Privacy Policy
Last updated: 2026-05-06
1. What we collect
Marketing-site visitors: standard server logs (IP, user agent, requested path), cookie-based analytics where consented, and any information you submit via the intake form.
Customers: account profile, organization profile, and the documents and data you upload to deliver the service (solicitations, drafts, evidence files, profile data).
2. How we use it
To deliver the service, route engagements, generate proposals and SSPs, surface analytic signals, bill the retainer and any win-share, communicate with you about your engagement, and improve the platform. We do not sell personal data and we do not use customer-uploaded content to train cross-customer models.
3. Tenancy and isolation
Customer data is partitioned via PostgreSQL Row-Level Security tied to the organization identifier.
4. Sub-processors
We engage a Bangladesh-based delivery team and standard infrastructure sub-processors. The current list is at /sub-processors. Customers receive a Data Processing Addendum (DPA) on request and material changes are communicated 30 days in advance.
5. Retention
Customer records and audit logs are retained for the period required by FAR 4.805 and applicable state procurement-records statutes (typically seven years). On request, we will export and delete customer data in accordance with the engagement letter and applicable law.
6. Security
We implement administrative, technical, and physical safeguards including encryption in transit, role-based access control, multi-tenant isolation via Row-Level Security, and a tamper-evident audit log. SOC 2 Type II is in progress.
7. Your rights
You may request access to, correction of, or deletion of your personal data, subject to procurement-records retention requirements. Requests to [email protected].