Bynaus

Bynaus, Inc. — Legal

Terms and Conditions

Last Updated: October 5, 2026

For Customers who accepted an earlier version, these updated Terms take effect on November 4, 2026.

These Terms and Conditions (“Agreement”) govern access to and use of the Bynaus Platform and Services by Customer. By executing an Order or using the Services, Customer agrees to be bound by this Agreement.

1. Overview

Subject to this Agreement, Bynaus, Inc. (“Bynaus”) provides access to its proprietary software-as-a-service platform available at https://www.bynaus.ai (the “Platform”), which enables AI-driven workflow automation, structured record capture, document processing, voice and messaging interfaces, analytics, and related functionality (collectively, the “Services”).

This Agreement applies exclusively to business-to-business use. The Services are not offered for personal, household, or consumer purposes.

Acceptance of Terms (Clickwrap Agreement)

BY CLICKING “ACCEPT,” “AGREE,” OR A SIMILAR BUTTON, OR BY ACCESSING OR USING THE SERVICES, CUSTOMER ACKNOWLEDGES THAT IT HAS READ, UNDERSTANDS, AND AGREES TO BE LEGALLY BOUND BY THIS AGREEMENT IN ITS ENTIRETY.

If Customer is accepting this Agreement on behalf of a company or other legal entity, Customer REPRESENTS AND WARRANTS THAT IT HAS THE AUTHORITY TO BIND SUCH ENTITY to this Agreement. If Customer does not have such authority, or does not agree to these terms, Customer must not click to accept or use the Services.

This Agreement is a legally binding electronic contract, and Customer agrees that electronic acceptance has the same legal effect as a handwritten signature.

2. Ordering, Access, and Use

2.1 Orders

Services are purchased pursuant to one or more written or electronic orders (“Order”) agreed to by the parties. Each Order specifies subscribed Services, usage limits (if any), fees, and term.

2.2 License Grant

During the Term and subject to compliance with this Agreement, Bynaus grants Customer a limited, non-exclusive, non-transferable, non-sublicensable right to access and use the Services solely for Customer’s internal business operations.

2.3 Users

“User” means an employee or contractor authorized by Customer to use the Services.

Customer:

3. Documentation

Bynaus may provide technical documentation, usage guides, and workflow descriptions (“Documentation”). Documentation is licensed solely for use with the Services and may be updated at any time.

4. Restrictions

Customer shall not, directly or indirectly:

  1. Resell, sublicense, or provide the Services to third parties
  2. Use the Services to develop or operate a competing product
  3. Reverse engineer, decompile, or access non-public APIs
  4. Modify or create derivative works of the Platform
  5. Remove proprietary notices
  6. Publish benchmarks without written consent
  7. Interfere with security, availability, or integrity
  8. Introduce malware or harmful code
  9. Use the Services in violation of applicable law

5. Support

Bynaus will use commercially reasonable efforts to provide support in accordance with its then-current support policy. Availability is not guaranteed.

6. Data and AI Output

6.1 Customer Data

Customer retains ownership of all data submitted to the Services (“Customer Data”).

Customer grants Bynaus a worldwide, royalty-free license to process Customer Data solely to:

6.2 Telemetry and Aggregated Data

Bynaus may freely use anonymized telemetry and aggregated data that does not identify Customer or individuals.

6.3 AI-Generated Output

The Services may generate AI-produced outputs, summaries, classifications, or recommendations (“Output”).

Customer acknowledges:

7. Privacy and Security

Bynaus will maintain the administrative, technical, and organizational safeguards described in the Data Processing Addendum attached as Exhibit A (the “DPA”). The DPA forms part of this Agreement and applies whenever Bynaus processes personal data within Customer Data on Customer’s behalf. By accepting this Agreement, Customer also accepts the DPA, including, where applicable, the Standard Contractual Clauses incorporated in it. If this Agreement and the DPA conflict on the processing of personal data, the DPA prevails.

8. Customer Obligations

Customer represents and warrants that:

Customer must provide reasonable cooperation for implementation or professional services.

8.1 Biometric Features

If Customer enables facial verification or other biometric features (the “Biometric Features”), Customer:

  1. is solely responsible for giving every individual whose biometric data is collected any notice required by law, and for obtaining, before collection, any consent or release required by law, including under Texas Business and Commerce Code §503.001, the Colorado Privacy Act, Washington RCW 19.375, any other applicable biometric privacy law, and, for individuals in the EEA, UK or Switzerland, a valid condition under GDPR Article 9(2);
  2. will keep records of those notices and consents and provide them to Bynaus on request;
  3. will offer a non-biometric alternative to individuals who decline consent where the law requires it;
  4. will delete a worker, or the worker’s ID photos, in the Services once the purpose of collection is satisfied (for example, when employment or engagement ends) and in any event within the period applicable law requires. Deleting a worker or their photos removes that worker’s facial template from the Services; and
  5. authorizes Bynaus, as Customer’s processor and service provider, to collect, store and use biometric data solely to provide the Biometric Features.

Bynaus will not sell, lease, trade or otherwise profit from biometric data, and will not disclose it except to its Sub-processors as needed to provide the Biometric Features or as required by law. Bynaus stores and transmits biometric data using measures at least as protective as those it uses for its other confidential information, and handles it under its Biometric Data Policy.

9. Suspension

Bynaus may suspend access immediately if:

10. Third-Party Services

The Services may integrate with third-party platforms (e.g., cloud storage, telephony, messaging, AI models). Bynaus is not responsible for third-party services or their data practices.

11. Fees and Taxes

11.1 Fees

Fees are as specified in the applicable Order. Fees are non-refundable except as expressly stated.

11.2 Taxes

Customer is responsible for all taxes other than Bynaus’s income taxes.

12. Warranties and Disclaimers

12.1 Limited Warranty

Bynaus warrants that the Services will materially conform to the Documentation.

12.2 Disclaimer

EXCEPT AS EXPRESSLY PROVIDED, THE SERVICES AND OUTPUT ARE PROVIDED “AS IS.” BYNAUS DISCLAIMS ALL IMPLIED WARRANTIES, INCLUDING MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, AND NON-INFRINGEMENT.

13. TCPA, Voice, and Messaging Compliance

Customer is solely responsible for compliance with all laws governing voice calls, SMS, automated outreach, consent, disclosures, opt-out handling, and AI disclosure requirements.

14. Term and Termination

14.1 Term

This Agreement continues for the Initial Term specified in the Order and renews automatically unless terminated with at least 60 days’ notice.

14.2 Termination

Either party may terminate for uncured material breach, insolvency, or cessation of business.

14.3 Effect of Termination

Upon termination or expiration:

15. Ownership and Feedback

Bynaus retains all rights to the Platform and Services. Customer retains ownership of Customer Data. Any feedback may be used by Bynaus without restriction or obligation.

16. Limitation of Liability

TO THE MAXIMUM EXTENT PERMITTED BY LAW:

17. Indemnification

17.1 By Bynaus

Bynaus will indemnify Customer against third-party IP infringement claims related to the Services.

17.2 By Customer

Customer will indemnify Bynaus for claims arising from:

18. Confidentiality

Each party must protect the other’s Confidential Information and use it solely to perform under this Agreement.

19. Binding Arbitration (B2B Only)

19.1 Governing Law

This Agreement is governed by the laws of the State of Nevada.

19.2 Arbitration

All disputes shall be resolved by binding arbitration administered by the American Arbitration Association (AAA) under its Commercial Arbitration Rules.

19.3 Seat

The arbitration seat and location shall be Las Vegas, Nevada.

19.4 Waiver of Jury Trial

THE PARTIES WAIVE ANY RIGHT TO A JURY TRIAL.

20. Class Action Waiver

ALL CLAIMS MUST BE BROUGHT INDIVIDUALLY. THE PARTIES WAIVE ANY RIGHT TO CLASS, COLLECTIVE, REPRESENTATIVE, OR PRIVATE ATTORNEY GENERAL ACTIONS.

21. B2B Mass Arbitration Procedures

These procedures apply only to business customers and not to consumers.

22. General Terms

22.1 Changes to this Agreement

Bynaus may update this Agreement from time to time. For material changes, Bynaus will notify Customer by email to its account administrator at least 30 days before the change takes effect and will post the updated Agreement with a new “Last Updated” date. Customer’s continued use of the Services after the effective date constitutes acceptance. If Customer does not agree, Customer may terminate before the effective date and receive a refund of prepaid fees for the unused period.

Exhibit A — Data Processing Addendum

1. Definitions

“Data Protection Laws” means all laws that apply to the processing of personal data under this Agreement, including the EU General Data Protection Regulation (Regulation 2016/679) (“GDPR”), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, and U.S. state privacy laws (including the CCPA/CPRA) where applicable. “Personal Data”, “Controller”, “Processor”, “Data Subject”, “Processing” and “Personal Data Breach” have the meanings given in the GDPR. “Customer Personal Data” means Personal Data within Customer Data. “Sub-processor” means any third party Bynaus engages to process Customer Personal Data.

2. Roles and scope

2.1 For Customer Personal Data, Customer is the Controller (or a Processor acting for its own Controller) and Bynaus is the Processor (or sub-processor). For the CCPA/CPRA, Bynaus is a “service provider”.

2.2 The subject matter, nature, purpose and duration of processing, and the categories of data and data subjects, are described in Annex I.

3. Customer instructions

3.1 Bynaus processes Customer Personal Data only on Customer’s documented instructions. This Agreement, Customer’s configuration and use of the Services, and any further written instructions agreed by the parties are Customer’s complete instructions.

3.2 Bynaus will tell Customer if it believes an instruction infringes Data Protection Laws, and may suspend the affected processing until the instruction is confirmed or changed.

3.3 Bynaus will not sell or share Customer Personal Data, retain, use or disclose it outside the direct business relationship with Customer, or combine it with personal data from other sources, except as Data Protection Laws permit for a service provider.

4. Confidentiality

Bynaus ensures that everyone authorized to process Customer Personal Data is bound by confidentiality obligations.

5. Security

Bynaus implements the technical and organizational measures in Annex II, which are appropriate to the risk. Bynaus may update them, provided the overall level of protection is not reduced.

6. Sub-processors

6.1 Customer gives general authorization for Bynaus to engage Sub-processors. Bynaus maintains a current list of Sub-processors at bynaus.ai/subprocessors (the “Sub-processor List”). Customer may subscribe to update notices by emailing privacy@bynaus.ai.

6.2 Bynaus imposes data protection obligations on each Sub-processor that are no less protective than this DPA, and remains responsible for its Sub-processors’ performance.

6.3 Bynaus will update the Sub-processor List at least 10 days before a new Sub-processor begins processing Customer Personal Data, and will email subscribers when it does. Customer may object on reasonable data protection grounds within that period. The parties will then discuss the objection in good faith. If they cannot resolve it, Customer may terminate the affected Services and receive a refund of prepaid fees for the unused period.

6.4 Emergency replacement. If a Sub-processor must be replaced or added urgently to protect the security, integrity or continuity of the Services, Bynaus may do so immediately and will update the Sub-processor List promptly afterwards. Customer’s objection right under Section 6.3 then applies from the date of that update.

7. Assistance

7.1 Data subject requests. Taking into account the nature of the processing, Bynaus will help Customer respond to requests to exercise data subject rights. Bynaus forwards any request it receives directly to Customer without undue delay and will not respond to it except on Customer’s instructions.

7.2 Impact assessments and consultations. Bynaus provides reasonable information to support Customer’s data protection impact assessments and prior consultations with supervisory authorities.

8. Personal Data Breaches

8.1 Bynaus notifies Customer without undue delay, and in any event within 48 hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data.

8.2 The notice describes, as far as known at the time, the nature of the breach, the categories and approximate numbers of data subjects and records affected, the likely consequences, and the measures taken or proposed.

8.3 Bynaus takes reasonable steps to contain and remedy the breach. A notification is not an admission of fault.

9. Deletion and return

When the Services end, Bynaus deletes or returns Customer Personal Data as set out in Section 14.3 of the Agreement (export available for 30 days; deletion from active systems within 90 days; backups overwritten on rotation), except data that the law requires Bynaus to retain, which remains protected under this DPA. Biometric data is deleted when Customer deletes the relevant worker or photos and, for all of Customer’s biometric data, when the Agreement ends under Section 14.3.

10. Audits

10.1 On written request, at most once every 12 months, Bynaus provides information reasonably necessary to demonstrate compliance with this DPA. This includes responses to security questionnaires and a copy of Bynaus’s most recent SOC 2 report, provided under confidentiality. That information is Bynaus’s Confidential Information.

10.2 If that information is insufficient, or a supervisory authority requires it, Customer may conduct an audit on at least 30 days’ notice, during business hours, at Customer’s cost, under confidentiality, and without access to other customers’ data.

11. International transfers

11.1 Bynaus processes Customer Personal Data in the United States and in the locations of its Sub-processors.

11.2 Where Customer Personal Data subject to the EU GDPR is transferred to Bynaus in a country without an adequacy decision, the parties enter into the Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), which are incorporated by reference: Module Two (controller to processor) where Customer is a controller, and Module Three (processor to processor) where Customer is a processor. Clause 7 (docking clause) applies. For Clause 9(a), Option 2 (general authorization) applies, with the 10-day notice period and mechanism in Sections 6.3 and 6.4. The optional language in Clause 11 does not apply. For Clause 13, the competent supervisory authority is the one competent for Customer or, where Customer has no EU establishment, for Bynaus’s EU representative. For Clauses 17 and 18, the governing law and courts are those of Ireland. Annexes I and II of the Clauses are completed by Annexes I and II of this DPA.

11.3 For the UK, the UK International Data Transfer Addendum (version B1.0) applies to the Standard Contractual Clauses, with Table 1 completed by the parties’ details and Tables 2 and 3 by this DPA. For Switzerland, the Standard Contractual Clauses apply as adapted for the Swiss FADP, with the Swiss Federal Data Protection and Information Commissioner as the competent authority.

11.4 Bynaus’s EU and UK representative under Article 27 is GDPREP.ORG (Data Priva Limited): EU — Suite 10357, 5 Fitzwilliam Square, Dublin 2, Ireland, D02 R744; UK — 3rd Floor, 86-90 Paul Street, London, EC2A 4NE; info@gdprep.org.

12. Liability and precedence

Each party’s liability under this DPA is subject to the limitations in the Agreement, except where Data Protection Laws or the Standard Contractual Clauses do not permit limitation. If this DPA and the Standard Contractual Clauses conflict, the Clauses prevail.

Annex I — Description of processing

Data exporterCustomer (the entity accepting the Agreement)
Data importerBynaus, Inc., 11801 La Barzola Bend, Austin, TX 78738, USA; privacy@bynaus.ai; Processor
Data subjectsCustomer’s employees, contractors and users; Customer’s clients, subcontractors, vendors and other business contacts; individuals appearing in documents, calls or messages Customer submits
Categories of dataBusiness contact data (name, email, phone, job title); workforce and scheduling data, including time and attendance where enabled; project and operational records; documents, images and drawings; voice recordings, call transcripts and SMS content where enabled; AI prompts and outputs; account and usage metadata
Special categoriesBiometric data (facial templates and the ID photos used to create them), only where Customer enables the Biometric Features, processed solely to verify the identity of Customer’s workers at clock-in or site check-in, including optional liveness (anti-spoofing) checks. Safeguards: a separate face collection per Customer; encryption in transit and at rest; access limited to the Services’ automated verification and Customer’s authorized administrators. Retention is controlled by Customer as described in Section 8.1 of the Agreement. No other special-category data is intended; Customer must not submit it unless agreed in writing.
FrequencyContinuous, for the term of the Agreement
Nature and purposeHosting, storage, document processing and OCR, AI-assisted extraction, summarization and workflow execution, voice and SMS handling, search, analytics and support, as necessary to provide the Services
Duration and retentionThe term of the Agreement plus the deletion periods in Section 9
Sub-processor transfersAs set out in the Sub-processor List

Annex II — Technical and organizational measures

  • Access control: role-based access; production cloud access limited to the company owner through AWS IAM Identity Center with multi-factor authentication; the root account reserved for break-glass use with MFA; service accounts scoped per workload.
  • Authentication: customer and user authentication through Auth0, with multi-factor authentication available.
  • Encryption: TLS 1.2 or higher for data in transit on public endpoints; encryption at rest for databases (Amazon RDS, MongoDB Atlas) and object storage.
  • Network security: Amazon RDS databases are not publicly accessible and sit behind security groups restricting inbound access. MongoDB Atlas accepts only authenticated (SCRAM), TLS-encrypted connections, with a separate database login per service, and every login attempt is recorded in Atlas database access history. DDoS protection via Cloudflare and AWS Shield.
  • Backup and recovery: daily backups kept 35 days and monthly backups kept 12 months; point-in-time recovery on primary databases; automated monthly restore testing.
  • Logging and monitoring: AWS CloudTrail (multi-region, with log file validation), application error monitoring, and daily automated compliance checks.
  • Secure development: source control with review, automated dependency updates, static code analysis (CodeQL) on the API service, and input validation libraries.
  • Vendor management: Sub-processors bound by written data protection terms; a vendor register is maintained.
  • Personnel: confidentiality obligations; prompt removal of access at offboarding.
  • Incident response: documented incident response and breach notification process; incident log maintained.