Security
Built to keep your data protected.
How business data is handled during the private beta. Confirm your access, integrations, and data requirements with the founder before onboarding.
🔒
Transport and credential protection
- Data is encrypted in transit using HTTPS/TLS
- Storage protection and backup retention depend on the infrastructure provider and configuration
- Integration credentials are handled server-side; do not send passwords or API keys through the website form
🏢
Per-organization data isolation
- Organization data is isolated through organization-scoped access controls and role-based permissions; authorized operational access may occur for support, security, incident response, maintenance, or legal compliance
- Access depends on the assigned organization, role, and resource permissions
- Confirm staff and partner access during onboarding before importing business records
🤖
AI data handling
- AI is powered by OpenAI; API inputs and outputs are not used to train OpenAI models by default, though data may be processed and temporarily retained under the applicable provider API terms
- Customer data is logically isolated by organization; selected data is processed by the subprocessors listed below solely to provide requested functionality (voice, messaging, AI, hosting, analytics, payments, bank connectivity)
- Knowledge Base (RAG) is isolated per organization — one business cannot see another's data
- Review and takeover rules are agreed before enabling customer-facing automation; some configured workflows can send automatically
📋
Data ownership & portability
- You retain ownership of your business data
- Available exports vary by workflow. Agree the required export scope and a migration plan before onboarding
- Request account deletion; associated data is removed, subject to retention windows and backup rotation
- We do not sell your business data. Service providers process selected data to deliver the configured features
🔗
Third-party integrations
- Integrations such as accounting exports, Google Calendar, and Twilio connect only at your explicit request
- Authentication varies by integration; supported OAuth connections and other credentials are configured during onboarding
- Webhook communications use provider-supported verification where available
- Ask the founder for help disconnecting an integration or changing its access
🛡️
Infrastructure & uptime
- Hosted on managed cloud infrastructure (Railway, Vercel, Supabase)
- Managed backups and recovery depend on the selected infrastructure provider and plan
- We work to keep the service reliable and communicate planned maintenance when practical
- Monitoring of critical services
Sub-processors
| Service | Purpose | Data processed |
|---|---|---|
| Railway | CRM application and database hosting | CRM records, account and communication data |
| Supabase | Website request storage where configured | Website contact details |
| Vercel | Website and request endpoint hosting | Website requests, submitted contact details, technical logs |
| OpenAI | AI responses & analysis | Selected messages and business context; processing and retention follow applicable API terms |
| Plaid | Bank account connectivity | Financial account data, transactions |
| Twilio | SMS & voice | Phone numbers, message content |
| Vapi | Voice AI | Call audio, transcripts |
| Resend | Email delivery | Email addresses, email content |
| Payment provider | Payment processing when enabled | Payment data handled by the approved payment processor |
| Accounting/export provider | Finance handoff when enabled | Invoices, payments, or export files at user request |
| Analytics, Calendar, OAuth | Usage data, calendar events | |
| Microsoft | Clarity website analytics | Website usage data, heatmaps, session replay |
| Cloudflare | CDN, file storage (R2) | Uploaded files (photos, documents) |
Providers used depend on your enabled features. Analytics providers process website usage; optional voice, messaging, bank, payment, and calendar integrations process the data needed for those workflows. See the Privacy Policy for details.
Security questions?
If you have questions about our security practices, data handling, or need a DPA (Data Processing Agreement), contact us.
hello@bazas.ai