Last Updated: 13 Jul 2026
At Binary, we are committed to protecting personal data and supporting our customers in meeting their obligations under the General Data Protection Regulation (GDPR). This page explains how our Platform handles personal data, the measures we take to keep it safe, and the tools we provide to help your organization stay compliant. For full details on how we collect, use, and protect data, please see our Privacy Policy.
The General Data Protection Regulation (EU) 2016/679 is the European Union's data protection law, in effect since 25 May 2018. It governs how organizations collect, store, use, and share the personal data of individuals in the European Economic Area (EEA). It applies to any organization that offers goods or services to people in the EEA or monitors their behavior, regardless of where that organization is located.
For hiring teams, this means that if any of your candidates are located in the EEA, GDPR applies to the personal data they submit through your application forms. As a platform that processes candidate and application data on behalf of organizations, we are committed to helping our customers meet these obligations.
Personal data is any information relating to an identified or identifiable person, such as a name, email address, phone number, resume, photo, or IP address.
Processing means anything done with personal data: collecting, recording, organizing, storing, using, sharing, or deleting it.
Your candidates are data subjects. They have the right to decide how their personal data is collected, stored, and used.
Your organization is the data controller. You determine what candidate data is collected, why it is processed, and how long it is retained, and you are responsible for handling it lawfully.
Binary is a data processor. We process candidate data on your behalf and only according to your instructions and our agreements with you.
A subprocessor is a third-party service a processor relies on to deliver its service, such as a cloud hosting provider. We remain responsible for the subprocessors we engage.
When candidates submit applications through forms created on our Platform, we process their data on behalf of the organization that created the form. The organization decides what data is collected and how it is used; we process it strictly under their instructions and our Terms of Service.
For the data of our own users, such as your account information, billing details, and Platform usage data, Binary acts as the data controller. Our Privacy Policy describes how we handle this data, the legal bases we rely on, and the rights available to you.
GDPR requires a valid lawful basis for every processing activity. As the data controller, your organization is responsible for identifying the lawful basis for processing candidate data. In recruitment this is most commonly legitimate interest (evaluating applicants for a role) or consent (for example, retaining a profile for future openings).
For the data we control ourselves, we rely on: contract, for processing necessary to provide the Platform and manage your account; legitimate interest, for improving our services, ensuring security, and understanding how users interact with the Platform; consent, where you have given specific consent, such as for marketing communications; and legal obligation, for processing necessary to comply with applicable laws.
On behalf of our customers and for our own operations, we process the following:
GDPR grants individuals a set of rights over their personal data. As the data controller, your organization is responsible for ensuring candidates can exercise these rights, and our Platform is built to make that practical:
If a candidate contacts us directly to exercise their rights over data we process on your behalf, we will not respond in your place. Instead, we will promptly forward the request to your organization and provide reasonable assistance so you can respond within the timelines GDPR requires (generally one month).
We rely on a limited set of third-party service providers to operate the Platform. All of these platforms are GDPR compliant:
We keep this list up to date. When we add or replace a subprocessor that processes candidate data, we update this page.
Our primary data storage is located in India (Mumbai region), using services such as AWS and MongoDB Atlas. Where personal data of individuals in the EEA is transferred to or accessed from a country outside the EEA, we ensure appropriate safeguards are in place in accordance with GDPR requirements, alongside technical measures such as encryption in transit and at rest.
As the data controller, your organization decides how long candidate data is retained. GDPR requires that personal data is kept no longer than necessary for the purpose it was collected. For recruitment, this typically means defining a retention period after which unsuccessful candidates' data is deleted unless they consent to being retained for future roles.
Candidate data can be deleted from the Platform at any time. When your account is closed or our services end, we delete personal data from our systems, except where retention is required by applicable law. For our own records, we retain personal data only for as long as your account is active or as needed to provide our services, comply with legal obligations, resolve disputes, and enforce our agreements.
We maintain technical and organizational measures designed to protect personal data:
No method of transmission over the Internet or method of electronic storage is 100% secure, so we cannot guarantee absolute security. We use commercially reasonable safeguards and continually work to improve them. For more details, refer to our Privacy Policy.
GDPR requires data controllers to report certain personal data breaches to their supervisory authority within 72 hours of becoming aware of them. To support this, if we become aware of a personal data breach affecting candidate data we process on your behalf, we will notify your organization without undue delay. We will share the information reasonably available to us, including the nature of the breach, the data and individuals affected, and the measures taken to address it, so you can meet your own notification obligations.
Our Platform offers AI-powered features that assist with candidate evaluation, such as providing suggestions, answers, and filtering options. These features are designed with GDPR's rules on automated decision-making (Article 22) in mind:
We build the Platform around data protection principles: we collect only the data needed to provide the service (data minimization), use it only for the purposes it was collected (purpose limitation), and limit internal access to a need-to-know basis. New features are designed with these principles from the start rather than added as an afterthought.
We use essential cookies required for the Platform to function, such as authentication and session management, along with a small number of analytics and support tools. You can control non-essential cookies through your browser settings. For details on the cookies and tracking technologies we use, see our Privacy Policy.
If you have any questions about our GDPR compliance or want to exercise your data protection rights, contact us at gdpr@binary.so. We respond to requests within 30 days. If you believe our processing of your personal data infringes applicable data protection laws, you also have the right to lodge a complaint with your local data protection authority.