BACI

PRIVACY POLICY

Version 1.0 · Effective Date: 10 September 2026 · Last Updated: 10 September 2026

BACI respects privacy and is committed to handling Personal Data responsibly, transparently and securely. This Privacy Policy explains how BACI LLC ("BACI", "we", "us" or "our") collects, uses, discloses, retains and otherwise processes Personal Data when BACI acts as a controller or business determining the purposes and means of processing. It also explains the rights and choices that may be available to individuals under applicable privacy and data-protection laws.

1. SCOPE

1.1 What This Policy Covers

This Privacy Policy applies to Personal Data BACI processes for its own business purposes in connection with BACI websites; BACI Accounts; BACI applications; sales and prospective-customer relationships; subscriptions and commercial relationships; billing and payment administration; support communications; BACI events, demonstrations and programmes; BACI marketing and communications; developer relationships; agency, adviser and partner relationships; affiliate programme administration; enterprise and public-sector relationships; suppliers and service providers; security, fraud prevention and compliance; recruitment and careers interactions, except where a separate candidate privacy notice applies; and other circumstances in which BACI determines the purposes and means of processing Personal Data.

1.2 Customer-Controlled Personal Data

This Privacy Policy does not govern Personal Data to the extent BACI processes that Personal Data solely on behalf of a Customer as a processor, service provider or equivalent role. In those circumstances, the Customer generally determines why and how the relevant Personal Data is processed; BACI processes the Personal Data according to the Agreement, Customer's documented instructions and Applicable Data Protection Law; BACI's Data Processing Addendum applies where applicable; and requests concerning that Personal Data may need to be directed to the relevant Customer. BACI will not use the distinction between controller and processor roles to avoid obligations imposed upon BACI by Applicable Data Protection Law.

1.3 BACI Legal Framework

This Privacy Policy forms part of the BACI Legal Framework. Depending upon the relevant relationship, additional documents may apply, including the Terms of Service; Data Processing Addendum; Cookie Policy; Security Policy or Security Addendum; Data Retention & Deletion Policy; Subprocessor Policy and List; International Data Transfer Addendum; Responsible AI Policy; AI & Autonomous Systems Terms; Developer & API Terms; and applicable regional, jurisdictional, product or commercial schedules. Where another BACI agreement expressly governs processing for a particular relationship, that document will apply according to the order of precedence established by the applicable Agreement.

2. WHO IS RESPONSIBLE FOR PERSONAL DATA

Unless an applicable Order, regional schedule or other agreement identifies another BACI entity, BACI LLC is responsible for Personal Data processed as controller under this Privacy Policy. BACI may establish Affiliates or regional entities as BACI expands internationally. Where another BACI entity becomes responsible for particular processing, BACI will identify that entity where required by Applicable Data Protection Law. Questions concerning this Privacy Policy may be directed to privacy@bacihq.com.

3. DEFINITIONS

For purposes of this Privacy Policy: "Applicable Data Protection Law" means privacy, data-protection, data-security and consumer-privacy laws applicable to relevant processing. "Customer" means a person or legal entity accessing, purchasing, subscribing to or using BACI Services. "Customer Data" has the meaning given in the BACI Terms of Service. "Personal Data" means information relating to an identified or identifiable individual, or information otherwise treated as personal data, personal information or an equivalent protected category under Applicable Data Protection Law. "Processing" means any operation performed upon Personal Data, including collection, recording, organisation, storage, alteration, retrieval, consultation, analysis, use, transmission, disclosure, combination, restriction, deletion or destruction. "Services" has the meaning given in the BACI Terms of Service. "Sensitive Personal Data" means Personal Data subject to enhanced protection under Applicable Data Protection Law, which may include information concerning health, biometric identifiers, precise geolocation, racial or ethnic origin, religious or philosophical beliefs, political opinions, sexual orientation, government identifiers, financial account credentials or other legally protected categories. "Usage Data" has the meaning given in the BACI Terms of Service.

4. PERSONAL DATA BACI MAY COLLECT

4.1 Identity Data

This may include name, username, account identifier, title, role, organisation, professional status and other information reasonably necessary to identify or authenticate an individual.

4.2 Contact Data

This may include email address, telephone number, business address, mailing address and communication preferences.

4.3 Organisation and Professional Data

This may include employer or organisation, job title, department, professional responsibilities, industry, business interests, organisation size, markets, commercial requirements and information relevant to a prospective or existing BACI commercial relationship.

4.4 Account and Authentication Data

This may include account identifiers, authentication information, login history, security events, authentication factors, permissions, organisation or workspace membership, administrator status and account recovery information. BACI should not receive or store a password in readable plaintext where BACI controls the authentication system.

4.5 Commercial and Transaction Data

This may include Services purchased, subscription information, plan, operating mode, Capacity, Order information, invoices, payment status, transaction identifiers, renewal information, credits, refunds, cancellations and commercial correspondence. Where payment credentials are submitted directly to an independent payment processor, BACI may receive transaction-related information without receiving complete payment-card credentials.

4.6 Technical and Device Data

This may include IP address, device identifiers, browser type, operating system, application version, language, time zone, network information, device characteristics, referring pages, timestamps and technical logs.

4.7 Usage and Interaction Data

This may include information about Services accessed, features used, pages viewed, navigation, searches, interactions, session activity, errors, performance, feature configuration and other operational use of BACI.

4.8 Communications Data

BACI may process communications sent to or received from BACI, including support requests, sales enquiries, contact forms, survey responses, feedback, correspondence, meeting information and other communications.

4.9 Marketing Data

This may include marketing preferences, communication engagement, campaign interaction, event participation, professional interests and information used to determine the relevance of BACI business communications.

4.10 Developer and Integration Data

Where an individual uses BACI developer functionality, BACI may process developer account information, API credential metadata, API activity, integration configuration, sandbox activity, authentication events, application identifiers, error and diagnostic information and information necessary to administer developer access.

4.11 Partner, Agency and Affiliate Data

BACI may process information concerning individuals acting for agencies, advisers, technology partners, affiliates, licensors, licensees, suppliers and other commercial counterparties.

4.12 Security and Compliance Data

BACI may process information reasonably necessary to authenticate users; protect Accounts; detect malicious activity; investigate abuse; prevent fraud; enforce contractual restrictions; investigate suspected security incidents; comply with sanctions or export-control requirements; respond to lawful governmental process; and protect BACI, Customers and third parties.

4.13 Recruitment Data

Where an individual applies to work with BACI, BACI may process information supplied through an application, including identity and contact information, CV or résumé, employment history, education, qualifications, professional experience, application responses, interview information and other information voluntarily provided during recruitment. BACI may issue a separate Candidate Privacy Notice as its recruitment programme develops.

5. SOURCES OF PERSONAL DATA

5.1 Directly From Individuals

For example, when an individual creates an Account, completes a form, purchases a Service, contacts BACI, requests access, attends an event, applies for a role, joins a programme, communicates with BACI or otherwise supplies information.

5.2 From Customers and Organisations

An organisation may provide Personal Data concerning its employees, contractors, representatives, administrators, Authorised Users or professional contacts.

5.3 Automatically

BACI may collect technical, device, security, cookie and Usage Data when Services or websites are accessed.

5.4 From Connected Services

Where an individual or Customer authorises an integration, BACI may receive information through that integration according to the authorisation and applicable contractual arrangements.

5.5 From Service Providers and Partners

BACI may receive Personal Data from providers assisting with matters such as payments, authentication, security, infrastructure, analytics, communications, sales, events and support.

5.6 From Publicly Available Sources

BACI may obtain professional or business-related information from lawful public sources. The fact that information is publicly accessible does not remove obligations that may apply to its processing.

5.7 From Licensed and Commercial Sources

BACI may receive information from data providers, partners or other sources where BACI has a lawful basis and appropriate rights to receive and process it.

6. HOW BACI USES PERSONAL DATA

6.1 Providing and Administering BACI

Including to establish Accounts, authenticate users, provide access, administer organisations and workspaces, process Orders, provide requested functionality, manage subscriptions, provide support and communicate operational information.

6.2 Operating and Improving BACI

Including to understand Service performance, diagnose problems, improve reliability, develop functionality, conduct quality assurance, perform capacity planning, understand legitimate product usage and improve user experience.

6.3 Security

Including to protect Accounts, detect attacks, identify suspicious activity, investigate security events, prevent unauthorised access, maintain audit information, enforce access controls and protect the integrity of BACI systems.

6.4 Fraud, Abuse and Misuse Prevention

Including to detect, investigate and prevent fraud, impersonation, credential abuse, unlawful activity, circumvention of Capacity or licensing restrictions, manipulation of BACI systems, malicious automation and violations of the Agreement.

6.5 Commercial Administration

Including to process purchases, issue invoices, administer payments, manage subscriptions, process cancellations and refunds, manage contracts, maintain commercial records and administer partner relationships.

6.6 Communications

Including to respond to enquiries, provide support, provide administrative notices, communicate security information, provide Service notices, communicate contractual changes and respond to privacy requests.

6.7 Sales and Marketing

Subject to Applicable Data Protection Law, BACI may use appropriate business-contact information to respond to prospective customers, communicate about BACI Services, provide relevant information, administer events, measure communication effectiveness and maintain business relationships. Individuals may exercise applicable marketing choices as described below.

6.8 Legal and Regulatory Compliance

Including to comply with Applicable Law, respond to lawful process, comply with accounting and tax obligations, satisfy sanctions and export-control requirements, maintain legally required records, respond to regulators and establish, exercise or defend legal claims.

6.9 Corporate Transactions

Personal Data may be processed as reasonably necessary in connection with a bona fide financing, investment, merger, acquisition, restructuring, reorganisation, sale of assets or similar corporate transaction, subject to appropriate confidentiality and legal safeguards.

7. LEGAL BASES FOR PROCESSING

7.1 Performance of a Contract

Processing may be necessary to enter into or perform a contract with an individual.

7.2 Legitimate Interests

BACI may process Personal Data where reasonably necessary for legitimate interests pursued by BACI or another party, provided those interests are not overridden by applicable rights and interests. Such interests may include operating a secure enterprise technology business, protecting BACI and Customers, preventing fraud, improving Services, managing commercial relationships, communicating with business contacts, protecting legal rights and maintaining business continuity. Where legally required, BACI will undertake an appropriate balancing assessment.

7.3 Legal Obligations

Processing may be necessary to comply with a legal obligation.

7.4 Consent

Where BACI relies upon consent, the individual may withdraw that consent as permitted by Applicable Data Protection Law. Withdrawal does not render unlawful processing that occurred lawfully before withdrawal.

7.5 Other Lawful Bases

BACI may rely upon another lawful basis where recognised by Applicable Data Protection Law.

8. ARTIFICIAL INTELLIGENCE AND PERSONAL DATA

8.1 AI-Enabled Services

BACI develops and operates artificial-intelligence, machine-learning, automated-reasoning and related technologies. The existence of AI functionality does not remove BACI's privacy obligations.

8.2 Customer Data and General Model Training

BACI's Terms establish a no general model training by default position for private Customer information. Unless a Customer expressly agrees otherwise in writing or affirmatively opts into a clearly identified programme, BACI will not use Customer Confidential Information, Customer Personal Data, private Inputs or private Outputs to train or fine-tune general-purpose or shared AI models for the benefit of other Customers.

8.3 Operational Processing

The preceding restriction does not prevent processing reasonably necessary to provide a requested AI-enabled Service, execute Customer instructions, maintain security, detect abuse, troubleshoot, provide support, maintain reliability or comply with lawful obligations.

8.4 Customer-Specific AI

Private model training, fine-tuning or other Customer-specific machine-learning activity requested by a Customer may be governed by an Order, DPA or Supplemental Terms.

8.5 Third-Party AI Providers

Where BACI uses a third-party AI provider to process Customer Personal Data on BACI's behalf, BACI will address that processing through its applicable contractual, DPA and subprocessor framework. BACI will not represent that a third-party AI provider provides a particular training, retention, localisation, confidentiality or security commitment unless BACI has a sufficient contractual or factual basis for that representation.

8.6 Automated Decisions

BACI will comply with Applicable Data Protection Law concerning decisions based solely on automated processing where such processing produces legal or similarly significant effects upon an individual. Where BACI merely provides technology to a Customer and the Customer determines the purpose and use of automated decision-making, the Customer remains responsible for its controller obligations, without limiting BACI's own obligations as processor or technology provider.

9. SENSITIVE PERSONAL DATA

BACI does not seek to collect Sensitive Personal Data merely because its systems are technically capable of processing information. Where BACI processes Sensitive Personal Data as controller, BACI will do so only where reasonably necessary for a legitimate and lawful purpose; an appropriate legal basis exists; any additional legally required condition is satisfied; and safeguards appropriate to the sensitivity and foreseeable consequences are applied. Customers must not submit specially regulated, classified or otherwise restricted information to an ordinary BACI environment where the Agreement requires a specifically authorised environment.

10. CHILDREN

BACI is designed primarily for businesses, organisations, professionals and developers. BACI Services are not directed to children unless BACI expressly identifies a Service as suitable for them and implements appropriate safeguards. BACI does not knowingly seek to collect Personal Data directly from children through its general commercial Services. If BACI learns that Personal Data concerning a child has been collected in circumstances requiring parental consent or another legal authorisation that was not obtained, BACI will take reasonable steps required by Applicable Data Protection Law.

11. DISCLOSURE OF PERSONAL DATA

11.1 Service Providers

BACI may engage service providers supporting cloud infrastructure, hosting, security, authentication, communications, customer support, analytics, payments, professional services and other legitimate business operations. Providers receiving Personal Data on BACI's behalf will be subject to appropriate contractual obligations where required.

11.2 BACI Affiliates

BACI may disclose Personal Data among BACI Affiliates where reasonably necessary for lawful business operations and subject to applicable protections.

11.3 Customer Organisations

Where an Account is controlled by an organisation, authorised administrators may have access to information concerning the organisation's users and use of BACI according to available administrative functionality. Individuals using an organisation-controlled Account should understand that the organisation may control the Account and associated information.

11.4 Professional Advisers

BACI may disclose information where reasonably necessary to professional advisers including lawyers, accountants, auditors, insurers and consultants subject to appropriate professional or contractual duties.

11.5 Corporate Transactions

Information may be disclosed to appropriate participants in a bona fide corporate transaction, subject to confidentiality and Applicable Law.

11.6 Legal Requirements and Protection

BACI may disclose Personal Data where reasonably necessary to comply with valid legal process, satisfy Applicable Law, respond to competent authorities, protect legal rights, investigate fraud, address security threats, protect individuals from serious harm or establish, exercise or defend legal claims. Where legally permitted and reasonably practicable, BACI may notify an affected Customer before disclosing Customer Data in response to compulsory governmental process. BACI may seek clarification, narrowing or legal review of a governmental request that BACI reasonably believes is unlawful, defective or overbroad.

11.7 With Direction or Consent

BACI may disclose Personal Data where an individual or authorised Customer directs, requests or validly consents to the disclosure.

12. SALE, SHARING AND TARGETED ADVERTISING

BACI's principal business is providing intelligence technology and related Services to Customers. BACI does not treat Personal Data as a commodity to be indiscriminately sold. Where Applicable Data Protection Law defines terms such as "sale", "sharing", "targeted advertising" or "cross-context behavioural advertising" more broadly than their ordinary commercial meaning, BACI will provide legally required disclosures and opt-out mechanisms concerning processing falling within those statutory definitions. BACI will not state that it "does not sell Personal Data" where BACI's actual practices would constitute a sale under an applicable statutory definition.

13. COOKIES AND SIMILAR TECHNOLOGIES

BACI may use cookies and similar technologies for purposes including essential website functionality, authentication, security, preference storage, analytics, performance and permitted communications or marketing. BACI's Cookie Policy provides additional information concerning categories, purposes and available controls. Where Applicable Law requires consent before non-essential technologies are used, BACI will implement an appropriate consent mechanism.

14. SECURITY

BACI will maintain reasonable and appropriate administrative, technical and organisational safeguards designed to protect Personal Data against unauthorised access, acquisition, alteration, disclosure, loss or destruction. Security measures may include, where appropriate, identity and access controls, authentication, encryption, tenant and organisational isolation, logging and monitoring, vulnerability management, secure development practices, incident response, backup and recovery measures, personnel controls, vendor risk management and business-continuity measures. Detailed contracted security commitments are governed by the applicable Security Policy or Security Addendum. No internet-connected system can guarantee absolute security. Individuals who believe a BACI Account or system may have been compromised should contact security@bacihq.com.

15. DATA RETENTION

BACI retains Personal Data only for periods reasonably necessary for the purposes for which it is processed, subject to Applicable Law. Retention periods may depend upon the nature of the information, purpose of processing, contractual requirements, Customer instructions where BACI acts as processor, security requirements, fraud-prevention requirements, statutory recordkeeping obligations, limitation periods, dispute or litigation requirements, backup architecture and whether information can appropriately be aggregated or de-identified. BACI's Data Retention & Deletion Policy provides additional rules. Deletion from backup systems may occur through ordinary secure backup rotation where permitted by Applicable Law.

16. DE-IDENTIFIED AND AGGREGATED INFORMATION

Subject to Applicable Law, BACI may create and use information that has been aggregated or de-identified so that it no longer reasonably identifies an individual, Customer or Customer Confidential Information. BACI may use such information for security, reliability, analytics, Service improvement, capacity planning, research and understanding Service performance. Where Applicable Law requires de-identified information to remain de-identified, BACI will not attempt to re-identify it except where permitted for testing, security, compliance or validation purposes.

17. INTERNATIONAL DATA TRANSFERS

BACI may operate internationally, and Personal Data may therefore be processed in countries other than the country in which it was originally collected. Where Applicable Data Protection Law requires a lawful transfer mechanism, BACI will use an appropriate mechanism. Depending upon the circumstances, mechanisms may include adequacy decisions, Standard Contractual Clauses, the UK International Data Transfer Addendum or other recognised UK mechanism, approved certifications or frameworks, legally recognised contractual safeguards, derogations expressly permitted by Applicable Data Protection Law or another valid transfer mechanism. BACI will not claim participation in a certification, adequacy framework, binding corporate rules programme or similar transfer mechanism unless BACI has actually obtained and maintains the necessary status. Additional provisions may be contained in BACI's International Data Transfer Addendum.

18. DATA LOCATION AND RESIDENCY

The location in which Personal Data is processed may depend upon Service architecture, infrastructure providers, Customer configuration, contracted data-residency options, support requirements, security and resilience requirements and Applicable Law. BACI will not represent that Personal Data remains exclusively within a particular country or region unless BACI has expressly contracted to provide that commitment. Enterprise Customers requiring specific residency arrangements should ensure those requirements are stated in the applicable Order or Supplemental Terms.

19. INDIVIDUAL PRIVACY RIGHTS

Depending upon Applicable Data Protection Law, an individual may have rights to obtain information concerning processing; access Personal Data; correct inaccurate Personal Data; complete incomplete Personal Data; request deletion; request restriction of processing; object to processing; withdraw consent; receive eligible Personal Data in a portable format; opt out of legally defined sale or sharing; opt out of targeted advertising where applicable; limit certain uses of Sensitive Personal Data where applicable; object to or obtain safeguards concerning certain automated decision-making; appeal a refusal of a privacy request where applicable; lodge a complaint with a competent supervisory or regulatory authority; and exercise other rights provided by Applicable Data Protection Law. Rights vary by jurisdiction and are not absolute. BACI may decline or limit a request where Applicable Law permits or requires it.

20. EXERCISING PRIVACY RIGHTS

Requests concerning Personal Data for which BACI acts as controller may be submitted to privacy@bacihq.com. BACI may require information reasonably necessary to verify identity, verify authority, identify relevant records, prevent fraudulent requests and satisfy Applicable Law. BACI will not require disproportionate information merely to discourage exercise of privacy rights. Where legally permitted, an authorised agent may submit a request on an individual's behalf. BACI may verify the agent's authority. BACI will respond within the period required by Applicable Law.

21. CUSTOMER-CONTROLLED DATA SUBJECT REQUESTS

If an individual submits a request concerning Personal Data that BACI processes solely on behalf of a Customer, BACI may direct the individual to the relevant Customer. Where required by the DPA or Applicable Data Protection Law, BACI will reasonably assist the Customer in responding to valid requests. BACI will not independently alter Customer-controlled Personal Data contrary to the Customer's lawful instructions merely because BACI technically possesses access to the data.

22. NON-DISCRIMINATION

BACI will not unlawfully discriminate against an individual for exercising a privacy right. This does not prevent BACI from charging lawful prices, providing different Services based upon legitimate commercial arrangements, restricting functionality where information is objectively required to provide it or taking another action permitted by Applicable Data Protection Law.

23. MARKETING CHOICES

Individuals may opt out of non-essential BACI marketing communications using an available unsubscribe mechanism or by contacting BACI. Opting out of marketing does not prevent BACI from sending communications reasonably necessary concerning an Account, transaction, security, Service operation, legal notices, contractual matters or a requested communication. BACI will honour legally valid marketing preferences within applicable timeframes.

24. GLOBAL PRIVACY AND REGIONAL REQUIREMENTS

BACI intends this Privacy Policy to provide a global baseline. Privacy rights and obligations vary between jurisdictions. Where required, BACI may publish regional privacy notices or schedules addressing requirements under applicable United States state privacy laws, European data-protection law, United Kingdom data-protection law, Canadian privacy law, Brazilian privacy law, African privacy and data-protection laws, Asia-Pacific privacy laws and other national or regional privacy regimes. A regional schedule may supplement this Policy but will not reduce a mandatory right provided by Applicable Law.

25. EUROPEAN ECONOMIC AREA AND UNITED KINGDOM

Where European or United Kingdom data-protection law applies, individuals may have rights including access, rectification, erasure, restriction, portability, objection, withdrawal of consent and safeguards concerning qualifying automated decisions. Where BACI relies upon legitimate interests, individuals may request information concerning those interests and may object where permitted by law. Individuals may lodge complaints with the competent supervisory authority. Where required, BACI will designate an appropriate Data Protection Officer, EU representative, UK representative or other legally required representative and publish the relevant contact details. BACI will not claim that such an appointment has been made until it has actually been made.

26. UNITED STATES PRIVACY RIGHTS

Residents of certain United States jurisdictions may possess additional privacy rights. Depending upon applicable state law, these may include rights to know or access categories and specific pieces of Personal Data; correct Personal Data; delete Personal Data; obtain portable data; opt out of sale; opt out of sharing; opt out of targeted advertising; limit certain uses or disclosures of Sensitive Personal Data; opt out of qualifying profiling or automated decision-making; appeal certain decisions concerning privacy requests; and receive equal treatment when exercising rights. BACI will maintain any legally required notice-at-collection, state-specific disclosures or request mechanisms as its processing and jurisdictional obligations require.

27. DO NOT TRACK AND UNIVERSAL OPT-OUT SIGNALS

Browser "Do Not Track" signals have not historically operated under a single universally applicable legal standard. Where Applicable Data Protection Law requires BACI to recognise a legally valid universal opt-out preference signal, BACI will honour that signal for processing to which the legal requirement applies.

28. THIRD-PARTY SERVICES

BACI Services may contain links to or integrate with Third-Party Services. Independent third parties may process Personal Data according to their own privacy notices and legal responsibilities. BACI is not responsible for an independent third party's privacy practices merely because BACI provides a link or Customer-authorised integration. Where a third party acts as BACI's processor or subprocessor rather than independently, BACI's applicable contractual and data-protection framework will govern that relationship.

29. GOVERNMENT AND LAW-ENFORCEMENT REQUESTS

BACI may disclose Personal Data where required by valid governmental, regulatory or judicial process. Where legally permitted and reasonably practicable, BACI will seek to verify that a request is directed to the appropriate BACI entity; assess apparent legal validity; seek clarification of ambiguous requests; seek narrowing of requests that appear materially overbroad; disclose only information legally required; and notify the affected Customer where permitted. BACI will not voluntarily provide governments with unrestricted access to Customer environments merely because a governmental authority requests information informally. Nothing in this section requires BACI to obstruct a lawful investigation or violate Applicable Law.

30. PRIVACY BY DESIGN AND GOVERNANCE

BACI's privacy programme is intended to incorporate privacy considerations into the design and operation of its systems. Depending upon risk and legal requirements, measures may include data minimisation, purpose limitation, access controls, separation of Customer environments, retention controls, privacy reviews, security reviews, vendor assessment, contractual controls, data-protection impact assessments, transfer assessments, AI governance, human oversight requirements, incident management and auditable governance controls. The level of governance applied should be proportionate to the sensitivity, scale, context and foreseeable consequences of processing.

31. ACCOUNTABILITY

BACI will maintain privacy governance appropriate to the nature and scale of its processing. This may include documented policies, assigned responsibility, employee confidentiality obligations, training, contractual safeguards, records of processing where required, risk assessments, incident procedures, request-handling procedures and periodic review. BACI's privacy commitments do not eliminate the independent privacy responsibilities of Customers, partners or other controllers.

32. CHANGES TO THIS PRIVACY POLICY

BACI may update this Privacy Policy to reflect changes in Services, technology, processing activities, Applicable Law, regulatory guidance, BACI's organisational structure or the BACI Legal Framework. Each version will identify its effective date and last-updated date. Where a material change significantly affects how BACI processes Personal Data, BACI will provide notice where required by Applicable Data Protection Law. BACI may maintain archived versions for transparency, contractual and compliance purposes.

33. CONTACT BACI

Questions, concerns and requests concerning this Privacy Policy may be directed to BACI Privacy, BACI LLC, Email: privacy@bacihq.com. Security matters should be directed to security@bacihq.com. Billing matters should be directed to billing@bacihq.com. Where Applicable Law requires BACI to publish additional contact details for a Data Protection Officer, representative, regulatory contact or regional entity, BACI will add those details to this Policy or an applicable regional notice.

34. COMPLAINTS

BACI encourages individuals to contact BACI concerning privacy concerns so that BACI can investigate and respond appropriately. Nothing in this Policy limits an individual's right to lodge a complaint with a competent data-protection, privacy or consumer-protection authority where that right exists under Applicable Law.

35. INTERPRETATION

This Privacy Policy is intended to provide transparent information concerning BACI's processing of Personal Data. It does not create rights contrary to Applicable Law; waive rights that cannot lawfully be waived; convert BACI into controller of Customer-controlled Personal Data merely because BACI provides technology capable of processing it; or reduce BACI's obligations where Applicable Data Protection Law imposes greater requirements. Where Applicable Data Protection Law grants an individual a mandatory right or imposes upon BACI a mandatory obligation inconsistent with this Policy, the mandatory law controls to the extent of the inconsistency.

RELATED

We're listening.