GDPR Compliance

Last Updated: 13 Jul 2026

  1. At Binary, we are committed to protecting personal data and supporting our customers in meeting their obligations under the General Data Protection Regulation (GDPR). This page explains how our Platform handles personal data, the measures we take to keep it safe, and the tools we provide to help your organization stay compliant. For full details on how we collect, use, and protect data, please see our Privacy Policy.

  2. What is GDPR?

    The General Data Protection Regulation (EU) 2016/679 is the European Union's data protection law, in effect since 25 May 2018. It governs how organizations collect, store, use, and share the personal data of individuals in the European Economic Area (EEA). It applies to any organization that offers goods or services to people in the EEA or monitors their behavior, regardless of where that organization is located.

    For hiring teams, this means that if any of your candidates are located in the EEA, GDPR applies to the personal data they submit through your application forms. As a platform that processes candidate and application data on behalf of organizations, we are committed to helping our customers meet these obligations.

  3. Key GDPR Terms

    Personal data is any information relating to an identified or identifiable person, such as a name, email address, phone number, resume, photo, or IP address.

    Processing means anything done with personal data: collecting, recording, organizing, storing, using, sharing, or deleting it.

    Your candidates are data subjects. They have the right to decide how their personal data is collected, stored, and used.

    Your organization is the data controller. You determine what candidate data is collected, why it is processed, and how long it is retained, and you are responsible for handling it lawfully.

    Binary is a data processor. We process candidate data on your behalf and only according to your instructions and our agreements with you.

    A subprocessor is a third-party service a processor relies on to deliver its service, such as a cloud hosting provider. We remain responsible for the subprocessors we engage.

  4. Our Role: Processor and Controller

    As a data processor

    When candidates submit applications through forms created on our Platform, we process their data on behalf of the organization that created the form. The organization decides what data is collected and how it is used; we process it strictly under their instructions and our Terms of Service.

    As a data controller

    For the data of our own users, such as your account information, billing details, and Platform usage data, Binary acts as the data controller. Our Privacy Policy describes how we handle this data, the legal bases we rely on, and the rights available to you.

  5. Lawful Bases for Processing

    GDPR requires a valid lawful basis for every processing activity. As the data controller, your organization is responsible for identifying the lawful basis for processing candidate data. In recruitment this is most commonly legitimate interest (evaluating applicants for a role) or consent (for example, retaining a profile for future openings).

    For the data we control ourselves, we rely on: contract, for processing necessary to provide the Platform and manage your account; legitimate interest, for improving our services, ensuring security, and understanding how users interact with the Platform; consent, where you have given specific consent, such as for marketing communications; and legal obligation, for processing necessary to comply with applicable laws.

  6. Categories of Data We Process

    On behalf of our customers and for our own operations, we process the following:

    • Candidate and application data: name, email address, phone number, resume or CV, cover letter, work history, portfolio links, answers to application questions, and any other information a candidate submits through a form, along with evaluations, notes, and communications your team adds during the hiring process.
    • Account data: your name, email address, workspace details, and billing information when you create and use a Binary account.
    • Usage data: IP address, browser type, operating system, and interactions with the Platform, collected automatically to operate, secure, and improve the service.
  7. Data Subject Rights

    GDPR grants individuals a set of rights over their personal data. As the data controller, your organization is responsible for ensuring candidates can exercise these rights, and our Platform is built to make that practical:

    • Right to be informed: candidates must know what data is collected and why. You can include privacy notices and consent disclosures in your forms so candidates are informed before they submit an application.
    • Right of access: candidates can request a copy of the personal data you hold about them. Candidate data stored on the Platform can be reviewed and exported to fulfill such requests.
    • Right to rectification: candidates can ask for inaccurate or incomplete data to be corrected. Candidate records on the Platform can be updated at any time.
    • Right to erasure (“right to be forgotten”): candidates can request deletion of their personal data. Candidate data can be permanently deleted from the Platform when such a request is received.
    • Right to restrict processing: candidates can ask you to limit how their data is used while, for example, a dispute or accuracy check is resolved.
    • Right to data portability: candidates can request their data in a structured, commonly used, machine-readable format. Candidate data can be exported from the Platform for this purpose.
    • Right to object: candidates can object to processing based on legitimate interest, including for direct marketing.
    • Rights related to automated decision-making: candidates have the right not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects. See the AI section below for how our Platform keeps humans in control of all final decisions.

    Requests we receive directly

    If a candidate contacts us directly to exercise their rights over data we process on your behalf, we will not respond in your place. Instead, we will promptly forward the request to your organization and provide reasonable assistance so you can respond within the timelines GDPR requires (generally one month).

  8. Subprocessors

    We rely on a limited set of third-party service providers to operate the Platform. All of these platforms are GDPR compliant:

    • Amazon Web Services (AWS): cloud hosting and infrastructure.
    • MongoDB Atlas: database services.
    • Google Gemini: AI-powered features.
    • OpenAI: AI-powered features.
    • Stripe: payment processing for customer billing.
    • Mixpanel: product analytics.
    • Postmark: transactional email delivery.
    • Intercom: customer support.
    • Slack: notifications and candidate updates through our Slack integration.
    • Sentry: error tracking and Platform stability monitoring.

    Changes to subprocessors

    We keep this list up to date. When we add or replace a subprocessor that processes candidate data, we update this page.

  9. International Data Transfers

    Our primary data storage is located in India (Mumbai region), using services such as AWS and MongoDB Atlas. Where personal data of individuals in the EEA is transferred to or accessed from a country outside the EEA, we ensure appropriate safeguards are in place in accordance with GDPR requirements, alongside technical measures such as encryption in transit and at rest.

  10. Data Retention and Deletion

    As the data controller, your organization decides how long candidate data is retained. GDPR requires that personal data is kept no longer than necessary for the purpose it was collected. For recruitment, this typically means defining a retention period after which unsuccessful candidates' data is deleted unless they consent to being retained for future roles.

    Candidate data can be deleted from the Platform at any time. When your account is closed or our services end, we delete personal data from our systems, except where retention is required by applicable law. For our own records, we retain personal data only for as long as your account is active or as needed to provide our services, comply with legal obligations, resolve disputes, and enforce our agreements.

  11. Security Measures

    We maintain technical and organizational measures designed to protect personal data:

    • Encryption: data is encrypted in transit (HTTPS/TLS) and at rest.
    • Access controls: access to personal data is restricted to personnel who need it to operate and support the Platform, protected by authentication and role-based permissions.
    • Infrastructure security: we host on established cloud providers (AWS, MongoDB Atlas) and rely on their physical and network safeguards in addition to our own.
    • Monitoring: we use error tracking and monitoring to detect and respond to issues affecting Platform stability and security.

    A note on security

    No method of transmission over the Internet or method of electronic storage is 100% secure, so we cannot guarantee absolute security. We use commercially reasonable safeguards and continually work to improve them. For more details, refer to our Privacy Policy.

  12. Data Breach Notification

    GDPR requires data controllers to report certain personal data breaches to their supervisory authority within 72 hours of becoming aware of them. To support this, if we become aware of a personal data breach affecting candidate data we process on your behalf, we will notify your organization without undue delay. We will share the information reasonably available to us, including the nature of the breach, the data and individuals affected, and the measures taken to address it, so you can meet your own notification obligations.

  13. AI and Automated Processing

    Our Platform offers AI-powered features that assist with candidate evaluation, such as providing suggestions, answers, and filtering options. These features are designed with GDPR's rules on automated decision-making (Article 22) in mind:

    • AI features do not make automated decisions that produce legal or similarly significant effects on candidates. All final decisions are made by human users of the Platform.
    • Data sent to AI services is processed under enterprise agreements and is not used to train third-party AI models.
    • We transmit only the minimum data necessary to fulfill the specific AI feature you are using, and you may choose not to use AI-powered features at all.
  14. Privacy by Design

    We build the Platform around data protection principles: we collect only the data needed to provide the service (data minimization), use it only for the purposes it was collected (purpose limitation), and limit internal access to a need-to-know basis. New features are designed with these principles from the start rather than added as an afterthought.

  15. Cookies

    We use essential cookies required for the Platform to function, such as authentication and session management, along with a small number of analytics and support tools. You can control non-essential cookies through your browser settings. For details on the cookies and tracking technologies we use, see our Privacy Policy.

  16. Questions?

    If you have any questions about our GDPR compliance or want to exercise your data protection rights, contact us at gdpr@binary.so. We respond to requests within 30 days. If you believe our processing of your personal data infringes applicable data protection laws, you also have the right to lodge a complaint with your local data protection authority.