Baseline PCR · Legal

Privacy Policy

What personal data Baseline PCR collects from firms that use it and from the evidence they upload, how it is used and shared, how long it is kept, and the rights you have over it.

Version 1 · effective 2026-09-17

This Privacy Policy explains how MoldMind LLC, doing business as Baseline PCR ("Baseline PCR," "we," "us"), collects, uses, shares and protects personal data in connection with the Baseline PCR platform (the "Service"). It applies to visitors to our website, to people who create Accounts, and to people whose data appears in Customer Content our customers upload.

1. Roles: Controller and Processor

For your Account and billing data, we are the controller. We decide how account, usage and billing information is processed.

For Customer Content, your Firm is the controller and we are the processor. Photographs, field notes, questionnaires, owner-provided documents, interview notes and Reports are uploaded by your Firm and processed on its instructions under the Terms of Service and, where executed, our Data Processing Addendum. People who appear in that content (for example a property manager named in an interview, or a person incidentally photographed on site) should direct requests about it to the Firm that prepared the Report; we will help that Firm respond.

2. Personal Data We Collect

You give us directly: name, work email, firm name and address, professional licence numbers you enter for letterheads and signature blocks, phone number, logo, and the content of messages you send us.

Through use of the Service: the jobs you create (property addresses, client names and roles, points of contact and interviewees named in field notes and questionnaires), photographs and their EXIF metadata (capture time; location if your camera records it), documents you upload and the facts extracted from them, edits you make, approvals and signatures, share links you create and email addresses you send Reports to, and an audit log of actions in your workspace.

Automatically: IP address, browser and device information, pages visited, timestamps and error diagnostics. Page-view analytics are collected by our hosting provider's cookieless analytics (Vercel Web Analytics), which records page views and aggregate device and country data and does not identify you. We use only the cookies needed to keep you signed in and to protect against abuse; we do not use advertising cookies or trackers.

From third parties: authentication data from our identity provider, and payment status from our payment processor. We never see or store full card numbers.

3. How We Use Personal Data

  • To provide the Service: store evidence, run automated classification and extraction, draft and render Reports, deliver them where you direct, and keep an audit trail.
  • To bill you and prevent fraud.
  • To support you and respond to requests.
  • To secure the Service, investigate abuse and enforce our Terms.
  • To improve the Service using aggregated or de-identified data (see Section 6).
  • To send transactional and regulatory messages (receipts, renewal reminders, security notices, changes to legal terms). We send marketing email only with consent and every such message carries an unsubscribe link.
  • To comply with law.

Where these laws apply we rely on: performance of a contract (providing the Service); our legitimate interests (security, fraud prevention, product improvement, and processing Customer Content as your processor); consent (marketing); and legal obligation (tax and accounting records).

5. Automated Processing and AI

The Service uses large language and vision models to classify photographs, read data plates, extract facts from documents and draft narrative text. No decision with legal or similarly significant effect on any person is made by automated means. Every Draft is reviewed and approved by a qualified professional at your Firm before it becomes a Report. Our AI Disclosure describes the models, their vendors and the restrictions we place on them. The models are instructed to state that something was not observed or not provided rather than invent it, and the Service runs checks designed to catch fabricated figures and citations; those checks are an aid to the Reviewer, not a guarantee.

6. Aggregated and De-identified Data

We may derive aggregated or de-identified statistics from use of the Service (for example, how often drafted quantities are edited, or the distribution of condition ratings by building age) and use them to operate and improve the Service and to publish industry information. We commit not to attempt to re-identify such data and to contractually prohibit recipients from doing so.

7. How We Share Personal Data

Subprocessors. We use service providers to host, store, process, bill and deliver. The current list, with the function and location of each, is our Subprocessor List. Each is bound by a written agreement to process data only on our instructions and to protect it.

Recipients you choose. When you email a Report, create a share link or send a questionnaire link, we send data to the addresses and people you specify.

Legal and safety. We disclose data when required by law, subpoena or court order; to protect the rights, property or safety of Baseline PCR, our customers or the public; or in connection with a merger, acquisition or sale of assets, in which case we will notify you before your data becomes subject to a different privacy policy.

We do not sell personal data and we do not share it for cross-context behavioral advertising.

We require valid legal process before disclosing Customer Content to a government or third party, and we will notify the affected customer before disclosure unless legally prohibited. We challenge requests we believe are overbroad.

9. Data Retention

DataRetention
Account and firm profileLife of the Account, then deleted within 90 days of closure
Customer Content and ReportsLife of the Account, then deleted within 90 days of closure; you may delete individual jobs at any time
Approved Report snapshotsAs above; an approved Report is kept while its job exists because your Report User may rely on it
AI processing cache (classification and extraction results keyed by content)Deleted with the Customer Content it derives from
Audit log3 years, for your own professional-records needs and ours
Billing records7 years, as required by tax and accounting law
Share-link tokensUntil expiry (30 days by default) or revocation
Server logs30 days
BackupsRolling; a deleted item leaves backups within the provider's retention window, currently up to 30 days

10. Your Rights

Wherever you are, you can access, correct, export and delete your personal data and object to or restrict certain processing by emailing privacy@baselinepcr.com or, for Customer Content, by using the tools in the Service. We respond within 30 days (45 for California requests) and will verify your identity first. We will not discriminate against you for exercising a right.

California (CCPA/CPRA): you have the rights to know, delete, correct, and opt out of sale or sharing (we do neither), and to limit use of sensitive personal information (we collect none). Connecticut (CTDPA): the same rights, plus the right to appeal a decision by emailing privacy@baselinepcr.com with "Appeal" in the subject. EEA, UK and Switzerland: in addition, the right to lodge a complaint with your supervisory authority; our lead authority questions can be sent to privacy@baselinepcr.com.

If you are a person whose data appears in a Firm's Customer Content, we will forward your request to that Firm and assist it.

11. International Transfers

We are established in the United States and store data with providers in the United States. If you access the Service from elsewhere, your data is transferred to and processed in the United States. For data subject to European or UK law we rely on the Standard Contractual Clauses and the UK Addendum with our subprocessors, and the Data Processing Addendum incorporates them for your Firm.

12. Account Deletion

Close your Account from Settings or by emailing privacy@baselinepcr.com. We delete or de-identify Customer Content, Reports and Account data within 90 days, except billing and audit records we must keep under Section 9, and except that a deleted item may persist in encrypted backups for the backup provider's retention window.

13. Children

The Service is for professionals and not directed to anyone under 18. We do not knowingly collect data from children; if you believe we have, contact us and we will delete it.

14. Security

We protect data with encryption in transit (TLS) and at rest, tenant isolation in the database and object store so one Firm cannot read another's data, authentication by a dedicated identity provider with multi-factor support, least-privilege access for our personnel, signed and expiring links for uploads and shares, and an audit log of actions in each workspace. No method is perfectly secure; report suspected vulnerabilities to security@baselinepcr.com.

15. Breach Notification

If a breach of security leads to the accidental or unlawful destruction, loss, alteration or unauthorized disclosure of personal data, we will notify affected customers without undue delay after becoming aware of it, and in any case within the time required by law (including 72 hours under GDPR where applicable, and the Connecticut breach-notification statute), with the information we have about the breach, its likely consequences and the measures taken.

16. Changes

We may update this Policy. Material changes are announced by email or in the Service at least 30 days before they take effect. The effective date is at the top of this page.

17. Contact

MoldMind LLC d/b/a Baseline PCR, 2389 Main Street, Suite 100, Glastonbury, CT 06033, United States. privacy@baselinepcr.com.