Controller–processor terms
Data Processing Agreement
The operating rules for customer-controlled personal data processed by Binta and its digital employees.
Last updated: 2026-08-29Effective: 2026-08-29
Scope, duration and roles
The customer is controller and Binta is processor for personal data in the contracted service. Processing lasts for the service term and the agreed deletion period. Subject matter is running the customer's authorised workflows, integrations, support and security controls.
Instructions, data and people
Binta processes data only on documented customer instructions, the agreement and applicable law. The Order Form describes enabled functions and region. Data may include business contacts, staff and counterparties, identifiers, communications, documents, transactions and audit events. Sensitive or specially regulated data is out of scope unless expressly agreed.
- The customer confirms that its instructions and data collection are lawful.
- Binta informs the customer if an instruction appears to breach applicable data-protection law, unless prohibited from doing so.
- Digital-employee authority is restricted by configured roles, limits and approvals.
Confidentiality and security
Personnel and subprocessors with access are bound by confidentiality. Binta applies risk-appropriate technical and organisational measures, including access control, tenant isolation, secure transmission, secrets management, resilience and auditability. The signed Security Schedule contains the tested controls and any customer-specific commitments.
Subprocessors and transfers
The customer gives general authorisation for the listed subprocessors. Binta provides notice of material changes and a reasonable objection process. Subprocessors receive equivalent data-protection obligations. International transfers use the lawful mechanism recorded in the signed documents.
Rights, assessments and incidents
Taking account of the processing, Binta assists with data-subject requests, security duties, impact assessments and regulator consultation where applicable. Binta notifies the customer without undue delay after confirming a personal-data breach affecting customer data and supplies available facts; contractual incident targets belong in the Security Schedule or SLA.
Return, deletion and assurance
At the customer's choice and subject to the signed schedule, Binta returns or deletes customer data after service end, except mandatory retention. Binta supplies information reasonably necessary to demonstrate compliance. Independent reports are the default assurance method; a scoped audit is available under confidentiality, security and cost safeguards agreed by the parties.