Version 2026-06-02 · Effective 2 June 2026
This Policy explains what personal information TenderTrust processes, why, how long we keep it, and your rights. It is designed for users in South Africa and Zimbabwe.
1. Data controller
The operator of TenderTrust is responsible for personal information processed through the platform unless a separate data-processing agreement applies to your organisation.
2. Information we collect
- Account data: name, email, password (stored hashed), role, country, username, address, national ID or equivalent (stored using one-way hashing where applicable), government unit assignment for officials.
- Profile and business data: company name, specializations, compliance profile (for example B-BBEE level, tax clearance references), avatars and logos.
- Procurement data: tenders, bids, contracts, expenses, comments, votes, service requests, attachments, and audit-related metadata.
- Technical data: IP address, device/browser type, session cookies, security logs, and API usage for rate limiting.
- Communications: optional phone number when you enable SMS or WhatsApp alerts, plus support or issue reports you submit.
3. How we use information
- Provide and secure the service (authentication, authorisation, fraud prevention).
- Run procurement workflows you initiate or participate in.
- Send transactional notifications (bid status, tender updates, contract reminders).
- Publish transparency datasets where tenders or awards are designated public (open-data endpoints).
- Improve reliability, support users, and comply with law.
4. Legal bases (South Africa & Zimbabwe)
Where the Protection of Personal Information Act (POPIA) applies in South Africa, we rely on lawful grounds such as consent, contract performance, legitimate interests (balanced against your rights), and legal obligation. In Zimbabwe, we process data consistent with applicable data-protection principles and your reasonable expectations when using a procurement platform.
6. Retention
We retain account and procurement records while your account is active and for a period afterward as needed for legal, audit, and dispute-resolution purposes. Public tender or award data may remain in open datasets after closure where transparency requires it.
7. Security
We use industry-standard measures including encrypted transport (HTTPS), hashed passwords, access controls, and rate limiting. No system is completely secure; report suspected incidents promptly.
8. Your rights
- Request access to personal information we hold about you (Settings → Download my data).
- Request correction of inaccurate data via profile settings or support.
- Request erasure of your account via Settings → Delete account. Procurement records that must stay public are retained in anonymised form.
- Object to or restrict certain processing where applicable law allows.
- Withdraw consent for optional processing (for example marketing) without affecting core service use.
- Lodge a complaint with the Information Regulator (South Africa) or relevant authority in Zimbabwe.
9. Children
TenderTrust is not directed at children under 18. We do not knowingly collect their personal information.
10. Changes
We may update this Policy. The effective date and version identifier on the Legal page will change when we do. Significant changes may be highlighted in the product or by email where appropriate.
11. Contact
Privacy requests and questions: use the privacy contact email published on the Legal hub page for your deployment.
Contact
Legal: info@coretrust.tech
Privacy: info@coretrust.tech