About

A privacy platform authored by the people who have to defend it.

Binary AIQ was built by DPOs, CISOs and privacy counsel who had run compliance programmes on spreadsheets, screenshots and shared drives — and knew that model would not survive the DPDP Act.

What we do

Turn privacy work into an operating system.

The Digital Personal Data Protection Act 2023 asks a regulated Indian enterprise to produce four things on demand: the record of every processing activity, the notice a data principal was shown, the consent that was captured, and the evidence that obligations were met. Binary AIQ produces those four things as a routine output of the way privacy work already happens.

The platform records processing under Section 4, publishes notices under Section 5, captures and withdraws consent under Section 6, answers data-principal rights under Sections 11–14, and notifies incidents under Section 8(6). Each artifact is versioned, attested and reproducible — the audit trail is a by-product of doing the work, not a separate exercise.

We are practitioners first. Every workflow was drafted against a real question a DPO had been asked by a board, a regulator or an auditor. Every screen was reviewed by counsel before it shipped.

What we believe

Four positions that shape every decision.

Compliance is an operating discipline, not a document.

A privacy policy PDF and a spreadsheet of vendors do not withstand a Section 8 enquiry. The record must be live, owned and evidenced. Binary AIQ replaces the document with the workflow that produces it.

Evidence is a first-class object.

Every action — a notice published, a consent withdrawn, a DSR closed, a vendor reviewed — leaves an attested record with actor, timestamp and lineage. Screenshots in a shared drive are not evidence; an attested record is.

The DPO, CISO and CIO must share one source of truth.

Legal writes the record. Security enforces the control. IT operates the system. Binary AIQ is the shared surface where those three roles reconcile — with scope limits so each sees only what their function requires.

Nothing ships that the customer cannot defend.

A generated notice is a draft until legal reviews it. A composed record is a draft until an owner attests it. The platform prompts and drafts; the accountable person decides.

Company facts

Stated plainly.

Registered as
Binary AIQ Technologies Private Limited
Founded
2024
Headquartered
Bengaluru, India
Primary data residency
Mumbai (ap-south-1)
Regulatory posture
Aligned to the DPDP Act 2023 and the draft DPDP Rules. Controls mapped to ISO 27001 and ISO 27701. SOC 2 Type II in progress.
Team composition
Product, engineering, security and privacy counsel. Every workflow reviewed by qualified privacy counsel before release.
Reachable at
hello@binaryaiq.com · security@binaryaiq.com · privacy@binaryaiq.com
Governance

Who is accountable for what.

Data Protection Officer

Owns the record of processing for Binary AIQ itself, the grievance channel and data-principal responses. Reachable at privacy@binaryaiq.com.

Head of Security

Owns the control library, sub-processor register, incident response and independent testing. Reachable at security@binaryaiq.com.

Legal counsel

Reviews every regulatory artifact — templates, notices, DPA clauses — before it is made available to customers. Reachable at legal@binaryaiq.com.