1. Introduction and who we are
This Data Protection & Privacy Policy explains how the Binary group of companies ("**Binary**", "**we**", "**us**" or "**our**") collects, uses, shares and protects personal data, and the rights available to individuals whose personal data we process. "Binary" is our trading brand; the services described here are provided by the legal entities set out below.
**Binary IS Limited** is the parent company and sole shareholder of the two subsidiaries listed below. Binary IS Limited sets group-wide data protection standards and acts as the controller for group functions; each entity is the controller for the personal data it processes in its own operations.
- **Binary IS Limited (UK parent)** — Incorporated in England and Wales, company no. 06305962. Registered office: 30 Victoria Avenue, Harrogate, North Yorkshire, HG1 5PR, United Kingdom. ICO registration reference: ZB034629.
- **Axponential (Ireland) Limited** — Incorporated in the Republic of Ireland, CRO company no. 665949 (registered 6 February 2020). Registered office: 3rd Floor, 40 Mespil Road, Dublin 4, D04 C2N4, Ireland.
- **Axponential, Inc.** — A Delaware corporation, file no. 6639298 (incorporated 30 November 2017). Registered agent: The Corporation Trust Company, Corporation Trust Center, 1209 Orange Street, Wilmington, New Castle County, DE 19801, USA.
This policy should be read alongside our website Terms and Conditions and any specific privacy notice provided to you at the point your data is collected. Please read it carefully.
2. Scope of this policy
This policy applies to personal data we process about:
- visitors to our website and people who contact us;
- prospective, current and former clients, and the individual contacts who act on their behalf;
- suppliers, partners and their individual contacts; and
- applicants for employment and members of our workforce (covered in more detail in separate internal notices).
It does not extend to third-party websites we may link to, which have their own privacy policies.
3. Personal data in the services we deliver to clients
Binary provides implementation, configuration and support services for **Microsoft Dynamics 365 Finance & Operations** ("D365 F&O") and related Microsoft technologies. It is important to be clear about our role in relation to the personal data held within our clients' own systems:
- Our client remains the **data controller** for the personal data held in their D365 F&O environment.
- **Microsoft** provides and hosts the D365 F&O software-as-a-service platform and processes that data on the client's behalf. Binary does not provide or host the application and is not the hosting provider.
- In delivering our services, Binary does not host, store or, in the ordinary course, access the personal data held within a client's environment, and we are **not appointed as a data processor** of that data.
Should a specific engagement ever require Binary to process personal data on a client's behalf, that processing would be governed by a separate written data processing agreement meeting the requirements of Article 28 of the UK GDPR (and the EU GDPR where relevant).
4. Definitions
- **Personal data** — Any information relating to an identified or identifiable living individual.
- **Processing** — Any operation performed on personal data, such as collection, storage, use, disclosure or deletion.
- **Data Protection Laws** — All applicable laws relating to the processing of personal data, including the UK GDPR, the EU GDPR, the Data Protection Act 2018, and applicable US state privacy laws.
- **UK GDPR** — The retained EU law version of the General Data Protection Regulation as it forms part of the law of England and Wales, Scotland and Northern Ireland.
- **Controller / Processor** — The party that determines the purposes and means of processing (controller), or that processes personal data on a controller's behalf (processor).
5. The personal data we collect and why
Depending on your relationship with us, we may process the following categories of personal data:
Website visitors
- technical data collected automatically, such as IP address, browser type and version, operating system, and information about how you interact with our website (including via cookies — see section 9).
Enquiries, clients and suppliers
- identity and contact details (name, job title, employer, email address, telephone number);
- correspondence and records of our dealings with you; and
- contract, engagement and billing information relating to the services we provide or receive.
We use this personal data to respond to enquiries, provide and manage our services, manage supplier relationships, meet our legal and regulatory obligations, and (where permitted) to send relevant business communications.
6. Our legal bases for processing
Where the UK GDPR or EU GDPR applies, we rely on one or more of the following legal bases:
- **Contract** — where processing is necessary to enter into or perform a contract with you or your organisation;
- **Legitimate interests** — to operate, promote and improve our business, manage relationships and secure our systems, where these interests are not overridden by your rights;
- **Legal obligation** — to comply with applicable law, regulation and tax requirements; and
- **Consent** — for certain cookies and marketing communications, which you may withdraw at any time.
7. How we share personal data
We do not sell personal data. We share it only where necessary, including with:
- **Microsoft** — which provides the cloud platforms (including Microsoft 365 and Microsoft Azure) on which our own business systems and data are hosted;
- **Atlassian** — which provides the collaboration and service-management tools (such as Jira and Confluence) we use to run our business;
- other trusted service providers acting on our instructions, and professional advisers, where required; and
- regulators, law enforcement or other authorities where we are legally required to do so.
Our critical systems and data are provided as software-as-a-service by Microsoft and Atlassian, who act as our processors and provide backup, resilience and security controls under their respective data processing terms.
8. International data transfers
Because our group operates in the United Kingdom, the Republic of Ireland and the United States, and because our cloud providers operate globally, personal data may be transferred outside the UK and the European Economic Area (EEA). Where we make such transfers, we put in place an appropriate safeguard recognised under Data Protection Laws, which may include:
- the UK International Data Transfer Agreement (IDTA), or the UK Addendum to the European Commission's Standard Contractual Clauses;
- the European Commission's Standard Contractual Clauses (SCCs) for transfers from the EEA; and
- the EU–US and UK Extension to the EU–US Data Privacy Framework, where the recipient is certified.
You may contact us for further information about the safeguards that apply to a specific transfer.
9. Cookies
Our website uses cookies to help it function, to understand how it is used and to remember your preferences. Before any non-essential cookies are set, we ask for your consent. For full details of the cookies we use and how to control them, please see our [Cookie Policy](https://binary.ax/cookies-policy).
10. How we keep personal data secure
We are a cloud-first, remote-first organisation and we apply technical and organisational measures appropriate to the risk. As our critical systems are delivered as software-as-a-service, we benefit from the enterprise-grade security, encryption and resilience provided by Microsoft and Atlassian, complemented by our own controls, which include:
- role-based access control and multi-factor authentication for access to business systems;
- encryption of data in transit and at rest as provided by our cloud platforms;
- resilient, high-availability internet connectivity with independent providers and firewalling; and
- policies and staff awareness measures covering acceptable use, access and incident handling.
We are actively working towards **Cyber Essentials Plus** certification, to be followed by certification to the ISO/IEC 27001 information security management standard.
privacy@binary.axprivacy@binary.ax.
11. How long we keep personal data
We keep personal data only for as long as necessary for the purposes for which it was collected, including to meet legal, accounting, tax or reporting requirements, after which it is securely deleted or anonymised. Even after deletion, data may persist for a limited period on backup or archival media held by our cloud providers.
12. Your rights
Subject to applicable law, you have the right to:
- be informed about how your personal data is used;
- access a copy of the personal data we hold about you;
- have inaccurate or incomplete data corrected;
- request erasure of your personal data;
- restrict or object to our processing of your data;
- data portability; and
- withdraw consent at any time where we rely on it.
privacy@binary.axprivacy@binary.ax. We will respond within the timeframes required by law and will not usually charge a fee.
13. How to contact us and how to complain
privacy@binary.axprivacy@binary.ax.
If you are not satisfied with our response, you have the right to complain to a supervisory authority:
- **United Kingdom** — the Information Commissioner's Office (ICO), ico.org.uk. Binary IS Limited is registered with the ICO under reference ZB034629.
- **Republic of Ireland / EEA** — the Data Protection Commission (DPC), dataprotection.ie.
14. Changes to this policy
We may update this policy from time to time to reflect changes in our practices or the law. The current version will always be available on our website, and the effective date will be updated accordingly.
15. Governing law
This policy and any dispute arising from it are governed by the law of England and Wales, without prejudice to the rights of individuals in the EEA to bring proceedings, or complain to a supervisory authority, in their country of residence.