Privacy Policy

BinaryPOS Privacy Policy

Effective Date: 12 August 2026
Last Updated: 12 August 2026

BinaryPOS (“BinaryPOS”, “we”, “us” or “our”) provides point-of-sale, restaurant management and related technology services to restaurants and other businesses.

We respect the privacy of individuals whose personal data is processed through our Services. This Privacy Policy explains what personal data we collect, how we use and protect it, when we disclose it, and the rights and choices available to individuals.

This Privacy Policy is intended to be consistent with applicable Indian laws relating to privacy and data protection, including the Digital Personal Data Protection Act, 2023 (“DPDP Act”), the Digital Personal Data Protection Rules, 2025 (“DPDP Rules”), the Information Technology Act, 2000 and applicable rules and regulations, as amended or replaced from time to time.

1. Our Role in Processing Personal Data

BinaryPOS provides software and technology infrastructure to restaurants.

In many cases, a restaurant using BinaryPOS determines:

  • what customer information it collects;
  • why the information is collected;
  • how the information is used;
  • how long the information should be retained; and
  • whether and how customer information is used for restaurant operations, communications, loyalty programmes or marketing.

In these circumstances, the restaurant is responsible for determining the purposes and means of processing the relevant personal data, and BinaryPOS processes that information as a technology/service provider on behalf of the restaurant.

Accordingly, BinaryPOS may act as a Data Processor for restaurant customer data, while the relevant restaurant may be the Data Fiduciary, where those terms apply under Indian data-protection law.

However, BinaryPOS may itself act as a Data Fiduciary for personal data that we collect and process for our own purposes, such as information relating to our website visitors, prospective customers, business contacts, users of our own services and customer support interactions.

Our role may therefore depend on the specific data and processing activity involved.

2. Personal Data We Process

Depending on how BinaryPOS is used, we may process the following personal data:

Restaurant customer information

When a restaurant uses BinaryPOS to manage its customers, the information processed through our platform may include:

  • customer's name;
  • customer's mobile or telephone number;
  • transaction-related information;
  • visit or purchase information;
  • loyalty or customer-programme information, where enabled by the restaurant; and
  • other information that the restaurant chooses to enter into or collect through BinaryPOS.

BinaryPOS does not require restaurants to collect more personal data than is reasonably necessary for the relevant functionality.

Business and account information

Where you interact directly with BinaryPOS, we may collect:

  • name;
  • business name;
  • email address;
  • telephone/mobile number;
  • job title or business role;
  • account and login information;
  • billing information;
  • support requests and communications; and
  • information submitted through our website, forms or other communications.

Technical information

We may also collect information automatically when our website or Services are accessed, including:

  • IP address;
  • browser and device information;
  • operating system;
  • access dates and times;
  • application and system logs;
  • authentication and security information;
  • diagnostic information; and
  • information concerning use of our website or Services.

3. How We Use Personal Data

Restaurant customer data

Where BinaryPOS processes customer information on behalf of a restaurant, we process that information to provide the Services requested by the restaurant.

This may include:

  • recording customer information;
  • enabling customer identification;
  • managing restaurant transactions;
  • supporting restaurant operations;
  • maintaining customer records;
  • enabling loyalty or customer-management functionality;
  • providing reports and analytics to the restaurant;
  • maintaining and securing the BinaryPOS platform;
  • providing technical and customer support;
  • preventing fraud, misuse and security incidents; and
  • performing other functions configured or authorised by the restaurant.

The restaurant is responsible for determining whether it has a lawful basis and appropriate notice/consent for the collection and use of customer personal data.

BinaryPOS's own processing

Where BinaryPOS acts independently as a Data Fiduciary, we may process personal data for purposes including:

  • providing and administering our Services;
  • creating and managing accounts;
  • communicating with customers and prospective customers;
  • providing support;
  • processing billing and payments;
  • maintaining security;
  • preventing fraud and abuse;
  • improving our products and Services;
  • troubleshooting and diagnosing technical problems;
  • complying with applicable laws;
  • establishing or defending legal claims; and
  • other purposes communicated to you at or before collection, or otherwise permitted by applicable law.

4. Notice and Consent

Where applicable law requires consent for processing personal data, the relevant Data Fiduciary will obtain consent in accordance with applicable law.

Where BinaryPOS acts as a Data Processor for a restaurant, the restaurant is responsible for providing the required notice to its customers and obtaining consent where consent is required.

Where BinaryPOS acts as the Data Fiduciary, BinaryPOS will provide an appropriate privacy notice and obtain consent where required.

Where consent is relied upon as the legal basis for processing, an individual may withdraw consent through the appropriate mechanism, subject to applicable law.

Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal.

5. Customer Data Processed for Restaurants

Restaurant customers should understand that BinaryPOS generally provides the technology used by the restaurant.

If you have provided your name or telephone number directly to a restaurant using BinaryPOS, questions concerning why the restaurant collected your information, how the restaurant uses it, or requests concerning restaurant-specific customer records may need to be directed to that restaurant.

BinaryPOS will reasonably assist its restaurant customers with applicable privacy requests relating to personal data processed through BinaryPOS.

Where required, we may forward or otherwise facilitate a privacy request to the relevant restaurant.

6. Disclosure of Personal Data

BinaryPOS may disclose or make personal data available where reasonably necessary to provide and secure the Services.

Recipients may include:

  • restaurants and businesses using BinaryPOS;
  • BinaryPOS employees and authorised personnel;
  • cloud and infrastructure providers;
  • technology and software providers;
  • payment service providers;
  • security and monitoring providers;
  • analytics and support providers;
  • professional advisers and auditors;
  • government authorities, regulators, courts or law-enforcement agencies where legally required or permitted; and
  • parties involved in a merger, acquisition, restructuring or sale of substantially all or part of our business.

We require appropriate contractual, confidentiality and security protections from service providers that process personal data on our behalf.

BinaryPOS does not sell restaurant customer personal data to third parties for monetary consideration.

7. Hosting and Storage in India

BinaryPOS hosts its primary production infrastructure using Amazon Web Services (AWS) infrastructure located in Mumbai, India, subject to the specific AWS services and architecture used by BinaryPOS.

We design our infrastructure to keep the primary production customer database within India.

Certain third-party services, support systems, security tools or other infrastructure providers used by BinaryPOS may process limited information outside India where necessary to provide the relevant service.

Where personal data is transferred outside India, BinaryPOS will comply with applicable Indian law and any applicable requirements concerning cross-border transfers.

8. Data Security

BinaryPOS implements reasonable technical and organisational security measures designed to protect personal data against unauthorised access, alteration, disclosure, loss, destruction or other unlawful processing.

Depending on the nature of the information and the risks involved, these measures may include:

  • access controls;
  • authentication and authorisation controls;
  • encryption where appropriate;
  • network and infrastructure security;
  • logging and monitoring;
  • backups and recovery procedures;
  • vulnerability management;
  • employee confidentiality obligations;
  • security testing and assessments; and
  • incident-response procedures.

Access to production systems and customer data is restricted to authorised personnel who require access for legitimate business or support purposes.

No electronic storage or transmission system can be guaranteed to be completely secure. We therefore cannot guarantee absolute security.

9. Personal Data Breaches

BinaryPOS maintains procedures designed to detect, investigate, contain and respond to personal data breaches.

If a personal data breach occurs, BinaryPOS will take reasonable steps to:

  1. identify and contain the incident;
  2. assess the nature and scope of the affected data;
  3. mitigate potential harm;
  4. investigate the cause;
  5. implement appropriate remedial measures; and
  6. provide notifications to the relevant customer, individuals and/or authorities where required by applicable law.

Where BinaryPOS is acting as a Data Processor, we will notify and assist the relevant Data Fiduciary in accordance with the applicable agreement and law.

10. Data Retention

BinaryPOS retains personal data only for as long as reasonably necessary for the purpose for which it is processed, unless a longer period is required or permitted by applicable law, contractual obligations, legitimate business requirements, dispute resolution, security requirements or other lawful purposes.

For certain restaurant records and transaction-related information, BinaryPOS may retain information for a minimum period of seven (7) years where required by the applicable restaurant's requirements, applicable law, accounting requirements, dispute resolution needs, fraud prevention requirements or other legitimate business requirements.

The seven-year retention period does not necessarily apply to every category of personal data.

Where appropriate, different categories of information may be retained for different periods.

When personal data is no longer required, BinaryPOS will take reasonable steps to delete, securely dispose of or anonymise the information, subject to applicable legal, contractual and security requirements.

Where BinaryPOS acts as a Data Processor, retention may be determined by the relevant restaurant's documented instructions and the applicable agreement, subject to applicable law.

11. Your Privacy Rights

Subject to applicable Indian law, individuals may have rights relating to their personal data, including rights to:

  • obtain information about processing of their personal data;
  • request correction of inaccurate or incomplete personal data;
  • request deletion of personal data where permitted by law;
  • withdraw consent where consent is the applicable basis for processing;
  • raise a grievance concerning processing of personal data; and
  • exercise other rights available under applicable law.

Certain rights may be subject to legal exceptions and limitations.

Where BinaryPOS processes personal data on behalf of a restaurant, some requests may need to be addressed to the relevant restaurant as the Data Fiduciary.

12. Privacy Requests

To submit a privacy request concerning personal data processed directly by BinaryPOS, you may contact us using the details provided below.

Where your request relates to information collected by a restaurant and processed through BinaryPOS, please also contact the relevant restaurant.

We may request reasonable information to verify your identity before processing a request.

This is intended to protect personal data from unauthorised access or disclosure.

13. Grievances and Privacy Contact

For privacy-related questions, requests or grievances concerning BinaryPOS's own processing of personal data, please contact:

Privacy / Grievance Officer
BinaryPOS
181/32, Industrial Area, Phase 1
Chandigarh, 160002, India

Email: [INSERT PRIVACY / GRIEVANCE EMAIL]

Telephone: +91 84279 82214

For restaurant customer data processed by BinaryPOS on behalf of a restaurant, individuals may also contact the relevant restaurant directly.

BinaryPOS will provide reasonable assistance in addressing privacy requests and grievances in accordance with applicable law and contractual obligations.

14. Children's Personal Data

BinaryPOS provides business software primarily to restaurants and businesses and does not intentionally design its Services to independently collect children's personal data for purposes unrelated to the restaurant's legitimate operations.

Where a restaurant collects information relating to a child through BinaryPOS, the restaurant is responsible for complying with applicable requirements relating to children's personal data.

BinaryPOS will process such information only as necessary to provide the Services and in accordance with the restaurant's lawful instructions and applicable law.

15. Cookies and Similar Technologies

Our website and applications may use cookies and similar technologies for purposes including:

  • authentication;
  • maintaining sessions;
  • security;
  • remembering preferences;
  • website analytics;
  • performance monitoring;
  • troubleshooting; and
  • improving our Services.

Where required by applicable law, we will provide appropriate information and choices regarding cookies and similar technologies.

16. Third-Party Services

BinaryPOS may integrate with third-party services, including payment, messaging, analytics, security, hosting and other technology providers.

Those providers may process personal data as necessary to provide their services.

Where appropriate, BinaryPOS requires such providers to maintain reasonable security and confidentiality protections.

Third-party services may have their own privacy policies and terms.

17. International Processing

Although BinaryPOS's primary production infrastructure is hosted in AWS Mumbai, India, certain supporting service providers may operate or process information outside India.

International processing will be undertaken in accordance with applicable Indian law.

Where appropriate, BinaryPOS will implement contractual, technical and organisational safeguards designed to protect personal data during such processing.

18. Business Transfers

If BinaryPOS is involved in a merger, acquisition, restructuring, financing, sale of assets or similar corporate transaction, personal data may be transferred as part of that transaction, subject to applicable law.

Where required, appropriate notice or other safeguards will be provided.

19. Legal Compliance

BinaryPOS may process or disclose personal data where reasonably necessary to:

  • comply with applicable law;
  • comply with a lawful order or direction of a court or governmental authority;
  • respond to lawful requests from law-enforcement or regulatory authorities;
  • detect, investigate or prevent fraud;
  • protect the security of our Services;
  • protect the rights, property or safety of BinaryPOS, our customers or other individuals; or
  • establish, exercise or defend legal rights.

20. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in:

  • our Services;
  • our data-processing practices;
  • technology;
  • security practices;
  • applicable laws or regulations; or
  • regulatory requirements.

Where changes are material, we may provide appropriate notice through our website, Services or other reasonable means.

The updated Policy will state its effective date.

21. Applicable Law

This Privacy Policy is governed by applicable laws of India.

Nothing in this Privacy Policy is intended to exclude or limit rights that cannot lawfully be excluded or limited under applicable law.

22. Contact Information

BinaryPOS
181/32, Industrial Area, Phase 1
Chandigarh, India – 160002

Privacy / Grievance Email: info at binarypos dot com

Phone: +91 84279 82214

Last Updated: 12 August 2026

RESTAURANT DATA PROCESSING AGREEMENT