Privacy Policy
Last updated: July 13, 2026
1. Who we are
This Privacy Policy describes how Drumgo Consulting, LLC (trading as BaselytIQ) processes personal data in connection with the BaselytIQ Utility Input Tool (the "Service"). For personal data you provide to us as a customer of the Service, Drumgo Consulting, LLC acts as the data controller.
2. Personal data we collect
- Account data: name, email address, hashed password (if you use email/password sign-in), and Google account identifier (if you sign in with Google).
- Session and security data: authentication tokens, IP address, browser user agent, sign-in timestamps.
- Project and utility data you enter: project names, building names and locations, utility account numbers, uploaded bill files, and the structured data extracted from them (dates, usage, demand, cost, notes). This data may incidentally contain personal information (e.g. a name on a utility account).
- Support communications: messages you send us and any attachments.
- Usage telemetry: anonymized events about which features are used, and error diagnostics.
- Billing metadata: your Paddle customer ID, plan, price, and subscription status. Payment card and full billing address data are collected and stored by Paddle, not by us.
3. Purposes and legal bases
- Providing the Service (contract): creating your account, storing your projects, running AI extraction, generating reports.
- Security and fraud prevention (legitimate interest, legal obligation): authentication, rate limiting, abuse detection, audit logs.
- Product improvement (legitimate interest): analyzing aggregated, anonymized usage to improve features.
- Customer support (contract, legitimate interest): responding to your questions.
- Billing and tax (contract, legal obligation): processed on our behalf by Paddle as Merchant of Record.
- Marketing communications (consent, where required): only if you have opted in.
4. Who we share personal data with
We share personal data with the following categories of recipients:
- Merchant of Record — Paddle.com: Paddle acts as the seller of record for all subscriptions and one-time purchases, and handles payments, tax compliance, invoicing, subscription management, chargebacks, and refunds. Paddle receives your name, email, billing address, and payment details.
- Cloud hosting and database subprocessors: the managed infrastructure providers that host our application and encrypted database.
- AI subprocessor: Google Gemini, accessed via the Lovable AI Gateway, receives uploaded bill files when you use AI extraction. Under our gateway terms, your files are not used to train third-party models.
- Professional advisers: our lawyers, accountants, and auditors, under confidentiality.
- Authorities: where required by law, valid legal process, or to protect our rights.
We do not sell personal data and we do not share it with advertising networks.
5. International transfers
Some of our subprocessors are located outside the UK/EEA (including in the United States). Where personal data of UK/EEA data subjects is transferred internationally, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses or an adequacy decision.
6. Data retention
- Account data: retained for the life of your account and deleted within 30 days after you request account deletion, except where longer retention is required by law.
- Project and utility data: retained for as long as your account is active. Deleting a project cascades to its buildings, accounts, bills, and upload records.
- Uploaded bill files: by default, we retain only the structured data extracted from bills, not the original files. Where the Bill Archive add-on is enabled, files are retained until you delete them or close your account.
- Support communications: up to 24 months after the conversation ends.
- Billing records: retained by Paddle and by us as required by tax and accounting law (typically 7 years).
- Backups: may persist for up to 35 days after deletion from active systems, then are overwritten.
7. Your rights
Depending on where you live, you may have the following rights regarding your personal data:
- access a copy of the personal data we hold about you;
- correct inaccurate or incomplete data;
- erase your personal data ("right to be forgotten");
- restrict or object to certain processing;
- portability of data you provided to us;
- withdraw consent where processing is based on consent;
- lodge a complaint with your local data protection authority.
To exercise any of these rights, contact us via the in-app support form or the contact details in Section 11. We will respond within one month (extendable by two additional months for complex requests, with notice).
8. Security
We implement appropriate technical and organizational measures to protect personal data, including TLS in transit, encryption at rest by our cloud provider, row-level security so that each customer can access only their own data, and least-privilege access controls for our team. No online service is 100% secure; you use the Service at your own risk. Additional detail is available on our Trust & Security page.
9. Cookies
We use strictly necessary cookies and similar technologies to keep you signed in, remember preferences, and secure the Service. We do not use third-party advertising cookies. Where required by law, we will ask for consent before setting non-essential cookies.
10. Children
The Service is not directed to children under 16 and we do not knowingly collect their personal data.
11. Contact
Privacy questions or requests can be sent to rdrumgo@drumgoconsulting.com, or via the in-app support form. Drumgo Consulting, LLC acts as the data controller.