Bynn Intelligence's trust center lists the current attestations (SOC 2, ISO 27001:2022, ISO/IEC 42001:2023, GDPR, CCPA, PCI DSS SAQ A, NIST Cybersecurity Framework, HIPAA (BAA available), EU AI Act aligned), monitored continuously in Vanta. HIPAA and the EU AI Act are not certifications: a Business Associate Agreement is available on request, and our practices are aligned with the Act.
- Model improvement
- Your requests and answers improve the models unless you opt out; never with zero retention, an Order Form or a Defence Contract Addendum
- Retention
- Requests and answers are deleted 30 days after each request
- Zero retention
- On request: requests and answers are not stored once the answer is returned
- Sessions
- The session's context is held for the life of the session only
- Batch jobs
- The request file is deleted when the results are written; results are kept 7 days
- Safety records
- Never hold the text of a request
- Your role
- You are the controller of the data you send; we process it for you under the DPA
What is kept, and for how long#
| Data | Kept | Then |
|---|---|---|
Requests and answers (state, images, questions, answers) | 30 days after each request | Deleted. Not stored at all under zero retention |
| A session's context (its instructions, state, questions and recent frames) | For the life of the session, only to answer its later frames, also under zero retention | Released when the session ends; its frames and replies are then kept as requests and answers |
| A batch's request file | Until the batch's results file is written, whatever the batch's end | Deleted. An ended batch holds no request body |
| A batch's results | 7 days after the batch ends | Deleted; the batch's counters stay, and its results answer 410 results_expired |
| Safety check records of flagged and refused requests | 90 days after the request | Deleted. They hold probabilities, the action taken and ids, never request text |
| Usage data (token counts, request ids, timings, the model that answered) | As long as billing and running the service need it | Deleted or aggregated. It holds no request content |
Image metadata such as EXIF is stripped when an image is read: only the pixels reach the model.
Model improvement, and how to opt out#
Unless you opt out, your requests and their answers may be used to train, evaluate and improve the models and the safety check, and to build datasets and models that we may license or sell. Identifiers and personal data are removed or reduced first where practicable, nothing is used to identify or contact anyone, personal data is never sold, and anything that leaves Bynn is de-identified first. Your data is never used this way when zero retention is on, when you are on an Order Form or dedicated plan, or under a Defence Contract Addendum. Opt out for the whole workspace in the console's settings, or by writing to privacy@bynn.com; it applies to requests sent after it takes effect. Usage data, which holds no request content, is used to run and improve the service. The binding text is section 8.4 of the Terms of Service and section 4 of the Privacy Policy.
Zero retention#
With zero retention, requests and answers are not stored once the answer is returned, and are never used to improve the models. It is offered on every plan: ask for it by writing to privacy@bynn.com with your workspace's name, and it applies to the keys of that workspace.
- Sessions still hold their context for the life of the session, because each frame is answered on it. It is released when the session ends.
- Batch jobs hold their request file until the results are written, and the results for the days above. For data that must never be stored, send it through
/v1/decide. - Usage data and safety records are kept as above; neither holds request text.
Personal data#
When your requests hold personal data, you are its controller and we process it on your behalf. The Data Processing Addendum is part of the terms and covers what the GDPR and similar laws require: processing only on your instructions, security measures, breach notice, deletion, audits and transfers under the Standard Contractual Clauses.
- Sub-processors fall into four categories: cloud computing and hosting, payment processing, email delivery, and error monitoring. The current list is in the console and on request, and we give 30 days' notice before adding one, so you can object.
- Security: our information security management system is certified to ISO/IEC 27001:2022 and we hold a SOC 2 report from an independent auditor. The trust center has the certificate, the report and the other frameworks we follow; ask at security@bynn.com for anything it keeps under confidentiality.
- Requests from the people in your data that reach us are forwarded to you, and we help you answer them.
- When you leave, you can export the data we still hold for 30 days after the agreement ends; then it is deleted.
Sending less#
- Send only what the decision needs. A ticket's text decides its route; the customer's name and address usually do not.
- Replace direct identifiers with your own ids before they reach the state:
customer_18342instead of an email address. - Never put keys, passwords or card numbers in a state or an image.
- For a consequential decision about a person, read Responsible use first: some need a qualified person's review.
Contacts#
Privacy questions, zero retention and data requests: privacy@bynn.com. Security issues: security@bynn.com.