cmdz
ProductThe limitMCPPricingRegionsDocs How it works Build with an agent Security Our hardware Blog About Start free trial Log in

For the data that you process inside your own applications we act as processor, and the data processing agreement applies to that. This policy covers our own business operations: accounts, billing and this website.

1. Data controller

Binadit B.V., established in Rotterdam, KvK 80923216, VAT NL861852990B01 is responsible for the processing of personal data described in this policy. Questions: [email protected].

2. What data we process

  • Account: name, company name, email address, and the metadata of your passkeys — never key material. We do not store passwords, because logging in is exclusively with passkeys.
  • Billing: VAT number, address, payment-method references via Mollie (we do not store full card details), and invoices via WeFact.
  • Usage: the technical and consumption data required to provide, meter and secure the Services.
  • Website: minimal, cookieless and EU-hosted usage statistics. No American trackers.
  • Communication: email and support correspondence.
  • Performance of the agreement (art. 6(1)(b) GDPR): providing the Services.
  • Legitimate interest (art. 6(1)(f) GDPR): security, fraud prevention and improvement.
  • Legal obligation (art. 6(1)(c) GDPR): tax retention obligation.
  • Consent (art. 6(1)(a) GDPR): any commercial communication.

4. Retention periods

  • Account data: for the duration of the term and up to 6 months after termination, subject to statutory retention obligations.
  • Billing data: 7 years, under the tax retention obligation.
  • Runtime logs: 7 days. Build logs: 90 days.
  • Website statistics: aggregated, up to 14 months.

5. Recipients and subprocessors

  • Mollie B.V. (Amsterdam) — payment processing and mandates.
  • WeFact B.V. — billing.
  • Hosting Concepts B.V. / Openprovider — domain registration.
  • Cloudflare — only if you enable Cloudflare DNS or proxy for your own domain.
  • Transactional email provider — outgoing email from the platform.
  • Our own infrastructure — hardware in the data center and region you choose.

We do not provide personal data to countries outside the EEA, unless appropriate safeguards under Chapter V GDPR have been put in place, or you yourself choose a region outside the EEA.

6. Your rights

You have the right to access, rectification, erasure, restriction, data portability and objection (art. 15–21 GDPR). Requests go to [email protected] and we respond within 30 days. You can file a complaint with the Dutch Data Protection Authority at autoriteitpersoonsgegevens.nl.

7. Cookies

This marketing site is as cookie-free as we can make it: the only thing stored in your browser is your light or dark theme preference, and that is functional. There are no tracking cookies and no advertising cookies. The portal uses exclusively functional session cookies.

8. Security

We take appropriate technical and organizational measures: encryption in transit (TLS) and at rest (LUKS2), access based on least privilege, passkeys instead of passwords, isolation of customer workloads in micro-VMs, and regular audits. The security page describes this in plain language.

9. Amendments and contact

We may update this policy; changes are published on this page with a new date.


Binadit B.V. · Seinhuiswachter 2, 3034 KH Rotterdam · Netherlands · [email protected] · +31 10 477 5362