Privacy draft

Privacy policy draft

Pilot privacy terms for the approved limited customer-data workflow.

Current readiness status

  • This text is approved for a controlled limited customer-data pilot, not for broad production or public self-service launch.
  • Supplier Copilot remains limited to approved pilot material handled by authorized workspace users.
  • Scanner-deferred upload handling is accepted for the limited Hostinger pilot under the recorded compensating controls and review expiry.

Data handled by the service

  • The app can store account, organization, membership, questionnaire project, uploaded document metadata, extracted question, draft answer, approved answer, evidence, gap, tender draft, assisted-service request, session, and audit records.
  • Uploaded questionnaire files are stored outside the database through the configured storage provider; the database stores metadata and storage references.
  • Parsed previews, generated answers, evidence notes, gaps, tender prose, and exports may contain confidential questionnaire or supplier information and must be treated as sensitive.

Processing boundaries

  • Questionnaire parsing is local to the configured runtime and does not use external parsing APIs.
  • Uploaded files are not sent to AI providers during parsing.
  • AI drafting is server-side only, isolated behind provider modules, and outputs remain drafts for human review.
  • Live tender AI is staging-gated and must not be enabled for production without a new approval decision.

Storage, retention, and deletion

  • Raw uploaded files can be deleted from the project document review flow while parsed metadata remains for auditability.
  • Owner and admin users can configure upload retention and purge expired stored files.
  • Full tenant deletion is implemented through the admin tenant-deletion flow and was smoke-tested before pilot approval.
  • Backups and restore rehearsal are verified for the current temporary Hostinger local-upload plus Neon PostgreSQL posture.

Security and monitoring

  • Authenticated app routes require sign-in, and tenant-owned records are scoped by organization.
  • Hostinger private upload storage is outside the public web root and has been verified for the temporary MVP path.
  • Active malware scanning is deferred on Hostinger under accepted pilot risk controls; uploaded files are still private, locally parsed, retained, and deletable.
  • The health endpoint is token-protected, and scheduled HTTPS health checks are active; hosted webhook alert delivery is deferred for the MVP.

User commitments

  • Do not submit secrets, credentials, payment data, special-category personal data, or unapproved sensitive records.
  • Only authorized users should upload or review questionnaire material for their organization.
  • Users remain responsible for reviewing all draft answers, tender prose, gaps, evidence, and exports before customer submission.