Privacy Policy
Introduction
At Binalyze, we are committed to safeguarding the privacy and confidentiality of personal information. This Privacy Policy outlines how we collect, use, disclose, and protect personal data in accordance with the General Data Protection Regulation (GDPR) and other applicable UK data protection laws.
Definitions
-
Personal Data: Any information relating to an identified or identifiable natural person.
-
Processing: Any operation or set of operations performed on personal data, whether or not by automated means.
-
Data Subject: An individual whose personal data is processed.
-
Data Controller: The entity that determines the purposes and means of processing personal data.
-
Data Processor: The entity that processes personal data on behalf of the Data Controller.
-
Consent: A freely given, specific, informed, and unambiguous indication of the Data Subject’s wishes by which they signify agreement to the processing of personal data.
Management Commitment
Our management is steadfast in ensuring adherence to data protection laws and regulations. We provide the requisite resources and support to implement and maintain this Privacy Policy, ensuring it aligns with the highest standards of data protection.
Personal Data Collection
We collect personal data for various purposes, including:
-
Providing and enhancing our services.
-
Communicating with customers and partners.
-
Complying with legal and regulatory obligations.
Types of Personal Data Collected
The types of personal data we may collect include:
-
Contact information (name, email address, phone number).
-
Billing information.
-
Usage data (IP address, browser type, access times).
-
Any other information provided by the Data Subject.
Legal Basis for Processing
We process personal data based on one or more of the following legal bases:
-
The Data Subject has given consent to the processing of their personal data.
-
Processing is necessary for the performance of a contract to which the Data Subject is a party.
-
Processing is necessary for compliance with a legal obligation.
-
Processing is necessary to protect the vital interests of the Data Subject or another natural person.
-
Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Data Controller.
-
Processing is necessary for the purposes of legitimate interests pursued by the Data Controller or a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the Data Subject.
Use of Personal Data
We use personal data for the following purposes:
-
To provide and manage our services.
-
To communicate with customers and partners.
-
To conduct data analysis and research to improve our services.
-
To comply with legal and regulatory requirements.
-
To protect the rights, property, or safety of Binalyze, our employees, and others.
Data Subject Rights
Data Subjects have the following rights regarding their personal data:
-
Right to Access: The right to request access to and obtain a copy of their personal data.
-
Right to Rectification: The right to request correction of inaccurate or incomplete personal data.
-
Right to Erasure: The right to request deletion of personal data, subject to certain conditions.
-
Right to Restrict Processing: The right to request restriction of processing of their personal data.
-
Right to Data Portability: The right to receive their personal data in a structured, commonly used, and machine-readable format and to transmit those data to another Data Controller.
-
Right to Object: The right to object to the processing of their personal data, particularly for direct marketing purposes.
-
Right to Withdraw Consent: The right to withdraw consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal.
Data Security
We implement appropriate technical and organisational measures to ensure the security of personal data, including:
-
Encryption: Applying encryption to protect personal data.
-
Access Controls: Restricting access to personal data to authorised personnel only.
-
Incident Response: Establishing procedures to respond to data breaches and security incidents.
-
Regular Audits: Conducting regular audits to ensure the effectiveness of security measures.
Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected or as required by law. We establish clear data retention policies to ensure compliance with this principle.
Third-Party Disclosure
We may disclose personal data to third parties under the following circumstances:
-
Service Providers: We engage third-party service providers to perform functions on our behalf, subject to data protection agreements.
-
Legal Obligations: We may disclose personal data to comply with legal obligations or to protect our rights and interests.
-
Business Transfers: In the event of a merger, acquisition, or sale of assets, personal data may be transferred to the acquiring entity.
International Transfers
When transferring personal data outside the European Economic Area (EEA) or the United Kingdom, we ensure appropriate safeguards are in place to protect the data in accordance with GDPR and UK data protection requirements.
Cookies and Tracking Technologies
We use cookies and similar tracking technologies to collect usage data and improve our services. Data Subjects can manage cookie preferences through their browser settings.
Contact Information
For any questions or concerns regarding this Privacy Policy or the processing of personal data, please contact us at:
Email: privacy@binalyze.com
Policy Updates
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will notify Data Subjects of any significant changes through appropriate channels.
Emre Tınaztepe
CEO
Processing purpose |
Legal basis for the processing purpose |
Personal Data used for the processing purpose |
Handling pre-contractual negotiations and communications, concluding of the contract and managing the contractual relationship |
If you as a natural person wish to become or are already our client or partner and the enquiry or request is related to your potential or ongoing customer or partnering relationship with us, the legal basis is taking and implementing the pre-contractual measures of the contract or performing the contract concluded between us If you as a representative of legal entity, who wishes to become or is already our client or partner and the enquiry or request is related to the legal entity’s potential or ongoing customer or partnering relationship with us, the legal basis is our legitimate interest in taking and implementing the pre-contractual measures of a contract or performing the contract concluded between the legal entity and us |
Main Data, Communication Data |
Responding to your enquiries and requests submitted via the Website, live chat, or e-mail, including submissions regarding partnership and receiving a demo |
Our legitimate interest in ensuring effective relations management with potential customers, partners and interested parties If you as a natural person wish to become or are already our client or partner and the enquiry or request is related to your potential or ongoing customer or partnering relationship with us, the legal basis is taking and implementing the pre-contractual measures of the contract or performing the contract concluded between us If you as a representative of legal entity, who wishes to become or is already our client or partner and the enquiry or request is related to the legal entity’s potential or ongoing customer or partnering relationship with us, the legal basis is our legitimate interest in taking and implementing the pre-contractual measures of a contract or performing the contract concluded between the legal entity and us. |
Main Data, Communication Data, Contract Data |
Performing the contract by delivering the purchased products (including providing you with free trial of our product), contacting you regarding the purchased products |
If the purchase is submitted by a natural person, the legal basis is performance of contract concluded between us If the purchase is submitted by a legal entity, the legal basis is our legitimate interest in performing the contract concluded between the legal entity and us |
Main Data, Contract Data, Communication Data |
Gathering information about you from publicly available resources and registrars for the purposes of creating client segments and customising the information we provide to you about our business |
Our legitimate interest in ensuring effective relations management with potential customers, partners and interested parties |
Communication Data |
Sending newsletters and other marketing information regarding us and our business via e-mail |
Consent given upon subscribing to our newsletter |
Main Data, Communications Data |
Administering newsletter subscription list |
Our legitimate interest in ensuring valid legal basis for sending newsletters and recording given and withdrawn consents (subscriptions) |
Main Data |
Diagnosing and repairing problems with the Website |
Our legitimate interest in providing data security and preventing fraudulent actions related to the Website; ensuring the functioning of the Website |
Technical Data |
Making available the basic functions of the Website and administering the Website, including gathering information about visitor’s navigation on the Website |
Our legitimate interest in providing the Website and understanding use patterns of the Website to be able to better the Website and enhance the user experience |
Technical Data |
Insurance and Risk Management |
Our legitimate interest is to process personal data where necessary for the purposes of obtaining or maintaining insurance coverage, managing risks and/or obtaining professional advice. |
Usage Data |
Analysing the use of our products |
Our legitimate interests in improving, upgrading, and enhancing our products |
Usage Data |
Data exchange with our distributors and co-operation partners for facilitating the provision of our products |
Our mutual legitimate interest in providing you with our product through our distributor or co-operation partner |
Main Data, Contract Data |
Storing information containing Personal Data in our backup systems |
Our legitimate interest in ensuring continuity and security of data processing operations |
All data categories named in Section 3.1 |
Disclosing data to our service providers or law enforcement and supervisory authorities |
Our legitimate interest in utilising the information technology infrastructure and services provided by our service providers or performance of our legal obligation |
All data categories named in Section 3.1 |
Intra-group data disclosures and transfers |
Our legitimate interest in utilising common technical infrastructure and performing internal administrative tasks |
All data categories named in Section 3.1 |
Arrange the sale or merger of our company and provide information for conducting the legal or other audit and the data exchange thereof |
Our legitimate interest in facilitating proper due diligence process and business continuity by ensuring a successful merger, acquisition or restructuring of the company |
All data categories named in Section 3.1 |
Establishment, exercise, or defence of legal claims, whether in court proceedings or in an administrative or out-of-court procedure in relation to our, our users’ or employees’ rights |
Our legitimate interest in facilitating effective establishment, exercise, or defence of legal claims |
All data categories named in Section 3.1 |
Type of the recipient |
Purpose of disclosure |
Law enforcement and supervisory authorities |
We disclose your Personal Data to law enforcement and supervisory authorities only if we are under a duty to disclose or share these data in order to comply with legal obligations (for example, if required to do so under applicable law, by a court order or for the purposes of prevention of fraud or other crime) |
Professional advisors (legal advisors, accounting, auditors etc) |
In case not operating as data processors, conducting and supporting our regular business activities |
Providers of support services related to fulfilling the contract |
For the purposes of performing our obligation related to the fulfilment of the contract we may disclose Personal Data to support service providers, such as payment service providers |
IT-service providers |
In case not acting as data processor, providing IT solutions necessary for daily business functions |
Distributors and co-operation partners |
Facilitating the provision of our products through our distributor or co-operation partner |
Group entities |
Utilising common technical infrastructure and performing internal administrative tasks |
Potential business acquirers, investors, and business transferee(s) |
If necessary and required for successfully transferring our business or for the purposes of mergers and acquisitions, your Personal Data may be disclosed to the specified acquirers and their representatives and / or legal counsels |
Category of the authorised processor |
Processing purpose |
Safeguard |
Location |
Providers of IT-services |
Providing IT-solutions necessary for the daily business functions (e.g. Microsoft Azure) |
Data processing agreements, standard contractual clauses |
World-wide, including the USA |
Providers of marketing and customer management software services |
Providing analytical insight and marketing tools for bettering daily business functions (e.g. MailChimp, HubSpot) |
Data processing agreements, standard contractual clauses |
World-wide, including the USA |
Binalyze AIR Guide
Download our DFIR Guide and learn more how you can elevate your incident response processes.