Bynaus, Inc. — Legal
Privacy Policy
Last Updated: October 5, 2026
This Privacy Policy describes how Bynaus, Inc. (“Bynaus,” “we,” “us,” or “our”) collects, uses, discloses, and protects information processed through the Bynaus platform and related services (the “Services”).
This Privacy Policy applies exclusively to business customers and authorized users acting on behalf of those businesses. The Services are not intended for consumer or personal use.
1. Scope and Role of Bynaus
Bynaus is a business-to-business SaaS provider. In most cases:
- Customer is the data controller
- Bynaus is a data processor or service provider, acting solely on Customer instructions
Customer determines what data is collected, uploaded, recorded, or processed using the Services.
2. Acceptance of This Privacy Policy
By clicking “Accept,” “Agree,” or similar, or by accessing or using the Services, Customer acknowledges and agrees to this Privacy Policy in its entirety.
If you are accepting this Privacy Policy on behalf of an organization, you represent and warrant that you have authority to bind that organization.
3. Information We Collect
3.1 Customer-Provided Data
We process information that Customer or its authorized users submit to the Services, including but not limited to:
- Names, emails, phone numbers, job titles (business contact data)
- Project, jobsite, workforce, schedule, or operational data
- Uploaded documents, files, images, and PDFs
- Voice recordings, call transcripts, and SMS content (if enabled)
- AI prompts, responses, and workflow inputs
- Records, logs, tasks, RFIs, reports, and audit artifacts
This data is referred to as Customer Data.
3.2 Voice, Call, and Messaging Data
If Customer enables voice calls, recordings, or SMS:
- Calls may be recorded or transcribed
- Messages may be logged
- Metadata (timestamps, duration, routing) is captured
Customer is solely responsible for providing any required notices and obtaining consent required by law (including TCPA or similar laws).
3.3 Automatically Collected Data (Telemetry)
We automatically collect technical and usage data, including:
- IP address, device type, browser
- Log files, timestamps, API calls
- Feature usage, workflow execution metadata
- Error logs and performance metrics
This data is used for security, reliability, billing, and product improvement.
3.4 Aggregated and Anonymized Data
We may generate aggregated or anonymized data that does not identify Customer or any individual. Bynaus may use this data freely for analytics, benchmarking, and product improvement.
3.5 Mobile Time Clock
When a Customer uses the Bynaus mobile time clock (Bynaus Time or the Bynaus app), we collect the following for that Customer:
- Location. At clock-in, the app checks that the worker is inside the job site. We record which job site they clocked in at. The app does not track location in the background.
- Photos and face verification. A photo is taken at clock-in and clock-out to confirm it is the right worker. See our Biometric Data Policy.
- Clock-in and clock-out answers. Answers to the Customer’s questions, such as whether the worker took lunch or was injured.
- Phone number. Used to send a sign-in code by text message.
The Customer, as employer, is responsible for giving workers any notice and getting any consent the law requires.
4. How We Use Information
We use information solely to:
- Provide, operate, and maintain the Services
- Execute workflows and AI-driven processes
- Generate records, logs, summaries, and outputs
- Provide support and customer communications
- Monitor performance, security, and abuse
- Improve and develop the platform
- Comply with legal obligations
We do not sell Customer Data.
5. AI and Automated Processing
The Services use artificial intelligence and automated systems to:
- Extract data from documents and voice
- Generate summaries, classifications, and recommendations
- Route workflows and trigger actions
Customer acknowledges that:
- AI output may be inaccurate or incomplete
- Output is not professional, legal, or safety advice
- Customer is responsible for review and final decisions
6. Data Sharing and Disclosure
We may disclose information only:
- At Customer direction
- To service providers and subprocessors (e.g., cloud hosting, OCR, voice, AI infrastructure), under contractual confidentiality and security obligations
- To comply with law, subpoena, or legal process
- To protect rights, safety, and security of Bynaus, Customers, or others
- In connection with corporate transactions (e.g., merger, acquisition)
Our current list of sub-processors is published at bynaus.ai/subprocessors.
7. Google Workspace APIs (Limited Use Policy)
Bynaus’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
8. Data Retention
Customer controls data retention through use of the Services. Unless otherwise agreed in writing:
- Customer Data is retained for the duration of the Customer’s account.
- After the account ends, Customer Data is deleted from active systems within 90 days, unless Customer asks for earlier deletion or an export.
- Backup copies are overwritten on their normal rotation: daily backups within 35 days, and monthly or yearly archive copies within 12 months. Backups are not used to restore deleted data except for disaster recovery.
- Account and support records about Customer’s authorized users (such as name, business email and support history) are kept while the account is active and afterwards only as long as needed for legal, audit and dispute purposes.
- Security and audit logs are kept only as long as needed to secure the Services and meet legal and audit obligations.
- Data may be kept longer where the law requires it.
9. Data Security
Bynaus maintains commercially reasonable administrative, technical, and organizational safeguards, including:
- Access controls and authentication
- Encryption in transit and at rest (where applicable)
- Audit logging and monitoring
- Role-based access controls
- Secure infrastructure and vendor management
No system is 100% secure, and absolute security is not guaranteed.
10. International Data Transfers
Bynaus is based in the United States. The Services are hosted in the United States (Amazon Web Services and MongoDB Atlas, AWS us-east-1), and some service providers process data in other countries. When personal data subject to the GDPR, UK GDPR or Swiss data protection law is transferred to a country without an adequacy decision, we rely on an approved transfer mechanism: the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum for UK data, or, where a recipient is certified, the EU-U.S. Data Privacy Framework and its UK and Swiss extensions.
For Customer Data, these Standard Contractual Clauses are part of the Data Processing Addendum in our Terms and Conditions (Exhibit A), which every Customer accepts. We also apply supplementary safeguards, including encryption in transit and at rest and access controls. You can request a copy of the relevant safeguards at privacy@bynaus.ai.
11. Customer Responsibilities
Customer is responsible for:
- Lawful collection and use of Customer Data
- Providing required notices and obtaining consents
- Configuring access controls and permissions
- Determining whether data is appropriate to upload
- Complying with industry-specific regulations (e.g., HIPAA, labor laws)
12. No Consumer Rights
The Services are not intended for consumers. Consumer privacy laws (e.g., CCPA/CPRA consumer rights) apply only where legally required and only to the extent applicable.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. The “Last Updated” date reflects the effective date of changes. Continued use of the Services constitutes acceptance of the updated Privacy Policy.
14. Contact Information
For privacy questions or requests:
Bynaus, Inc. — 11801 La Barzola Bend, Austin, TX 78738, USA
Email: privacy@bynaus.ai
Privacy request form: bynaus.ai/privacy-request
Privacy contact: Dan Cornish
EU Representative (GDPR Article 27): GDPREP.ORG (Data Priva Limited), Suite 10357, 5 Fitzwilliam Square, Dublin 2, Ireland, D02 R744 — info@gdprep.org — www.gdprep.org
UK Representative (UK GDPR Article 27): GDPREP.ORG (Data Priva Limited), 3rd Floor, 86-90 Paul Street, London, EC2A 4NE, United Kingdom — info@gdprep.org — www.gdprep.org
15. Information for Individuals in the EEA, United Kingdom and Switzerland
This section applies where the EU General Data Protection Regulation (GDPR), the UK GDPR or the Swiss Federal Act on Data Protection applies to our processing of your personal data.
15.1 Our role
- Customer Data (Bynaus as processor). For personal data that Customers submit to the Services, the Customer is the controller and Bynaus processes it only on the Customer’s documented instructions. If you are an employee, contractor or contact of a Customer, contact that Customer first about your data. If you contact us, we will pass your request to the relevant Customer without undue delay and help them respond.
- Account, website and business data (Bynaus as controller). Bynaus is the controller for information about Customers’ account administrators and authorized users that we need to run the account (name, business email, phone, role, login and security data), billing contacts, support and sales correspondence, and visitors to bynaus.ai.
15.2 Legal bases for our processing (where Bynaus is the controller)
| Purpose | Legal basis |
|---|---|
| Creating and administering accounts, authenticating users, providing support | Performance of a contract (Art. 6(1)(b)), or our legitimate interest in serving our business Customers (Art. 6(1)(f)) |
| Security, fraud and abuse prevention, service reliability, audit logging | Legitimate interests in protecting the Services and our Customers (Art. 6(1)(f)) |
| Billing, tax and accounting | Legal obligation (Art. 6(1)(c)) and contract (Art. 6(1)(b)) |
| Product improvement using usage telemetry and aggregated or anonymized data | Legitimate interests (Art. 6(1)(f)) |
| Business-to-business communications about our Services | Legitimate interests (Art. 6(1)(f)); you can opt out at any time |
| Optional features or cookies that require consent | Consent (Art. 6(1)(a)), which you can withdraw at any time |
Where we rely on legitimate interests, we have weighed those interests against your rights. You can ask us for details.
15.3 Your rights
Subject to the conditions and exceptions in applicable law, you have the right to:
- Access — confirmation of whether we process your personal data, and a copy of it.
- Rectification — correction of inaccurate or incomplete data.
- Erasure — deletion of your data.
- Restriction — limiting how we use your data.
- Data portability — receiving data you provided to us in a structured, machine-readable format, or having it sent to another controller.
- Objection — objecting to processing based on legitimate interests, and to direct marketing at any time.
- Withdraw consent — at any time, where processing is based on consent, without affecting processing that already took place.
- Complain to a supervisory authority — in the EU/EEA, the authority in your country of residence or work; in the UK, the Information Commissioner’s Office (ico.org.uk); in Switzerland, the Federal Data Protection and Information Commissioner (FDPIC).
15.4 How to make a request
Email privacy@bynaus.ai or use our privacy request form. You can also contact our EU or UK Representative (Section 14). We may need to verify your identity before acting on a request. We respond within one month; if a request is complex or we receive many, we may extend this by up to two further months and will tell you why within the first month. Requests are free unless they are manifestly unfounded or excessive. Requests about Customer Data are handled with the relevant Customer, as described in 15.1.
15.5 Automated decision-making
The Services use AI to extract information, summarize and recommend (Section 5). Bynaus does not make decisions about individuals based solely on automated processing that produce legal effects or similarly significant effects on them. Customers remain responsible for reviewing outputs and making final decisions.
15.6 Sub-processors
We use sub-processors for hosting, databases, authentication, AI model processing, communications, monitoring and payments. Each is bound by a written contract with data protection obligations equivalent to ours. The current list is published at bynaus.ai/subprocessors.
15.7 Children
The Services are for businesses and are not directed at children. We do not knowingly collect personal data from children under 16.
15.8 Data Protection Officer
Based on the nature and scale of our processing, Bynaus is not required to appoint a Data Protection Officer under Article 37 GDPR. Privacy matters are handled by our privacy contact (Section 14).