Privacy Policy
Last updated: May 27, 2026
GovnBidAI ("we," "our," or "us"), a wholly owned operating subsidiary of Deye Solutions, is committed to protecting the privacy and security of your data. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you use the GovnBidAI procurement platform and related services (the "Service").
We follow data minimization: we only collect and process information reasonably necessary to provide our AI-driven procurement services.
1. Information We Collect
Enterprise and user-provided data
- Account credentials: name, business email, corporate phone, password, and billing details (processed via Stripe).
- Corporate context: company profiles, NAICS codes, past performance, capability statements, and structural business documents uploaded to improve AI accuracy.
- Solicitation inputs: federal, state, or commercial RFPs, links, or text provided for parsing and match analysis.
Automatically collected data
- Usage logs: AI queries, proposal drafts, feature usage, and access timestamps.
- Device and network data: IP address, browser type, device identifiers, and OS attributes for integrity and audit logging.
2. How We Use Data & AI Practices
- We use data only to operate, maintain, and secure the Service.
- Zero-training guarantee: your corporate data, RFPs, and custom documents are never used to train, fine-tune, or feed public or multi-tenant foundational LLMs. Processing uses isolated infrastructure (including AWS Amplify Gen-2).
- Scope-bounded inference: data is used solely for context-aware recommendations, your P-Win metrics, and your automated proposal deliverables.
- Automated decision-making: algorithmic scoring of contract fit is advisory only and does not produce legally binding outcomes without human review ("human-in-the-loop").
3. Data Retention
- Account information and business profiles are kept for the life of your subscription.
- Compliance matrices and parsed text from RPA tools can be permanently purged on request via the admin dashboard.
- Security audit logs are retained as required for compliance, then compressed or deleted.
4. How We Share Information
- We do not sell, rent, or trade your personal or corporate data.
- Authorized providers (e.g., AWS, Stripe, Pinecone, Supabase) process data under confidentiality agreements and may not use it for independent purposes.
- We may disclose data when required by applicable U.S. federal or state law, court order, or enforceable administrative rule.
- In a merger, acquisition, or asset sale by Deye Solutions, data transfers remain subject to this Policy.
5. Security & Compliance
- Aligned with ISO/IEC 27001:2022 principles: administrative, technical, and physical safeguards.
- Encryption in transit (TLS 1.3) and at rest (AES-256).
- Role-based access control (RBAC) and mandatory MFA.
- Client-isolated vector indices; zero-training pipelines block leakage to public interfaces.
6. Your Privacy Rights
Depending on your state (including CA, CO, CT, IN, NJ, DE, MD, and others), you may exercise rights to know/access, delete, correct, and opt out of automated profiling used for contract scoring. We honor Global Privacy Control (GPC) signals. Contact privacy.govnbidai@deyesolutions.com. We do not discriminate or change pricing when you exercise these rights.
- Right to know and access — including technical inferences about your business context.
- Right to deletion and correction of your profile.
- Right to opt out of automated profiling for contract fitness scoring.
7. International Boundaries
- Processing occurs on U.S.-based cloud infrastructure. We restrict transfer of sensitive or government-adjacent data to foreign jurisdictions of concern, per applicable U.S. regulations.
- The Service is for adult business users only. We do not knowingly collect data from anyone under 18.
8. Changes to This Policy
We may update this Policy for AI governance, FTC guidance, and state privacy law. Material changes will be announced on the platform and reflected in the date above.
See also Terms of Service.