Launch draft
Privacy Policy
A draft explanation of what GTender collects, why it is used, and which launch decisions remain open.
This document is prepared for founder and legal review. It is not effective, is not a legal promise, and must not be treated as final customer terms.
- Status
- Not effective. Human and legal approval required before customer launch.
- Technical truth reviewed
- 24 August 2026
- Proposed operator description
- GTender, a product of Fashol. Exact legal entity name and registered address require founder confirmation.
1. Public procurement data
GTender collects tender, buyer, award, planning, supplier, and related records from public procurement sources. Public-source records are kept separate from customer-private workspace information and retain source and freshness information where available.
2. Account and organization data
GTender processes names, business email addresses, identity-provider subjects, language preference, organization membership, roles, sign-in history, security events, and subscription state to operate and protect accounts. Password credentials are handled by the configured identity provider and are not stored by GTender.
3. Company and workspace data
Customers may provide company profile facts, financial facts, licences, personnel and equipment records, experience, private tender documents, evidence, decisions, tasks, work products, and internal bid material. This information is organization-private and is access-controlled by tenant, role, and plan.
4. Technical and security data
GTender records bounded operational and security information such as request time, IP address for security-classified events, browser user agent, audit actions, failures, and service health. Secrets, raw credentials, private document text, and invitation capabilities must not be written to application logs.
5. Why data is used
Data is used to authenticate users, enforce organization access, provide requested product functions, preserve source provenance, process safe uploads, send enabled notifications, maintain audit history, prevent abuse, support customers, and improve service reliability. GTender does not sell customer personal data.
6. Service providers and processing location
The current architecture uses Google Cloud and Google Identity Platform. Production infrastructure is planned for Google Cloud asia-south1 in Mumbai, India, so customer data would be processed outside Bangladesh. The final entity, processor terms, transfer basis, safeguards, and customer notice require privacy and legal approval before launch. Transactional email, SMS, payment, and external AI providers are not connected.
7. Disclosure
GTender should disclose customer data only to approved service providers acting under instructions, to authorized members of the customer's organization, when the customer directs it, or when required by applicable law. A final processor list and lawful-request procedure must be approved before launch.
8. AI and automated processing
No approved external AI provider receives customer-private documents or workspace content. Current drafting demonstrations are deterministic local operations. Any future external model use requires separate provider, privacy, region, retention, evaluation, spend, and organization-private approval gates plus truthful customer notice.
9. Retention and deletion
A production retention and deletion schedule is not yet approved. GTender must define account, audit, invitation, document, backup, workspace, and post-cancellation periods, including export and deletion handling, before broad customer launch. Database and storage deletion must remain controlled and auditable.
10. Requests and choices
A person may contact GTender to ask about their personal data, request correction, request deletion where applicable, withdraw an optional consent, or raise a concern. The final identity-verification, response-time, exception, appeal, and regulator process requires review under the Personal Data Protection Ordinance, 2025 and other applicable Bangladesh law.
Contact
Questions, privacy requests, security reports, and policy concerns can currently be sent to sakib@fashol.com