Privacy Policy
Binder Community Limited · No. 17058768
Contents
• 1. Summary — at a glance
• 2. About this Policy and who we are
• 3. Definitions
• 4. Who this Policy is for (18+ only)
• 5. The personal data we collect, and where it comes from
• 6. Do you have to provide your data?
• 7. How and why we use your data, and our lawful bases
• 8. Sensitive (special category) data and your explicit consent
• 9. Children's data
• 10. Marketing and your communication preferences
• 11. Cookies and similar technologies
• 12. Matching, profiling, image moderation and automated decisions
• 13. How we use data to improve and train our own systems
• 14. Location data
• 15. Who we share your data with
• 16. Where your data is held, and which law applies
• 17. How long we keep your data
• 18. How we protect your data
• 19. Your rights
• 20. How to complain
• 21. Third-party links and services
• 22. Changes to this Policy
• 23. Contact us
1. Summary — at a glance
This summary helps you navigate the Policy. It does not replace the full text below.
Who we are— Binder Community Limited, a UK company, is the controller of your personal data.
Who can use Binder— Adults aged 18 and over, in the United Kingdom.
Sensitive data— We use data about your sexual orientation, gender identity, religious or philosophical beliefs, or health only where you give explicit consent, to keep people safe, to comply with legal or regulatory obligations, or to deal with legal claims.
Matching and profiling— We use an automated compatibility algorithm to suggest people, content and events. We may also analyse your activity (including the posts and events you engage with) to build a picture of what you like to attend. This is profiling; it affects only the relevance and ordering of what you see, is not a solely automated decision with legal or similarly significant effects, and you have a right to object at any time. See sections 12.2 and 12.4.
Age assurance— Age assurance is being finalised for public launch. Access to the closed beta is limited to invited adults who confirm they are 18 or over; the Stripe Identity age-verification flow (identity document + biometric liveness check) is not yet operational in the beta and will be enabled before public launch. Where enabled, Binder retains only a confirmation of age status (an 18+ pass/fail flag, the verification date and the provider session reference) and does not store the identity document, date of birth or biometric data. See section 12.1.
Location— Optional and consent-based. We apply location fuzzing to help protect your precise location.
Images and safety— Images you upload are automatically screened using Microsoft PhotoDNA against databases of known illegal content (CSAM); this screening operates now, and any further automated classifiers will be covered by an update to this Policy before they are used. No automated screening can detect all illegal or harmful content; we apply reasonable endeavours and do not warrant that every item is detected. We do not use your data to train general-purpose or third-party AI models; we may use limited content only to improve our own safety and moderation systems (sections 12.3 and 13).
Your content— Your messages and profile content are not end-to-end encrypted; we can access them to run the service and keep users safe.
Selling data— We do not sell your personal data.
Your rights— Access, correct, delete, restrict, object (including to profiling and to any use of your data to train our own systems), portability, withdraw consent, complain to the ICO, and claim compensation under data-protection law.
2. About this Policy and who we are
This Policy covers both this website (including the waitlist sign-up) and the Binder app and related services (together, the Platform). Some parts apply only once the app launches; where that is so, we say so at the start of the section.
Binder Community Limited is the controller of your personal data, except where this Policy says we act as a processor on behalf of another party. Our details are:
Controller: Binder Community Limited, registered in England and Wales (Registered No. 17058768).
Registered office: 15 Montpelier Vale, London SE3 0TA.
Privacy contact: Cameron Farquhar, cameron@bindercommunity.app.
ICO registration number: ZC191474.
Our data-protection principles.
We follow the UK GDPR principles: we use your personal data lawfully, fairly and transparently; only for specified, explicit and legitimate purposes; limited to what is necessary; kept accurate and up to date; kept no longer than necessary; and protected by appropriate security. We are accountable for meeting these principles. We keep the records needed to demonstrate our compliance with them.
3. Definitions
‘Platform’ means the Binder mobile application, website and related services.
‘Stripe’ means Stripe Payments UK, Ltd, our age-verification and payment services provider.
‘personal data’, ‘special category data’, ‘controller’, ‘processor’ and ‘processing’ have the meanings given in the UK GDPR (the retained EU GDPR as it forms part of UK law, read with the Data Protection Act 2018).
4. Who this Policy is for (18+ only)
The Platform is for adults aged 18 or over in the United Kingdom. It is not directed at children, and we do not knowingly collect personal data from anyone under 18. Age assurance is being finalised for public launch: access to the closed beta is limited to invited adults who confirm they are 18 or over, and the Stripe Identity age-verification flow (identity document + biometric liveness check) is not yet operational in the beta and will be enabled before public launch (section 12.1). If we learn that we hold personal data of a person under 18, we will delete it.
5. The personal data we collect, and where it comes from
We collect the following categories of personal data, from you directly unless stated otherwise.
| Category | Examples | Source |
|---|
| Waitlist data (this website) | Email address; your consent to receive Binder waitlist emails; timestamps and consent version | You |
| Account data (once the app launches) | Name/username, email, phone number, password | You |
| Profile data | Photos, bio, interests, prompts, the contexts you express | You |
| Special category data | Data revealing sexual orientation, gender identity, religious or philosophical beliefs, or health data you choose to share (see section 8) | You — via your profile settings |
| Age-assurance and identity data | Government-issued identity document; biometric liveness data used to confirm you are 18+ (processed by Stripe Identity); the confirmation result Binder retains (18+ pass/fail flag, verification date and provider session reference) | You; Stripe Identity |
| Content and communications | Posts, images, messages and related metadata | You |
| Posts, events and activity data | The posts and events you post, join, RSVP to and attend, and related activity on the Platform | You; automatically |
| Payment data | Billing details and transaction records | You; Stripe Payments UK Ltd |
| Technical and usage data | IP address, device identifiers, OS, app version, interactions, session data | Automatically |
| Cookies and similar | Identifiers and preferences (see section 11) | Automatically; with consent |
| Safety and moderation data | Reports you make, moderation results, CSAM-incident records, anti-abuse signals, account-status records | You; our moderation tools |
| Compatibility scores | Scores generated by our matching system to rank suggestions | Automatically |
6. Do you have to provide your data?
Some personal data is necessary to provide the Platform. You must provide account data to create and use an account, and, once the Stripe Identity age-verification flow is enabled for public launch, you will need to complete age verification. Access to the closed beta is limited to invited adults who confirm they are 18 or over. If you do not provide the data we need, we cannot provide the Platform to you.
Other data is optional. You choose whether to share profile details, sensitive preference attributes, and location. Not sharing them only means certain features may be unavailable. Marketing is always optional.
You choose whether to share special category data through your profile and matching settings, using a control you can turn on or off at any time. If you turn it off, we stop using that data for matching and some features become unavailable, so you use Binder in a more limited way (section 12.2).
7. How and why we use your data, and our lawful bases
We must have a lawful basis to use your personal data, and an additional condition for special category data. We rely on your consent to process the information you choose to share that reveals, or may reveal, special category information such as your religious or philosophical beliefs, sexual orientation, gender identity, or health, in order to provide our compatibility matching services (section 12.2). We ask for this consent separately and specifically at sign-up, through a distinct opt-in. This consent is optional and you can withdraw it at any time (section 8). Without it, some features - including compatibility matching that relies on this information - may be unavailable to you, though you can still use the core Platform. You can turn this consent on or off at any time in your settings. Our main purposes are set out below.
| Purpose | Lawful basis (Art 6) and special-category condition (Art 9 / DPA 2018 Sch 1) |
|---|
| Waitlist sign-up (this website) | Consent (Art 6(1)(a)) — you opted in to receive Binder waitlist emails; withdraw at any time via the unsubscribe link. |
| Create and manage your account | Contract (Art 6(1)(b)). |
| Operate the Platform — profile and discovery | Contract (Art 6(1)(b)). Special-category elements you display: explicit consent (Art 9(2)(a)). |
| Compatibility matching and profiling (section 12.2) | Contract (Art 6(1)(b)) for the matching service. Explicit consent (Art 9(2)(a)) for special-category profile attributes. Withdrawable at any time. |
| Profiling of your activity and attendance preferences (section 12.4) | Legitimate interests (Art 6(1)(f)), with a right to object at any time (Art 21). |
| Use sexual orientation, gender identity, religion/belief data to help you connect | Explicit consent (Art 9(2)(a)); withdrawable at any time. |
| Location-based discovery and events | Consent (Art 6(1)(a)); withdrawable at any time. |
| Age verification, once enabled for public launch (Stripe Identity — biometric liveness + document review) | Legal obligation (Art 6(1)(c)) — Online Safety Act 2023. Biometric data: substantial public interest — safeguarding (Art 9(2)(g); DPA 2018 Sch 1 para 18), per our Appropriate Policy Document. |
| Automated image and content moderation (detecting CSAM, illegal and harmful content) | Legal obligation (Art 6(1)(c)) and legitimate interests (Art 6(1)(f)). Special category: substantial public interest — safeguarding (Art 9(2)(g); DPA 2018 Sch 1 para 18) and preventing/detecting unlawful acts (Art 9(2)(g); DPA 2018 Sch 1 para 10), per our Appropriate Policy Document. |
| Calibrating our own safety/moderation classifiers | Legitimate interests (Art 6(1)(f)). Special category: explicit consent (Art 9(2)(a)); substantial public interest — safeguarding (Art 9(2)(g); DPA 2018 Sch 1 para 18) where applicable, per our Appropriate Policy Document. |
| Developing, training, testing and improving our own moderation and matching systems (section 13) | Legitimate interests (Art 6(1)(f)) with a right to object (Art 21) for identifying data; explicit consent (Art 9(2)(a)) for special-category data; subject to a DPIA and transparency. |
| Keep users safe; prevent abuse, illegal content and fraud | Legal obligation (Art 6(1)(c)) and legitimate interests (Art 6(1)(f)). Special category: as above (Art 9(2)(g); DPA 2018 Sch 1 para 18 (safeguarding) and para 10 (unlawful acts)). |
| Take payments and keep financial records | Contract (Art 6(1)(b)); legal obligation (Art 6(1)(c)). |
| Service messages (security, changes to terms) | Contract (Art 6(1)(b)); legitimate interests (Art 6(1)(f)). |
| Marketing | Consent (Art 6(1)(a)); PECR. |
| Analytics, security and improving the Platform | Legitimate interests (Art 6(1)(f)); consent for non-essential cookies. |
| Legal claims; responding to lawful requests | Legal obligation (Art 6(1)(c)); legitimate interests (Art 6(1)(f)). Special category: legal claims (Art 9(2)(f)). |
Where we rely on legitimate interests, we have weighed those interests against your rights, and you can ask us about that assessment. Where we rely on consent, you can withdraw it at any time without affecting earlier processing.
8. Sensitive (special category) data and your explicit consent
Data about special category data such as your sexual orientation, gender identity, religious or philosophical beliefs, and health is treated as especially sensitive. We therefore rely on you providing your consent to process it. Binder may from time to time process certain special category data under specific legal bases, for example to ensure user safety or to comply with legal or regulatory obligations, or to deal with legal claims (see section 7 and our Appropriate Policy Document).
We may collect sensitive data through our systems during onboarding and profile setup. This data may be used to calculate compatibility scores between users as part of Binder’s matching service (section 12.2). You control which information you share or whether to share any information at all, and you may withdraw consent for individual attributes at any time in Profile Settings. If you withdraw consent for special category data processing, then your account type changes to a minimal layer and we cease processing any further special category data.
You can turn consent for special category data processing on or off at any time. If you turn it off, we immediately stop using and hide this information; it is then automatically deleted within 48 hours unless you turn consent back on before then, in which case everything is restored exactly as it was. This scope is limited to Binder’s own use of these attributes for compatibility matching; it does not require us to retrospectively remove content you have chosen to share with other users (for example in messages, group chats or community areas), which is a separate activity governed by section 15.1. You can ask us to delete specific content, or close your account, at any time (section 19).
Please also take care with sensitive information you include in messages or share with other users. Once you share it with another person, you may not be able to control how they use it.
9. Children's data
Because the Platform is for adults, we do not knowingly process the personal data of under-18s. If you believe a child is using the Platform, please report it through the app or contact us, and we will take appropriate action, including removing the account and deleting the data.
10. Marketing and your communication preferences
We send marketing by email, SMS or push notification only where you have opted in, and you can opt out at any time using the unsubscribe link or your notification settings. We will still send essential service messages (for example about security, payments, or changes to our terms), which are necessary to provide the Platform and are not marketing.
Separately, where we use your content in our own external or public marketing (including where that marketing appears on third-party platforms such as social media), we use content that identifies you only with your opt-in consent. We do not hand your personal data to third parties for their own marketing. You can withdraw that consent at any time; withdrawal takes effect for the future only and does not affect uses that were lawful before withdrawal, materials already published or distributed, or sub-licences already granted. Where identifying content is personal data, your data-protection rights (withdrawing consent and erasure), not the content licence, govern its removal; and on withdrawal or erasure we take reasonable steps to notify any sub-licensees to cease further use, consistent with Article 17(2) UK GDPR. This use is a licence of the intellectual property in your content and not a sale of your personal data. Further detail on the licence over your content is in our
Terms of Service and the UGC Licence.
11. Cookies and similar technologies
We use a small number of strictly necessary cookies to operate the Platform and remember your preferences. The Platform does not currently set non-essential or analytics cookies, and no cookie-consent banner is shown. If this changes, we will update this Policy and our separate Cookie Policy and, where the law requires, ask for your consent first. Full details are in our Cookie Policy.
On this website (including the waitlist) we do not currently use analytics or visitor-tracking technologies; we rely only on the strictly necessary processing needed to run the site securely.
12. Matching, profiling, image moderation and automated decisions
Image and content moderation (12.3) and profiling of your activity and attendance preferences (12.4) operate now, including during our current closed beta. Age verification (12.1) and compatibility matching (12.2) apply as those parts of the app become available. If you are taking part in the closed beta, your participation is also governed by the Beta Tester Terms & NDA.
12.1. Age verification
To confirm that you are aged 18 or over, we are finalising age assurance for public launch. Access to the closed beta is limited to invited adults who confirm they are 18 or over; the Stripe Identity age-verification flow (identity document + biometric liveness check) is not yet operational in the beta and will be enabled before public launch. Where enabled, you upload a government-issued identity document and complete a biometric liveness check, and an automated decision is made on whether you meet the age threshold. Stripe Identity processes your identity document and biometric data on our behalf. Binder retains only a confirmation of your age status (an 18+ pass/fail flag, the verification date and the provider session reference) and does not store the identity document, your date of birth or biometric data itself. Where enabled, the legal basis is our legal obligation under the Online Safety Act 2023 (Art 6(1)(c)); biometric data is justified by substantial public interest — safeguarding (Art 9(2)(g); DPA 2018 Sch 1 para 18), per our Appropriate Policy Document.
12.2. Matching and compatibility profiling
Binder uses an automated matching system to suggest other users, content and events that may be relevant to you. This involves profiling within the meaning of Article 4(4) UK GDPR. It draws on your profile and preferences, your approximate location (to which we apply location fuzzing), your activity on the Platform, and - where you have given explicit consent - the sensitive attributes you have chosen to share, to estimate how relevant a suggestion may be to you.
This affects only the order and prominence of the suggestions you see. Scores are used only to rank suggestions. It does not decide who may contact you and does not restrict your access to the Platform, and it is not a solely automated decision producing legal or similarly significant effects, so Article 22 UK GDPR does not apply. You may object at any time (Profile Settings > Privacy > Matching Preferences) and may withdraw consent for specific sensitive attributes (section 8).
12.3. Image and content moderation
To keep the Platform safe, images you upload are automatically screened at the point of upload using Microsoft PhotoDNA, which matches them against databases of known child sexual abuse material (CSAM) and other illegal imagery. This screening operates now, including during our current closed beta. Images are not served to any user until they have been cleared (‘fail-closed’). No automated screening can detect all illegal or harmful content; we apply reasonable endeavours and do not warrant that every item is detected. Any further automated classifiers will be covered by an update to this Policy before they are used.
If a scan identifies a potential problem, the content is quarantined and not shown to any user, a safety record is created, your account may be suspended or restricted, and, where required by law, we report the content to the National Crime Agency via CEOP. Where a moderation decision significantly affects you, you can request human review, put your point of view, and contest the outcome.
We do not use your personal data, images or messages to train general-purpose or third-party AI models. We may use limited content only to develop and improve our own content-moderation and matching/compatibility systems, and only on anonymised content or on content for which you have given separate explicit consent (Article 9(2)(a) UK GDPR). This is part of the wider use described in section 13.
12.4. Profiling of your activity and attendance preferences
We retain details about your activity to operate our features. Separately, we may analyse this activity to build a picture of the kinds of plans, events and activities you like to attend, so as to make discovery and suggestions more relevant to you. Any such analysis is profiling within the meaning of Article 4(4) UK GDPR.
Our lawful basis for this profiling is our legitimate interests (Article 6(1)(f)) in operating and improving a relevant, useful service, weighed against your rights (and you can ask us about that assessment), and you have the right to object at any time (Article 21 UK GDPR — see section 19). This affects only the relevance and ordering of what you see; it does not produce legal or similarly significant effects and is not a solely automated decision of that kind, so Article 22 UK GDPR does not apply.
Where we go further and use this activity to develop or train our own systems, that is a separate purpose described in section 13.
13. How we use data to improve and train our own systems
Binder may use user data and content to develop, train, test and improve its own content-moderation and matching/compatibility systems. This is limited to our own systems: we do not use your data, content, images or messages to develop or train general-purpose or third-party AI models.
Wherever possible, we use anonymised or aggregated data for this purpose, so that it does not identify you. Any use of data that identifies you, or of special category data, is subject to a further lawful basis:
• for data that identifies you, our legitimate interests (Article 6(1)(f)), and you have the right to object to this use at any time (Article 21 UK GDPR); and
• for special category data (such as sensitive profile attributes), your explicit consent (Article 9(2)(a) UK GDPR).
Any such use is also subject to a data protection impact assessment and to being transparent with you about what we are doing.
You can object to this use, and to profiling, at any time — see section 19 (Your rights).
14. Location data
This section applies once the app launches.
We apply location fuzzing and other measures (such as coarsening or ‘ghosting’ location) to help protect your precise location. We do not collect location in the background unless strictly necessary for a feature you have enabled. Because the Platform can facilitate meeting people in person, please also read our
Safety Guidelines before arranging to meet anyone.
15. Who we share your data with
15.1. Other users
Information you choose to make visible is seen by other users in line with your privacy settings and your engagement with community-based functions and systems. Other users may see information you make publicly visible, and we encourage you to take care when posting sensitive information. Each user is responsible for the information they make publicly available — see our
Terms of Service for our liability position.
15.2. Service providers (processors)
We put in place written contracts with our providers who process data on our behalf, in line with Article 28 UK GDPR, including those listed below. Microsoft’s processing of images through PhotoDNA is carried out under Microsoft’s data-processing terms, which incorporate the Article 28 UK GDPR processor obligations.
| Provider | Role | Data-transfer safeguard |
|---|
| Stripe Payments UK, Ltd | Age verification (Stripe Identity) and payment processing. | Processed in the UK; any international transfer is made under the UK International Data Transfer Agreement (IDTA)/Addendum with a transfer risk assessment. |
| Microsoft (PhotoDNA) | Automated hash-matching of images against known CSAM databases, under Microsoft's Article 28 UK GDPR data-processing terms. | Microsoft Azure, UK/EU region; where any transfer occurs it is made under the UK International Data Transfer Agreement (IDTA)/Addendum with a transfer risk assessment. |
| Application hosting provider | Application hosting for the Binder platform. | Application hosting. US-based; transfers made under the UK International Data Transfer Agreement (IDTA)/Addendum with a transfer risk assessment. |
| Database hosting provider | Database hosting and storage of account and profile data. | Hosted in the UK/EEA; any support access from outside the UK/EEA is made under the UK International Data Transfer Agreement (IDTA)/Addendum with a transfer risk assessment. |
| Website hosting provider | Hosting of the Binder website. | Hosting of the Binder website. US-based; transfers made under the UK International Data Transfer Agreement (IDTA)/Addendum with a transfer risk assessment. |
| Push-notification and diagnostics providers | Push-notification delivery (Expo); crash/error diagnostics (Sentry — identifiers scrubbed). | Push-notification delivery (Expo, US - transfers under the UK International Data Transfer Agreement (IDTA)/Addendum with a transfer risk assessment); crash and error diagnostics (Sentry, hosted in the UK/EEA, identifiers scrubbed, no restricted transfer). |
| Apple | App distribution and Sign in with Apple. | Apple standard terms. |
| Google | App distribution (Play) and location autocomplete (Places). | Google standard terms. |
| Gmail (Google Workspace) | Sending safety/report/verification emails. | Google Workspace DPA. |
15.3. Access to your content
Your profile content and messages are not end-to-end encrypted, which means we (and our service providers acting on our instructions) can access them to operate the Platform, provide support, and keep users safe. We do not have access to your password, which is stored in a secured (hashed) form. We use encryption at rest rather than end-to-end encryption so that we can meet our legal and safety obligations, including where we are lawfully required to access content.
15.4. Safety, legal and regulatory
We may disclose data where necessary to protect users or the public, to detect or prevent abuse, harassment, illegal content or fraud, to comply with a legal obligation or court order, to respond to lawful requests from law enforcement or regulators (including the National Crime Agency, CEOP, the ICO, and Ofcom), or to bring or defend legal claims.
15.5. Corporate transactions
In a merger, acquisition, financing or asset sale, data may be disclosed or transferred subject to appropriate confidentiality protections. Any new owner must continue to honour this Policy for data already held, and we will notify you of a change of control affecting your data and give you the opportunity to delete your account beforehand.
15.6. Selling data
We do not sell your personal data, and we do not share your personal data with third parties for their own marketing or other commercial purposes. Where we share personal data with third-party partners at all, it is for the limited operational purposes described in this Policy — principally age verification and content moderation (section 15.2) — and not for marketing or commercial exploitation.
We distinguish your personal data from your user-generated content (‘UGC’). The licence we reserve over your content for marketing and other purposes applies to non-personally-identifying UGC unless consented to. That is a licence of the intellectual property in the content; it is not a sale, and it is not a marketing use of your personal data.
Binder takes the safety of its users seriously and so does not licence Content that identifies you personally to third parties, and where Binder may use Content for its own marketing and business purposes, this is subject to your consent. That consent is the lawful basis; it is optional and you can withdraw it at any time. Withdrawal and erasure of identifying content are governed by your data-protection rights, not by the content licence (see sections 10 and 19, and our
Terms of Service).
16. Where your data is held, and which law applies
The Platform is offered to users in the United Kingdom, and this Policy is governed by the law of England and Wales. We aim to host personal data in the United Kingdom, but some providers are based outside the UK or may process data outside it. Where personal data is transferred outside the UK, we rely on an appropriate safeguard, such as the ICO’s IDTA or the UK Addendum to the EU SCCs, together with a transfer risk assessment. Transfer-mechanism details for each provider are set out in section 15.
17. How long we keep your data
We keep personal data only as long as necessary for the purposes in this Policy, then delete or anonymise it. The table below is an indicative summary. Our full retention periods, triggers and bases are set out in our Data Retention Schedule, which is the controlling document; if this summary and the Data Retention Schedule ever differ, the Schedule governs.
| Data | Indicative period |
|---|
| Waitlist data (this website) | Deleted if we do not launch within 12 months, or 6 months after your last interaction — whichever is sooner |
| Account and profile data | Life of account + a 90-day non-extendable grace after closure, then hard deletion |
| Messages and content | 12 months, then automatically deleted (soft-deleted, then hard-deleted); this deletion is automated and operating now |
| Photos and other media | Life of account + a 90-day grace after closure |
| Posts, events and RSVPs | Live on the surface until they expire; the raw event is then deleted or anonymised around 12 months after expiry, with only anonymised or aggregated derivations kept longer |
| Consent records | Duration of the account + 6 years |
| Proof-of-consent record (kept after erasure) | A minimal record only (the consent event, its date, and the scope/policy version) is kept after an erasure request for accountability, bounded to a maximum of 6 years from account closure or erasure, then deleted or anonymised; subject to annual review |
| Safety, moderation and CSAM-reporting records | At least 3 years (Online Safety Act 2023), aligned to 6 years (Limitation Act 1980), and for the duration of any investigation or legal proceedings; never reused commercially or to train our systems. CSAM itself is not retained — we make the required report and keep a minimal incident record only |
| Payment and transaction records | 6 years (tax / limitation period) |
| Age-assurance records | In the closed beta, none are collected (access is limited to invited adults who self-declare they are 18+). At launch, only an 18+ pass/fail flag, the verification date and the provider (Stripe) session reference — no date of birth, no identity document and no biometric data — kept for the life of the account plus an audit/fraud tail. Any identity document or biometric data is processed by Stripe under Stripe's policy and is not held by Binder |
| Diagnostic (application) logs | 30 days |
| Security, authentication and abuse logs | Up to 12 months, extendable where an identified incident requires it; personal data, special category data and credentials are scrubbed from these logs |
| Location data | We apply location fuzzing to reduce precision; retained only as long as needed to provide location-based features |
| Backups / disaster recovery | If we use backups, they are brought within our deletion and erasure processes and retained no longer than necessary for that purpose |
| Special category data (sensitive profile attributes) | Hidden immediately on withdrawal; automatically deleted within 48 hours unless consent is re-granted in that window |
| Compatibility scores | Retained while your account is active, to rank suggestions |
A legal hold (for a safety, Online Safety Act, investigation or litigation matter) overrides every routine deletion period above and the 90-day deletion grace: where a hold applies, the affected account and data are kept until the matter closes plus a defined tail, notwithstanding any deletion request, expiry or grace period. Where Binder is required to retain data records by law enforcement agencies or regulators, we may retain data for longer subject to our obligations and requirements under applicable law and authority.
18. How we protect your data
We design the Platform with privacy and security in mind (‘privacy by design and by default’) and apply technical and organisational measures appropriate to the sensitivity of the data, including encryption and access controls. No system can be guaranteed completely secure; we work to protect your data and will notify you and the ICO of a personal data breach where required.
19. Your rights
Subject to conditions and exemptions in data protection law, you have the right to: access your data; have it corrected; have it erased; restrict processing; object to processing — including the right under Article 21 UK GDPR to object to direct marketing, to profiling based on our legitimate interests (such as the activity and attendance-preference profiling described in section 12.4), and to any use of your data to develop or train our own systems (section 13); data portability; withdraw consent at any time (including consent to sensitive or preference-based profile attributes, or to location); and request human review of any significant automated decision. You may also be entitled to compensation for damage under data-protection law (Article 82 UK GDPR and sections 168–169 of the Data Protection Act 2018); nothing in this Policy or the wider suite limits that entitlement.
Erasure and our deletion grace.
When you delete your account or ask us to erase your personal data, your account first enters a 90-day, non-extendable reactivation grace period; after it ends, your account, profile and media are locked out and then hard-deleted (section 17), unless the account is under a hold or we need to keep data to comply with legal obligations, or in reasonable contemplation of defending or bringing a claim. Some data may be kept for longer where the law requires or permits it — for example payment records and safety/moderation records — and any legal hold overrides this process (section 17). After deletion we keep a minimal proof-of-consent record — the consent event, its date, and the scope/policy version — for accountability under Article 7(1) UK GDPR. This minimal record is kept for up to 6 years from closure or erasure and is then deleted or anonymised.
Where you ask us to erase your personal data, or you withdraw consent, and we have shared that data with recipients or sub-licensees, we will take reasonable steps to notify them to cease further use, consistent with Articles 17(2) and 19 UK GDPR, taking account of available technology and the cost of doing so and where it is reasonably practicable, and subject to Binder giving no warranty or guarantee over the acts or omissions of third parties outside its direct control.
To exercise a right, contact us using the details in section 23. We respond within one month (extendable for complex requests) and there is normally no charge; we may need to verify your identity first. Some rights are not absolute — for example, we may need to keep certain data for safety or legal reasons.
20. How to complain
If you are unhappy with how we have handled your personal data, please contact us first — including through the in-app ‘Data Complaint’ channel — so we can try to put it right. You also have the right to complain to the Information Commissioner’s Office (ICO): ico.org.uk; helpline 0303 123 1113; Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF.
21. Third-party links and services
The Platform may link to or integrate third-party websites or services we do not control. This Policy does not apply to them, and we are not responsible for their privacy practices. Please review their privacy notices before sharing your data.
22. Changes to this Policy
We may update this Policy from time to time. If we make material changes, we will give you reasonable notice through the Platform or by email; where a change affects the basis for consent-based processing, we will ask you to review and re-accept it before we rely on the change for that purpose. The version currently published on the Platform is the one in force; we keep internal records of earlier versions.
23. Contact us
For any question about this Policy or your personal data, contact our privacy contact at cameron@bindercommunity.app or at Binder Community Limited, 15 Montpelier Vale, London SE3 0TA. Controller: Binder Community Limited (Registered No. 17058768). If you need this Policy in an accessible format, please contact us and we will help.