The DPA prohibits Customer from submitting to Baseten any personal data constituting Restricted Data, defined to include government identifiers, HIPAA-protected health information, biometric data, financial account credentials, payment card data, children's personal data under age thirteen, GDPR special category data, and criminal conviction data, unless a separate written agreement with Baseten expressly permits such submission.
This analysis describes what Baseten's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision creates a contractual data intake restriction that Customer organizations must operationalize through data classification and platform intake controls, and allocates to Customer full contractual responsibility for any breach of this prohibition.
Under this clause, Customer is contractually prohibited from submitting sensitive personal data categories to the Baseten platform without a separate written agreement, and bears responsibility for ensuring that Customer Content and model inputs are screened against this restriction prior to submission.
Cross-platform context
See how other platforms handle Restricted Data Category Prohibition and similar clauses.
Compare across platforms →"Unless otherwise agreed upon with Baseten in writing, Customer shall not provide or otherwise make available to Baseten any Customer Personal Data that contains any (a) Social Security numbers or other government-issued identification numbers; (b) protected health information subject to the Health Insurance Portability and Accountability Act (HIPAA) or other information regarding an individual's medical history, mental or physical condition, or medical treatment or diagnosis by a health care professional; (c) health insurance information; (d) biometric information; (e) passwords to any online accounts; (f) credentials to any financial accounts; (g) tax return data; (h) any payment card information subject to the Payment Card Industry Data Security Standard; (i) Personal Data of children under 13 years of age; or (j) any other information that falls within any special categories of personal data (as defined in GDPR) and/or data relating to criminal convictions and offenses or related security measures (together, "Restricted Data").Excerpt from Baseten's Terms of Service
(1) REGULATORY LANDSCAPE: This provision directly engages HIPAA (for PHI), COPPA (for children's data under 13), GDPR Article 9 (special categories of personal data) and Article 10 (criminal conviction data), CCPA and CPRA (for sensitive …
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This provision creates a contractual data intake restriction that Customer organizations must operationalize through data classification and platform intake controls, and allocates to Customer full contractual responsibility for any breach of this prohibition.
Under this clause, Customer is contractually prohibited from submitting sensitive personal data categories to the Baseten platform without a separate written agreement, and bears responsibility for ensuring that Customer Content and model inputs are screened against this restriction prior to submission.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Baseten.