Skip to main content
← Back to BASEERA

Privacy Policy

Last updated: 12 April 2026

1. Introduction

BASEERA (“we”, “us”, or “our”) operates the outbreak intelligence platform available at baseera.health. This Privacy Policy explains how we collect, use, protect, and share information when you use our Service.

BASEERA is designed for humanitarian and public-health response in low-resource settings. We take the privacy of patients, field workers, and organizations seriously, and we follow the principle of data minimization: we only collect what is necessary to support outbreak response.

2. Information We Collect

2.1 Account information

When you sign up, we collect your name, email address, organization name, and role (Admin, Coordinator, Field Collector, or Viewer). Authentication is handled by Supabase Auth.

2.2 Outbreak response data

When you use BASEERA as part of an outbreak response, you may enter data about cases, contacts, water sources, community alerts, and events. This data may include personally identifiable health information about patients and contacts. This information is stored in an encrypted database (Supabase PostgreSQL) with row-level security enforcing organization-scoped access.

2.3 Technical information

We automatically collect standard server logs (IP address, browser user agent, timestamps) for security and debugging. We do not use tracking cookies or third-party analytics that identify individual users.

3. How We Use Information

  • Provide and operate the Service
  • Authenticate users and enforce role-based access
  • Send transactional emails (account confirmation, password reset, team invitations)
  • Improve the Service and fix bugs
  • Respond to security incidents and legal obligations

We do not sell your data, use it for advertising, or share it with third parties except as described in this policy.

4. Data Sharing

We share information only with:

  • Members of your organization — data you enter is visible to other users within the same organization, subject to role-based permissions.
  • Service providers — Supabase (database + authentication), Vercel (hosting), Resend (transactional email). These providers are bound by their own privacy policies and terms.
  • Legal requirements — if required by law, court order, or to protect the safety of users.

5. Data Security

All data is transmitted over HTTPS and stored in an encrypted database. Access is controlled by row-level security policies that enforce organization-scoped permissions. Passwords are hashed using industry-standard algorithms. We follow the principle of least privilege for administrative access.

6. Data Retention

Active accounts retain data indefinitely. If you delete your account or organization, all associated data is permanently deleted within 30 days. You may request an export of your organization's data at any time by emailing support.

7. Your Rights

Depending on your jurisdiction (GDPR, CCPA, etc.), you may have rights to access, correct, delete, or export your personal data. To exercise any of these rights, email hello@baseera.health.

8. Patient Data and Humanitarian Principles

BASEERA is used to track disease outbreaks that may include identifiable health information about patients. Organizations using BASEERA are responsible for obtaining appropriate consent and following applicable health privacy regulations in their jurisdiction (e.g., national health laws, WHO guidelines, humanitarian data protection principles).

We recommend that users follow the principles of the IASC Operational Guidance on Data Responsibility in Humanitarian Action.

9. Children's Privacy

BASEERA is intended for professional use by health workers and public-health officials. We do not knowingly collect information from children under 16 directly through the Service. Patient records may include minors as subjects of case reports — this is handled through organizational consent processes, not direct collection from children.

10. Changes to This Policy

We may update this Privacy Policy. We will notify users of material changes via email and by posting the new policy on this page with an updated date.

11. Contact

For questions about this Privacy Policy or our data practices:
hello@baseera.health