GDPR and data protection
How personal information, individual rights, and customer processing responsibilities fit into a Binomial review.
Updated
Scope and responsibilities
Binomial handles public website and inquiry information as described in our Privacy notice. Customer product environments have a separate scope: the selected sources, authorized reviewers, purposes, and processing terms established for that customer.
Under the GDPR, a controller decides why and how personal information is processed; a processor handles it on the controller's behalf. The role for each activity depends on the actual arrangement. Where Binomial processes customer personal information on a customer's behalf, the applicable data-processing agreement must establish the responsibilities and documented instructions.
This page is an overview of practices and review topics. It is not a certification of GDPR compliance or a substitute for the applicable agreement.
Information within the review
Website inquiries can include a name, work email, organization, and the message you choose to send. Technical website information and consent-based analytics are described separately in the Privacy notice.
Customer-selected engineering evidence can contain personal information, such as contributor identities and activity associated with commits, pull requests, and reviews. Customers should identify what is necessary for their engineering question, the people included, and who is authorized to see the resulting findings.
Customers are responsible for establishing an appropriate legal basis and providing required notices for the information they authorize Binomial to process. Do not supply unrelated personal information or sensitive records without an agreed purpose and appropriate processing terms.
Privacy practices
Our procedures apply purpose limitation, data minimization, authorized access, transparency, and retention review. We follow defined procedures for access, correction, and deletion requests.
Optional public-site analytics loads only after you allow it. You can change that choice through Cookie preferences or Privacy choices.
Binomial does not use data to train artificial intelligence (AI) or machine-learning (ML) models. This includes visitor information and customer data processed by Binomial.
Individual findings support authorized coaching and development, with evidence, confidence, and limitations attached. They do not make automated personnel decisions.
Individual rights and requests
Where the GDPR applies, individuals may have rights to access, correct, or erase personal information, restrict or object to processing, and receive certain information in a portable form. Where processing depends on consent, that consent can be withdrawn. These rights have conditions and exceptions.
For information controlled by Binomial, email [email protected] or follow Privacy choices. Explain the request and the email or organization associated with the information. We confirm identity or authority when reasonably necessary and review any applicable retention requirements.
For information controlled by your organization, contact its administrator or privacy contact. Binomial handles customer-directed requests under the applicable processing terms. Applicable legal time limits govern requests.
Individuals can also raise concerns with the relevant data-protection authority. The European Commission's information for individuals explains GDPR rights and complaint routes.
Customer processing terms
A customer review should establish the processing purpose and duration, categories of information and people, permitted instructions, confidentiality, security measures, assistance with rights requests, incident handling, and end-of-service return or deletion.
It should also establish the suppliers involved, any required subprocessor authorizations, and how the customer receives information about changes. Public website provider disclosures do not constitute a complete customer-product subprocessor inventory.
Contact [email protected] to confirm the data-processing terms and documentation that apply to your environment. This page does not provide an executable Binomial data-processing addendum or establish that one has been signed.
Hosting and international transfers
Customer product data is hosted on Amazon Web Services (AWS) in the geographic region where the customer is located. Hosting region alone does not establish the locations of all processing, backups, suppliers, or support access.
Our hosting and international-transfer disclosure explains the current AWS reference and how to request deployment-specific details. AWS's published contractual terms concern the processing covered by those terms; they do not establish transfer coverage for every Binomial activity or supplier.
Confirm the actual data flows, applicable transfer safeguards, and contractual terms for your environment as part of the customer review.
Retention and deletion
We review whether information is still needed and delete information eligible for deletion, subject to applicable retention requirements. If information must be retained after a request, we explain what is retained and why.
Customer product retention, return, and deletion requirements should be set out in the applicable agreement. See Privacy and Privacy choices for website and inquiry requests.