BidLyft
Log inRequest a demo

Privacy Policy

Effective 12 August 2026

BidLyft is bid and tender analysis software. This policy explains what personal data we handle, why we handle it, and what you can ask of us.

1. The two roles we play

Who decidesOur roleExamples
Account & business dataWe doControllerYour name, work email, login records, billing details, demo requests, support correspondence
Customer ContentYou doProcessorTender and RFP documents you upload, your proposal drafts, your answer library, and anything our AI derives from them

For Customer Content we act only on your documented instructions. We do not decide what you upload, we do not use it for our own purposes, and we do not sell or share it. Where you are an EU or UK controller, our Data Processing Agreement governs that data and is available on request.

2. What we collect

You give us:

  • Account data name, work email, password (stored only as a secure hash, never in plain text), role, team membership, job title.
  • Demo and enquiry data name, email, phone, company, designation, team size, tender volume, and anything you write in the message field.
  • Customer Content the tender documents, questionnaires, proposals and knowledge-base material you upload, and the content your team authors in the product.
  • Billing data where paid plans apply, our payment processor handles card details. We never see or store full card numbers.

We generate or observe:

  • Usage and audit records logins, actions taken in the workspace, records of who viewed or changed what, and AI usage metering.
  • Technical data IP address, browser and device type, timestamps, and error diagnostics.

We do not collect special-category data (health, biometrics, religion, political opinion), and you should not upload it. The service is intended for business users and is not directed at anyone under 18.

3. Why we process it, and on what legal basis

PurposeDataLegal basis (GDPR)
Provide the service, host and analyse your documentsAccount data, Customer ContentContract (Art. 6(1)(b))
Authenticate users, prevent unauthorised accessAccount data, technical dataContract; legitimate interests
Security monitoring, audit trails, abuse preventionUsage, audit, technical dataLegitimate interests (Art. 6(1)(f))
Support and correspondenceAccount data, your messagesContract; legitimate interests
Respond to a demo requestDemo dataConsent; steps before a contract
Improve reliability and performanceAggregated, non-identifying usage dataLegitimate interests
Billing, tax and statutory recordsBilling dataContract; legal obligation
Marketing email to business contactsName, work emailConsent, or legitimate interests where permitted — withdrawable at any time

Where we rely on legitimate interests we have balanced them against your rights, and we will share that assessment on request.

4. AI processing

Because this is the question every bid team asks first:

  • We do not train, fine-tune or evaluate any model on your Customer Content. Not our own models, and not our providers' — their terms prohibit it. This is a standing commitment, not a default setting: there is no toggle and no “improve the product” opt-out buried in your account.
  • We do not use your Customer Content to improve the service for other customers. No part of your tender data, pricing or proposal text becomes another customer's answer.
  • Your content is isolated per team. Retrieval and generation are scoped to your team's data only.
  • To produce analysis, extracts of your documents are processed by enterprise AI services under contracts that prohibit training and require the data to be used solely to return our result.
  • AI output is decision support, not advice. Eligibility findings, risk flags, Go/No-Go signals and drafted text are there to be checked — every material output is traceable to its source clause. You remain responsible for what you submit.
  • We do not make decisions producing legal or similarly significant effects about you by automated means alone.

5. Who we share it with

We do not sell personal data. We share it only with service providers who process it on our instructions under written contracts:

CategoryPurposeData
Cloud infrastructureHosting, database, file storage, backupsAll hosted data
AI processing servicesDocument analysis, extraction and generationExtracts of Customer Content
Identity providerOptional single sign-onEmail, name, profile image
Email deliveryTransactional and notification emailName, email, message content
Payment processorBilling for paid plansBilling data

Our current sub-processor list, naming each provider, is available on request. We give 30 days' notice before adding a new sub-processor that handles Customer Content, so you can object.

We also disclose data where the law requires it — a valid court order or lawful government request. Where we are permitted to, we will tell you first. If the business is acquired or merged, data transfers with it and this policy continues to apply until replaced on notice.

6. Where your data lives

Your data is stored in India.Our infrastructure runs on Amazon Web Services in the Asia Pacific (Mumbai) region. The database, your uploaded tender documents, the search indexes built from them, and all backups are held there.

We chose this deliberately: Indian public-sector and PSU tenders increasingly require it, and your bid documents are commercially sensitive in a market where competitors are often bidding the same tender.

If a specific tender or internal policy imposes additional residency or processing requirements, tell us before you upload and we will confirm in writing what we can meet.

If you are in the EU or UK: transfers of personal data to India are made under Standard Contractual Clauses and the UK International Data Transfer Addendum, which form part of our Data Processing Agreement.

7. How long we keep it

DataRetention
Customer ContentFor the life of your account. Deleted within 30 days of account closure or of your written deletion request
Account dataLife of the account, then 30 days
Audit and security logs24 months
Demo and enquiry data24 months from last contact, unless you ask sooner
Billing and tax records8 years, as Indian tax law requires
BackupsRolling 30-day cycle; deleted data ages out within that window
What deletion means here.Within 30 days we remove your records from the database, delete your uploaded files from storage, and purge the search embeddings derived from your documents. Deleted data then ages out of encrypted backups within the backup cycle above. We keep no shadow copy, and nothing derived from your content survives in a form usable by another customer.

You can export your Customer Content at any time before deletion. Once deleted, we cannot recover it.

8. How we protect it

  • Encryption in transit (TLS 1.2+) and at rest (AES-256).
  • Passwords stored only as secure hashes; session-based authentication.
  • Role-based access control within each team, with strict tenant isolation between teams.
  • Audit logging of security-relevant actions, retained and exportable.
  • Least-privilege administrative access, limited to named personnel.
  • Regular patching, monitoring and backups.
  • Confidentiality obligations on everyone with access.
Certifications.Our controls are built to align with ISO 27001 and SOC 2 practice — access control, audit logging, encryption, sub-processor governance, retention discipline and incident response — and formal certification is underway. We will state the date and scope here once certified. If your procurement process needs evidence now, write to us and we will complete your security questionnaire.

If a breach affects your personal data, we will notify the relevant authority within 72 hours where the law requires, and tell affected customers without undue delay.

9. Your rights

Wherever you are, you can ask us to access a copy of your data, correct it, delete it, export it in a portable format, restrict or object to processing, or withdraw consent (which does not undo processing already carried out).

  • India (DPDP Act, 2023) the rights above, plus the right to nominate someone to exercise them on your behalf, and access to our grievance-redressal process.
  • EU/UK (GDPR) the rights above, plus the right to complain to your supervisory authority.
  • California (CCPA/CPRA) rights to know, delete, correct and opt out. We do not sell or share personal information as those terms are defined, and we do not process it for cross-context behavioural advertising.

Write to engineering@bidlyft.com. We respond within 30 days and acknowledge grievances within 7 days. We will not charge you or treat you differently for exercising a right. If you use BidLyft through your employer's workspace, ask them first — for Customer Content we act on their instructions, and we will refer your request to them.

10. Cookies

We use only what the site needs to work: a session cookie to keep you signed in, and a security cookie to prevent request forgery. We do not run advertising or cross-site tracking cookies. If we add analytics, we will update this policy and, where consent is required, ask for it before setting anything non-essential.

11. Changes

We will post any change here with a new effective date. For material changes we will give notice by email or in-product before they take effect.

12. Contact

Privacy queries and rights requestsengineering@bidlyft.com
Grievance Officer (India, DPDP Act)engineering@bidlyft.com
Security disclosureengineering@bidlyft.com

If you are in India and remain unsatisfied after our Grievance Officer has responded, you may escalate to the Data Protection Board of India. If you are in the EU or UK, you may complain to your national data protection authority.