# Privacy Policy
Base2Summit — CMDB-360
Effective Date: January 1, 2026
# 1. Introduction
Base2Summit LLC (“Base2Summit,” “we,” “us,” or “our”) develops and publishes CMDB-360, a cloud-based configuration management database (CMDB) appliance for Managed Service Providers (MSPs) and enterprise IT organizations. CMDB-360 is distributed as a virtual machine or container appliance image through public cloud marketplaces, including Oracle Cloud Infrastructure (OCI) Marketplace, AWS Marketplace, Microsoft Azure Marketplace, and others (collectively, the “Marketplace” or “Marketplaces”).
This Privacy Policy explains how Base2Summit collects, uses, stores, and protects information in connection with CMDB-360 and the activities associated with its distribution and licensing. It also describes the limited nature of Base2Summit’s access to data in the context of a customer-deployed appliance model.
# 2. Deployment Model — How CMDB-360 Works
CMDB-360 is a self-contained appliance that customers acquire through a public cloud marketplace and deploy directly into their own cloud tenancy, subscription, or virtual network environment. This is a fundamentally different model from a Software-as-a-Service (SaaS) offering.
Key characteristics of this deployment model include:
• Customer-controlled infrastructure: CMDB-360 runs exclusively within the customer’s own cloud account or tenancy (e.g., an OCI tenancy or an Azure subscription). The deployed appliance instance is never hosted, managed, or operated by Base2Summit.
• No Base2Summit access to deployed instances: Base2Summit personnel do not have access to any deployed CMDB-360 instance, nor to any data processed or stored within that instance, including discovered cloud asset data, configuration records, credentials, or any other operational data. This is a core architectural principle of the product.
• No data transmission to Base2Summit: CMDB-360 does not transmit any cloud asset data, CMDB records, discovered infrastructure data, or customer operational data back to Base2Summit or any Base2Summit-controlled systems.
• CMDB-360 only transmits the ID, name, type and version of a provisioned CMDB-360 Satellite for the purpose of validating the license. No other details about the resources managed by the satellite are transmitted.
• Customer responsibility for deployed data: All data generated, processed, and stored within a deployed CMDB-360 instance is entirely within the customer’s control and responsibility. Customers should apply their own organizational data governance, security, and privacy policies to their CMDB-360 deployment.
Because Base2Summit does not collect, receive, or have access to the data processed within deployed CMDB-360 instances (other than the described provisioning data related to CMDB-360 Satellites), this Privacy Policy addresses only the limited personal and business information Base2Summit collects in connection with marketplace transactions, software licensing, and customer support.
# 3. Information Base2Summit Collects
Base2Summit collects only the information necessary to distribute, license, and support CMDB-360. This is limited to the following categories:
# 3.1 Marketplace Transaction and Licensing Data
When a customer acquires CMDB-360 through a public cloud marketplace, the marketplace provider (such as Oracle, AWS or Microsoft) may share certain transaction-related information with Base2Summit in accordance with the marketplace’s publisher agreements and privacy policies. This information may include:
• Organization or company name
• Marketplace account identifiers or tenant/subscription identifiers (as provided by the marketplace)
• License entitlement details (product edition, quantity, and term)
• Transaction date and region
Base2Summit does not receive payment card details directly; all payment processing is handled by the respective marketplace platform.
# 3.2 Customer and Contact Information
When customers or prospective customers contact Base2Summit directly — for example, to request support, request a trial license, submit a support ticket, or inquire about the product — we collect the information provided in those communications, which may include:
• Name and job title
• Business email address and phone number
• Company name and general location
• The content of the inquiry or support request
# 3.3 License Activation and Registration Data
If CMDB-360 requires a license key activation or product registration, we may collect information necessary to issue, validate, and manage licenses, such as:
• Contact name and business email address
• Organization name
• Deployment region or cloud platform (e.g., OCI, Azure)
• License activation timestamps and status
# 3.4 Website and Marketing Communications Data
If you interact with the Base2Summit website, sign up for product information, or subscribe to communications, we may collect standard web analytics data (such as IP addresses, browser type, and pages visited) and your contact details for the purposes you authorize.
# 4. How We Use Information
Base2Summit uses the limited information it collects for the following purposes:
• Fulfilling and managing software license entitlements and marketplace transactions
• Responding to customer support requests and technical inquiries
• Communicating product updates, security advisories, and release notifications relevant to licensed versions of CMDB-360
• Managing the business relationship between Base2Summit and its customers and partners
• Complying with applicable laws, regulations, and marketplace publisher obligations
• Enforcing our licensing terms and other agreements
• Improving our products and documentation based on support interactions and product feedback (using only anonymized or aggregated insights, not operational customer data)
We do not use any information obtained through marketplace transactions or customer communications to access, analyze, or derive insights from deployed CMDB-360 instances or the data contained within them.
# 5. Data Base2Summit Does Not Collect
For clarity, Base2Summit does not collect, receive, access, or process any of the following categories of data as part of the CMDB-360 product:
• Cloud infrastructure asset data, configuration records, or CMDB data discovered and stored within a customer’s deployed CMDB-360 instance
• Cloud provider credentials, API keys, or authentication tokens stored within a customer’s deployment
• Customer workload data, application data, or content residing within cloud resources monitored by CMDB-360
• End-user activity logs, session data, or platform usage data from within a customer’s CMDB-360 deployment
• Any data transmitted between CMDB-360 and a customer’s cloud provider APIs within the customer’s environment
Customers bear sole responsibility for the security, privacy, and governance of all data within their CMDB-360 deployments.
# 6. Data Sharing and Disclosure
Base2Summit does not sell, rent, or trade personal or business information. We may share the limited information we collect in the following circumstances:
# 6.1 Marketplace Platforms
Marketplace transactions are conducted on and governed by the respective marketplace platform (e.g., Oracle Cloud Infrastructure Marketplace, Microsoft Azure Marketplace). Information shared between Base2Summit and these platforms is governed by the applicable marketplace publisher agreements and platform privacy policies.
# 6.2 Service Providers
We may engage third-party vendors to assist with business operations such as email communications, customer relationship management, or support ticketing. These vendors access only the information necessary to perform their functions and are bound by confidentiality obligations.
# 6.3 Legal Requirements
We may disclose information when required by applicable law, regulation, or legal process, or where necessary to protect the rights, property, or safety of Base2Summit, our customers, or the public.
# 6.4 Business Transfers
In the event of a merger, acquisition, or sale of business assets, limited customer information held by Base2Summit may be transferred as part of that transaction. Affected customers will be notified of any material changes.
# 7. Data Security
Base2Summit applies reasonable administrative and technical safeguards to protect the limited information it collects (primarily contact information and licensing data) against unauthorized access or disclosure. These measures include access controls, secure communications, and restricted access to customer records on a need-to-know basis.
Security of the deployed CMDB-360 appliance and all data within it is the sole responsibility of the customer. Customers are responsible for securing their cloud environment, managing access to their CMDB-360 instance, rotating credentials, and applying configuration hardening appropriate to their organization’s security requirements. Base2Summit publishes security hardening guidance and best practice documentation for deployment environments.
# 8. Data Retention
Base2Summit retains licensing and contact information for the duration of the customer relationship and for a reasonable period thereafter as needed to fulfill legal, contractual, or business obligations. When information is no longer needed, it is securely deleted or anonymized.
Customer data within deployed CMDB-360 instances is entirely under the customer’s control. Customers may delete, export, or manage such data at any time in accordance with their own data governance policies.
# 9. Marketplace Platform Privacy
CMDB-360 is made available through third-party cloud marketplaces. The collection and use of information by those platforms in connection with marketplace transactions — including account data, billing, and usage metrics collected by the platform itself — is governed exclusively by those platforms’ own privacy policies and terms of service:
• Oracle Cloud Infrastructure Marketplace: governed by Oracle’s Privacy Policy (https://www.oracle.com/legal/privacy/)
• Microsoft Azure Marketplace: governed by Microsoft’s Privacy Statement (https://privacy.microsoft.com/en-us/privacystatement)
Base2Summit is not responsible for the privacy practices of marketplace platforms.
# 10. Children’s Privacy
CMDB-360 is an enterprise software product not directed at individuals under the age of 18. Base2Summit does not knowingly collect personal information from minors.
# 11. International Considerations
Base2Summit operates in the United States. Any limited contact or licensing information collected by Base2Summit may be stored and processed in the United States. For customers in jurisdictions with data transfer restrictions (such as the European Economic Area), Base2Summit will apply appropriate safeguards as required by applicable law.
CMDB-360 appliance deployments are hosted entirely within the customer’s chosen cloud region and jurisdiction. Customers are responsible for ensuring their deployment configuration complies with applicable data residency and sovereignty requirements.
# 12. Your Privacy Rights
Depending on your jurisdiction, you may have rights to access, correct, delete, or restrict the processing of personal information held by Base2Summit (limited to contact and licensing data as described in Section 3). To exercise these rights, please contact us at the address below.
Rights over data within a deployed CMDB-360 instance are governed entirely by the customer organization, which acts as the data controller for that deployment.
# 13. California Privacy Rights
California residents may have rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) with respect to the limited personal information Base2Summit holds. We do not sell personal information. To exercise your California rights, please contact us using the information below.
# 14. Changes to This Privacy Policy
We may update this Privacy Policy periodically. When material changes are made, we will update the Effective Date and, where appropriate, provide notice through our website or direct communication to known contacts. Continued use of CMDB-360 after the effective date of any update constitutes acceptance of the revised policy.
# 15. Contact Information
For questions, concerns, or privacy-related requests, please contact:
Base2Summit / CMDB-360 — Privacy Officer
Email: support@cmdb360.com
Website: https://www.cmdb360.com
Address: 13467 King Lake Trl
Broomfield, CO 80020
United States
We will respond to privacy inquiries within a reasonable timeframe and in accordance with applicable legal requirements.