Legal
Privacy Policy
Last updated: July 20, 2026
This Privacy Policy explains how Basirix, LLC (“Basirix,” “we,” “us,” or “our”) collects, uses, discloses, and retains personal information when you access or use Basirix websites, applications, tools, calculators, accounts, subscriptions, APIs, MCP servers, reports, benchmarks, and related services, whether offered free or for payment (collectively, the “Service”). It also explains the choices and rights that may be available to you.
The Service is intended for business and professional use from within the United States. This Privacy Policy should be read together with the Basirix Terms of Use (“Terms”). Capitalized terms not defined here have the meanings stated in the Terms.
Important data boundary. The standard Service, whether free or paid, is not intended to receive protected health information, claims data, member records, medical records, or other Prohibited Data. Do not submit such information. Creating an account or purchasing a paid plan does not authorize PHI processing or establish a business-associate relationship. The standard Service is not offered under a business associate agreement, and Basirix does not promise to review or detect Prohibited Data before processing a submission. Any separately contracted service designated for PHI processing will be governed by its applicable written agreement and, where required, a business associate agreement.
1. Scope
This Privacy Policy applies when Basirix acts as the business or controller responsible for personal information collected through free and paid versions of the Service, account and billing administration, support channels, business communications, and related websites. It does not apply to personal information processed under a separate enterprise agreement, data-processing agreement, or business associate agreement where Basirix acts solely on a customer’s instructions; that processing is governed by the applicable agreement and customer notice.
The Service may link to websites or services operated by others. Their privacy practices are governed by their own notices, not this Privacy Policy.
2. Information We Collect
We collect only the categories reasonably needed to provide, secure, support, and improve the Service and conduct our business.
| Category | Examples | Primary purposes | Typical retention |
|---|---|---|---|
| Contact, account, and business information | Name, business email, employer, job title, account identifier, login credentials, subscription or plan details, and Terms-acceptance records. | Create and administer free or paid accounts; authenticate users; communicate; document acceptance; manage subscriptions and business relationships. | While the account or relationship is active and afterward as reasonably necessary for legal, security, and business records. |
| Acceptance and interaction records | Applicable Terms, Privacy Policy, Acceptance Language, supplemental-terms, and disclosure versions; exact acceptance text displayed; timestamp; acceptance event; available user or account ID; session, transaction, interaction, or submission ID; IP address; and, where applicable, an associated material or record ID or hash. | Document affirmative acceptance; associate accepted terms and disclosures with the relevant Service interaction, feature, transaction, access credential, or submission; maintain evidence; enforce agreements; and protect legal rights. | For as long as reasonably necessary to maintain appropriate legal, security, and business records and resolve disputes. |
| Communications | Support requests, questions, feedback, survey responses, and related correspondence. | Respond to requests; provide support; troubleshoot; improve the Service; maintain appropriate business records. | As reasonably necessary to resolve the matter and maintain appropriate legal and business records. |
| Technical and usage information | IP address, browser, operating system, device and connection information, timestamps, referring pages, Service activity, error records, and security events. | Operate, secure, debug, measure, and improve the Service; prevent abuse; enforce the Terms. | Processing and security logs generally up to 30 days; longer only where needed for security, legal compliance, or aggregated analytics. |
| Submitted Documents | SBCs, similar plan-description documents, files, URLs, and linked materials submitted for processing. | Extract and analyze plan information; provide Outputs; troubleshoot and improve extraction quality; create Derived Data as described below. | Standard Service: up to 7 days, unless applicable written terms state a different period. With user permission for an extraction or quality investigation: up to 30 days. |
| Transaction information | Service or subscription purchased, billing contact, payment status, renewal or cancellation information, and transaction identifier. Payment-card details are generally handled by the payment processor rather than Basirix. | Process purchases and renewals; provide and administer paid Services; manage cancellations and refunds; prevent fraud; maintain tax, accounting, and transaction records. | For the period required by applicable tax, accounting, contractual, and legal obligations. |
Submitted Documents and Prohibited Data
Submitted Documents are governed by Sections 3 through 7 of the Terms. Basirix may reject any submission that it reasonably believes contains Prohibited Data. A rejected upload is not intentionally retained, except for limited security or incident records that do not contain the rejected document. If Basirix later discovers Prohibited Data, it may quarantine and delete the submission and document the incident under its incident-response process. Basirix is not obligated to review or detect Prohibited Data before processing a submission, and users remain responsible for complying with the submission restrictions in the Terms.
Essential Technologies and Analytics
Basirix uses technologies necessary to operate, secure, and maintain the Service and remember user settings. Basirix also uses Vercel Web Analytics to understand aggregate Service usage and performance. Vercel Web Analytics operates without cookies and uses anonymized, aggregated data rather than cross-site tracking or individual visitor profiles. If these practices materially change, Basirix will update this Privacy Policy and provide any notice or choices required by applicable law.
3. Sources of Information
We collect personal information:
- directly from you when you use the Service, create an account, purchase or activate a Service, affirmatively accept applicable terms, policies, disclosures, or Acceptance Language, submit information or materials, access a feature, obtain credentials, or contact us;
- from your employer, organization, or account administrator when they arrange or manage access to the Service;
- automatically from your browser, device, and interaction with the Service; and
- from service providers, payment processors, security vendors, and lawfully available public sources as needed to operate the Service and conduct our business.
4. How We Use Information
We use personal information to:
- provide, operate, maintain, and support the Service and generate requested Outputs;
- authenticate users and administer accounts, API credentials, and MCP access;
- process transactions and maintain business, accounting, and acceptance records;
- communicate about the Service, respond to requests, and provide support;
- protect the Service and investigate security threats, fraud, abuse, and violations of the Terms;
- debug errors, assess performance, and improve extraction and product quality;
- comply with law and enforce or defend legal rights; and
- complete a merger, financing, acquisition, reorganization, bankruptcy, or sale of all or part of the business, subject to applicable law.
AI-assisted processing
Basirix uses automated and AI-assisted tools to extract plan information, classify plan terms, identify potential issues, and generate comparison estimates. The Service does not use personal information to make eligibility, coverage, pricing, employment, credit, medical, insurance-underwriting, or benefits-administration decisions about an individual.
Basirix does not authorize third-party AI service providers to use Submitted Documents to train their general-purpose models. Basirix may use Submitted Documents and Derived Data to test and improve the Service only as described in the Terms and this Privacy Policy.
5. Derived Data and Benchmarking
As described in Section 5 of the Terms, Basirix creates Derived Data from Submitted Documents. Derived Data may include De-identified Data, Aggregate Data, and Public-Source Plan Data.
- De-identified Data does not identify and is not reasonably linkable to a user, individual, employer, or plan sponsor.
- Aggregate Data relates to multiple plans or sources and does not identify a specific user, individual, employer, or plan sponsor.
- Public-Source Plan Data may identify a public entity where the underlying plan information is lawfully publicly available.
Basirix may retain, use, reproduce, disclose, license, and commercialize Derived Data to operate and improve the Service, develop and test products, build benchmark datasets, create plan-design and market benchmarks, and generate aggregate analytics and insights. Basirix does not sell or share personal information for cross-context behavioral advertising. Commercialization of De-identified Data, Aggregate Data, and Public-Source Plan Data is not a sale of personal information when those datasets are not personal information under applicable law.
Basirix will maintain De-identified Data in de-identified form, will not attempt to identify any individual, user, employer, or nonpublic plan sponsor from it, and will maintain reasonable measures designed to prevent it from being associated with those persons or entities. Basirix may test its de-identification controls to validate their effectiveness.
6. How We Disclose Information
We may disclose personal information to the following recipients for the purposes described in this Privacy Policy:
- Service providers that host, secure, analyze, operate, and support the Service; provide communications, customer support, analytics, or payment processing; or perform professional services for Basirix.
- Professional advisers, including lawyers, auditors, accountants, insurers, and consultants, where reasonably necessary for their services.
- Government authorities, courts, litigants, or other parties when required by law or reasonably necessary to protect rights, safety, security, or the integrity of the Service.
- A buyer, investor, lender, or successor in connection with an actual or proposed corporate transaction, subject to appropriate confidentiality and legal requirements.
- Other recipients at your direction or with your consent.
Basirix does not sell personal information or share personal information for cross-context behavioral advertising, as those terms are defined by applicable U.S. state privacy laws. Basirix also does not knowingly use personal information for targeted advertising based on activity across nonaffiliated websites or services.
7. Retention and Deletion
Basirix retains personal information only for as long as reasonably necessary for the purposes described in this Privacy Policy, including to provide and secure the Service, maintain appropriate business and acceptance records, comply with legal obligations, resolve disputes, and enforce agreements.
Some Services process user-provided inputs without storing Submitted Documents. Where a Service accepts Submitted Documents, Basirix deletes accepted Submitted Documents from active production systems within seven days after submission, unless a different period is disclosed in the applicable user flow, Acceptance Language, supplemental terms, order form, or separate written agreement. If Basirix requests and receives permission to retain a Submitted Document for an extraction, support, or quality investigation, it may retain that document for up to 30 days.
Basirix may retain limited technical and security records as reasonably necessary to operate and protect the Service, investigate errors or misuse, and comply with legal obligations. These records are designed not to contain Submitted Documents or Prohibited Data.
If Submitted Documents are included in encrypted disaster-recovery backups, deleted documents may remain in those backups until overwritten through the applicable backup cycle. During that period, they will not be accessed except for disaster recovery, security, or legal compliance.
Where Basirix obtains affirmative acceptance or acknowledgment, it may retain records of the acceptance and relevant Service interaction, including the applicable Terms, Privacy Policy, Acceptance Language, supplemental terms, and disclosure versions, as described in this Privacy Policy.
8. Information Security
Basirix uses administrative, technical, and organizational safeguards designed to protect personal information against unauthorized access, loss, misuse, alteration, and disclosure. Safeguards may include encryption in transit and at rest, access controls, logging, monitoring, and vendor-risk controls, as appropriate to the information and Service. No system is completely secure, and Basirix cannot guarantee absolute security.
9. Your Privacy Rights
Depending on where you live and whether applicable law covers Basirix or the relevant processing, you may have rights to request access to, correction of, deletion of, or a portable copy of personal information; to obtain information about certain disclosures; to opt out of certain processing; or to appeal a decision concerning a privacy request. Basirix will not unlawfully discriminate against you for exercising an applicable privacy right.
To submit a request, contact us using the information in Section 12. Basirix may request information reasonably necessary to verify your identity and authority. An authorized agent may submit a request where permitted by law, but Basirix may require proof of authorization and verification of the requester’s identity.
Basirix may be unable or not required to identify, access, correct, or delete De-identified Data or Aggregate Data because those datasets are not maintained in a manner reasonably linkable to a requester. Public-Source Plan Data may also remain available where it is not personal information or is lawfully retained under applicable law.
10. Children
The Service is intended for business users who are at least 18 years old. Basirix does not knowingly collect personal information from children. If you believe a child has provided personal information through the Service, contact us so that Basirix can investigate and take appropriate action.
11. Changes to This Privacy Policy
Basirix may update this Privacy Policy to reflect changes in the Service, data practices, or legal requirements. Basirix will post the updated policy with a revised “Last updated” date and provide additional notice where required by law. Material changes will apply prospectively unless applicable law permits otherwise. Depending on the affected Service or interaction, Basirix may request renewed acknowledgment or acceptance under the process described in the Terms.
12. Contact Us
Questions, privacy requests, and concerns about this Privacy Policy or Basirix’s privacy practices may be sent to:
- Email: support@basirix.com
If applicable law gives you a right to appeal a privacy-request decision, you may submit the appeal through the same contact method and include “Privacy Appeal” in the subject line.