GTender
Sign in

Launch draft

Privacy Policy

A draft explanation of what GTender collects, why it is used, and which launch decisions remain open.

This document is prepared for founder and legal review. It is not effective, is not a legal promise, and must not be treated as final customer terms.

Status
Not effective. Human and legal approval required before customer launch.
Technical truth reviewed
24 August 2026
Proposed operator description
GTender, a product of Fashol. Exact legal entity name and registered address require founder confirmation.

1. Public procurement data

GTender collects tender, buyer, award, planning, supplier, and related records from public procurement sources. Public-source records are kept separate from customer-private workspace information and retain source and freshness information where available.

2. Account and organization data

GTender processes names, business email addresses, identity-provider subjects, language preference, organization membership, roles, sign-in history, security events, and subscription state to operate and protect accounts. Password credentials are handled by the configured identity provider and are not stored by GTender.

3. Company and workspace data

Customers may provide company profile facts, financial facts, licences, personnel and equipment records, experience, private tender documents, evidence, decisions, tasks, work products, and internal bid material. This information is organization-private and is access-controlled by tenant, role, and plan.

4. Technical and security data

GTender records bounded operational and security information such as request time, IP address for security-classified events, browser user agent, audit actions, failures, and service health. Secrets, raw credentials, private document text, and invitation capabilities must not be written to application logs.

5. Why data is used

Data is used to authenticate users, enforce organization access, provide requested product functions, preserve source provenance, process safe uploads, send enabled notifications, maintain audit history, prevent abuse, support customers, and improve service reliability. GTender does not sell customer personal data.

6. Service providers and processing location

The current architecture uses Google Cloud and Google Identity Platform. Production infrastructure is planned for Google Cloud asia-south1 in Mumbai, India, so customer data would be processed outside Bangladesh. The final entity, processor terms, transfer basis, safeguards, and customer notice require privacy and legal approval before launch. Transactional email, SMS, payment, and external AI providers are not connected.

7. Disclosure

GTender should disclose customer data only to approved service providers acting under instructions, to authorized members of the customer's organization, when the customer directs it, or when required by applicable law. A final processor list and lawful-request procedure must be approved before launch.

8. AI and automated processing

No approved external AI provider receives customer-private documents or workspace content. Current drafting demonstrations are deterministic local operations. Any future external model use requires separate provider, privacy, region, retention, evaluation, spend, and organization-private approval gates plus truthful customer notice.

9. Retention and deletion

A production retention and deletion schedule is not yet approved. GTender must define account, audit, invitation, document, backup, workspace, and post-cancellation periods, including export and deletion handling, before broad customer launch. Database and storage deletion must remain controlled and auditable.

10. Requests and choices

A person may contact GTender to ask about their personal data, request correction, request deletion where applicable, withdraw an optional consent, or raise a concern. The final identity-verification, response-time, exception, appeal, and regulator process requires review under the Personal Data Protection Ordinance, 2025 and other applicable Bangladesh law.

Questions, privacy requests, security reports, and policy concerns can currently be sent to sakib@fashol.com