GDPR Agreement

Effective Date: August 5, 2026 · Last Updated: August 5, 2026

This GDPR Agreement (“Agreement“) applies to users, customers, and data subjects located in the European Union (EU), European Economic Area (EEA), and the United Kingdom (UK). It supplements our main Privacy Policy and establishes the framework for personal data processing in compliance with the General Data Protection Regulation (EU) 2016/679 (“GDPR“) and UK GDPR.

1. Data Controller vs. Data Processor Roles

In accordance with GDPR requirements, BINOM AI, Inc. clarifies the division of responsibilities as follows:

Binom AI as Data Controller: BINOM AI, Inc. acts as the Data Controller for personal data provided directly by our Customers during account registration, billing, and system administration (e.g., name, email address, company details, payment metadata).

Binom AI as Data Processor: BINOM AI, Inc. acts strictly as a Data Processor regarding personal data uploaded, connected via integrations (e.g., Google, Meta, CRMs), or transmitted by End Users during interactions with AI agents (“synthetic employees”) created by our Customers. The Customer remains the Data Controller for all End User data and is solely responsible for establishing a lawful basis for its collection and processing.

2. Legal Bases for Processing (GDPR Art. 6)

We process personal data only when a valid legal basis exists under GDPR Article 6:

  • Performance of Contract: To provide, operate, and maintain the Service under our contractual agreement with the Customer.
  • Explicit Consent: Where consent has been explicitly granted by the user (e.g., connecting third-party OAuth integrations or opting into non-essential cookies).
  • Legitimate Interests: To ensure platform security, prevent fraud, logs administration, and optimize specific AI agent performance within the requesting Customer’s account.
  • Compliance with Legal Obligations: To satisfy tax, accounting, or regulatory requirements.

3. EU Representative (GDPR Art. 27)

Pursuant to Article 27 of the GDPR, BINOM AI, Inc. has designated an EU Representative to act on its behalf with regard to data processing activities involving individuals located in the EU/EEA:

Digital Forest OÜ
Registry code: 14207360
Address: Kaupmehe tn 7-120, Kesklinna linnaosa, Tallinn, Harju maakond, 10114, Estonia
Email: support+dfOU@binomai.com

EU data subjects and supervisory authorities may contact Digital Forest OÜ on matters relating to the processing of personal data by BINOM AI, Inc.

4. Your Rights Under GDPR

If you are located in the EEA or UK, you possess the following statutory rights regarding your personal data:

  • Right to Access (Art. 15): Request confirmation and a copy of the personal data we hold about you.
  • Right to Rectification (Art. 16): Request correction of inaccurate or incomplete personal data.
  • Right to Erasure / “Right to be Forgotten” (Art. 17): Request deletion of personal data where legal retention grounds no longer apply.
  • Right to Restriction of Processing (Art. 18): Request suspension of processing under specific legal conditions.
  • Right to Data Portability (Art. 20): Receive personal data in a structured, commonly used, machine-readable format.
  • Right to Object (Art. 21): Object to data processing based on legitimate interests.
  • Right to Withdraw Consent (Art. 7(3)): Withdraw consent at any time where processing was based on consent.
  • Right to Lodge a Complaint: Lodge a complaint with your local Data Protection Supervisory Authority.

5. International Data Transfers

BINOM AI, Inc. is incorporated in the United States. When transferring personal data originating from the EEA, UK, or Switzerland outside those regions, we ensure appropriate safeguards are implemented in compliance with Chapter V of the GDPR. We execute European Commission-approved Standard Contractual Clauses (SCCs) to guarantee a level of data protection equivalent to European standards.

6. Data Processing Agreement (DPA) & Subprocessors

To satisfy GDPR Article 28 requirements, the processing of data where the Customer acts as Controller and Binom AI as Processor is governed by a formal Data Processing Agreement (DPA). The DPA covers subprocessor authorizations, technical and organizational security measures (TOMs), breach notification procedures (within 72 hours), and data erasure upon contract termination.

Customers can request an executed copy of our DPA and the current list of authorized subprocessors by emailing support@binomai.com.

7. Contact for GDPR Requests

To exercise any of your statutory rights, or for inquiries regarding our GDPR compliance framework, please contact us or our EU representative:

BINOM AI, Inc.
1111B S Governors Ave STE 20321, Dover, DE 19904, USA
Data Protection Email: support@binomai.com

For full information regarding our general data collection, retention, and integration practices, please review our comprehensive Privacy Policy.