Introduction
Bidovate ("we," "us," or "our"), is committed to protecting the privacy and security of your personal information. This Privacy Policy describes how we collect, use, disclose, and safeguard your data when you use our AI-powered procurement intelligence platform and related services (the "Service").
By accessing or using the Service, you consent to the practices described in this policy. If you do not agree, please discontinue use of the Service immediately.
Information We Collect
Information You Provide Directly
- Account registration details: name, email address, job title, organization name
- Billing and payment information (processed by our PCI-DSS-compliant payment processor)
- Support requests, feedback, and correspondence
- Uploaded documents and procurement data you choose to analyze through the platform
Information Collected Automatically
- Log data: IP address (anonymized), browser type, operating system, referring URL
- Usage data: features used, pages viewed, timestamps, session duration
- Device identifiers (anonymized)
Information We Do NOT Collect
- We do not purchase or obtain personal data from third-party data brokers
- We do not collect biometric data
How We Use Your Information
We use your information exclusively for the following purposes:
- Providing, maintaining, and improving the Service
- Processing transactions and sending related information
- Responding to support requests and customer service inquiries
- Sending administrative notifications (service updates, security alerts)
- Analyzing usage patterns in aggregate to improve product experience
- Complying with legal obligations
Zero Model Training Guarantee: Your data is never used to train, fine-tune, or improve any AI or machine learning models. Your procurement data remains yours exclusively.
Data Security
We maintain industry-leading security standards:
- SOC 2 Type II certified: independently audited controls for security, availability, and confidentiality
- ISO 27001 certified: information security management system
- AES-256 encryption at rest and TLS 1.3 encryption in transit
- Role-based access controls and multi-factor authentication
- Regular penetration testing and vulnerability assessments
- On-premise deployment option available for organizations with strict data residency requirements
Data Sharing and Disclosure
We do not sell your personal information to third parties. We share data only in the following limited circumstances:
- Service providers: Trusted vendors who assist in operating our platform (hosting, payment processing, analytics), bound by contractual confidentiality obligations
- Legal compliance: When required by law, subpoena, court order, or government request
- Business transfers: In connection with a merger, acquisition, or sale of assets, with advance notice to you
- With your consent: When you explicitly authorize sharing
CCPA Compliance (California Residents)
If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA):
- Right to Know: Request disclosure of the categories and specific pieces of personal information we have collected
- Right to Delete: Request deletion of your personal information, subject to certain exceptions
- Right to Correct: Request correction of inaccurate personal information
- Right to Opt-Out of Sale: We do not sell personal information; no opt-out is necessary
- Right to Non-Discrimination: We will not discriminate against you for exercising your rights
To exercise these rights, contact us at support@bidovate.co. We will respond within 45 days. You may also designate an authorized agent to make requests on your behalf.
Data Retention and Deletion
We retain your personal information only as long as necessary to fulfill the purposes described in this policy or as required by law. You may request deletion of your account and associated data at any time by contacting support@bidovate.co. Upon receiving a verified deletion request, we will delete your data within 30 days, except where retention is required by law.
Children's Privacy
The Service is not directed to individuals under the age of 16. We do not knowingly collect personal information from children. If we become aware that we have collected data from a child, we will promptly delete it.
Changes to This Policy
We may update this Privacy Policy periodically. We will notify you of material changes by posting the revised policy on our website and updating the "Last Updated" date. Continued use of the Service after changes constitutes acceptance.
Contact Us
For privacy-related inquiries, data deletion requests, or complaints:
Email: support@bidovate.co
Entity: Bidovate