Legal
Privacy policy
Last updated: 16 August 2026
Who the controller is
The data controller is Renaiss AI Solutions, S.L., Spanish tax ID B13645973, registered office at Calle Conde de Peñalver 26, 28006 Madrid, España. This policy covers the Renbase website, the workspace and the API — including the MCP endpoint agents connect to. Write to [email protected] with any question about it.
We have not appointed a data protection officer: the processing does not fall under any of the cases in article 37 of the GDPR. Privacy matters are handled at that same address.
For the content of your corpus we act as a processor, on your instructions — you are the controller. For account data and billing, the controller is us.
What we process
Account data
Your email address and your organization's name. Sign-in is passwordless: we email a one-time code, so we never hold a password of yours. Members carry a role — admin or read — and admins can issue API keys for services and agents.
Content you put in the corpus
The documents you upload and the business definitions your team writes or approves. We process them only to run the service: parsing, chunking, indexing and serving them back with citations. We do not train models on your content and we do not share it with third parties beyond the sub-processors listed below.
Questions and answers
The questions your people and agents ask, the answers returned and the feedback you leave on them. Answers are cached per organization so a repeated question doesn't re-run the whole pipeline; any change to approved context invalidates that cache.
Usage data
Request metadata — endpoint, timestamp, status, credits consumed — to operate the service, enforce per-organization rate limits and account for usage.
On what legal basis
- Performance of the contract (GDPR art. 6(1)(b)): creating your account, signing you in, indexing your corpus, answering questions and accounting for credits.
- Legal obligation (art. 6(1)(c)): billing and the accounting and tax duties that come with it.
- Legitimate interest (art. 6(1)(f)): keeping the service up and protecting it from abuse — rate limits, fraud detection, operational logs — balanced by processing only request metadata and never your corpus content for this purpose.
What we never touch
Renbase serves context; your agent acts. We do not run or generate SQL against your warehouse and we never hold its credentials: schema introspection runs as a CLI on your own machine and submits only draft entries for your team to review. There is more detail on the security page.
Isolation
The organization is the unit of isolation, enforced across the dense vector index, the lexical index and the relational database. Every request — from a person, a service or an agent — is scoped to the organization behind its credential, so another organization's content is out of reach rather than merely filtered out.
Sub-processors
We rely on a small number of providers to run the managed service:
- Application hosting and the managed database that stores the corpus and account data
- Transactional email, to deliver sign-in codes
- A large-language-model provider, to generate answers from the context retrieved for a question
- An embeddings and reranking provider, where those models are not run in our own infrastructure
Each one is bound by a data-processing agreement; the current list with names and locations is available on request at [email protected]. Under the Enterprise BYOC model none of this applies: the whole platform runs inside your own infrastructure and no corpus data leaves it.
Some of those providers may process data outside the European Economic Area. Where they do, the transfer relies on a European Commission adequacy decision or, failing that, on the standard contractual clauses of GDPR article 46(2)(c) with any supplementary measures needed. Ask us at the same address for a copy of those safeguards.
Retention
We keep account data and corpus content while your organization's account is active. You can delete documents and definitions at any time from the workspace; deleting a definition keeps its superseded versions queryable as part of the audit trail, which is the point of governed context.
When an account is closed, the periods are these:
- Corpus and account data: deleted within 30 calendar days of closure, and gone from backups within the following 90 days, which is their rotation cycle.
- Operational logs (request metadata, security events): 90 days.
- Billing and accounting records: 6 years, under article 30 of the Spanish Commercial Code, and available to the tax authorities while their claims have not lapsed.
Your rights
You can request access, correction, deletion, restriction, objection and portability of your personal data, and withdraw any consent you gave without affecting the lawfulness of processing before that. Write to [email protected] and we will respond within the one-month period the GDPR sets, extendable by two more if the request is complex.
If you think we handled your request poorly, you can complain to a supervisory authority; in Spain, the Agencia Española de Protección de Datos ( www.aepd.es, calle de Jorge Juan 6, 28001 Madrid).
Security
Traffic is encrypted in transit. API keys are issued per integration so each can be revoked in isolation, and revocation takes effect immediately. If you believe an account has been compromised, write to [email protected] and we will treat it as urgent.
Changes
When this policy changes we update the date at the top of this page, and we notify account admins by email if the change is material.