What we do with your data
Every claim on this page maps to something the product actually does — and to a control you can use yourself.
- 6 hrs
- To report an incident to CERT-In
- 30 days
- To answer a privacy grievance
- 180 days
- Security logs kept, inside India
- Mumbai
- Primary data residency
Frameworks
The laws we hold ourselves to
Three instruments govern how we handle personal data. Each one is named here with what it actually asks of us.
General Data Protection Regulation
European Union · 2016
Lawful basis for every use, data portability, erasure, and breach notice within 72 hours.
Digital Personal Data Protection Act
India · Act of 2023
Purpose-scoped consent you can withdraw, a nominee, a grievance officer, and a 30-day clock.
Sensitive Personal Data Rules
India · IT Act Rules 2011
Reasonable security practices for sensitive data, a published policy, and a named officer.
Data rights
Your rights
Each of these is a button in your account, not a form to fill in and wait on.
Delete your account
Erase your personal data. Records the law requires us to keep are retained and named.
Go thereManage your consent
Choose what we may do with your data, purpose by purpose. Withdrawing is as easy as granting.
Go thereNominate someone
Name someone who may exercise these rights if you die or cannot act for yourself.
Go thereRaise a grievance
Unhappy with how your data was handled? File a grievance and get a response within 30 days.
Go thereTransparency
What we collect, and why
The full record is in our Privacy Policy; this is the same list in plain words.
| What | Why | Lawful basis |
|---|---|---|
| Account and profile: name, email, phone, password hash, sign-in metadata | To give you an account and keep it secure | |
| Identity verification: Aadhaar (masked), PAN, passport, driving licence, selfie | To verify you are who you say you are, as regulated onboarding requires | |
| Business records: GSTIN, CIN, Udyam, bank proof, team membership | To verify a business and let its team act for it | |
| Marketplace activity: listings, catalogues, tenders, enquiries, bids | To run the marketplace you came here for | |
| Payments and wallet: order data, invoices, ledger entries | To process payments and keep an auditable ledger | |
| Messaging: email address, phone number, notification content | To send transactional notices, and marketing only where you allow it | |
| Consent records: which purpose, which version, when, from where | To prove what you agreed to and honour a withdrawal | |
| Activity and technical logs: actions taken, IP address, device | Security, accountability, and the incident reporting the law requires |
Consent
What you can turn off
Consent is per purpose, and withdrawing is as easy as granting.
- Identity verification (KYC)
Required Verify your identity using government-issued documents. Required to use a verified-only marketplace.
- Marketing email
Optional Product news, feature announcements and offers by email. Transactional email is not affected.
- WhatsApp notifications
Optional Deliver notifications you have enabled to your WhatsApp number.
- Analytics cookies
Optional Cookies that measure how Bidancer is used. Strictly necessary cookies are always set.
- Public profile visibility
Optional Show your public profile page to visitors who are not signed in.
Retention
How long we keep it
These periods are enforced by a scheduled job, not by intention.
- Account and profile data
- Life of the account, then up to 90 days
- Identity verification (KYC)
- As long as the law requires, then deleted or anonymised
- Financial records, invoices, ledger
- 8 years (Indian tax and company law)
- Consent records
- Life of the account, then the limitation period for claims
- Activity and technical logs
- Up to 12 months
- Data export files you request
- 7 days, then deleted automatically
Sub-processors
Where your data lives
Our primary infrastructure runs in India (Mumbai). These processors help us run the service.
Google Cloud
Hosting, databases, storage
Sandbox
Aadhaar-based identity verification
Cashfree
DigiLocker KYC and verification
Razorpay
Payments
Zavu
WhatsApp and SMS messaging
Resend
Transactional email
Quick reference
Where every claim stands
One table, every standard we name anywhere on this site, and the honest status of each.
| Area | Standard | Status |
|---|---|---|
| EU privacy | GDPR | Self-assessed |
| India privacy | DPDP Act 2023 | Self-assessed |
| India sensitive data | IT Act SPDI Rules | Self-assessed |
| Independent audit | SOC 2 / ISO 27001 | Not held — no audit claimed |
| Data in transit and at rest | TLS 1.2+ and provider-managed encryption | In place |
| Account security | TOTP, email and backup codes | In place |
| Incident reporting | CERT-In 6-hour directive | Procedure documented |
| Records of processing | GDPR Art. 30 register | Maintained |
| Erasure and retention | Automated retention sweep | Running daily |
| Consent evidence | Append-only consent ledger | In place |
Incidents
If something goes wrong
We report qualifying security incidents to CERT-In within 6 hours. Where the GDPR applies, we notify the supervisory authority within 72 hours. We notify the Data Protection Board and affected people as the DPDP Act requires. We keep security logs for at least 180 days, in India.
Grievance Officer
Responsible for privacy grievances, with a response within 30 days.
To be named before public launch
privacy@bidancer.com
Your data, your call
Every right on this page is a button in your settings, not a form you have to email us.