Legal
Data Security and Retention Policy
Last updated 8 September 2026
We handle company documents, financials and — in some engagements — access to your own seller account. This sets out how that is protected, how long it is kept, and how it is disposed of.
1. What this covers
This policy sits alongside our Privacy Policy, which explains what we collect and why. This one is about safeguards and timeframes: how the material is held, who can reach it, and when it is destroyed.
2. Your portal account stays yours
We do not take ownership of your seller account. Where an engagement requires us to work inside your GeM, IREPS, CPPP or state portal account, we do so alongside your credentials, with your approval, and you can revoke access at any time.
Our rules on access:
- Use a secondary user where the portal supports it, scoped to what the work needs, rather than sharing the primary login.
- Credentials are never sent over unsecured channels. Do not email us a password or forward a one-time password in plain text; we will agree a safer route.
- Credentials are not stored in our systems beyond the engagement, and are never written into shared documents, spreadsheets or messaging history.
- Change any credential shared with us when the engagement ends. We will remind you, but the account is yours and the change should be yours.
- Every filing is documented so you can see exactly what was submitted under your account, and when.
3. How data is held
- The website is served over HTTPS. Enquiry, booking and subscription forms are encrypted in transit.
- Booking and enquiry records are stored outside the public web directory, so they cannot be reached by a browser, with filesystem permissions restricting access to the application.
- Configuration secrets are stored outside the published site and are never committed to the website's code.
- No payment credentials are held by us at all — see section 5.
- Client documents are kept in access-controlled storage and shared only with the people working on your engagement.
4. Who can access it
Access is limited to the consultant working on your engagement and, where necessary, the person supervising it. We are a small practice, which is a genuine security advantage: the list of people who can reach your documents is short and known.
Where we use an external adviser — an accountant, for instance — they are bound by confidentiality and receive only what they need.
5. Payment data
Card numbers, UPI IDs, net banking credentials and one-time passwords are entered on the payment provider's own screens. They never pass through our website and we never store them. What we retain is a transaction reference, the amount and the payment status.
6. How long we keep things
- Enquiries that do not become engagements — up to 24 months, then deleted.
- Engagement records, filings and correspondence — for the engagement and up to 8 years afterwards. Public procurement matters can be revisited long after the event, and a documented record of what was filed protects you as much as us.
- Invoices, payment and booking records — up to 8 years, to meet tax and accounting requirements.
- Portal credentials — not retained after the engagement ends.
- Newsletter subscriptions — until you unsubscribe.
- Server logs — a short rolling window set by our hosting provider, for security and troubleshooting.
- Calendar entries for past meetings — retained as part of the engagement record.
Where a retention period has expired and no legal reason to keep something remains, it is deleted.
7. Asking us to delete your data
Email info@tenderbuddy.in and we will delete what we hold, except anything we are legally required to keep — chiefly invoices and records of filings made on your behalf. We will tell you specifically what is being retained and why, rather than refusing in general terms.
8. If something goes wrong
If a breach affecting your personal data occurs, we will investigate immediately, take steps to contain it, notify you without undue delay, and report it to the Data Protection Board of India as required. We will tell you what happened, what data was involved, and what we are doing about it.
9. What we ask of you
- Send sensitive documents by the channel we agree, not to a personal inbox or a group chat.
- Tell us promptly if someone leaves your team who had access to a shared engagement.
- Keep your own portal credentials secure, and change them when an engagement ends.
- Do not send us more than the work needs — the safest data is the data nobody holds.
10. Review
We review this policy as our systems change and as the Digital Personal Data Protection Act, 2023 and the Rules under it come fully into force. The date at the top shows the current version.
11. Contact
Jugaad Studio Tradex Private Limited, trading as TenderBuddy
New Delhi, India
info@tenderbuddy.in · +91 95993 36133