1. Who we are and what this policy covers
Ternary Solutions, Inc. ("Ternary", "we", "us") designs, builds and operates custom software for client organisations. Our operating office is in Dhaka, Bangladesh. input neededstate or country of incorporation, and the registered address to publish here.
This policy explains how we handle personal information when you visit our website, contact us, apply for a role with us, or deal with us as a client, supplier or partner.
It does not describe how we handle personal data inside software we build and run on behalf of a client. In those engagements the client decides what data is collected and why, and we act only on their instructions. Section 3 explains that distinction, and section 12 tells you who to contact instead.
2. Contacting us about privacy
Questions, requests and complaints about this policy or about personal data we hold should go to input neededprivacy contact address to publish — privacy@ternary.solutions?. We aim to acknowledge within five business days.
3. Two different roles: controller and processor
We handle personal data in two distinct capacities, and your rights differ depending on which applies.
As a controller. For our own website visitors, enquirers, job applicants, employees, client contacts and supplier contacts, we decide why and how the data is used. This policy governs that data, and you can exercise the rights in section 9 directly with us.
As a processor. When we build or operate a product for a client, personal data belonging to that client's users is processed strictly on the client's documented instructions under a written agreement. The client is the controller. We do not use that data for our own purposes, do not sell it, and do not use it to train models. If you are a user of a client's product and want to exercise a right over your data, contact that organisation; if you approach us, we will pass your request to them and support their response.
4. Information we collect as a controller
| Category | What it includes | Where it comes from |
|---|---|---|
| Enquiry and contact data | Name, email address, organisation, message content | You, via our website form or by emailing us |
| Client and supplier contact data | Names, business email addresses, telephone numbers, job titles | You or your organisation, in the course of an engagement |
| Recruitment data | CV, work history, education, portfolio or code samples, interview notes and assessment scores, references | You, and referees you nominate |
| Employee and contractor data | Identity and contact details, contract and payroll data, training and policy acknowledgement records, access and equipment records | You, during onboarding and employment |
| Technical and usage data | IP address, browser and device type, pages viewed, referring page, approximate location derived from IP | Automatically, when you use our website |
| Support and correspondence | Email threads, meeting notes, tickets you raise | You |
| Security and access logs | Authentication events, administrative actions, timestamps and source addresses | Automatically, from our systems |
We do not deliberately collect special category data about website visitors or enquirers. Please do not send us health, biometric, religious, political or similar information through our contact form.
5. Why we use it, and our legal basis
| Purpose | Legal basis |
|---|---|
| Responding to your enquiry | Legitimate interests, or steps prior to entering a contract |
| Delivering services and managing an engagement | Performance of a contract |
| Invoicing, accounting and tax records | Legal obligation, and performance of a contract |
| Assessing candidates and making hiring decisions | Steps prior to entering a contract, and legitimate interests |
| Employing and paying staff | Performance of a contract, and legal obligation |
| Operating, securing and troubleshooting our systems | Legitimate interests, and legal obligation where security law applies |
| Meeting our information security and audit obligations | Legitimate interests, and legal obligation |
| Sending occasional updates about our work | Consent, which you may withdraw at any time |
Where we rely on legitimate interests, we have considered whether our interest is overridden by your rights, and we will explain that assessment on request.
6. Cookies and analytics
Our website uses cookies and similar technologies that are strictly necessary to serve the site, and input neededwhich analytics product, if any, is deployed on ternary.solutions — and whether a consent banner is required for the jurisdictions the site serves. Strictly necessary cookies cannot be disabled without breaking the site. You can block or delete other cookies through your browser settings.
7. Who we share it with
We do not sell personal data, and we do not share it for third-party advertising.
We share it with service providers who process it on our behalf under contract. Our principal providers are:
| Provider | Purpose | Primary data location |
|---|---|---|
| Amazon Web Services | Cloud hosting, storage and email delivery | ap-southeast-1 (Singapore) |
| Google Workspace | Email, calendar, document storage | Google global infrastructure |
| Atlassian (Jira, Confluence) | Project tracking and internal documentation | Atlassian cloud |
| Vercel | Front-end hosting | Vercel global edge |
| Supabase, Neon | Managed PostgreSQL | Per-project region |
| Sentry | Application error monitoring | Sentry cloud |
| Slack | Internal communication | Slack cloud |
| Vanta | Security compliance monitoring | Vanta cloud |
We also disclose personal data to professional advisers, and to a regulator, court or law enforcement body where we are legally required to. If we are ever party to a merger or acquisition, data may transfer as part of that transaction, and we will notify affected individuals.
8. International transfers
We operate from Bangladesh and use providers whose infrastructure sits outside it, principally in Singapore, the European Union and the United States. Where we transfer personal data originating in the United Kingdom or European Economic Area, we rely on the transfer mechanism specified in our agreement with the relevant provider or client. input neededthe default transfer mechanism to state publicly — standard contractual clauses, or client-specified terms.
9. Your rights
Subject to the law that applies to you, you may ask us to:
- confirm whether we hold personal data about you, and give you a copy;
- correct data that is inaccurate or incomplete;
- delete data where we no longer have grounds to keep it;
- restrict or object to a particular use, including any use based on legitimate interests;
- provide your data in a portable, machine-readable format;
- withdraw consent you previously gave, without affecting what we did before you withdrew it.
We will not charge for a request unless it is manifestly unfounded or excessive. We may ask you to verify your identity before we act, and we will respond within the period the applicable law requires. If we decline a request we will explain why. You may also complain to your data protection authority.
10. How long we keep it
| Data | Retention |
|---|---|
| Website enquiries with no engagement | input needed12 or 24 months? |
| Unsuccessful candidate records | input neededretention period, and whether consent is taken to hold candidates in a talent pool |
| Client engagement and project records | input neededcommonly 6 or 7 years after closure, for contractual limitation — confirm the period |
| Employment and payroll records | input neededstatutory minimum under Bangladesh labour and tax law |
| Financial and tax records | input neededstatutory minimum |
| Security and access logs | Retained for the period the generating system provides; AWS control-plane events are presently available for 90 days |
When a retention period ends we delete the data or irreversibly anonymise it. Copies held in backup media are protected by the same confidentiality obligations until they expire on the normal backup cycle.
11. How we protect it
We run an information security management system aligned to ISO 27001:2022 and SOC 2, monitored continuously in Vanta. Access to systems holding personal data is restricted to named individuals, granted on least privilege, and protected by multi-factor authentication. Data is encrypted in transit and at rest. Staff are bound by confidentiality agreements and receive security awareness training. We maintain an incident response process and will notify affected individuals and regulators where the law requires and within the applicable deadline.
No system is perfectly secure, and we do not claim otherwise. Our security whitepaper describes our controls in more detail and is available on request.
12. Data in products we build for clients
If you are a user of a product Ternary built or operates for another organisation, that organisation is the controller and its own privacy notice governs your data. Please direct requests to them. If you contact us instead, we will forward your request to the client without undue delay and tell you that we have done so.
13. Children
Our website and our business services are directed at organisations, not children, and we do not knowingly collect personal data from anyone under input neededage threshold appropriate to the jurisdictions served — commonly 16 or 18. If you believe a child has given us personal data, contact us and we will delete it.
14. Changes to this policy
We review this policy at least annually and whenever our processing changes materially. The effective date above shows the current version. Where a change materially affects your rights we will take reasonable steps to notify you directly.
15. Contact
Ternary Solutions, Inc.
input neededregistered address and operating office address to publish
Privacy contact: input neededprivacy contact address