Privacy Notice
How Binnovy collects, uses, shares, protects and transfers personal data, with Qatar law as the primary legal baseline and additional rights applied where other laws govern.
01Who we are
BINNOVY BUSINESS INNOVATION TECHNOLOGY QFZ LLC ("Binnovy", "we", "us", "our") is a limited liability company registered with the Qatar Free Zones Authority under Registration No. FZA 1075, with registered address Building 1, Street 504, Zone 49, Qatar Free Zones, Doha, State of Qatar. Binnovy operates its public websites and a portfolio of digital, cloud, software and artificial-intelligence services.
For personal data processed through our public websites for our own purposes, Binnovy generally acts as the data controller. Where Binnovy processes personal data on documented instructions for an enterprise customer, that customer generally acts as controller and Binnovy acts as processor, subject to the applicable commercial agreement and Data Processing Agreement (DPA).
02Legal framework and scope
This notice is designed primarily around Qatar Law No. 13 of 2016 concerning Personal Data Privacy Protection (PDPPL), related decisions and guidance administered by the competent Qatar data-protection authority, and applicable Qatar electronic-commerce requirements. Where Binnovy is subject to additional privacy laws because of the location of an individual, customer, establishment, processing activity or offering, we apply those requirements as applicable, including the EU General Data Protection Regulation (GDPR), UK GDPR and other mandatory local privacy laws.
This notice applies to binnovy.com, Binnovy-controlled public websites, enquiry and contact channels, events and marketing interactions, and other services that link to this notice. Customer-controlled platform processing is additionally governed by the DPA and the customer’s own privacy notices.
03Personal data we collect
We collect personal data that is relevant and proportionate to the purpose for which it is used. Depending on how you interact with Binnovy, this may include:
- Identity and business-contact data — name, job title, organization, work email, telephone number, country and business address where provided.
- Enquiry and relationship data — messages, meeting requests, business needs, proposals, support requests, feedback and other communications with us.
- Account data — account identifiers, authentication and access information for services that require an account. Passwords should be stored only in protected, non-plain-text form.
- Transaction and subscription data — service or product selected, order or subscription details, invoices, payment status and related business records. Payment-card data may be handled directly by an authorized payment provider where used and should not be stored by Binnovy unless expressly required and protected.
- Technical and security data — IP address, device/browser information, timestamps, security events, audit records, session identifiers and other information necessary to operate, defend and troubleshoot the service.
- Usage data — information about how authorized users interact with a Binnovy service, where needed for delivery, security, reliability, product improvement or contractual reporting.
- Preference and consent data — language, cookie choices, marketing preferences and records of consent or withdrawal.
- Customer-provided platform data — data uploaded, generated, connected or configured by a customer within a Binnovy service. The customer determines the relevant categories and lawful basis where Binnovy acts as processor.
04How we collect personal data
- Directly from you when you complete a form, contact us, create an account, enter into an agreement, attend an event or otherwise communicate with Binnovy.
- From your organization or an authorized administrator when it provisions access or supplies information for a business engagement.
- Automatically from devices, systems and security controls when you use our websites or services, subject to the Cookie Notice and applicable consent requirements.
- From service providers, partners or public business sources where the collection and use are lawful and reasonably expected for the stated purpose.
05Purposes and lawful grounds
We process personal data only for specified, legitimate purposes. Under the Qatar PDPPL, processing generally requires consent unless it is necessary for a legitimate purpose permitted by law. Where the GDPR or another law requiring a specific lawful basis applies, we rely on the basis appropriate to the activity. Typical purposes include:
- Responding to enquiries and taking steps requested before entering into a contract.
- Providing, administering, supporting, securing and improving contracted services.
- Creating and managing accounts, authentication, access rights and service communications.
- Billing, accounting, tax, record-keeping, audit and corporate administration.
- Preventing fraud, abuse, cyber incidents, unauthorized access and other threats.
- Complying with legal obligations, valid regulatory requirements, court orders and lawful government requests.
- Defending legal claims and enforcing agreements and policies.
- Sending optional marketing only where the required prior consent or other lawful permission exists.
We do not sell personal data. We do not use personal data for materially incompatible purposes without a lawful basis and, where required, additional notice or consent.
06Direct marketing
Binnovy does not send electronic direct-marketing communications to an individual where prior consent is required unless that consent has been obtained. Marketing communications identify Binnovy as the sender, state their commercial or marketing nature where required, and provide an accessible method to unsubscribe or withdraw consent. Withdrawal applies to future marketing and does not affect service, security, legal or transactional communications that are necessary for an existing relationship.
07Sharing and disclosure
We disclose personal data only where reasonably necessary and legally permitted. Recipients may include:
- Authorized Binnovy personnel and controlled entities that need the data for their duties.
- Approved service providers and sub-processors operating under written confidentiality, security and data-protection obligations.
- Professional advisers, auditors, insurers and financial institutions where necessary for legitimate business or legal purposes.
- Competent authorities, courts, law-enforcement bodies or regulators where disclosure is legally required or lawfully requested.
- A purchaser, investor or successor in connection with a genuine corporate transaction, subject to appropriate confidentiality and legal safeguards.
We require processors and sub-processors to handle personal data consistently with applicable law, customer instructions where relevant, and contractual security and confidentiality requirements.
08Data residency and international transfers
Binnovy’s architecture is designed to support customer-defined residency and sovereignty requirements. The actual processing location depends on the service, deployment model, customer configuration, approved vendors and commercial agreement. We do not describe data as remaining in a particular country or boundary unless the relevant service has been configured and contractually committed that way.
Where personal data is transferred across borders, we apply the safeguards required by the law governing that transfer. For EEA or UK restricted transfers, this may include an adequacy decision, approved contractual clauses or another valid transfer mechanism, together with supplementary measures where required. Qatar PDPPL requirements remain applicable to processing subject to Qatar law.
09Retention and deletion
We retain personal data only for as long as reasonably necessary for the purpose for which it was collected, the term of an applicable contract, legitimate security and audit needs, and mandatory legal, accounting or dispute-retention periods. We then securely delete or irreversibly anonymize the data unless continued retention is required by law. Customer-controlled platform data is returned or deleted according to the DPA, commercial agreement and documented customer instructions.
10Security
Binnovy uses administrative, technical and physical measures proportionate to the nature and sensitivity of the personal data and the risks of processing. Depending on the service and deployment, these may include identity and access controls, least privilege, encryption in transit and at rest, secure configuration, logging and monitoring, vulnerability management, backups, incident response, segregation of environments and supplier controls. No system is absolutely secure, and we do not represent that risk can be eliminated entirely.
11Personal-data breaches
We maintain procedures to identify, contain, investigate and document personal-data breaches. Where Binnovy acts as controller, we notify affected individuals and the competent authority when required by applicable law, including where a breach is likely to cause the level of harm that triggers notification under Qatar law. Where Binnovy acts as processor, we notify the relevant customer without undue delay after becoming aware of a breach affecting customer personal data and provide information reasonably necessary for the customer’s compliance obligations.
12Special categories and children
Under Qatar law, certain personal data is treated as having a special nature, including data relating to racial origin, children, health or physical or psychological condition, religious beliefs, marital relations and criminal offences. Binnovy will not intentionally process such data where a specific authorization or additional safeguard is required unless the legal and operational prerequisites have been satisfied.
Binnovy’s general business websites and enterprise services are not directed to children. If a Binnovy service is intentionally directed to children, we will implement the notices, parental or guardian consent, access and deletion mechanisms required by applicable law before collecting the relevant data.
13Your rights
Subject to applicable law, exemptions and identity verification, you may have rights to:
- Be informed about whether and why your personal data is processed.
- Access and obtain a copy of personal data held about you.
- Request correction of inaccurate or incomplete personal data.
- Withdraw consent where processing is based on consent.
- Object to processing that is unnecessary, excessive, discriminatory, unfair or unlawful.
- Request deletion where the purpose has ended or there is no lawful reason to retain the data.
- Restrict processing, request portability or object to certain automated processing where an applicable law provides those rights.
- Opt out of direct marketing at any time.
We will respond within the timeframe required by the applicable law. For requests governed by Qatar PDPPL guidance, Binnovy’s operational target is to respond within 30 calendar days unless a lawful exception or permitted extension applies.
14Complaints and regulatory contact
If you have a privacy concern, please contact Binnovy first so we can investigate it. Individuals whose processing is governed by Qatar law may also have the right to complain to the competent Qatar authority responsible for administering and enforcing the PDPPL. Individuals in other jurisdictions may have the right to complain to their local supervisory authority where that law applies.
15Cookies and similar technologies
Our use of cookies and similar technologies is described in the Cookie Notice. Non-essential cookies are activated only where the required consent has been obtained. You may change or withdraw cookie consent through the website’s cookie controls where available.
16Changes to this notice
We may update this notice to reflect changes in law, guidance, our services or processing practices. Material changes will be identified through the "Last updated" date and, where required, an additional notice or renewed consent will be provided.
17Contacting Binnovy
Privacy and data-protection requests may be submitted through Binnovy’s Contact page at /contact, marked for the attention of Privacy & Data Protection. Binnovy’s current business contact details, including an electronic mail address, must remain directly and continuously accessible on the website as required by applicable Qatar electronic-commerce rules.
Reach our data protection point of contact through the contact page.