This document is provided for transparency about how we operate the platform. It is not a substitute for legal advice. Programme organisations may also be covered by a separate written agreement.
1. Introduction
This Privacy Policy describes how Basecamp Platform (“we”, “us”, or “our”) collects, uses, discloses, stores, and otherwise processes personal data in connection with the Basecamp participant readiness platform (the “Service”), including the website operated at https://basecampportal.com and related applications and communications.
By accessing or using the Service, or by providing personal data to us (or having personal data provided about you by your educational institution or programme organisation), you acknowledge the practices described in this Policy. If you do not agree with this Policy, you should not use the Service.
This Policy is intended to provide clear notice of our practices. It does not create rights beyond those that already exist under applicable law. We may update this Policy from time to time as described in Section 16.
2. Roles: Controllers, Processors, and Institutional Accounts
Basecamp is primarily offered to universities, schools, and programme organisations (each a “Programme Organisation”). Programme Organisations invite participants and staff, configure cohorts, and use administrative dashboards to monitor readiness, compliance declarations, reflections, and wellbeing-related signals.
Depending on the context:
- For personal data that a Programme Organisation submits, collects, or instructs us to process about enrolled participants and programme staff in the course of administering a programme (for example enrolment details, progress records, reflections, and final readiness forms), the Programme Organisation is typically the data controller (or similar role under applicable law), and Basecamp Platform acts as a data processor (or service provider) processing such data on the Organisation’s documented instructions, as further set out in an order form, pilot agreement, or data processing terms where applicable.
- For personal data we process independently in operating and securing the platform—such as account authentication data we maintain to provide access, technical logs, marketing website analytics (when enabled), and communications with prospective customers—we may act as a data controller.
- Individuals should generally direct access, correction, and related privacy requests first to their Programme Organisation, which decides how participant records for a programme are managed. We will assist Organisations in responding where appropriate.
3. Scope and Who This Policy Applies To
This Policy applies to visitors of our public website; participants and other end users invited to use the Service; programme leaders, organisation administrators, and other staff users; and any person whose personal data is submitted through the Service (for example emergency contacts named on readiness forms).
This Policy does not apply to third-party websites, video hosts, or services that may be linked from or embedded within the Service (for example external video platforms used for lesson content), which are governed by their own privacy practices.
4. Categories of Personal Data We Process
Depending on role and programme configuration, we may process the following categories of personal data:
- Identity and account data: name, email address, authentication credentials or magic-link tokens, role (for example participant, programme leader, organisation administrator), and organisation or cohort membership.
- Profile and enrolment data: profile fields configured for a programme (which may include university or programme affiliation and other administrative fields), enrolment status, and onboarding information.
- Learning and progress data: module and lesson progress, completion records, quiz attempts and scores, declaration and form submissions, and versioned content acknowledgements.
- Reflection data: written reflections and related assignment metadata (open and deadline times, late submissions).
- Wellbeing and safeguarding-related data: responses to wellbeing check-ins or prompts and derived severity or alert signals presented to authorised programme staff. Such data may be sensitive and is processed for programme duty-of-care and operational safety purposes as directed by the Programme Organisation.
- Final readiness and compliance declarations: personal details, emergency contacts, medical and health-related declarations, dietary needs, travel and accommodation information, electronic signatures (typed name and related attestation), and other fields required by a given programme’s form configuration.
- Documents and uploads: files participants or staff upload where the programme enables document storage (for example supporting documents requested by the institution).
- Communications: content of support or demo enquiries, transactional email logs (such as invitation, reminder, and notification delivery), and related metadata.
- Technical and usage data: IP address, browser and device characteristics, approximate location derived from network information, timestamps, security logs, error reports, and cookie or similar technology identifiers.
5. Sources of Personal Data
We obtain personal data from:
- You, when you create or access an account, complete onboarding or profile flows, submit modules, quizzes, reflections, forms, or documents, or contact us.
- Programme Organisations and their staff, when they invite users, configure programmes, review dashboards, or enter or import programme-related information.
- Automated collection when you use the Service (logs, cookies, and similar technologies).
- Service providers assisting with hosting, authentication, email delivery, error monitoring, or analytics, as described in Section 10.
6. Purposes of Processing
We process personal data for the following purposes:
- To provide, operate, maintain, and improve the Service, including authentication, authorisation, course delivery, progress tracking, and administrative tooling.
- To support Programme Organisations in readiness, compliance, safeguarding awareness, and operational oversight—including dashboards, alerts, and configurable notification settings.
- To send transactional communications essential to the Service (invitations, magic links, password recovery, reflection deadline reminders, and similar operational emails).
- To respond to enquiries (including demo or pilot requests) and to communicate about the Service where lawful.
- To secure the Service, prevent abuse, enforce terms, detect and debug errors, and maintain auditability of key actions where logged.
- To comply with legal obligations and to establish, exercise, or defend legal claims.
- Where enabled by configuration, to understand aggregate usage of the marketing site or application via analytics tools, and to diagnose production errors via error-reporting tools.
7. Legal Bases (Where Applicable)
Where data protection laws require a legal basis for processing (for example under the GDPR or similar frameworks), we rely on one or more of the following as appropriate to the activity and our role:
- Performance of a contract: processing necessary to provide the Service to institutional customers and invited users under applicable agreements and terms.
- Legitimate interests: operating, securing, and improving the platform; communicating about the Service with existing users and prospective institutional customers; preventing fraud and misuse—balanced against individuals’ rights and expectations.
- Consent: where we request consent for a specific processing activity (for example certain cookies or optional communications), if and when such consent is lawfully required. Consent may be withdrawn where applicable without affecting the lawfulness of processing before withdrawal.
- Legal obligation: processing necessary to comply with applicable law.
- Vital interests or public interest / safeguarding grounds: in limited circumstances, processing may be necessary to protect vital interests or to support safeguarding and duty-of-care functions as required or permitted by law and institutional policy.
8. Special Category and Sensitive Data
Certain features of the Service are designed so that Programme Organisations can collect health-related declarations, medical information, dietary needs, wellbeing responses, and similar sensitive information when required for programme administration and safeguarding. Such data should only be requested where necessary and proportionate for the programme’s purposes.
Where we act as a processor, Programme Organisations are responsible for ensuring they have a valid legal basis and appropriate notices and, where required, additional conditions or safeguards for processing special category or sensitive data under applicable law.
We implement technical and organisational measures intended to restrict access to authorised users (for example organisation-scoped roles and database access controls). Unauthorised access is prohibited.
9. Disclosures and Recipients
We may disclose personal data to:
- Authorised users within your Programme Organisation (for example programme leaders and administrators reviewing participant readiness, submissions, and alerts).
- Service providers (sub-processors) that host infrastructure, provide authentication and database services, deliver email, store files, monitor errors, or provide analytics—only as needed to perform their services and subject to contractual confidentiality and security obligations.
- Professional advisers, insurers, or authorities where required or permitted by law, or to protect rights, safety, and security.
- A successor entity in connection with a merger, acquisition, financing, reorganisation, or sale of assets, subject to appropriate confidentiality arrangements.
We do not sell personal data. We do not share personal data for cross-context behavioural advertising as those concepts are defined under certain US state privacy laws, except to the extent an optional analytics integration enabled for a deployment could be characterised as such under a specific statute—in which case we will update this Policy and related notices as required.
10. Service Providers and Sub-Processors
We use reputable third-party service providers to operate the Service. Depending on configuration and environment, these may include:
- Supabase — authentication, database, and file storage infrastructure.
- Resend — transactional and operational email delivery.
- Vercel — application hosting and related edge or serverless infrastructure.
- Google Analytics or Google Tag Manager — website or product analytics, only when explicitly configured for a deployment.
- Sentry — application error monitoring and diagnostics, only when explicitly configured for a deployment.
Providers may process data in jurisdictions other than your own. Where transfers of personal data from a territory that requires transfer safeguards occur, we take steps designed to ensure an appropriate level of protection, including contractual measures with providers where applicable.
12. Retention
We retain personal data for as long as necessary to fulfil the purposes described in this Policy, including to provide the Service to Programme Organisations, satisfy legal, accounting, or reporting requirements, resolve disputes, and enforce agreements.
Programme Organisations may define retention periods for programme records under their own policies. We will delete or anonymise personal data when no longer needed, or upon valid instruction from a controller customer where we act as a processor, subject to legal hold and backup limitations.
Backup systems may retain residual copies for a limited period before automatic rotation. Logs and security records may be retained for a period consistent with security and operational needs.
13. Security
We implement technical and organisational measures designed to protect personal data against unauthorised access, alteration, disclosure, or destruction. These measures include encryption in transit (HTTPS), authentication controls, role-based access within organisations, and database row-level security policies where applicable.
No method of transmission or storage is completely secure. We cannot guarantee absolute security. You are responsible for maintaining the confidentiality of credentials used to access your account and for using devices and networks appropriate for the sensitivity of the data you submit.
14. Children and Participant Users
The Service is designed for use in connection with educational and institutional programmes, typically higher-education or professional programmes administered by Programme Organisations. We do not knowingly market the Service directly to children as a consumer product independent of an institutional programme.
If a Programme Organisation enrols individuals who are minors under applicable law, the Organisation is responsible for obtaining any required consents or authorisations and for ensuring that use of the Service is appropriate. If you believe we have collected personal data from a child inconsistently with applicable law, please contact us using the details in Section 17 so we can take appropriate action.
15. Your Rights and Choices
Depending on your location and role, you may have rights under applicable data protection laws, which may include rights to access, correct, update, delete, restrict, or object to certain processing; to withdraw consent where processing is based on consent; and to lodge a complaint with a supervisory authority.
If your data is processed in connection with a Programme Organisation’s use of Basecamp, please contact your institution or programme team first. You may also contact us at legal@basecampportal.com, and we will coordinate with the relevant Organisation as appropriate.
Account-holders may update certain profile information through in-product settings where available. Transactional emails related to account security and programme obligations may continue even if you opt out of optional marketing (if any).
16. Changes to This Policy
We may revise this Privacy Policy from time to time. The “Effective date” shown at the top of the Policy indicates when the current version took effect. Material changes will be indicated by updating that date and, where appropriate, providing additional notice (for example via the Service or email to account contacts).
Continued use of the Service after the effective date of a revised Policy constitutes acknowledgment of the updated Policy, except where applicable law requires a different standard.
17. Contact Us
For questions about this Privacy Policy or our privacy practices, contact Basecamp Platform at legal@basecampportal.com.
Unless a different governing arrangement is agreed with a Programme Organisation in writing, privacy matters under this Policy are intended to be handled in a manner consistent with the laws of Hong Kong, without prejudice to mandatory protections that may apply in your place of residence.