EU AI Act transparency

WASH AI is an AI system under Regulation (EU) 2024/1689 (the EU AI Act). You are told that you are interacting with an AI, and AI-generated content is labelled as such, in line with Article 50. WASH AI is not deployed for any high-risk use listed in Annex III. An organisation that intends to use WASH AI in a high-risk workflow must agree governance arrangements with us in advance.


14. Digital Services Act

Where WASH AI falls within Regulation (EU) 2022/2065 (the Digital Services Act), we maintain:

  • a single point of contact for authorities and users (Articles 11 and 12): support@washai.org;
  • a notice-and-action mechanism for illegal content (Article 16): support@washai.org;
  • internal complaint handling (Article 20);
  • transparency reporting where applicable (Article 15);
  • measures to protect minors (Article 28), by restricting use to adults.

WASH AI is not a Very Large Online Platform under Article 33.


15. Automated decision-making

WASH AI generates answers to your queries. It makes no automated decisions with legal or similarly significant effects on you under Article 22 GDPR. It is a decision-support tool, and you remain responsible for decisions you take based on its outputs.


16. Changes to this policy

We notify material changes through the WASH AI interface or by email at least 30 days before they take effect, unless the law requires a shorter period. Earlier versions are available on request.


17. Contact

Baobab Tech (Mills IT Consulting Ltd.)
2836 29 St SW, Calgary, Alberta, Canada
General queries and security reports: support@washai.org
Privacy and data-subject requests: privacy@washai.org

You can lodge a complaint with your local data protection supervisory authority at any time.


© 2026 Baobab Tech (Mills IT Consulting Ltd.). All rights reserved.