- We hold your account, workspace and billing data, and very little else.
- Where you bring your own LLM keys (for example Anthropic or Google), we do not see the content your AI agents send to or receive from your provider. That traffic flows directly between you and them. Where you enable the built-in Crewspace AI option, inference requests are routed through Crewspace's managed model provider and processed transiently to provide the Service.
- You can ask us to show, correct, export or delete your personal data at any time by emailing privacy@crewspace.ai.
1. Who we are
This Privacy Policy explains how Base 1 Media Limited, trading as Crewspace ("Crewspace", "we", "us", "our") handles personal data.
- Registered entity: Base 1 Media Limited, trading as Crewspace
- Company number: 07293735
- Registered office: 3rd Floor, 45 Albemarle Street, Mayfair, London, W1S 4JL, United Kingdom
- ICO registration: ZC159929 (registered 29 May 2026, Tier 1)
- Contact: privacy@crewspace.ai
For the marketing site crewspace.ai we act as a data controller. For personal data you upload into the Crewspace application (your "Workspace"), we act as a data processor on your behalf. Your organisation is the controller. See our Terms for the processor terms.
2. What personal data we collect
2.1 Account data
Name, work email address, password hash, role within your workspace, profile photo (optional), preferred language and time zone.
2.2 Workspace data
Company name, workspace settings, the names and email addresses of the colleagues you invite, the configuration of the AI agents you build (their names, instructions, tools), and any knowledge documents you choose to upload.
2.3 Usage and run data
Metadata about how agents ran for you: timestamps, which tools were called, success/failure status, token counts, audit-log entries. We use this so you can see what your agents did and so we can keep the service running and secure.
2.4 Support correspondence
Emails, chat messages and screenshots you send to support@crewspace.ai.
2.5 Billing data
Billing contact, VAT number, plan and invoice history. Card details are held by Stripe (our payment processor). We never see or store full card numbers.
2.6 Analytics
We use Plausible Analytics for our website. Plausible uses no cookies, collects no personal data, and anonymises IP addresses. We see aggregate counts of page views, referrers and country (not city). That's why this site has no cookie banner: we don't need one.
3. What we do not collect
3.1 LLM inference content
If you bring your own keys. Where you use BYO LLM Keys, when one of your agents calls an LLM the request is signed with your API key and routed directly to that provider. The prompt content and the model's response do not pass through Crewspace's application servers as data we process or store as such. We may store the metadata (token counts, timestamps, which agent ran) so you can audit usage; we do not store the conversation bodies as a Crewspace data asset. Your relationship with your chosen LLM provider (for example Anthropic or Google) is governed by their terms and privacy policies.
If you use built-in Crewspace AI. Where you enable the built-in Crewspace AI option, inference requests are routed through Crewspace's managed model provider and prompt and response content is processed transiently to provide the Service; usage is metered and billed at the pay-as-you-go rates shown in your workspace.
3.2 Microsoft 365 message content
When you connect a Microsoft 365 account, Crewspace authenticates via the Microsoft Graph API against your M365 tenant. Email bodies, calendar entries, SharePoint files and Teams messages stay inside your tenant. Crewspace reads what your agents need at the moment they need it, under the OAuth scopes you have granted, and does not bulk-copy your mailbox into our database.
4. Lawful basis (UK GDPR Article 6)
| What we do | Lawful basis |
|---|---|
| Provide the Crewspace service to your organisation | Performance of a contract (Art 6(1)(b)) |
| Keep the service secure, prevent fraud and abuse | Legitimate interests (Art 6(1)(f)) |
| Send you product, service or security notices | Performance of a contract (Art 6(1)(b)) |
| Send you marketing emails | Consent (Art 6(1)(a)), withdrawable at any time |
| Keep accounting and tax records | Legal obligation (Art 6(1)(c)), HMRC |
5. How long we keep your data
| Category | Retention |
|---|---|
| Account data | Lifetime of the account + 12 months after closure |
| Workspace data, knowledge documents, agent memory | Lifetime of the account; deleted 30 days after termination unless you export sooner |
| Audit logs and run metadata | 24 months |
| Backups | 90 days rolling |
| Billing and invoice records | 7 years (HMRC requirement) |
| Support correspondence | 3 years from last contact |
| Marketing leads | 2 years from last engagement |
6. Your rights under UK GDPR
You have the right to: access (Art 15), rectify (Art 16), erasure (Art 17, subject to retention obligations), restrict processing (Art 18), portability (Art 20), object to processing based on legitimate interests (Art 21), withdraw consent at any time, and complain to the UK Information Commissioner's Office (ico.org.uk).
To exercise any of these rights email privacy@crewspace.ai. We aim to respond within 30 days.
7. International data transfers
- EU-hosted by default. Our application servers run in Railway's EU-West region.
- LLM providers. Where you use BYO LLM Keys, inference by your chosen LLM provider (for example Anthropic or Google) happens in the United States. Because you bring your own API key, that transfer is between you and the provider under their contract. Where you enable the built-in Crewspace AI option, inference is routed through Crewspace's managed model provider in the United States, protected by the UK International Data Transfer Addendum / EU Standard Contractual Clauses (SCCs).
- Microsoft Graph. Data remains in your Microsoft 365 tenant region.
- US sub-processors we contract with (e.g. Cloudflare for CDN/DNS). Transfers are protected by the UK International Data Transfer Addendum / EU Standard Contractual Clauses (SCCs).
8. Sub-processors
The current sub-processor list is published on our Security page. We update it before adding a new one. See clause 11 of our Terms for objection rights.
9. Cookies
We use one essential first-party cookie to keep you signed in. We do not use any third-party advertising, analytics or fingerprinting cookies.
10. Security
We use encryption at rest (AES-256 via our hosting provider) and TLS 1.3 in transit. We enforce role-based access controls, audit-log administrative access, require MFA for staff who access production systems, and run regular backups. Full details on our Security page.
11. Children
Crewspace is a B2B service and not intended for anyone under 16.
12. Changes to this Policy
We will email registered users at least 14 days before any material change takes effect, and we'll show the change history on the page.
13. Contact
- Email: privacy@crewspace.ai
- Post: 3rd Floor, 45 Albemarle Street, Mayfair, London, W1S 4JL, United Kingdom
- ICO complaints: ico.org.uk
legal@crewspace.ai · Base 1 Media Limited, trading as Crewspace · Company 07293735 · v0.1: legal review pending