Skip to main content
privacy-policyLast Updated: June 2, 2026
Legal

Privacy Policy

Download PDF

Working draft. A few company-specific details are still to be confirmed. They appear below as highlighted input needed fill-ins, and must be completed before this document is published.

1. Who we are and what this policy covers

Ternary Solutions, Inc. ("Ternary", "we", "us") designs, builds and operates custom software for client organisations. Our operating office is in Dhaka, Bangladesh. input neededstate or country of incorporation, and the registered address to publish here.

This policy explains how we handle personal information when you visit our website, contact us, apply for a role with us, or deal with us as a client, supplier or partner.

It does not describe how we handle personal data inside software we build and run on behalf of a client. In those engagements the client decides what data is collected and why, and we act only on their instructions. Section 3 explains that distinction, and section 12 tells you who to contact instead.

2. Contacting us about privacy

Questions, requests and complaints about this policy or about personal data we hold should go to input neededprivacy contact address to publish — privacy@ternary.solutions?. We aim to acknowledge within five business days.

3. Two different roles: controller and processor

We handle personal data in two distinct capacities, and your rights differ depending on which applies.

As a controller. For our own website visitors, enquirers, job applicants, employees, client contacts and supplier contacts, we decide why and how the data is used. This policy governs that data, and you can exercise the rights in section 9 directly with us.

As a processor. When we build or operate a product for a client, personal data belonging to that client's users is processed strictly on the client's documented instructions under a written agreement. The client is the controller. We do not use that data for our own purposes, do not sell it, and do not use it to train models. If you are a user of a client's product and want to exercise a right over your data, contact that organisation; if you approach us, we will pass your request to them and support their response.

4. Information we collect as a controller

CategoryWhat it includesWhere it comes from
Enquiry and contact dataName, email address, organisation, message contentYou, via our website form or by emailing us
Client and supplier contact dataNames, business email addresses, telephone numbers, job titlesYou or your organisation, in the course of an engagement
Recruitment dataCV, work history, education, portfolio or code samples, interview notes and assessment scores, referencesYou, and referees you nominate
Employee and contractor dataIdentity and contact details, contract and payroll data, training and policy acknowledgement records, access and equipment recordsYou, during onboarding and employment
Technical and usage dataIP address, browser and device type, pages viewed, referring page, approximate location derived from IPAutomatically, when you use our website
Support and correspondenceEmail threads, meeting notes, tickets you raiseYou
Security and access logsAuthentication events, administrative actions, timestamps and source addressesAutomatically, from our systems

We do not deliberately collect special category data about website visitors or enquirers. Please do not send us health, biometric, religious, political or similar information through our contact form.

PurposeLegal basis
Responding to your enquiryLegitimate interests, or steps prior to entering a contract
Delivering services and managing an engagementPerformance of a contract
Invoicing, accounting and tax recordsLegal obligation, and performance of a contract
Assessing candidates and making hiring decisionsSteps prior to entering a contract, and legitimate interests
Employing and paying staffPerformance of a contract, and legal obligation
Operating, securing and troubleshooting our systemsLegitimate interests, and legal obligation where security law applies
Meeting our information security and audit obligationsLegitimate interests, and legal obligation
Sending occasional updates about our workConsent, which you may withdraw at any time

Where we rely on legitimate interests, we have considered whether our interest is overridden by your rights, and we will explain that assessment on request.

6. Cookies and analytics

Our website uses cookies and similar technologies that are strictly necessary to serve the site, and input neededwhich analytics product, if any, is deployed on ternary.solutions — and whether a consent banner is required for the jurisdictions the site serves. Strictly necessary cookies cannot be disabled without breaking the site. You can block or delete other cookies through your browser settings.

7. Who we share it with

We do not sell personal data, and we do not share it for third-party advertising.

We share it with service providers who process it on our behalf under contract. Our principal providers are:

ProviderPurposePrimary data location
Amazon Web ServicesCloud hosting, storage and email deliveryap-southeast-1 (Singapore)
Google WorkspaceEmail, calendar, document storageGoogle global infrastructure
Atlassian (Jira, Confluence)Project tracking and internal documentationAtlassian cloud
VercelFront-end hostingVercel global edge
Supabase, NeonManaged PostgreSQLPer-project region
SentryApplication error monitoringSentry cloud
SlackInternal communicationSlack cloud
VantaSecurity compliance monitoringVanta cloud

We also disclose personal data to professional advisers, and to a regulator, court or law enforcement body where we are legally required to. If we are ever party to a merger or acquisition, data may transfer as part of that transaction, and we will notify affected individuals.

8. International transfers

We operate from Bangladesh and use providers whose infrastructure sits outside it, principally in Singapore, the European Union and the United States. Where we transfer personal data originating in the United Kingdom or European Economic Area, we rely on the transfer mechanism specified in our agreement with the relevant provider or client. input neededthe default transfer mechanism to state publicly — standard contractual clauses, or client-specified terms.

9. Your rights

Subject to the law that applies to you, you may ask us to:

  • confirm whether we hold personal data about you, and give you a copy;
  • correct data that is inaccurate or incomplete;
  • delete data where we no longer have grounds to keep it;
  • restrict or object to a particular use, including any use based on legitimate interests;
  • provide your data in a portable, machine-readable format;
  • withdraw consent you previously gave, without affecting what we did before you withdrew it.

We will not charge for a request unless it is manifestly unfounded or excessive. We may ask you to verify your identity before we act, and we will respond within the period the applicable law requires. If we decline a request we will explain why. You may also complain to your data protection authority.

10. How long we keep it

DataRetention
Website enquiries with no engagementinput needed12 or 24 months?
Unsuccessful candidate recordsinput neededretention period, and whether consent is taken to hold candidates in a talent pool
Client engagement and project recordsinput neededcommonly 6 or 7 years after closure, for contractual limitation — confirm the period
Employment and payroll recordsinput neededstatutory minimum under Bangladesh labour and tax law
Financial and tax recordsinput neededstatutory minimum
Security and access logsRetained for the period the generating system provides; AWS control-plane events are presently available for 90 days

When a retention period ends we delete the data or irreversibly anonymise it. Copies held in backup media are protected by the same confidentiality obligations until they expire on the normal backup cycle.

11. How we protect it

We run an information security management system aligned to ISO 27001:2022 and SOC 2, monitored continuously in Vanta. Access to systems holding personal data is restricted to named individuals, granted on least privilege, and protected by multi-factor authentication. Data is encrypted in transit and at rest. Staff are bound by confidentiality agreements and receive security awareness training. We maintain an incident response process and will notify affected individuals and regulators where the law requires and within the applicable deadline.

No system is perfectly secure, and we do not claim otherwise. Our security whitepaper describes our controls in more detail and is available on request.

12. Data in products we build for clients

If you are a user of a product Ternary built or operates for another organisation, that organisation is the controller and its own privacy notice governs your data. Please direct requests to them. If you contact us instead, we will forward your request to the client without undue delay and tell you that we have done so.

13. Children

Our website and our business services are directed at organisations, not children, and we do not knowingly collect personal data from anyone under input neededage threshold appropriate to the jurisdictions served — commonly 16 or 18. If you believe a child has given us personal data, contact us and we will delete it.

14. Changes to this policy

We review this policy at least annually and whenever our processing changes materially. The effective date above shows the current version. Where a change materially affects your rights we will take reasonable steps to notify you directly.

15. Contact

Ternary Solutions, Inc.

input neededregistered address and operating office address to publish

Privacy contact: input neededprivacy contact address

Questions about privacy?

We are committed to protecting your data. Reach out if you have any questions or wish to exercise your privacy rights.