Privacy Policy

Version 2.0 · 20 July 2026 · Aveosoft Private Limited, Ahmedabad, Gujarat, India

In short:

  • We collect what we need to run the service — your account and company details, the targeting criteria you set, the documents you upload, billing details, and basic technical logs. Nothing more.
  • Tender data is public. Notices published by GeM and nProcure are government information, not your personal data.
  • Your content is not training data. We never use your uploaded documents or bid records to train AI models, ours or anyone else's.
  • AI runs only when you ask. When you run an analysis, the tender text and the profile details needed for that analysis are sent to our AI provider for processing and are not retained by them for training.
  • Separate by design. Each agency runs on its own application instance and its own database. One session cookie, no advertising trackers.
  • Your rights. Under India's DPDP Act 2023 you can ask for access, correction, erasure or nomination, and raise a grievance. Write to contact@bidshakti.com.

Version 2.0 — 20 July 2026

1. Who We Are and What This Policy Covers

  1. This Privacy Policy explains how Aveosoft Private Limited ("Aveosoft", "we", "us", "our") collects, uses, shares, stores and protects personal data.
  2. Our details:
    • Registered office: 616, Sharan Circle Business Hub, Zundal, Ahmedabad – 382424, Gujarat, India
    • GSTIN: 24AAVCA4288N1ZU
    • Email: contact@bidshakti.com
  3. Scope. This Policy applies to the website at bidshakti.com and to every BidShakti portal at <agency>.bidshakti.com (together, the "Platform"), and to email, support and billing correspondence connected with them.
  4. This Policy forms part of the Terms of Use and, for subscribers, of the Subscriber Service Agreement. Where those documents address a matter commercially, they prevail; this Policy governs the handling of personal data.
  5. Terminology. We use the terms of the Digital Personal Data Protection Act, 2023 ("DPDP Act"): a Data Principal is the individual whose personal data is processed; a Data Fiduciary decides why and how it is processed; a Data Processor processes it on a Data Fiduciary's instructions.
  6. Our role.
    • For website visitors, enquirers, trial sign-ups and account holders, and for our billing records, we act as a Data Fiduciary.
    • For personal data that a subscriber uploads into its own portal — for example the details of its employees, directors, authorised signatories or contacts — the subscriber is the Data Fiduciary and Aveosoft acts as a Data Processor on that subscriber's documented instructions.
  7. For EU and UK visitors. BidShakti is an India-focused business service and is not directed at the EU or UK. If you visit the website from there, we handle your data in a manner consistent with the GDPR and UK GDPR: the "lawful basis" column in Clause 3 states the applicable basis, and the rights in Clause 12 are available to you together with the right to object, the right to restrict processing, the right to data portability, and the right to complain to your local supervisory authority.

2. What Is Not Personal Data — Tender Information

  1. Tender notices, bid details, documents, dates, corrigenda and related information collected from the Government e-Marketplace (GeM) and nProcure are public government information. They are published by the procuring authorities on those portals for open access.
  2. Such tender information is not your personal data, and processing it is not processing of your personal data. Where a tender document happens to contain an official's name or office contact details, that is data made publicly available by the authority itself, and under Section 3(c)(ii) of the DPDP Act the Act does not apply to personal data a Data Principal has made or caused to be made publicly available.
  3. We do not enrich tender information with personal data about you, and we do not sell tender information or any personal data to anyone.

3. What We Collect, Why, and On What Basis

Category What it includes Why we collect it Lawful basis
Account and identity Name, designation, work email address, mobile number, username, password (stored in hashed form), portal subdomain, role and permissions, acceptance record (date, time, version, user) To create and secure your account, authenticate you, provide the portal, provide support, and record acceptance of our agreements Performance of the service you asked for; certain legitimate uses under Section 7 of the DPDP Act; consent where given at sign-up. (EU/UK: contract; legitimate interests in account security)
Company and KYC-type documents Legal entity name, constitution, registered and site addresses, GSTIN, PAN, CIN or registration number, MSME/Udyam details, bank details where you supply them, registration and empanelment certificates, ISO and other certificates, past work orders and completion certificates, turnover and experience records To populate bid documents accurately, assess eligibility against tender conditions, generate annexures and declarations, and meet our own tax and accounting obligations Performance of the service; legal obligation (tax, GST, accounting). Where an individual's data appears, we act as Processor for the subscriber (EU/UK: contract; legal obligation)
Targeting criteria Departments, keywords, categories, work types, geographies, value ranges and other filters set in Profile & Targeting; alert preferences To filter tender information so the portal shows what is relevant to you, and to send alerts you have asked for Performance of the service (EU/UK: contract)
Uploaded documents and branding Letterhead image, signature image, seal or stamp image, draft and final bid documents, technical write-ups, pricing sheets, notes, correspondence you save in the portal To store your working material and to print generated documents on your own letterhead and signature; where no signature image is uploaded, a blank signature area is printed instead Performance of the service; we act as Processor on your instructions (EU/UK: contract)
Usage, device and technical data IP address, browser type and version, operating system, timestamps, pages and features used, actions taken in the portal, error and diagnostic logs, security and audit logs To keep the Platform running and secure, detect and investigate abuse or unauthorised access, diagnose faults, and understand aggregate usage so we can improve the product Legitimate uses under Section 7 of the DPDP Act (security, prevention of fraud); performance of the service (EU/UK: legitimate interests in security and service integrity)
Communications Enquiry and demo-request form submissions, support tickets and email correspondence, call or meeting notes, feedback, grievance records To respond to you, provide support, maintain a record of what was asked and answered, and handle grievances Consent where you contacted us voluntarily; performance of the service for existing subscribers; legal obligation for grievance records (EU/UK: consent; contract; legitimate interests)
Billing and payment Billing name and address, GSTIN, plan and pricing, invoices, payment references, transaction IDs, TDS certificates, payment status To raise invoices, collect fees, account for GST and TDS, and maintain statutory books Performance of the contract; legal obligation under tax and company law (EU/UK: contract; legal obligation)

We do not collect: your GeM, nProcure or Digital Signature Certificate credentials — we will never ask for them; payment card numbers, which are handled by the payment provider and never stored by us; special-category or sensitive personal data such as health, biometric, caste, religion or political data; or location data beyond the coarse indication implied by an IP address.

4. How We Use Personal Data

  1. To provide the Platform — create and maintain your portal, authenticate users, filter tender information against your criteria, run analyses you request, generate documents, and store your records.
  2. To support you — answer questions, investigate faults, assist with onboarding and targeting configuration, and handle grievances.
  3. To secure the Platform — detect, investigate and prevent unauthorised access, abuse, scraping, fraud and security incidents, and maintain audit logs.
  4. To bill and account — issue invoices, collect payment, and meet tax, GST, TDS, accounting and audit obligations.
  5. To communicate — send service messages such as tender alerts you configured, trial expiry notices, invoices, security notices, and notices of changes to our agreements or policies. These are service communications and are not marketing.
  6. To improve the product — analyse aggregated and de-identified usage patterns to decide what to build and fix.
  7. Marketing — we may send occasional product updates to business contacts who have asked for them or who are existing subscribers. Every such message carries an unsubscribe link, and unsubscribing does not affect service messages.

4.1 What we do not do

  • We do not use subscriber content to train third-party AI models, and we do not use it to train models of our own that serve other subscribers.
  • We do not sell, rent or trade personal data.
  • We do not share one subscriber's content, branding, letterhead, signature or records with another subscriber.
  • We do not use advertising cookies, third-party ad networks, cross-site tracking, or behavioural profiling.
  • We do not carry out automated decision-making that produces a legal or similarly significant effect on any individual.

5. AI Processing — Exactly What Is Sent, and When

  1. AI processing happens only when a user runs it — for example by requesting a tender analysis, a Go/No-Go verdict, a tailored specification, or a drafted bid document. It is not continuous, and it is not applied to your stored content in the background.
  2. When an analysis is run, we send to our AI provider:
    • the text of the tender and its documents, which is public government information; and
    • only those profile details necessary for that specific analysis — for example the entity name, category of work, relevant certifications, turnover band or past-experience entries needed to assess eligibility or draft the requested document.
  3. We do not send your full document store, your unrelated bid records, your bank details, your letterhead or signature image, or the content of any other subscriber's portal.
  4. Our AI provider processes the request under terms that require it to use the data only to return the output, and not to train or improve its models on that data. It is not permitted to retain the data beyond any short abuse-monitoring period allowed by its terms.
  5. The output is written into your portal, inside your isolated instance, and is available only to your users.
  6. AI output is decision support, not advice. It can be incorrect or incomplete and must be reviewed and verified by a competent person on your side before submission. This is set out more fully in the Terms of Use and the Subscriber Service Agreement.

6. Who We Share Data With — Sub-Processors

  1. We use a small number of service providers to run the Platform. Each is engaged under written terms requiring confidentiality, security safeguards, use limited to our instructions, and no independent use of the data. We remain responsible for their handling of the data.
Category What they do Data involved Location
Cloud hosting and storage Host the application instances, databases, uploaded files and backups All categories in Clause 3 India
Email delivery Deliver transactional email — alerts, invoices, notices, password resets Name, email address, message content India or another jurisdiction with appropriate safeguards
AI model provider Process a specific analysis request and return the output Tender text and the profile details necessary for that analysis only (Clause 5) Provider's processing region, under no-training terms
Payment and accounting Collect payment and maintain statutory records Billing name, address, GSTIN, invoice and transaction data India
  1. We may also disclose personal data:
    • where required by law, court order, or a lawful request from a government or regulatory authority — we assess each request and disclose only what is legally required, and we will tell you unless prohibited from doing so;
    • to our professional advisers — auditors, lawyers, accountants — under confidentiality;
    • in connection with a merger, reorganisation or sale of our business, subject to the acquirer being bound by protections no less protective than this Policy, and on notice to you; or
    • with your instruction or consent.
  2. A current list of sub-processors is available on request at contact@bidshakti.com. We will give subscribers reasonable advance notice by email before adding a sub-processor in a new category.

7. Per-Agency Isolation

  1. Each subscriber runs on a separate application instance with a separate database, reached at its own subdomain <agency>.bidshakti.com. This is not a shared multi-tenant table with a tenant column — the separation is at instance and database level.
  2. Your content is not commingled with, visible to, or reachable from another subscriber's instance in the ordinary operation of the Platform.
  3. Access by Aveosoft personnel to a subscriber instance is limited to what is necessary for provisioning, support, maintenance, security and legal compliance, is restricted to authorised personnel bound by confidentiality, and is logged.
  4. Generated documents draw only on the branding and content of the portal in which they are generated. One subscriber's letterhead or signature is never used in another subscriber's documents.

8. Cookies and Similar Technologies

  1. The Platform uses a single session cookie. Its only purpose is to keep you signed in and to maintain the security of your session. It is strictly necessary for the Platform to function.
  2. The session cookie expires when your session ends or after a period of inactivity, and it carries no advertising identifier.
  3. We do not use advertising cookies, retargeting pixels, social media trackers, cross-site tracking, fingerprinting, or third-party behavioural analytics.
  4. Because the only cookie we set is strictly necessary, no consent banner is required under Indian law, and none is required for strictly necessary cookies under EU/UK rules either.
  5. Your browser may be set to block cookies. If you block the session cookie, you will not be able to sign in to the portal.

9. Security

  1. We apply reasonable technical and organisational security safeguards appropriate to the nature of the Platform, including:
    • encryption in transit using TLS for all connections to the Platform;
    • encryption at rest for stored files and database volumes;
    • passwords stored only as salted hashes, never in readable form;
    • instance- and database-level isolation between subscribers;
    • role-based access control, with access granted on a need-to-know basis and reviewed periodically;
    • audit logging of administrative and security-relevant actions;
    • regular backups, held in India, with restoration tested periodically;
    • patching of operating systems and dependencies, and periodic security review of the application;
    • confidentiality obligations binding all personnel and contractors, and security terms binding all sub-processors.
  2. No system is beyond compromise. We do not warrant that the Platform is impenetrable, and you should keep your own credentials secure as required by the Terms of Use.
  3. Breach notification. If a personal data breach occurs, we will:
    • contain and investigate it without delay;
    • notify the Data Protection Board of India and each affected Data Principal in the form and within the timelines required by the DPDP Act and its rules;
    • notify affected subscribers without undue delay, describing the nature of the breach, the data involved, the likely consequences and the steps taken; and
    • where we act as a Processor for a subscriber, support that subscriber in making any notification it is required to make.
  4. For EU/UK visitors, where the GDPR or UK GDPR applies, we will notify the relevant supervisory authority within 72 hours of becoming aware where the breach is notifiable.
  5. Please report any suspected security issue to contact@bidshakti.com. We investigate all good-faith reports and do not pursue researchers who report responsibly.

10. How Long We Keep Data

Category Retention period
Account and identity data For the life of the account, then deleted after the 60-day export window in Clause 11
Company and KYC-type documents For the life of the account, then deleted after the 60-day export window; copies referenced in an issued invoice are retained with the billing record
Targeting criteria For the life of the account, then deleted after the 60-day export window
Uploaded documents, letterhead and signature image Until you delete them, or for the life of the account, then deleted after the 60-day export window
Usage, device and technical logs 12 months from creation; security and audit logs may be kept up to 24 months where needed for investigation
Communications and support records 24 months from the last message in the thread; grievance records for 3 years
Billing, invoices and tax records 8 years, as required under the Companies Act, 2013 and GST law
Acceptance records (agreement version, date, time, user) For the life of the account and 3 years thereafter
Backups Purged on the ordinary backup cycle, no later than 90 days after the source data is deleted
Marketing contact records Until you unsubscribe or ask us to delete them, whichever is earlier

Where a legal obligation, an ongoing dispute, or a lawful direction requires longer retention, we keep the data for that period only, and only for that purpose.

11. Deletion and Export When You Leave

  1. On termination or expiry of a subscription, and for sixty (60) days afterwards, we will on written request provide an export of your content in a commonly used machine-readable format — typically CSV together with your uploaded files. One export is provided at no charge.
  2. Where an account was suspended for non-payment, export is provided once undisputed dues are cleared.
  3. We will not delete your content during the export window unless you instruct us to.
  4. After the sixty-day window, we may delete your content, your application instance and your database. Residual copies in routine backups are purged on the ordinary backup cycle, and remain confidential until purged.
  5. Data we are required to retain by law — principally billing and tax records — is retained for the statutory period stated in Clause 10, and is not deleted on request.
  6. When a trial ends without a paid plan, the portal is paused, not deleted. Your content remains stored and is subject to the retention periods above; you may request export or deletion at any time.

12. Your Rights as a Data Principal

Under the DPDP Act, and subject to its conditions, you have the following rights in relation to personal data for which Aveosoft is the Data Fiduciary:

  1. Right to access information. To obtain a summary of the personal data we process about you, the processing activities undertaken, and the identities of other Data Fiduciaries and Processors with whom it has been shared.
  2. Right to correction and completion. To have inaccurate or misleading data corrected, incomplete data completed, and data updated.
  3. Right to erasure. To have your personal data erased where it is no longer needed for the purpose for which it was collected, and where no legal obligation requires us to keep it.
  4. Right to grievance redressal. To raise a grievance with us about our handling of your data, and to receive a response within the prescribed period, before approaching the Data Protection Board of India.
  5. Right of nomination. To nominate another individual who may exercise these rights on your behalf in the event of your death or incapacity. To register a nomination, write to us with the nominee's name and contact details.
  6. Right to withdraw consent. Where processing rests on your consent, you may withdraw it at any time, as easily as it was given. Withdrawal does not affect processing already carried out, and it may mean we can no longer provide part or all of the service.

12.1 How to exercise your rights

  1. Write to contact@bidshakti.com from the email address registered with us, stating the right you wish to exercise and enough detail to identify your record.
  2. We may ask you to verify your identity before we act, to protect your data from disclosure to the wrong person.
  3. We will acknowledge within forty-eight (48) hours and respond substantively within thirty (30) days. If a request is complex and needs longer, we will tell you why and give a revised date.
  4. There is no charge for exercising these rights. We may decline or charge a reasonable fee only where a request is manifestly unfounded, repetitive or excessive, and we will explain why.

12.2 If we are a Processor, not a Fiduciary

Where your personal data was uploaded into a subscriber's portal by that subscriber — for example if you are an employee, director or contact of a BidShakti customer — that subscriber is the Data Fiduciary. Please direct your request to them. If you contact us instead, we will forward your request to them without undue delay and help them respond, but we cannot act on their data without their instruction.

12.3 EU and UK visitors

If the GDPR or UK GDPR applies to you, you additionally have the right to object to processing based on legitimate interests, the right to restrict processing, the right to data portability, and the right to lodge a complaint with your national supervisory authority. Please use the same contact address to exercise them.

13. Children's Data

  1. BidShakti is a business-to-business service. It is intended solely for use by contractors, suppliers, resellers and agencies, acting through adults authorised to represent them.
  2. The Platform is not directed at children, and we do not knowingly collect personal data of any person under eighteen (18) years of age. Accounts may be created only by persons aged 18 or above.
  3. We do not carry out tracking, behavioural monitoring or targeted advertising directed at children, as prohibited by Section 9 of the DPDP Act.
  4. If we learn that we hold personal data of a child collected without verifiable parental consent, we will delete it promptly. If you believe a child's data has been provided to us, please write to contact@bidshakti.com.

14. Where Data Is Stored and Transferred

  1. Personal data is stored and processed in India. Our hosting, databases and backups are located in India.
  2. Two components may involve processing outside India: email delivery, and the AI model provider that processes an analysis request. In each case we use providers that offer appropriate contractual safeguards, including confidentiality, security obligations, purpose limitation and — for the AI provider — no use of the data for model training.
  3. We do not transfer personal data to any country to which transfer is restricted by an order of the Central Government under Section 16 of the DPDP Act.
  4. For EU/UK visitors, where personal data is transferred out of the EEA or UK, we rely on the applicable Standard Contractual Clauses or the UK International Data Transfer Addendum, together with the safeguards described above. A copy of the relevant mechanism is available on request.

15. Grievance Officer

In accordance with Section 13 of the DPDP Act and the Information Technology (Intermediary Guidelines) Rules, the following officer handles data protection grievances:

Grievance Officer: Deval Chauhan
Designation: Director, Aveosoft Private Limited (Grievance Officer)
Email: contact@bidshakti.com
Address: 616, Sharan Circle Business Hub, Zundal, Ahmedabad – 382424, Gujarat, India

  1. Please mark your email "Data Protection Grievance" and include your name, contact details, account identifier if any, and a clear description of the issue.
  2. We will acknowledge within forty-eight (48) hours and aim to resolve within thirty (30) days.
  3. If you are not satisfied with our response, or we do not respond within the prescribed period, you may complain to the Data Protection Board of India in accordance with the DPDP Act.

16. Changes to This Policy

  1. We may update this Policy as the Platform, our providers or the law change.
  2. Each version carries a version number and effective date. The current version is always published at bidshakti.com and is available in your portal.
  3. Where a change is material — for example a new category of data, a new purpose, a new sub-processor category, or a change to retention — we will give registered users at least thirty (30) days' notice by email to the registered address before it takes effect. Changes required by law or for urgent security reasons may take effect sooner, with such notice as is practicable.
  4. Where a change requires your consent under applicable law, we will ask for it rather than relying on notice.
  5. Continued use of the Platform after the effective date means you accept the updated Policy.

17. Contact

Aveosoft Private Limited
616, Sharan Circle Business Hub, Zundal, Ahmedabad – 382424, Gujarat, India
GSTIN: 24AAVCA4288N1ZU
Email: contact@bidshakti.com
Website: bidshakti.com

This Policy is governed by the laws of India. Disputes relating to it are subject to the exclusive jurisdiction of the courts at Ahmedabad, Gujarat, India, following good-faith discussion as described in the Terms of Use.

Version 2.0 — Effective 20 July 2026. This version supersedes all earlier versions from the effective date.

See also our Terms of Use and Subscriber Service Agreement.