Trust

What we do with your data

Every claim on this page maps to something the product actually does — and to a control you can use yourself.

6 hrs
To report an incident to CERT-In
30 days
To answer a privacy grievance
180 days
Security logs kept, inside India
Mumbai
Primary data residency

Frameworks

The laws we hold ourselves to

Three instruments govern how we handle personal data. Each one is named here with what it actually asks of us.

GDPR Self-assessed

General Data Protection Regulation

European Union · 2016

Lawful basis for every use, data portability, erasure, and breach notice within 72 hours.

DPDP Self-assessed

Digital Personal Data Protection Act

India · Act of 2023

Purpose-scoped consent you can withdraw, a nominee, a grievance officer, and a 30-day clock.

SPDI Self-assessed

Sensitive Personal Data Rules

India · IT Act Rules 2011

Reasonable security practices for sensitive data, a published policy, and a named officer.

These are self-assessments, not third-party certifications. We hold no SOC 2 or ISO 27001 audit today, and we will not imply one until an auditor signs it.

Data rights

Your rights

Each of these is a button in your account, not a form to fill in and wait on.

Get a copy of your data

Download a machine-readable copy of the data we hold about you.

Go there

Correct your details

Correct anything wrong in your profile or business records.

Go there

Delete your account

Erase your personal data. Records the law requires us to keep are retained and named.

Go there

Manage your consent

Choose what we may do with your data, purpose by purpose. Withdrawing is as easy as granting.

Go there

Nominate someone

Name someone who may exercise these rights if you die or cannot act for yourself.

Go there

Raise a grievance

Unhappy with how your data was handled? File a grievance and get a response within 30 days.

Go there

Transparency

What we collect, and why

The full record is in our Privacy Policy; this is the same list in plain words.

What Why Lawful basis
Account and profile: name, email, phone, password hash, sign-in metadataTo give you an account and keep it secureContract
Identity verification: Aadhaar (masked), PAN, passport, driving licence, selfieTo verify you are who you say you are, as regulated onboarding requiresLegal obligation
Business records: GSTIN, CIN, Udyam, bank proof, team membershipTo verify a business and let its team act for itContract
Marketplace activity: listings, catalogues, tenders, enquiries, bidsTo run the marketplace you came here forContract and legal obligation
Payments and wallet: order data, invoices, ledger entriesTo process payments and keep an auditable ledgerContract and legal obligation
Messaging: email address, phone number, notification contentTo send transactional notices, and marketing only where you allow itConsent and contract
Consent records: which purpose, which version, when, from whereTo prove what you agreed to and honour a withdrawalLegal obligation
Activity and technical logs: actions taken, IP address, deviceSecurity, accountability, and the incident reporting the law requiresLegitimate purpose

Consent

Consent is per purpose, and withdrawing is as easy as granting.

  • Identity verification (KYC) Required

    Verify your identity using government-issued documents. Required to use a verified-only marketplace.

  • Marketing email Optional

    Product news, feature announcements and offers by email. Transactional email is not affected.

  • WhatsApp notifications Optional

    Deliver notifications you have enabled to your WhatsApp number.

  • Analytics cookies Optional

    Cookies that measure how Bidancer is used. Strictly necessary cookies are always set.

  • Public profile visibility Optional

    Show your public profile page to visitors who are not signed in.

Retention

How long we keep it

These periods are enforced by a scheduled job, not by intention.

Account and profile data
Life of the account, then up to 90 days
Identity verification (KYC)
As long as the law requires, then deleted or anonymised
Financial records, invoices, ledger
8 years (Indian tax and company law)
Consent records
Life of the account, then the limitation period for claims
Activity and technical logs
Up to 12 months
Data export files you request
7 days, then deleted automatically

Sub-processors

Where your data lives

Our primary infrastructure runs in India (Mumbai). These processors help us run the service.

Google Cloud

Hosting, databases, storage

India (Mumbai)

Sandbox

Aadhaar-based identity verification

India

Cashfree

DigiLocker KYC and verification

India

Razorpay

Payments

India

Zavu

WhatsApp and SMS messaging

India

Resend

Transactional email

United States

Quick reference

Where every claim stands

One table, every standard we name anywhere on this site, and the honest status of each.

Area Standard Status
EU privacyGDPRSelf-assessed
India privacyDPDP Act 2023Self-assessed
India sensitive dataIT Act SPDI RulesSelf-assessed
Independent auditSOC 2 / ISO 27001Not held — no audit claimed
Data in transit and at restTLS 1.2+ and provider-managed encryptionIn place
Account securityTOTP, email and backup codesIn place
Incident reportingCERT-In 6-hour directiveProcedure documented
Records of processingGDPR Art. 30 registerMaintained
Erasure and retentionAutomated retention sweepRunning daily
Consent evidenceAppend-only consent ledgerIn place

Incidents

If something goes wrong

  • We report qualifying security incidents to CERT-In within 6 hours.
  • Where the GDPR applies, we notify the supervisory authority within 72 hours.
  • We notify the Data Protection Board and affected people as the DPDP Act requires.
  • We keep security logs for at least 180 days, in India.

Grievance Officer

Responsible for privacy grievances, with a response within 30 days.

To be named before public launch
privacy@bidancer.com

File a grievance

Your data, your call

Every right on this page is a button in your settings, not a form you have to email us.