Privacy Policy
Effective 12 August 2026
BidLyft is bid and tender analysis software. This policy explains what personal data we handle, why we handle it, and what you can ask of us.
1. The two roles we play
| Who decides | Our role | Examples | |
|---|---|---|---|
| Account & business data | We do | Controller | Your name, work email, login records, billing details, demo requests, support correspondence |
| Customer Content | You do | Processor | Tender and RFP documents you upload, your proposal drafts, your answer library, and anything our AI derives from them |
For Customer Content we act only on your documented instructions. We do not decide what you upload, we do not use it for our own purposes, and we do not sell or share it. Where you are an EU or UK controller, our Data Processing Agreement governs that data and is available on request.
2. What we collect
You give us:
- Account data — name, work email, password (stored only as a secure hash, never in plain text), role, team membership, job title.
- Demo and enquiry data — name, email, phone, company, designation, team size, tender volume, and anything you write in the message field.
- Customer Content — the tender documents, questionnaires, proposals and knowledge-base material you upload, and the content your team authors in the product.
- Billing data — where paid plans apply, our payment processor handles card details. We never see or store full card numbers.
We generate or observe:
- Usage and audit records — logins, actions taken in the workspace, records of who viewed or changed what, and AI usage metering.
- Technical data — IP address, browser and device type, timestamps, and error diagnostics.
We do not collect special-category data (health, biometrics, religion, political opinion), and you should not upload it. The service is intended for business users and is not directed at anyone under 18.
3. Why we process it, and on what legal basis
| Purpose | Data | Legal basis (GDPR) |
|---|---|---|
| Provide the service, host and analyse your documents | Account data, Customer Content | Contract (Art. 6(1)(b)) |
| Authenticate users, prevent unauthorised access | Account data, technical data | Contract; legitimate interests |
| Security monitoring, audit trails, abuse prevention | Usage, audit, technical data | Legitimate interests (Art. 6(1)(f)) |
| Support and correspondence | Account data, your messages | Contract; legitimate interests |
| Respond to a demo request | Demo data | Consent; steps before a contract |
| Improve reliability and performance | Aggregated, non-identifying usage data | Legitimate interests |
| Billing, tax and statutory records | Billing data | Contract; legal obligation |
| Marketing email to business contacts | Name, work email | Consent, or legitimate interests where permitted — withdrawable at any time |
Where we rely on legitimate interests we have balanced them against your rights, and we will share that assessment on request.
4. AI processing
Because this is the question every bid team asks first:
- We do not train, fine-tune or evaluate any model on your Customer Content. Not our own models, and not our providers' — their terms prohibit it. This is a standing commitment, not a default setting: there is no toggle and no “improve the product” opt-out buried in your account.
- We do not use your Customer Content to improve the service for other customers. No part of your tender data, pricing or proposal text becomes another customer's answer.
- Your content is isolated per team. Retrieval and generation are scoped to your team's data only.
- To produce analysis, extracts of your documents are processed by enterprise AI services under contracts that prohibit training and require the data to be used solely to return our result.
- AI output is decision support, not advice. Eligibility findings, risk flags, Go/No-Go signals and drafted text are there to be checked — every material output is traceable to its source clause. You remain responsible for what you submit.
- We do not make decisions producing legal or similarly significant effects about you by automated means alone.
6. Where your data lives
We chose this deliberately: Indian public-sector and PSU tenders increasingly require it, and your bid documents are commercially sensitive in a market where competitors are often bidding the same tender.
If a specific tender or internal policy imposes additional residency or processing requirements, tell us before you upload and we will confirm in writing what we can meet.
If you are in the EU or UK: transfers of personal data to India are made under Standard Contractual Clauses and the UK International Data Transfer Addendum, which form part of our Data Processing Agreement.
7. How long we keep it
| Data | Retention |
|---|---|
| Customer Content | For the life of your account. Deleted within 30 days of account closure or of your written deletion request |
| Account data | Life of the account, then 30 days |
| Audit and security logs | 24 months |
| Demo and enquiry data | 24 months from last contact, unless you ask sooner |
| Billing and tax records | 8 years, as Indian tax law requires |
| Backups | Rolling 30-day cycle; deleted data ages out within that window |
You can export your Customer Content at any time before deletion. Once deleted, we cannot recover it.
8. How we protect it
- Encryption in transit (TLS 1.2+) and at rest (AES-256).
- Passwords stored only as secure hashes; session-based authentication.
- Role-based access control within each team, with strict tenant isolation between teams.
- Audit logging of security-relevant actions, retained and exportable.
- Least-privilege administrative access, limited to named personnel.
- Regular patching, monitoring and backups.
- Confidentiality obligations on everyone with access.
If a breach affects your personal data, we will notify the relevant authority within 72 hours where the law requires, and tell affected customers without undue delay.
9. Your rights
Wherever you are, you can ask us to access a copy of your data, correct it, delete it, export it in a portable format, restrict or object to processing, or withdraw consent (which does not undo processing already carried out).
- India (DPDP Act, 2023) — the rights above, plus the right to nominate someone to exercise them on your behalf, and access to our grievance-redressal process.
- EU/UK (GDPR) — the rights above, plus the right to complain to your supervisory authority.
- California (CCPA/CPRA) — rights to know, delete, correct and opt out. We do not sell or share personal information as those terms are defined, and we do not process it for cross-context behavioural advertising.
Write to engineering@bidlyft.com. We respond within 30 days and acknowledge grievances within 7 days. We will not charge you or treat you differently for exercising a right. If you use BidLyft through your employer's workspace, ask them first — for Customer Content we act on their instructions, and we will refer your request to them.
11. Changes
We will post any change here with a new effective date. For material changes we will give notice by email or in-product before they take effect.
12. Contact
| Privacy queries and rights requests | engineering@bidlyft.com |
| Grievance Officer (India, DPDP Act) | engineering@bidlyft.com |
| Security disclosure | engineering@bidlyft.com |
If you are in India and remain unsatisfied after our Grievance Officer has responded, you may escalate to the Data Protection Board of India. If you are in the EU or UK, you may complain to your national data protection authority.