Privacy Policy

Version 2026-06-02 · Effective 2 June 2026

This Policy explains what personal information TenderTrust processes, why, how long we keep it, and your rights. It is designed for users in South Africa and Zimbabwe.

Important: These documents are standard platform templates. Have them reviewed by qualified legal counsel for your jurisdiction and operating entity before production reliance.

1. Data controller

The operator of TenderTrust is responsible for personal information processed through the platform unless a separate data-processing agreement applies to your organisation.

2. Information we collect

  • Account data: name, email, password (stored hashed), role, country, username, address, national ID or equivalent (stored using one-way hashing where applicable), government unit assignment for officials.
  • Profile and business data: company name, specializations, compliance profile (for example B-BBEE level, tax clearance references), avatars and logos.
  • Procurement data: tenders, bids, contracts, expenses, comments, votes, service requests, attachments, and audit-related metadata.
  • Technical data: IP address, device/browser type, session cookies, security logs, and API usage for rate limiting.
  • Communications: optional phone number when you enable SMS or WhatsApp alerts, plus support or issue reports you submit.

3. How we use information

  • Provide and secure the service (authentication, authorisation, fraud prevention).
  • Run procurement workflows you initiate or participate in.
  • Send transactional notifications (bid status, tender updates, contract reminders).
  • Publish transparency datasets where tenders or awards are designated public (open-data endpoints).
  • Improve reliability, support users, and comply with law.

5. Sharing and processors

We share information only as needed to operate the service: hosting and database providers (for example Vercel, MongoDB Atlas), email or messaging providers if configured, and other users according to your role (for example issuers viewing bids on their tenders). We do not sell personal information.

International transfers may occur when infrastructure is hosted outside your country. We use appropriate safeguards where required.

6. Retention

We retain account and procurement records while your account is active and for a period afterward as needed for legal, audit, and dispute-resolution purposes. Public tender or award data may remain in open datasets after closure where transparency requires it.

7. Security

We use industry-standard measures including encrypted transport (HTTPS), hashed passwords, access controls, and rate limiting. No system is completely secure; report suspected incidents promptly.

8. Your rights

  • Request access to personal information we hold about you (Settings → Download my data).
  • Request correction of inaccurate data via profile settings or support.
  • Request erasure of your account via Settings → Delete account. Procurement records that must stay public are retained in anonymised form.
  • Object to or restrict certain processing where applicable law allows.
  • Withdraw consent for optional processing (for example marketing) without affecting core service use.
  • Lodge a complaint with the Information Regulator (South Africa) or relevant authority in Zimbabwe.

9. Children

TenderTrust is not directed at children under 18. We do not knowingly collect their personal information.

10. Changes

We may update this Policy. The effective date and version identifier on the Legal page will change when we do. Significant changes may be highlighted in the product or by email where appropriate.

11. Contact

Privacy requests and questions: use the privacy contact email published on the Legal hub page for your deployment.

Contact

Legal: info@coretrust.tech

Privacy: info@coretrust.tech

← All legal documents