Privacy Policy
Effective Date: December 1, 2025
1. Introduction
BaseState Compliance, operated by Mounted Rifles Management Limited ("we," "us," or "BaseState"), respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, and safeguard your information when you use our services.
2. Information We Collect
2.1 Account Information: When you create an account, we collect your name, email address, and profile information provided through authentication services.
2.2 Training Records: We collect and store training completion records, quiz scores, certificate data, and acknowledgements as part of our core service.
2.3 AI Readiness Self-Test: When you use our free self-test, we collect your responses and, if provided, your email address to send results.
2.4 Payment Information: Payment processing is handled by Square. We do not store your full credit card details.
3. How We Use Your Information
- To provide and maintain our Service
- To generate compliance certificates and audit records
- To enable third-party verification of training completions
- To send you test results and service-related communications
- To process payments and prevent fraud
- To improve our services and develop new features
4. Data Retention
Training records and certificates are retained for the duration of your subscription plus 7 years to support audit and legal defense requirements. You may request earlier deletion subject to regulatory requirements.
5. Data Security
We implement industry-standard security measures including:
- Encryption of data in transit (TLS) and at rest
- SHA-256 hashing for certificate verification
- Secure authentication through OAuth providers
- Regular security audits and monitoring
6. Third-Party Services
We use the following third-party services:
- Replit: Application hosting and authentication
- Square: Payment processing
- OpenAI: AI-powered policy generation and assessments
- PostgreSQL (Neon): Database hosting
7. Your Rights
Depending on your jurisdiction, you may have rights to:
- Access your personal data
- Correct inaccurate data
- Request deletion of your data
- Export your data in a portable format
- Opt out of marketing communications
8. Quebec Law 25 Compliance
For users in Quebec, Canada, we comply with Law 25 requirements including designated privacy officer, consent management, and data breach notification procedures.
9. Contact Us
For privacy inquiries or to exercise your rights:
Email: basestate@trustedbyheroes.com
Website: www.basestatecompliance.com
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by posting the new policy on this page and updating the effective date.