Privacy and data

Privacy Notice

A practical account of what data Binta uses, why it is needed, how AI participates in the workflow and what choices people have.

Last updated: 2026-08-29Effective: 2026-08-29

Who is responsible

The contracting Binta entity named in the Order Form acts as controller for website, account, billing and support data. When Binta handles business data on a customer's instructions, the customer is controller and Binta is processor under the DPA.

Data, purposes and legal bases

We use registration and account details, authorised user actions, workspace content, support messages, security events, device and service diagnostics. We process them to provide the contract, secure and support the service, meet legal duties and improve reliability. Optional analytics and marketing require the choice shown at collection where consent is the applicable basis.

  • Binta does not need full payment-card numbers; the checkout provider handles them.
  • Customers decide what lawful business content is placed in their workspace.
  • Necessary session and security storage works independently of optional analytics.

AI and digital employees

Digital employees read authorised workspace evidence, prepare next steps, identify exceptions and record their reasoning inside the business process. The customer sets their authority. External messages, money movement and irreversible actions remain approval-gated according to the configured policy.

  • The public sales chat clearly identifies itself as AI. It processes the visitor's message and optional contact details to answer product questions and arrange human follow-up; contact details are stored only after an explicit request for follow-up.
  • Binta does not use customer workspace content to train a general model unless a separate written agreement explicitly says so.
  • Model output may be incomplete or wrong and must not be the sole basis for high-impact legal or human decisions.
  • Instructions, approvals and audit records are kept according to the customer's service settings and retention schedule.

Providers, recipients and transfers

Binta uses vetted infrastructure, communications, payment, monitoring and model providers only to deliver the service. The current subprocessor list and hosting region are supplied with the Order Form or DPA. If data leaves its protected region, Binta uses the transfer mechanism required by applicable law and documents it for the customer.

Retention and security

Data is kept only for the period needed for the service, the signed retention schedule, dispute protection and mandatory legal records. Account deletion does not override records that law requires a party to retain. Binta applies role-based access, tenant isolation, encryption in transit, secrets controls, backups and auditable privileged actions; precise commitments belong in the Security Schedule or SLA.

Your choices and rights

Depending on applicable law, a person may request access, correction, deletion, restriction, portability, objection or withdrawal of consent, and may complain to the competent supervisory authority. For customer workspace data, start with the organisation that controls that workspace. Binta supports the customer under the DPA.

  • Use the secure form below; do not send identity documents or sensitive records in ordinary email.
  • We may ask for proportionate verification before disclosing or changing data.
  • Response periods follow the applicable law and start once the request can be verified.

Send a secure privacy request