Provision record
Baseten · Baseten Terms of Service · View original document ↗

Restricted Data Category Prohibition

High severity High confidence Explicit document language Unique · 0 of 352 platforms
Stay ahead of the changes
Track Baseten and get the diff the day its terms change.
Share 𝕏 Share in Share 🔒 PDF
Document Record

What it is

The DPA prohibits Customer from submitting to Baseten any personal data constituting Restricted Data, defined to include government identifiers, HIPAA-protected health information, biometric data, financial account credentials, payment card data, children's personal data under age thirteen, GDPR special category data, and criminal conviction data, unless a separate written agreement with Baseten expressly permits such submission.

ⓘ

This analysis describes what Baseten's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision creates a contractual data intake restriction that Customer organizations must operationalize through data classification and platform intake controls, and allocates to Customer full contractual responsibility for any breach of this prohibition.

Consumer impact (what this means for users)

Under this clause, Customer is contractually prohibited from submitting sensitive personal data categories to the Baseten platform without a separate written agreement, and bears responsibility for ensuring that Customer Content and model inputs are screened against this restriction prior to submission.

Cross-platform context

See how other platforms handle Restricted Data Category Prohibition and similar clauses.

Compare across platforms →
▸ View Original Clause Language DOCUMENT RECORD
"
Unless otherwise agreed upon with Baseten in writing, Customer shall not provide or otherwise make available to Baseten any Customer Personal Data that contains any (a) Social Security numbers or other government-issued identification numbers; (b) protected health information subject to the Health Insurance Portability and Accountability Act (HIPAA) or other information regarding an individual's medical history, mental or physical condition, or medical treatment or diagnosis by a health care professional; (c) health insurance information; (d) biometric information; (e) passwords to any online accounts; (f) credentials to any financial accounts; (g) tax return data; (h) any payment card information subject to the Payment Card Industry Data Security Standard; (i) Personal Data of children under 13 years of age; or (j) any other information that falls within any special categories of personal data (as defined in GDPR) and/or data relating to criminal convictions and offenses or related security measures (together, "Restricted Data").

Excerpt from Baseten's Terms of Service

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

(1) REGULATORY LANDSCAPE: This provision directly engages HIPAA (for PHI), COPPA (for children's data under 13), GDPR Article 9 (special categories of personal data) and Article 10 (criminal conviction data), CCPA and CPRA (for sensitive …

Insight

Unlock the full institutional analysis

Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.

Applicable agencies

  • Department Of Health & Human Services, Office For Civil Rights (hhs Ocr)
    Enforces HIPAA Privacy and Security Rules, which protect health information held by healthcare providers, health plans, and their business associates.
    Who can file: Anyone whose HIPAA rights may have been violated by a covered entity (healthcare provider, health plan, or healthcare clearinghouse)
    What you need: Name of the entity, description of the violation, date of the incident, and your contact information. Must file within 180 days of the violation.
    What to expect: HHS OCR investigates and may require the entity to take corrective action. Does not provide individual compensation. Serious violations can result in civil monetary penalties.
    File a complaint →
  • Federal Trade Commission (ftc)
    Oversees unfair or deceptive business practices and can investigate companies that mislead consumers about data collection, sharing, or use.
    Who can file: Anyone affected by the company's practices (US or international)
    What you need: Your account details, a timeline of relevant events, and a description of the specific issue
    What to expect: Complaints inform FTC enforcement priorities and investigations but do not result in individual resolution or compensation
    File a complaint →

Provision details

Document information
Document
Baseten Terms of Service
Entity
Baseten
Document last updated
May 12, 2026
Tracking information
First tracked
July 12, 2026
Last verified
July 12, 2026
Record ID
CA-P-074199
Document ID
CA-D-00813
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
e9d44a36c9ed500a74656ec3e22a7892bc5e72790392b3c71bde1cc0e32cc19a
Analysis generated
July 12, 2026 14:23 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Baseten
Document: Baseten Terms of Service
Record ID: CA-P-074199
Captured: 2026-07-12 14:23:23 UTC
SHA-256: e9d44a36c9ed500a…
URL: https://conductatlas.com/platform/baseten/baseten-terms-of-service/provision/CA-P-074199/restricted-data-category-prohibition/
Accessed: Sept. 26, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
High
Categories

Other risks in this policy

Get the research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.

Frequently Asked Questions

What does Baseten's Restricted Data Category Prohibition clause do?

This provision creates a contractual data intake restriction that Customer organizations must operationalize through data classification and platform intake controls, and allocates to Customer full contractual responsibility for any breach of this prohibition.

How does this clause affect you?

Under this clause, Customer is contractually prohibited from submitting sensitive personal data categories to the Baseten platform without a separate written agreement, and bears responsibility for ensuring that Customer Content and model inputs are screened against this restriction prior to submission.

Is ConductAtlas affiliated with Baseten?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Baseten.