Privacy Notice
This Privacy Notice explains what data Bid.Guide collects, why we collect it, how we store and protect it, who else processes it, and the rights you can exercise. It applies to bidders (firms and the individuals they nominate), tender issuers (government entities, GREs, primes), and visitors to bid.guide.
1. Who we are
Tender Guide (operating Bid.Guide) is the controller of personal data you provide to us as a customer-facing account holder. For data you provide as a bidder to a tender issued by a third-party buyer, we are the processor and that buyer is the controller. Registered office in Dubai, UAE. Local representative in Saudi Arabia per Article 29 of the Saudi PDPL.
Data Protection Officer: dpo@bid.guide
2. What data we collect
From bidders (firm + nominated individuals)
- Firm: legal name (EN/AR), home country, HQ city, year founded, commercial registration, website, sectors, capabilities, classifications, certifications (with expiry), local-content scores (IKTVA, ICV, Tawteen, Oman ICV), bonding capacity, staff band, revenue band.
- Primary contact: name, role, work email, mobile (optional, for deadline alerts), LinkedIn (optional, for verification).
- Documents you upload: certificates, project references, financials, technical materials, bid bonds.
- Submission metadata: IP address at submit, user agent, SHA-256 hashes of every file, tamper-evident timestamps.
- Consent records: each consent checkbox you tick, UTC timestamp, version of this notice you saw.
From tender issuers
- Organisation name, team roster, evaluation criteria, tender content, audit-trail entries you generate.
From everyone
- Authentication tokens (hashed at rest), session metadata, log data for security & abuse prevention.
3. Lawful basis for each purpose
| Purpose | Lawful basis | Where collected |
|---|---|---|
| Match you to tenders, run the platform | Contract (Art. 6(1)(b) GDPR · Art. 5(2) Saudi PDPL) | Required at registration |
| Verify your identity / firm (KYC) | Legal obligation + legitimate interest (procurement integrity) | Required at registration |
| Show your profile in the public directory | Explicit consent · withdrawable in dashboard | Optional consent |
| Share your profile with verified GCC buyers | Explicit consent · withdrawable | Optional consent |
| Send tender alerts (email, push, WhatsApp) | Explicit consent · withdrawable | Optional consent |
| Process your tender submission on behalf of a buyer | Contract between you and the buyer (we are processor) | Triggered when you accept an invite or submit a bid |
| Security, fraud prevention, abuse | Legitimate interest + legal obligation | Always |
| Comply with KSA Government Tenders & Procurement Law (10-year record retention) | Legal obligation | For bids you submit into KSA tenders |
4. Where data comes from
Directly from you when you register, accept an invite, submit a bid, or interact with the platform. Indirectly from an issuer when they invite you (firm name + email). Where you explicitly authorise it, from public registries (e.g. KSA MoCI for CR verification) and from official local-content programs (e.g. Aramco IKTVA portal) for verification.
6. International transfers
Your data is processed primarily in UAE-North and KSA-Riyadh. Where data crosses borders (e.g. EU residents using the platform, or for specific sub-processors), we rely on Standard Contractual Clauses + a documented Transfer Impact Assessment, or on the relevant adequacy decision. GCC public-procurement data does not leave the GCC without an explicit lawful basis.
7. How long we keep data
| Category | Retention | Reason |
|---|---|---|
| Bid submission records (KSA tenders) | 10 years | KSA Government Tenders & Procurement Law |
| Bid submission records (other GCC) | 7 years | Standard procurement retention |
| Account profile (when active) | Until you close your account | Operate the service |
| Account profile (after closure) | 30 days, then erased | Allow account recovery |
| Authentication tokens (OTP, magic links) | 10–60 minutes | Single-use security |
| Audit logs | 10 years | Procurement integrity, legal defence |
| Marketing consent records | Until withdrawn + 1 year | Prove consent existed |
8. Security
- TLS 1.3+ in transit, AES-256 at rest.
- Authentication tokens hashed (SHA-256 + per-env pepper), never stored plaintext, single-use, time-bound.
- Role-based access control with least privilege; SSO/SAML for enterprise; optional MFA on every account.
- Immutable audit logs in WORM storage.
- Annual third-party penetration test. SOC 2 Type II in progress. ISO 27001 certified.
- Breach notification: regulator within 72 hours, affected users within 24 hours where high-risk, with what was accessed and what we've done.
9. Your rights
Under GDPR + UAE PDPL + Saudi PDPL + the other GCC frameworks, you have the right to:
- Access — download a JSON of everything we hold about you in < 60 seconds from your dashboard.
- Rectify — edit your firm profile and contact info anytime.
- Erase — request deletion (we honour within 30 days, retaining only what KSA tenders law mandates).
- Restrict — pause processing of optional categories.
- Object — to processing based on legitimate interest.
- Portability — receive your data in machine-readable form.
- Withdraw consent — for any optional consent, effective within 24 hours.
- Lodge a complaint with your home DPA (SDAIA · KSA / UAE Data Office / NDMO Qatar / OPDP Oman / Bahrain PDPA / Kuwait).
Exercise any right by emailing dpo@bid.guide or self-service from your dashboard. We respond within 30 days.
10. Automated decisions & AI
No bidder is qualified, shortlisted, awarded, or rejected on the basis of an algorithm without a named human approver. The AI win-score, partner-matching, AI bid-writing, and compliance flagging are decision-support tools only. We publish the drivers behind every score. Per GDPR Article 22 and Saudi PDPL Article 32, you have the right not to be subject to a decision based solely on automated processing where it produces legal or similarly significant effects.
We do not use your data to train third-party general-purpose AI models. Where we use AI services (e.g. Anthropic Claude for content extraction and bid drafting), we operate under their data-processing addendum, with data residency in the relevant region and no training opt-in.
12. Children & sensitive data
Bid.Guide is for business use only. We do not knowingly collect data from individuals under 18. By registering a firm you confirm you are authorised on behalf of that firm. We do not collect or process special-category data: race, religion, political opinion, health, biometric, genetic, sexual orientation, or trade-union membership.
13. Changes to this notice
Material changes are emailed to active users with 30 days' notice. Non-material changes (clarifications, typos) are dated above. All historical versions are available on request from the DPO.
14. How to reach us
- Email DPO: dpo@bid.guide
- Postal address available on request
- For Saudi residents — KSA local representative listed in our SDAIA registration
- For EU residents — Article 27 representative listed in our EU privacy registration