Rockbase

Legal

Privacy

What we hold, where it lives, and who else can touch it. Short version: your data stays in the European region, in our own cloud projects, and exactly one other company is involved.

Last updated 24 August 2026

Early access, and honest about it. Rockbase is onboarding founding clients, and this document is under legal review ahead of general availability. It describes what the system actually does today. If anything here matters to your decision, ask us and we will answer plainly rather than point you back at the page.

01Who we are

Rockbase is a strategy-to-execution platform for scaling businesses. This notice explains what we do with personal data, both on this website and inside the product.

Rockbase is an independent product. Postworks is its founding test client, and shares no infrastructure, identity or code with it.

02Which hat we are wearing

The distinction matters, because it decides who you ask for what.

  • We are the controller for this website and for people who contact us — visitors, early-access applicants, and anyone who emails us. We decided to collect that data and we decide what happens to it.
  • We are a processor for everything inside a customer account. Your employer or client decided to put that data into Rockbase and instructs us on it. If you are an employee whose record sits in someone else's Rockbase account, ask them first — we will help them answer you, but we will not go behind them.

03If you are a visitor or applicant

This website runs no analytics, no advertising pixels, no session recording and no third-party trackers. It sets no cookies at all. We do not know who visited, and there is no profile of you to ask us for.

If you apply for early access you email us, so we hold what you chose to send: your name, work email, company, and whatever you tell us about your business. We use it to decide whether we are a fit and to talk to you. We do not sell it, share it, or add you to a list you did not ask for. If we do not proceed together, we delete the correspondence within 12 months of our last exchange, unless you ask us to keep in touch.

04If you use the product

A Rockbase account belongs to the company that signed up. Within it, the categories below are held on that company's instruction. The right-hand column is what actually governs access — Rockbase records a source of truth per field rather than per record, so a person can be editable in one respect and read-only in another.

CategoryWhat it coversNotes
IdentityEmail address, name, sign-in credentials, multi-factor settings, sessionsHeld by our self-hosted identity provider. We never see or store your password.
People recordsEmployment records, roles, seats, reporting lines, appointments, leave, caseworkCarries a sensitivity level; casework and similar records are restricted further than ordinary fields.
Work recordsGoals, objectives, KPIs, tasks, processes, documents, knowledge, registersThe substance of the account. Every relationship carries why and how it is measured.
Integrated dataRecords pulled from systems you connect, such as CRM contacts and dealsStamped with where it came from and how fresh it is. We never write back unless you ask us to.
Audit recordsWho changed what, when, from which IP addressAppend-only. Not editable, and not deletable by anyone — including us.
AI prompts and outputsThe text sent to and returned from the model, which may contain your dataSee section 07.

05Why we are allowed to hold it

  • Contract. To provide the product to the company that signed up, and to bill for it.
  • Legitimate interests. To keep the service secure, to keep the audit trail that makes it trustworthy, and to reply when you contact us. We have weighed this against your interests; the audit trail in particular exists to protect the people in the account, not to watch them.
  • Legal obligation. Where we must keep records, or must respond to a lawful request.
  • Consent, where we ask for it — and where we do, you can withdraw it.

For data inside a customer account, the customer determines the lawful basis for the people whose records they hold. We tell them what the system does so they can.

06Where your data lives

In the European region, in our own cloud projects, in London (Google Cloudeurope-west2). Not in a shared account, not in a US region, and not moved for convenience.

Two components other products would buy as a service, we run ourselves inside that same region: the identity provider that holds your credentials, and the workflow engine that runs long-running automation. Both are in our projects, under our access controls, which is why neither appears as a third party below.

One honest caveat, because it matters more than the marketing version: "in-region" here means the European region and, for the components above, London specifically. Where any future vendor offers EU residency but replicates account metadata elsewhere, we will say so on this page rather than describe it as EU-only.

07Who else processes your data

One company: Google. That is the whole list today, and we would rather show you a short true list than a long reassuring one.

Sub-processorWhat forWhereBasis
Google CloudThe platform Rockbase runs on — database, storage, compute, secretseurope-west2 (London), our own projectsProcessor under our Google Cloud terms
Google Cloud (Vertex AI)Claude model inference, pinned to the EUEUProcessor under our Vertex terms
Google WorkspaceSending invitation and account emailEUProcessor under our Workspace terms

Before any vendor joins that list it has to clear a written bar: keep data in the European region, and be audit-grade — SOC 2 Type II and/or ISO 27001 — with the strictness scaled to how sensitive the data is. Vendors that failed it are recorded internally with the reason, because a rejection is evidence too. We will name additions here before they start processing, not after.

We do not sell personal data, and we do not share it with advertising networks. There are none involved in this product. For the boundary this all sits inside, and the tiered bar a vendor has to clear, see security.

08AI, and what it does with your data

Every AI feature in Rockbase goes through one internal gateway. There is no second route and no direct call to a model provider from anywhere else in the system, which is what makes the following statements checkable rather than promises.

  • Inference runs inside our own EU project through Vertex AI, so the prompt does not leave the region to be answered.
  • We do not train models on your data, and we do not let anyone else do so on our behalf.
  • Every call is metered and capped against your plan. AI never runs on credit.
  • AI proposes; a person disposes. Recommendations are written into your account only when someone confirms them, and the record shows that they did.
  • Model output can be wrong. It is a starting point for a human decision, never a substitute for one — and never professional, legal or financial advice.

09Cookies

This website sets none, so there is no consent banner to click. The product sets two, both strictly necessary to sign you in and keep you signed in. Neither tracks you, and there is no third-party cookie in either place.

CookiePurposeLifetime
rb_sessionHolds your signed-in session. Encrypted, and unreadable to scripts.12 hours
rb_auth_flowProtects the sign-in redirect against interception and cross-site request forgery.10 minutes

10How long we keep it, and what deletion means

While an account is live, we keep its data. Archiving a record inside Rockbase retires it and cuts its connections, but keeps its history — deliberately, because a quality system whose records can be quietly removed is not evidence of anything. That is a design decision with a privacy consequence, so we would rather state it than let you discover it.

  • Audit records are append-only. Nobody can edit or delete them, including us. They are kept for the life of the account.
  • Archived records keep their history and stop appearing in the working views.
  • On termination, we return or delete account data on the customer's instruction, and delete our copies within 90 days of the account closing — except where we must keep something by law.
  • Backups roll off on their own schedule, so a deletion can persist in a backup for up to 35 days before it ages out.

11Who can see what, inside an account

Authorization is ours, not a bought add-on, and it is enforced at the database rather than in the interface — so a request that should see nothing sees nothing, whatever route it arrives by. Accounts are isolated from each other by the database itself.

  • Permission is granted in rings, and sensitive people data sits behind its own ring rather than being visible to anyone who can see the person.
  • Inviting someone is treated as granting access, so only an account owner can do it. Nobody else can bind a login to another person's record.
  • Suspension takes effect on our side, so it works even when the identity provider is unreachable — which is exactly when someone is being offboarded.
  • Every change records who made it. Including ours.

Our own staff access is limited to what is needed to run and support the service, is audited, and is never used to read customer content out of curiosity. At our current size that is a short and easily verified list of people.

12Security

Encrypted in transit and at rest. Multi-factor authentication available on every account. Least-privilege service identities, so the running application cannot alter its own database structure. Isolation between accounts tested on every change, and the tests fail the build rather than filing a warning.

No system is perfect and we do not claim ours is. If you find something, tell us at security@rockbase.app and we will work with you. We will not threaten you for reporting it.

If a breach affects your data, we will tell the customer whose account it is without undue delay, and notify the regulator where the law requires it.

13International transfers

Processing takes place in the European region. Where a transfer outside the UK or EEA ever becomes necessary, we will rely on an approved safeguard — adequacy, or the standard contractual clauses with a transfer risk assessment — and name it here. We are not relying on one today.

14Your rights

You can ask us for a copy of your data, to correct it, to delete it, to restrict or object to what we do with it, or to have it sent to someone else in a portable form. You can withdraw consent where we relied on it. We will not charge you or make it difficult, and we will respond within one month.

If your data sits inside a customer's account, ask that company first: they decide, and we act on their instruction. Tell us anyway if they are unresponsive.

Write to privacy@rockbase.app. If we get it wrong, you can complain to the Information Commissioner's Office at ico.org.uk, or to your local supervisory authority. We would rather you came to us first, but it is your right either way.

15Changes to this notice

This page describes a system under active development, so it will change. When it changes in a way that affects you, we will update the date at the top and tell account owners.

We publish what the build actually does — see the architecture behind these claims.

16Contact

Build on solid ground.

We're taking on a small number of founding clients. If your strategy and your work have drifted apart, let's fix the foundation.

Apply for early access