Data Processing Addendum
Last updated: June 2, 2026
You're the data controller; we're the processor and act on your instructions. The product is engineered to minimize personal data. We list every subprocessor, support EU/UK data-transfer mechanisms, and notify you of a breach within 72 hours. This summary is for convenience; the full terms below govern. EU/EEA, UK, Swiss, and other customers who need a counter-signed DPA can request one.
This Data Processing Addendum ("DPA") forms part of the agreement between the Customer and C2Consultants, LLC ("C2"), [Registered address — Charlotte, NC], for the Binary Intelligence service. It applies where C2 processes Personal Data on the Customer's behalf.
1. Roles
The Customer is the Controller. C2 is the Processor. C2 processes Personal Data only on documented instructions from the Customer; this DPA and the EULA constitute those instructions.
2. Personal data processed
By design, Binary Intelligence minimizes Personal Data. The categories processed in normal operation are:
- Account data: the email address used at checkout and (for billing) the billing address collected by Stripe.
- Telemetry: anonymized error signatures, remediation outcomes, and performance metrics — excluding machine names, user identifiers, file contents, and other PII by design. See the Privacy Notice.
- Support data: information you submit through a support ticket, including a diagnostic bundle if you attach one (PII is redacted from the bundle by the client).
Data subjects are the Customer's authorized users and billing contacts. Processing lasts for the term of the subscription plus the retention period in Section 9.
3. Subprocessors
C2 uses the subprocessors below. Customers are notified at least 30 days before C2 adds or replaces a subprocessor and may object on reasonable data-protection grounds.
- Microsoft Azure (United States; region configurable) — hosting for the licensing API, customer portal, Mimir corpus, and client downloads.
- Stripe, Inc. (United States) — payment processing, billing, tax compliance, and the billing portal.
- Microsoft 365 / Microsoft Graph (United States) — transactional email (activation emails, magic links, support replies).
A current subprocessor list is available at legal@binaryintelligence.ai.
4. International transfers
For Customers in the EEA, UK, or Switzerland, C2 relies on the EU Standard Contractual Clauses (with the UK and Swiss addenda where applicable) for transfers to the United States, and will execute the SCCs on request.
5. Security
C2 maintains a security program appropriate to the risk, including:
- HTTPS-only public surface with HSTS; TLS 1.2+ minimum.
- License envelopes signed in Azure Key Vault using RS256-PSS; private keys never leave the HSM.
- Activation keys stored only as
sha256(pepper || key). - Customer-portal cookies are HttpOnly + Secure + SameSite=Lax with server-side HMAC signing.
- Stripe webhook signatures verified on every event.
- Logging excludes activation keys, envelope JSON, and other secrets.
6. Subprocessor assurances
Microsoft (Azure, M365) and Stripe maintain SOC 2 / ISO 27001 attestations available through their trust portals. C2 imposes data-protection obligations on subprocessors no less protective than those in this DPA.
7. Data subject rights
C2 assists the Customer in responding to data subject requests (access, rectification, erasure, portability, restriction, objection) without undue delay. The Customer is the primary point of contact for its end users; C2 acts on the Customer's instructions.
8. Personal data breach notification
C2 notifies the Customer without undue delay, and in any case within 72 hours of becoming aware, of a Personal Data breach affecting the Customer's data, with the information reasonably available to support the Customer's own obligations.
9. Retention and deletion
On termination, C2 retains license-audit metadata (claim IDs and issuance/renewal/revocation events) for the period required to maintain the integrity of the licensing system (typically 7 years). Account Personal Data (e.g. email address) is deleted within 30 days of a verified deletion request, except where retention is required by law.
10. Audit
On reasonable written request and no more than once per year (or following a breach), C2 will provide information reasonably necessary to demonstrate compliance with this DPA, which may include subprocessor attestation reports in lieu of on-site audits.
Contact
Data-protection inquiries: legal@binaryintelligence.ai.