Skip to content
DecisionNodeDecisionNde
  • Model
  • Inference
  • Benchmarks
  • Examples
  • Docs
  • Pricing

api all systems normal

Get API keyGet API key
  • dnModelTyped answers, calibrated confidence
  • msInferenceOur own stack and GPUs, answers in ms
  • %BenchmarksAccuracy per suite, with intervals
  • exExamplesBuilds you can start from today
  • /v1DocsQuickstart, API reference, recipes
  • $PricingPay per input token, output is free
  1. legal
  2. /data processing addendum
addendum

Data Processing Addendum.

The Article 28 terms under which Bynn processes personal data in API requests for its Customers.

sections
17
linkable clauses
31
defined terms
20
min read
15
version
1.1
last updated
6 October 2026
status
Draftnot yet in effect
applies to
Customers whose Input contains Personal Data

Questions: legal@bynn.com

Draft for legal review, not yet in effect. These documents are drafts prepared for counsel and do not yet bind anyone. Values shown in amber are still open and are to be confirmed before these terms take effect.These documents are drafts prepared for counsel and do not yet bind anyone. Values set in italics and underlined are still open and are to be confirmed before these terms take effect.

contents0% read

  1. 11. Definitions
  2. 22. Roles and scope
  3. 33. Details of the processing
  4. 44. Instructions
  5. 55. Confidentiality of personnel
  6. 66. Security measures
  7. 77. Sub-processors
  8. 88. Data Subject requests
  9. 99. Impact assessments and prior consultation
  10. 1010. Personal Data Breach
  11. 1111. Deletion or return
  12. 1212. Audits
  13. 1313. International transfers
  14. 1414. United States privacy laws
  15. 1515. Liability
  16. 1616. Term, precedence and changes
  17. 1717. Contact
  18. ·Points awaiting review
  1. 11. Definitions
  2. 22. Roles and scope
  3. 33. Details of the processing
  4. 44. Instructions
  5. 55. Confidentiality of personnel
  6. 66. Security measures
  7. 77. Sub-processors
  8. 88. Data Subject requests
  9. 99. Impact assessments and prior consultation
  10. 1010. Personal Data Breach
  11. 1111. Deletion or return
  12. 1212. Audits
  13. 1313. International transfers
  14. 1414. United States privacy laws
  15. 1515. Liability
  16. 1616. Term, precedence and changes
  17. 1717. Contact
  18. ·Points awaiting review

This Data Processing Addendum (the DPA) forms part of the Agreement between Bynn Intelligence, Inc. (Bynn) and the Customer. It applies where, and to the extent that, Bynn processes Customer Personal Data on behalf of the Customer in providing the Service, and sets out the terms required by Article 28 of the GDPR and the UK GDPR and by other Data Protection Laws. The Customer accepts this DPA by accepting the Terms of Service; no separate signature is required, and Bynn will countersign a copy on request to privacy@bynn.com. Capitalised terms not defined in this DPA have the meanings given in the Terms of Service.

1Section 1. Definitions

#
Controller, Processor, Data Subject, Personal Data, Processing, Personal Data Breach and Supervisory Authority
have the meanings given in the GDPR, and include the equivalent terms under other Data Protection Laws, such as business, service provider and contractor under the CCPA.
CCPA
the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020, and its regulations.
Customer Personal Data
Personal Data contained in Customer Data that Bynn processes as a Processor on behalf of the Customer.
Data Protection Laws
all laws on the protection of Personal Data that apply to the processing under the Agreement, including the GDPR, the UK GDPR, the UK Data Protection Act 2018, the Swiss Federal Act on Data Protection and the comprehensive privacy laws of the states of the United States, including the CCPA.
GDPR
Regulation (EU) 2016/679, the General Data Protection Regulation.
Instructions
the Customer's documented instructions for the processing of Customer Personal Data, as described in Section 4.1.
Restricted Transfer
a transfer of Customer Personal Data to a country that Data Protection Laws do not recognise as providing an adequate level of protection, where the transfer would be prohibited without the safeguards in Section 13.
Standard Contractual Clauses
the standard contractual clauses annexed to European Commission Implementing Decision (EU) 2021/914 of 4 June 2021.
Sub-processor
any Processor, including an Affiliate of Bynn, that Bynn engages to process Customer Personal Data.
UK Addendum
the International Data Transfer Addendum to the European Commission's Standard Contractual Clauses issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018.
UK GDPR
the GDPR as it forms part of the law of the United Kingdom.

2Section 2. Roles and scope

#
2.1

Roles. The Customer is the Controller of Customer Personal Data and Bynn is its Processor. Where the Customer acts as a Processor on behalf of a third-party Controller, Bynn is the Customer's Sub-processor, and the Customer warrants that its Instructions and its engagement of Bynn have been authorised by that Controller.

2.2

Bynn as Controller. Bynn processes the following as a Controller, as described in Section 1.1 of the Privacy Policy: Account Data, Usage Data, safety records, communications with Bynn and data collected through the Website. Bynn processes safety records, which hold the API Key, the time, a cryptographic hash of a request and the probability returned by the Safety Check and are derived from Customer Data, for its own purposes of preventing abuse, protecting the security of the Service, keeping an audit trail and meeting its legal obligations. This DPA does not apply to that processing.

2.3

The Customer's responsibility for its data. The Customer is responsible for the accuracy, quality and lawfulness of Customer Personal Data and of the means by which it obtained it, and for having a lawful basis for every processing it instructs.

3Section 3. Details of the processing

#

The processing under this DPA has the following characteristics. This Section 3 forms Annex I.B of the Standard Contractual Clauses where they apply.

Subject matter
the provision of the Service: receiving Input through the API, including the Frames of a Session, and returning Output.
Duration
the term of the Agreement and the period until deletion under Section 11.
Nature
automated processing in which Input is received, analysed by the Models, answered with Output, held for the life of a Session where the Customer opens one, retained for the retention period where applicable, and deleted.
Purpose
to provide, secure and support the Service in accordance with the Agreement and the Instructions, to prevent abuse and enforce the Acceptable Use Policy, and to comply with the law.
Categories of Personal Data
any Personal Data the Customer chooses to include in Input, which may include contact details, identifiers, the text of messages and documents, transaction details, images of people or documents, and images and readings from cameras and sensors, such as those on vehicles, unmanned aircraft or machines, which may show persons who are not the Customer's End Users, and the Output derived from it.
Special categories
the Customer shall not submit special categories of Personal Data or Personal Data relating to criminal convictions and offences unless it has a lawful basis, the conditions of Data Protection Laws are met, and the processing is necessary for its purpose, subject to Section 3 of the Acceptable Use Policy.
Data Subjects
as determined by the Customer, and which may include its End Users, its customers, its personnel and any person whose information appears in Input.
Frequency
continuous, with each request to the API and each Frame of a Session.
Retention
Input and Output are deleted thirty (30) days to be confirmed after each request, or are not stored after the Output is returned where zero retention applies, which Bynn offers on the plans to be confirmed before these terms take effect, subject to Section 11 and Section 8.5 and Section 8.11 of the Terms of Service.

4Section 4. Instructions

#
4.1

Processing on Instructions. Bynn shall process Customer Personal Data only on the Customer's documented Instructions, including with regard to transfers, unless the law to which Bynn is subject requires otherwise, in which case Bynn shall inform the Customer of that legal requirement before processing unless the law prohibits it. The Agreement, the Customer's configuration of the Service, including its retention settings, and its use of the API are the Customer's complete Instructions. Any additional Instruction requires Bynn's written agreement and may be subject to additional Fees.

4.2

Unlawful Instructions. Bynn shall inform the Customer without delay if, in its opinion, an Instruction infringes Data Protection Laws, and may suspend the processing concerned until the Customer confirms or changes the Instruction.

4.3

The Customer's Instructions. The Customer shall ensure that its Instructions comply with Data Protection Laws, and that it has given every notice and obtained every consent needed for Bynn to process Customer Personal Data under the Agreement.

4.4

Use limitation. Bynn shall not use Customer Personal Data for any purpose other than those in Section 3. In particular, Bynn shall not use it to train, retrain or fine-tune any Model without the Customer's written consent under Section 8.4 of the Terms of Service, and shall not sell it or share it for cross-context behavioural advertising.

5Section 5. Confidentiality of personnel

#

Bynn shall ensure that every person it authorises to process Customer Personal Data is bound by an appropriate contractual or statutory duty of confidentiality, has access only to the extent needed for that person's role, and is trained in the handling of Personal Data.

6Section 6. Security measures

#
6.1

Measures. Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of the processing, and the risks to Data Subjects, Bynn shall implement and maintain the technical and organisational measures required by Article 32 of the GDPR. They include at least the following categories, which form Annex II of the Standard Contractual Clauses where they apply:

  1. (a)(a) encryption of Customer Personal Data in transit over public networks and at rest;
  2. (b)(b) access control on a need-to-know basis, with individual accounts and authentication for personnel;
  3. (c)(c) management of encryption keys and credentials, including their rotation;
  4. (d)(d) logical separation of each customer's data;
  5. (e)(e) logging and monitoring of access to production systems;
  6. (f)(f) vulnerability management and timely application of security updates;
  7. (g)(g) documented procedures for responding to security incidents; and
  8. (h)(h) confidentiality undertakings and security training for personnel.
6.2

Updates. Bynn may update the measures from time to time, provided that the update does not materially reduce the overall level of protection of Customer Personal Data.

6.3

The Customer's security. The Customer is responsible for the security of its own systems and API Keys, and for deciding whether the measures in this Section 6 are appropriate for the Customer Personal Data it submits. By submitting Customer Personal Data, the Customer agrees that they provide an appropriate level of protection for it.

7Section 7. Sub-processors

#
7.1

General authorisation. The Customer gives Bynn general written authorisation to engage Sub-processors. Bynn's Sub-processors fall into the following categories: cloud computing and hosting; payment processing; and email delivery. The current list, with each Sub-processor's function and location, is available to Customers in the Console and on request at privacy@bynn.com, and forms Annex III of the Standard Contractual Clauses where they apply.

7.2

Notice of changes. Bynn shall give the Customer at least thirty (30) days' notice, in the Console or by email, before authorising a new Sub-processor to process Customer Personal Data.

7.3

Right to object. The Customer may object in writing to a new Sub-processor on reasonable grounds relating to data protection within the notice period. Bynn shall discuss the objection with the Customer in good faith and may propose a change to the Customer's configuration or use of the Service that avoids processing by that Sub-processor. If the objection is not resolved within thirty (30) days of its receipt, the Customer may terminate the affected part of the Service by notice, and Bynn shall refund the unused Credits attributable to it. This is the Customer's sole and exclusive remedy for its objection. If the Customer does not object within the notice period, it is deemed to accept the new Sub-processor.

7.4

Urgent replacement. Where a Sub-processor must be replaced urgently for reasons of security or continuity of the Service, Bynn may engage its replacement immediately and shall give notice as soon as practicable; the Customer's right to object under Section 7.3 applies from that notice.

7.5

Flow-down and responsibility. Bynn shall impose on each Sub-processor, by written contract, data protection obligations no less protective than those in this DPA, to the extent appropriate to the services the Sub-processor provides, and remains liable to the Customer for each Sub-processor's performance of those obligations to the extent required by Data Protection Laws.

8Section 8. Data Subject requests

#

Taking into account the nature of the processing, Bynn shall assist the Customer, by appropriate technical and organisational measures and insofar as possible, in responding to requests from Data Subjects to exercise their rights. Bynn shall promptly forward to the Customer any such request it receives that identifies the Customer, and shall not respond to it except to direct the Data Subject to the Customer, unless the law requires otherwise. The Customer acknowledges that, because Input and Output are deleted after the retention period, Bynn may no longer hold the data concerned. Where the law permits, Bynn may charge its reasonable costs for assistance beyond the self-service functions of the Service.

9Section 9. Impact assessments and prior consultation

#

Taking into account the nature of the processing and the information available to it, Bynn shall provide the Customer with reasonable assistance, including the Documentation and information about the Service, for any data protection impact assessment and any prior consultation with a Supervisory Authority that Data Protection Laws require of the Customer in relation to the Service. Where the law permits, assistance beyond that information is at the Customer's cost.

10Section 10. Personal Data Breach

#

Important: Breach notice

10.1

Notice within 72 hours. Bynn shall notify the Customer without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data.

10.2

Content of the notice. The notice shall describe, to the extent then known, the nature of the breach, the categories and approximate number of Data Subjects and records concerned, its likely consequences, the measures taken or proposed to address it, and a contact point at security@bynn.com. Where the information is not available at once, Bynn may provide it in phases.

10.3

Containment. Bynn shall take reasonable steps to contain, investigate and mitigate the breach, and shall give the Customer reasonable assistance with the notifications to Supervisory Authorities and Data Subjects that the Customer, as Controller, is responsible for making. Bynn shall not notify the Customer's Data Subjects or Supervisory Authorities on the Customer's behalf unless the law requires it or the Customer agrees.

10.4

No admission. A notice under this Section 10 is not an acknowledgement of fault or liability. Unsuccessful attempts or activities that do not compromise the security of Customer Personal Data, such as pings, port scans and failed log-in attempts, are not Personal Data Breaches.

11Section 11. Deletion or return

#

Customer Personal Data is deleted in the ordinary course after the retention period in Section 3. On termination of the Agreement, the Customer may export the Customer Personal Data that Bynn still holds within the thirty (30) days provided in Section 16.6 of the Terms of Service, after which Bynn deletes it, unless the law of the European Union, of a Member State or of another applicable jurisdiction requires its storage, in which case Bynn keeps it confidential and processes it only for that purpose. Output is returned to the Customer in response to each request, which satisfies any obligation to return it. Bynn shall confirm deletion in writing on the Customer's written request.

12Section 12. Audits

#
12.1

Information. Bynn shall make available to the Customer the information necessary to demonstrate its compliance with Article 28 of the GDPR, consisting of this DPA, its security documentation, its answers to a reasonable security questionnaire not more than once in any twelve (12) month period, and any independent audit report that Bynn chooses to obtain.

12.2

Audits and inspections. Where that information is reasonably insufficient to demonstrate compliance, or where a Supervisory Authority requires it, the Customer may carry out an audit, including an inspection, itself or through an independent auditor that is bound by confidentiality and is not a competitor of Bynn. The Customer shall give at least thirty (30) days' written notice, agree the scope in advance, conduct the audit during business hours with minimal disruption, and not seek access to other customers' data or to information unrelated to the processing. Audits are limited to one (1) in any twelve (12) month period, except after a Personal Data Breach or where a Supervisory Authority requires one. The Customer bears its own costs and, where the law permits, Bynn's reasonable costs of supporting the audit. The results are Bynn's Confidential Information.

12.3

Standard Contractual Clauses. Audits under the Standard Contractual Clauses are carried out in accordance with this Section 12.

13Section 13. International transfers

#
13.1

Location of processing. Bynn and its Sub-processors may process Customer Personal Data outside the European Economic Area, the United Kingdom and Switzerland, including in the United States, subject to this Section 13.

13.2

European Economic Area. For a Restricted Transfer from the European Economic Area, the Standard Contractual Clauses are incorporated into this DPA, with Module Two (Controller to Processor) applying where the Customer is a Controller and Module Three (Processor to Processor) where it is a Processor, as follows:

  1. (a)(a) the docking clause in Clause 7 applies;
  2. (b)(b) under Clause 9(a), Option 2 (general written authorisation) applies, with the notice period in Section 7.2;
  3. (c)(c) the optional wording in Clause 11 does not apply;
  4. (d)(d) under Clause 13, the competent Supervisory Authority is that of the Customer's establishment or, where it has none in the European Union, of its representative;
  5. (e)(e) under Clauses 17 and 18, the clauses are governed by the law of the EU Member State to be confirmed before these terms take effect, whose courts have jurisdiction; and
  6. (f)(f) Annexes I, II and III are completed by Section 3, Section 6 and Section 7.1 of this DPA and by the details of the parties in the Agreement.
13.3

United Kingdom. For a Restricted Transfer from the United Kingdom, the UK Addendum is incorporated into this DPA, with its Tables 1 to 3 completed by the information in this DPA and in Section 13.2, and neither party may end it under its Table 4 except as the UK Addendum requires.

13.4

Switzerland. For a Restricted Transfer from Switzerland, the Standard Contractual Clauses apply as set out in Section 13.2, with references to the GDPR read as references to the Swiss Federal Act on Data Protection, and the Swiss Federal Data Protection and Information Commissioner as the competent Supervisory Authority.

13.5

Requests from public authorities. Where legally permitted, Bynn shall notify the Customer of any legally binding request from a public authority for disclosure of Customer Personal Data, shall challenge a request it considers unlawful after careful assessment, and shall disclose only the minimum information the request requires.

13.6

Precedence and alternatives. In the event of conflict between this DPA and the Standard Contractual Clauses or the UK Addendum, the latter prevail. If Bynn adopts another lawful transfer mechanism recognised by Data Protection Laws, that mechanism applies in its place to the extent it covers the transfer.

14Section 14. United States privacy laws

#

To the extent the CCPA or another United States state privacy law applies, Bynn is the Customer's service provider, contractor or Processor, and shall not (a) sell or share Customer Personal Data; (b) retain, use or disclose it outside the direct business relationship with the Customer or for any purpose other than the business purposes in the Agreement; or (c) combine it with Personal Data from other sources, except as those laws permit. Bynn shall provide the level of privacy protection those laws require, shall notify the Customer if it can no longer meet its obligations under them, and agrees that the Customer may take reasonable and appropriate steps to stop and remediate any unauthorised use. Bynn certifies that it understands and will comply with these restrictions.

15Section 15. Liability

#

Bynn's liability arising out of or relating to this DPA and the Standard Contractual Clauses, whether in contract, tort or otherwise, is subject to Section 15 of the Terms of Service, to the extent permitted by law. The Customer's liability under this DPA is not limited, and the Customer's indemnity under Section 14.1 of the Terms of Service extends to every claim arising from its Instructions or from Customer Personal Data. Nothing in this DPA limits a party's liability to Data Subjects under Article 82 of the GDPR, or any right of a Data Subject under the Standard Contractual Clauses, that cannot lawfully be limited.

16Section 16. Term, precedence and changes

#
16.1

Term. This DPA applies for as long as Bynn processes Customer Personal Data.

16.2

Precedence. As to the processing of Customer Personal Data, this DPA prevails over the Terms of Service, and the Standard Contractual Clauses prevail over this DPA.

16.3

Changes. Bynn may update this DPA where required by a change in Data Protection Laws or a decision of a competent authority, or on at least thirty (30) days' notice under Section 17 of the Terms of Service. No update shall reduce the overall level of protection of Customer Personal Data without the Customer's consent, except as the law requires.

17Section 17. Contact

#
Data protection questions and countersigned copies
privacy@bynn.com
Security incidents
security@bynn.com

Points awaiting review

Open points for counsel and the owner, to be settled before this document takes effect. This list is removed when the document is published.

For counsel

  • The law and courts under Clauses 17 and 18 of the Standard Contractual Clauses, and the competent Supervisory Authority under Clause 13.
  • Whether the Swiss provisions in Section 13.4 are needed at launch.
  • The Controller basis for safety records derived from Customer Data (Section 2.2), and whether it needs its own mention in the Standard Contractual Clauses.
  • Whether applying the Terms of Service liability cap to this DPA is acceptable to EU customers, and the allocation of audit costs in Section 12.2.
  • Sessions in Section 3: Frames as Input in the subject matter, nature and frequency of processing, a Session's context held for its life under Section 8.11 of the Terms of Service, and images and sensor readings from vehicles, unmanned aircraft and machines that may show bystanders, and whether the Customer's duties in Section 2.3 need more for that data.

For the owner

  • Confirm that the security measures in Section 6.1 match current practice before launch.
  • Publish the Sub-processor list in the Console, with a way to subscribe to change notices.
  • Request retention (30 days drafted) and the plans on which zero retention is offered.
  • Confirm the breach notice process run from security@bynn.com.

Values still open in this document

  • The date on which these documents take effect
  • How long Input and Output are kept before deletion (30 days proposed)
  • The plans on which zero retention is offered
  • The law and courts chosen under Clauses 17 and 18 of the Standard Contractual Clauses
← previousPrivacy Policynext →Defence Contract Addendum
DecisionNodeDecisionNde

The decision model, and the inference API that serves it.

one endpoint: POST api.decisionnode.com/v1/decidePOST /v1/decide

start building

Your first decision in minutes.

Make a key, paste one curl, branch on a typed answer. Prepaid, no sales call.

  • api all systems normalapi normal
  • output is always freeoutput always free
  • same request, same answersame request, same answer

DecisionNode is built and run by Bynn Intelligence, Inc.

We train the model and serve it on our own GPUs.

hello@bynn.com

product

  • Model
  • Inference
  • Benchmarks
  • Pricing

developers

  • Docs
  • Quickstart
  • Examples
  • Playground
  • Console

company

  • Contact
  • Security
  • Report abuse
  • Dedicated

legal

  • Terms
  • Acceptable use
  • Privacy
  • Data processing
  • Defence addendum
  • Cookies

© 2026 Bynn Intelligence, Inc.

prices in USD per 1M input tokens