This Privacy Policy (the Policy) explains how Bynn Intelligence, Inc. (Bynn, we or us) collects, uses, discloses and otherwise processes Personal Data in connection with the DecisionNode Service and the website at decisionnode.com, including the Console, the playground and the Documentation (the Website), and the rights available to the individuals concerned. Capitalised terms not defined in this Policy have the meanings given in the Terms of Service.
Section 1. Who we are and the scope of this Policy
#Bynn as Controller. Bynn is the Controller of the Personal Data in Account Data, Usage Data, safety records, communications with Bynn and data collected through the Website. Bynn Intelligence, Inc. has its registered address to be confirmed before these terms take effect.
Bynn as Processor of Customer Data. When a Customer submits Input containing Personal Data, Bynn processes that Personal Data, and the Output derived from it, as a Processor on behalf of the Customer, which is the Controller, under the Data Processing Addendum. This Policy describes Bynn's practices for that data for transparency, but the Customer's own privacy notice governs it. An individual whose Personal Data a Customer has submitted should contact that Customer; Bynn forwards any request it receives about such data to the Customer concerned.
Business service. The Service is provided to businesses and is intended for use by persons aged eighteen (18) or older acting on behalf of an organisation.
Section 2. Personal Data we collect
#Categories. Bynn collects the following categories of Personal Data:
| Category | What it includes | Source |
|---|---|---|
| Account Data: profile | Name, business email address, organisation, role, workspace membership and settings, and authentication credentials, which are stored only in protected form. | You, or the Customer that invites you |
| Account Data: billing | Billing contact, billing address, tax identifiers and transaction records. Card details are collected by Bynn's payment processor; Bynn receives only limited details such as card brand, last four digits and expiry date. | You and Bynn's payment processor |
| Customer Data | Input (state, questions, criteria, instructions, images and the Frames of a Session) and Output. It contains Personal Data only if the Customer chooses to include it, for example where an image or a camera Frame shows a person. | The Customer, through the API |
| Usage Data | Request identifiers, Session identifiers, Frame sequence numbers, timestamps, token counts, latency, model identifiers, error codes, API Key identifiers, and the IP address and user agent of each request. | Generated automatically |
| Safety records | Records of requests refused or flagged by the Safety Check and, under a Defence Contract Addendum, of requests served with the Safety Check switched off: the API Key, the time, a cryptographic hash of the request and the check's probability. | Generated automatically |
| Communications | Support requests, feedback, and reports of abuse or security issues, with their contents and contact details. | You |
| Website data | Device and browser information, pages viewed, referring page, IP address, your cookie choices and the browser storage described in the Cookies Policy. | Generated automatically |
- Category
- Account Data: profile
- What it includes
- Name, business email address, organisation, role, workspace membership and settings, and authentication credentials, which are stored only in protected form.
- Source
- You, or the Customer that invites you
- Category
- Account Data: billing
- What it includes
- Billing contact, billing address, tax identifiers and transaction records. Card details are collected by Bynn's payment processor; Bynn receives only limited details such as card brand, last four digits and expiry date.
- Source
- You and Bynn's payment processor
- Category
- Customer Data
- What it includes
- Input (state, questions, criteria, instructions, images and the Frames of a Session) and Output. It contains Personal Data only if the Customer chooses to include it, for example where an image or a camera Frame shows a person.
- Source
- The Customer, through the API
- Category
- Usage Data
- What it includes
- Request identifiers, Session identifiers, Frame sequence numbers, timestamps, token counts, latency, model identifiers, error codes, API Key identifiers, and the IP address and user agent of each request.
- Source
- Generated automatically
- Category
- Safety records
- What it includes
- Records of requests refused or flagged by the Safety Check and, under a Defence Contract Addendum, of requests served with the Safety Check switched off: the API Key, the time, a cryptographic hash of the request and the check's probability.
- Source
- Generated automatically
- Category
- Communications
- What it includes
- Support requests, feedback, and reports of abuse or security issues, with their contents and contact details.
- Source
- You
- Category
- Website data
- What it includes
- Device and browser information, pages viewed, referring page, IP address, your cookie choices and the browser storage described in the Cookies Policy.
- Source
- Generated automatically
Section 3. How we use Personal Data and our legal bases
#Purposes and legal bases. Bynn uses Personal Data for the following purposes. Where the GDPR or the UK GDPR applies, Bynn relies on the legal basis stated for each purpose.
| Purpose | Data used | Legal basis |
|---|---|---|
| Providing the Service: processing API requests and returning Outputs | Account Data, Customer Data, Usage Data | Performance of the contract with the Customer (Article 6(1)(b)); for Customer Data, the Customer's instructions as Controller |
| Administering Accounts, authentication and support | Account Data, communications | Performance of the contract; Bynn's legitimate interest in supporting its customers (Article 6(1)(f)) |
| Billing, payment, tax and accounting | Account Data (billing), Usage Data | Performance of the contract; compliance with legal obligations (Article 6(1)(c)) |
| Security, abuse prevention, the Safety Check and enforcement of the Terms of Service and the Acceptable Use Policy | Usage Data, safety records and, where an investigation requires it, Customer Data | Bynn's legitimate interest in protecting the Service, its customers and the public; compliance with legal obligations |
| Service notices, such as changes to terms, security notices and incident notifications | Account Data | Performance of the contract; compliance with legal obligations |
| Operating, analysing and improving the Service, without training Models on Customer Data | Usage Data, Website data, aggregated or de-identified data | Bynn's legitimate interest in running and developing its Service |
| Product news to business contacts | Account Data | Bynn's legitimate interest in business communications, or consent where the law requires it; you may opt out at any time |
| Operating the Website; analytics and marketing cookies only where you allow them | Website data | Strictly necessary storage: Bynn's legitimate interest in providing the Website you request; analytics and marketing: consent (Article 6(1)(a)) |
| Complying with the law, responding to lawful requests, and establishing, exercising or defending legal claims | Any of the above, as necessary | Compliance with legal obligations; Bynn's legitimate interest in protecting its rights |
- Purpose
- Providing the Service: processing API requests and returning Outputs
- Data used
- Account Data, Customer Data, Usage Data
- Legal basis
- Performance of the contract with the Customer (Article 6(1)(b)); for Customer Data, the Customer's instructions as Controller
- Purpose
- Administering Accounts, authentication and support
- Data used
- Account Data, communications
- Legal basis
- Performance of the contract; Bynn's legitimate interest in supporting its customers (Article 6(1)(f))
- Purpose
- Billing, payment, tax and accounting
- Data used
- Account Data (billing), Usage Data
- Legal basis
- Performance of the contract; compliance with legal obligations (Article 6(1)(c))
- Purpose
- Security, abuse prevention, the Safety Check and enforcement of the Terms of Service and the Acceptable Use Policy
- Data used
- Usage Data, safety records and, where an investigation requires it, Customer Data
- Legal basis
- Bynn's legitimate interest in protecting the Service, its customers and the public; compliance with legal obligations
- Purpose
- Service notices, such as changes to terms, security notices and incident notifications
- Data used
- Account Data
- Legal basis
- Performance of the contract; compliance with legal obligations
- Purpose
- Operating, analysing and improving the Service, without training Models on Customer Data
- Data used
- Usage Data, Website data, aggregated or de-identified data
- Legal basis
- Bynn's legitimate interest in running and developing its Service
- Purpose
- Product news to business contacts
- Data used
- Account Data
- Legal basis
- Bynn's legitimate interest in business communications, or consent where the law requires it; you may opt out at any time
- Purpose
- Operating the Website; analytics and marketing cookies only where you allow them
- Data used
- Website data
- Legal basis
- Strictly necessary storage: Bynn's legitimate interest in providing the Website you request; analytics and marketing: consent (Article 6(1)(a))
- Purpose
- Complying with the law, responding to lawful requests, and establishing, exercising or defending legal claims
- Data used
- Any of the above, as necessary
- Legal basis
- Compliance with legal obligations; Bynn's legitimate interest in protecting its rights
Legitimate interests. Where Bynn relies on its legitimate interests, it has balanced them against your interests and rights, and you may object as described in Section 9.
No sale and no targeted advertising. Bynn does not sell Personal Data, and does not share it for cross-context behavioural advertising or targeted advertising.
No automated decisions about you. Bynn does not make decisions based solely on automated processing that produce legal or similarly significant effects for you. A Customer that uses the Service to make decisions about people does so as Controller, under Section 3 of the Acceptable Use Policy.
Section 4. No model training on Customer Data
#Important: No model training
Bynn does not use Input or Output to train, retrain or fine-tune any Model unless the Customer has agreed in writing, and then only within the scope of that consent. Usage Data, which does not include the content of Input or Output, may be used to operate and improve the Service.
Section 5. Retention
#Customer Data. Input and Output are deleted thirty (30) days to be confirmed after each request, unless (a) the Customer has chosen zero retention, which Bynn offers on the plans to be confirmed before these terms take effect, in which case they are not stored after the Output is returned; (b) a longer period is required by law; or (c) they are needed to investigate a suspected breach of the Acceptable Use Policy or of Section 4 of the Terms of Service, in which case only what the investigation requires is kept, for as long as it requires.
Safety records. Records of requests refused or flagged by the Safety Check are kept for a period to be confirmed before these terms take effect. Logs of requests served with the Safety Check switched off under a Defence Contract Addendum are kept for two (2) years. Safety records are kept for abuse prevention, security and audit, and are not used to train Models.
Account Data and communications. Account Data and communications are kept while the Account is open and afterwards for as long as necessary to comply with legal obligations, resolve disputes and enforce Bynn's agreements.
Billing records. Billing records are kept for the period that tax and accounting law requires.
Usage Data and Website data. Usage Data is kept for as long as needed for the purposes in Section 3 and is then deleted or aggregated. Website data is kept as described in the Cookies Policy.
Sessions. coming soonDuring a Session, its instructions, state, questions and most recent Frames are held for the life of the Session, solely to answer later Frames, including where zero retention applies, as Section 8.11 of the Terms of Service provides. Frames and their Outputs are Input and Output, and are deleted as Section 5.1 describes once the Session ends.
Section 6. Security
#Bynn protects Personal Data with technical and organisational measures appropriate to the risk, including encryption in transit and at rest, access on a need-to-know basis, rotation of keys and credentials, and logical separation of each Customer's data. The measures that apply to Customer Data are described in the Data Processing Addendum. No method of transmission or storage is completely secure, and Bynn cannot guarantee absolute security. Bynn notifies Customers of a Personal Data Breach affecting Customer Data as the Data Processing Addendum provides, and notifies authorities and individuals where the law requires.
Section 7. Disclosure and Sub-processors
#Sub-processors and service providers. Bynn uses service providers in the following categories, each bound by a written agreement that requires it to protect Personal Data and to use it only to provide its services to Bynn: (a) cloud computing and hosting; (b) payment processing; and (c) email delivery. The current list of Sub-processors is available to Customers in the Console and on request at privacy@bynn.com. Customers receive thirty (30) days' notice of changes, as the Data Processing Addendum provides.
Other recipients. Bynn may also disclose Personal Data (a) to its Affiliates, for the purposes in this Policy; (b) to its professional advisers, under a duty of confidentiality; (c) to courts, regulators, law enforcement or other authorities, where the law requires it or where necessary to protect the rights, property or safety of Bynn, its customers or others, including reports of apparent child sexual abuse material; (d) to a successor or acquirer in a merger, acquisition, financing or sale of all or part of Bynn's business, subject to this Policy; (e) to the Customer, where you are its Authorised User, which may see your activity in its Account; and (f) with your consent.
Section 8. International transfers
#Bynn and its Sub-processors may process Personal Data in countries other than the one in which you live, including the United States. Where Personal Data is transferred from the European Economic Area, Bynn relies on the Standard Contractual Clauses adopted by the European Commission in Implementing Decision (EU) 2021/914 or on an adequacy decision. Where it is transferred from the United Kingdom, Bynn relies on the International Data Transfer Addendum to those clauses issued by the Information Commissioner. A copy of the relevant safeguards is available on request at privacy@bynn.com.
Section 9. Your rights
#European Economic Area and United Kingdom. Where the GDPR or the UK GDPR applies, you have the right to access your Personal Data; to have it rectified; to have it erased; to restrict its processing; to receive it in a portable format; to object to processing based on legitimate interests, and at any time to direct marketing; to withdraw consent at any time, without affecting earlier processing; not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects; and to lodge a complaint with a Supervisory Authority, in particular in the country where you live or work, or with the Information Commissioner in the United Kingdom.
United States. Where a United States state privacy law applies, including the California Consumer Privacy Act as amended by the California Privacy Rights Act and the comprehensive privacy laws of other states, you may have the right to know what Personal Data Bynn collects and how it uses and discloses it; to access, correct and delete it; to receive it in a portable format; to opt out of its sale, its sharing for cross-context behavioural advertising, targeted advertising and profiling, none of which Bynn carries out; to limit the use of sensitive personal information, which Bynn uses only as those laws permit; to appeal a decision about your request; and not to be discriminated against for exercising any of these rights. You may use an authorised agent, who must provide proof of authority.
How to exercise your rights. Send your request to privacy@bynn.com. Bynn will verify your identity before acting on it, and responds within one (1) month where the GDPR or the UK GDPR applies, or within forty-five (45) days where a United States state law applies, extendable as those laws permit. To appeal a decision, reply to Bynn's response with the word "appeal"; if your appeal is refused, you may contact the attorney general of your state.
Requests about Customer Data. Where your request concerns Personal Data that a Customer submitted through the API, Bynn forwards it to that Customer, which decides how to respond, and assists the Customer as the Data Processing Addendum provides. Because Input and Output are deleted after the retention period, Bynn may no longer hold the data concerned.
Section 10. Children
#The Service and the Website are not directed at children, and Bynn does not knowingly collect Personal Data, as a Controller, from anyone under eighteen (18). If Bynn learns that it has done so, it deletes that data. A Customer that submits Personal Data of children as Input is responsible, as Controller, for having a lawful basis to do so. Contact privacy@bynn.com if you believe a child has provided Personal Data to Bynn.
Section 12. Changes to this Policy
#Bynn may update this Policy. Bynn gives at least thirty (30) days' notice of a material change before it takes effect, by email to Account contacts or by a notice on the Website, and shows the date of the latest version at the top of this page.
Section 13. Contact
#Postal address: Bynn Intelligence, Inc., registered address to be confirmed before these terms take effect. Where Bynn is required to appoint a representative in the European Union or the United Kingdom, or a data protection officer, their details will be published in this Section.
- Privacy questions and requests
- privacy@bynn.com
- Security issues
- security@bynn.com
Points awaiting review
Open points for counsel and the owner, to be settled before this document takes effect. This list is removed when the document is published.
For counsel
- Whether Bynn must appoint a representative in the EU and the UK (Article 27) or a data protection officer.
- The transfer mechanism for Bynn's own processing as a Controller in the United States.
- The notice at collection and the thresholds of the US state privacy laws that apply.
- Reliance on legitimate interests for product news to business contacts in each market.
- The Controller basis for safety records derived from Customer Data (Section 1.1), which the Data Processing Addendum also states in its Section 2.2.
- Sessions: the Frames of a Session added to Customer Data and Session identifiers and Frame sequence numbers to Usage Data (Section 2.1), and Section 5.6 (new) on holding a Session's context for its life, including where zero retention applies. Whether images from cameras on vehicles and unmanned aircraft, which may show bystanders, need their own mention in this Policy.
For the owner
- Request retention (30 days drafted) and the plans on which zero retention is offered.
- How long records of requests refused or flagged by the Safety Check are kept (logs of requests served with the check switched off: two years, decided).
- The Sub-processor list to publish in the Console before launch.
- Confirm that the security measures in Section 6 and the statement in Section 3.3 that Bynn does not sell Personal Data match current practice.
Values still open in this document
- The registered address of Bynn Intelligence, Inc.
- The date on which these documents take effect
- How long Input and Output are kept before deletion (30 days proposed)
- The plans on which zero retention is offered
- How long records of requests refused or flagged by the Safety Check are kept