BharatTender
🔒BharatTender.ai

Privacy Policy

Acquorum Technologies Private Limited

CIN: U62011DL2026PTC464595

Registered Office: P No 56, Sector 12-A, Dwarka, New Delhi – 110078

Effective Date: June 2026  |  Last Updated: June 2026

1. Introduction and Scope

Acquorum Technologies Private Limited (hereinafter referred to as "the Company", "we", "us", or "our"), incorporated under the Companies Act, 2013, bearing Corporate Identification Number U62011DL2026PTC464595, operates the digital B2B procurement marketplace available at bharattender.ai and the BharatTender mobile application (collectively, the "Platform").

This Privacy Policy describes how we collect, use, store, process, disclose, and protect the personal data and business information of all users — including Buyers (companies posting tenders), Vendors (businesses submitting bids), and visitors — who access or use the Platform.

By accessing or using the Platform, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. If you do not agree with any part of this policy, you must immediately discontinue use of the Platform.

This Privacy Policy is published in compliance with:

  • The Information Technology Act, 2000 and the Information Technology (Amendment) Act, 2008
  • The Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 ("SPDI Rules")
  • The Digital Personal Data Protection Act, 2023 ("DPDPA 2023") and rules framed thereunder
  • The Reserve Bank of India's guidelines on payment data storage and processing
  • Any other applicable laws and regulations in India

2. Definitions

For the purposes of this Privacy Policy:

  • "Personal Data" means any data about an individual who is identifiable by or in relation to such data.
  • "Sensitive Personal Data or Information (SPDI)" includes passwords, financial information (bank account, debit/credit card, other payment instrument details), physical, physiological and mental health conditions, sexual orientation, medical records and history, biometric information, and any detail relating to the above.
  • "Business Data" means information pertaining to a company's procurement activities, vendor relationships, tender documents, bid data, pricing, and transactional records.
  • "Platform" refers to bharattender.ai website, associated mobile applications, APIs, and all related digital infrastructure operated by the Company.
  • "Buyer" means any company, organisation, or individual that accesses the Platform to post tenders, evaluate bids, or engage vendors.
  • "Vendor" means any company, organisation, or individual that accesses the Platform to discover opportunities, submit bids, or fulfil work orders.
  • "User" means any Buyer, Vendor, visitor, or any other person who accesses or uses the Platform.
  • "Data Fiduciary" refers to the Company, which determines the purpose and means of processing personal data.
  • "Data Principal" refers to any natural person whose personal data is processed by the Platform.

3. Information We Collect

3.1 Information Provided Directly by You

When you register, onboard, or use the Platform, we may collect:

  • Full name, designation, and professional contact details (email address, phone number)
  • Company name, registered address, GST Identification Number (GSTIN), PAN, CIN, MSME/Udyam registration number
  • Business sector, industry category, and annual turnover range
  • Director/partner/proprietor identification details as required for KYC compliance
  • Bank account details including account number, IFSC code, and account holder name (for payment and escrow-linked settlements)
  • Payment card details, UPI IDs, or other payment instrument information processed through RBI-compliant payment gateway integrations
  • Documents uploaded to the Platform including tender documents, bid proposals, certificates, compliance declarations, financial statements, work orders, and digital signatures
  • Login credentials (stored only in hashed and salted form; plaintext passwords are never stored)
  • Digital Signature Certificate (DSC) metadata used for contract execution
  • Communication records including messages sent through the Platform's internal messaging system
  • Feedback, ratings, dispute filings, and review content

3.2 Information Collected Automatically

When you access the Platform, our systems automatically collect:

  • IP address, browser type and version, operating system, device type and identifiers
  • Referring URLs, pages visited, time and date of access, duration of sessions
  • Clickstream data and interaction patterns on the Platform
  • Cookies, web beacons, pixel tags, and similar tracking technologies (see Section 10 on Cookies)
  • Google Analytics 4 data (Tracking ID: G-WLF41F8CPQ) including demographic and interest data where consented
  • Server log files capturing access events, error logs, and API call metadata
  • Device location data (city/state level, not GPS-precise) derived from IP address

3.3 Information from Third Parties

We may also receive information about you from:

  • Payment gateways and RBI-regulated payment aggregators (transaction status, payment confirmation, settlement data)
  • Escrow service providers (transaction identifiers, disbursement status)
  • KYC verification partners and credit bureaus (business verification status, GST validation results)
  • AWS infrastructure services (cloud storage and compute metadata)
  • Government databases accessed for GSTIN/PAN/CIN validation purposes
  • Any third-party integration you explicitly authorise while using the Platform

4. How We Use Your Information

We use the information we collect for the following purposes:

4.1 Platform Operations and Service Delivery

  • Creating, verifying, and maintaining your user account
  • Enabling Buyers to post, manage, and evaluate tenders
  • Enabling Vendors to discover opportunities, submit sealed bids, and manage their profiles
  • Facilitating sealed bid procurement processes and bid evaluation workflows
  • Processing, routing, and settling payments through RBI-compliant payment infrastructure
  • Generating, managing, and archiving digital contracts and work orders
  • Administering escrow-linked payment holds, releases, and reversals
  • Sending transactional notifications, tender alerts, bid status updates, and contract milestones

4.2 Compliance and Legal Obligations

  • Conducting Know Your Customer (KYC) and Know Your Business (KYB) verification
  • Complying with GST, income tax, and other statutory reporting obligations
  • Responding to lawful requests from government authorities, courts, and regulatory bodies
  • Maintaining audit trails and transaction records as required by applicable law
  • Detecting, investigating, and preventing fraud, money laundering, and other illegal activities

4.3 Platform Improvement and Analytics

  • Analysing usage patterns to improve Platform features, UI/UX, and performance
  • Conducting internal research, benchmarking, and product development
  • Generating anonymised and aggregated market intelligence reports (no personally identifiable information is included in such reports)
  • Testing new features and conducting A/B experiments
  • Training and improving AI/ML models that power Platform features (using anonymised data only)

4.4 Communication and Marketing

  • Sending product updates, feature announcements, and service notifications
  • Delivering promotional communications where you have given consent
  • Responding to your support queries, feedback, and dispute filings
  • Inviting participation in surveys, research, and feedback programmes

You may opt out of marketing communications at any time by clicking "Unsubscribe" in any email or by writing to contact@bharattender.ai.

We process your personal data on the following legal grounds:

  • Consent: Where you have given explicit consent, such as for marketing communications or cookies beyond strictly necessary.
  • Performance of Contract: Processing necessary to perform our contract with you, including account creation, tender management, payment processing, and service delivery.
  • Legal Obligation: Processing required for compliance with applicable laws including the IT Act, DPDPA 2023, GST Act, income tax laws, PMLA, and RBI regulations.
  • Legitimate Interest: Processing for fraud prevention, security, business analytics, and Platform improvement, where such interests are not overridden by your fundamental rights.

6. Data Storage, Security, and Retention

6.1 Storage Infrastructure

All data is stored on Amazon Web Services (AWS) infrastructure, including AWS EC2 compute instances and AWS Amplify hosting, operating within data centres located in India. Primary databases include PostgreSQL (relational transaction data) and MongoDB (document storage). Vector data for AI/search functionality is stored in Pinecone and Qdrant. All storage systems implement encryption at rest and in transit.

6.2 Security Measures

We implement industry-standard security measures including:

  • TLS 1.2/1.3 encryption for all data in transit
  • AES-256 encryption for sensitive data at rest
  • Salted and hashed storage for all passwords using bcrypt or equivalent
  • Role-based access control (RBAC) limiting internal access to data on a need-to-know basis
  • Secure API architecture using JWT authentication and GraphQL with field-level authorisation
  • Regular penetration testing and vulnerability assessments
  • Web Application Firewall (WAF) and DDoS protection
  • Multi-factor authentication for admin and high-privilege accounts
  • Automated backups with point-in-time recovery capabilities

Despite these measures, no system is completely secure. In the event of a data breach affecting your personal data, we will notify you and relevant authorities as required under applicable law.

6.3 Retention Periods

We retain your data for the following periods:

  • Active account data: For the duration of your account's existence on the Platform, plus 5 years after account closure
  • Transaction records (tenders, bids, contracts, payments): 7 years from the date of transaction, in compliance with statutory audit and taxation requirements
  • KYC and verification documents: 5 years from the date of last transaction, per PMLA requirements
  • Communication logs and messages: 3 years from the date of communication
  • Server and access logs: 12 months
  • Payment data held by payment gateways: As per the respective gateway's RBI-mandated retention policies
  • Dispute and legal hold data: Until the dispute or legal proceeding is fully resolved, plus applicable statutory limitation periods

7. Sharing and Disclosure of Your Data

7.1 Sharing with Other Platform Users

By participating on the Platform, you acknowledge and consent to the following limited disclosures:

  • Buyers' company name, industry, and tender details are visible to verified Vendors who match the tender's eligibility criteria
  • Vendors' company name, registered state, and verified status are visible to Buyers evaluating bids
  • Individual bid pricing and proposal content remain sealed and confidential until the Buyer initiates the bid opening process
  • Post-award, the winning Vendor's company name and work order details are shared with the Buyer
  • Dispute communications may be reviewed by both parties in a structured process administered by BharatTender

7.2 Sharing with Service Providers

We share data with trusted third-party service providers who process data on our behalf under strict confidentiality agreements, including:

  • Cloud infrastructure providers (Amazon Web Services)
  • Payment gateway and payment aggregator partners (RBI-licensed)
  • Escrow service providers (regulated financial institutions)
  • KYC/KYB verification partners
  • Email and SMS communication service providers (transactional notifications only)
  • Analytics providers (Google Analytics 4 — anonymised aggregate data only)
  • Legal, audit, and professional advisors under attorney-client or similar privilege

7.3 Government and Legal Disclosure

We may disclose your data without notice if required to do so by law, court order, or governmental authority, or if we believe in good faith that such disclosure is necessary to:

  • Comply with a legal obligation
  • Protect the rights, property, or safety of the Company, our users, or the public
  • Detect, prevent, or address fraud, security breaches, or technical issues
  • Enforce our Terms and Conditions

7.4 Business Transfers

In the event of a merger, acquisition, restructuring, or sale of all or part of the Company's assets, your data may be transferred to the acquiring entity, subject to equivalent or higher data protection standards. We will notify affected users of any such transfer.

7.5 No Sale of Personal Data

We do not sell, rent, or trade your personal data to third parties for their independent marketing or commercial purposes. BharatTender.ai and its products are free from third-party advertising.

8. Your Rights as a Data Principal

Under the Digital Personal Data Protection Act, 2023, and applicable regulations, you have the following rights:

  • Right to Access: Request a copy of personal data we hold about you and information on how it is processed.
  • Right to Correction: Request correction of any inaccurate or incomplete personal data.
  • Right to Erasure: Request deletion of your personal data where it is no longer necessary for the purposes for which it was collected, subject to legal retention obligations.
  • Right to Withdraw Consent: Withdraw consent at any time for processing based on consent, without affecting the lawfulness of prior processing.
  • Right to Grievance Redressal: Raise a grievance with our Grievance Officer (details in Section 13).
  • Right to Nominate: Nominate another individual to exercise rights on your behalf in the event of death or incapacity.

To exercise any of these rights, write to us at contact@bharattender.ai with the subject line "Data Rights Request" and your registered email address. We will respond within 30 days.

9. Payment Data and Financial Information

BharatTender operates as a neutral technology intermediary and does not directly hold or process payment funds. All payment processing is handled by RBI-licensed payment gateways and payment aggregators. The following applies to financial data on the Platform:

  • Payment card data (card numbers, CVVs) is never stored on BharatTender's servers. All card data is tokenised and processed exclusively by our certified PCI-DSS compliant payment gateway partners.
  • Bank account details provided for settlement purposes are stored in encrypted form and accessed only for the purpose of initiating approved settlements.
  • Escrow-linked transactions are processed through regulated financial institutions and are governed by applicable RBI guidelines on escrow accounts.
  • UPI transaction references and payment confirmation data are retained for reconciliation and dispute resolution purposes for 7 years.
  • Transaction metadata (amount, date, parties, status) is retained as part of the tender/contract record for audit and legal compliance purposes.

Any dispute related to a payment transaction must be raised at contact@bharattender.ai within 7 days of the disputed transaction.

10. Cookies and Tracking Technologies

We use the following types of cookies and tracking technologies:

  • Strictly Necessary Cookies: Essential for Platform functionality, login sessions, and security. Cannot be disabled.
  • Analytics Cookies: Google Analytics 4 (GA4, Tracking ID: G-WLF41F8CPQ) collects anonymised usage data to help us understand how users interact with the Platform. You may opt out via Google's opt-out browser add-on.
  • Functional Cookies: Store your preferences (language, theme, notification settings) to personalise your experience.
  • Session Cookies: Temporary cookies that expire when you close your browser, used to maintain your login state.

You may control cookie preferences through your browser settings. Disabling cookies may impair certain Platform functionality. We do not use advertising or cross-site tracking cookies.

11. Artificial Intelligence and Automated Processing

BharatTender incorporates an agentic AI layer to power features including intelligent tender matching, vendor recommendation, bid analysis, and procurement insights. The following principles govern AI processing:

  • AI features use anonymised or pseudonymised data where possible. Personally identifiable information is not used to train external AI models.
  • AI-generated tender evaluations or vendor recommendations are advisory in nature. All final procurement decisions are made by the Buyer.
  • Our AI infrastructure uses vector databases (Pinecone and Qdrant) to power semantic search. Bid content and tender documents stored in these systems are subject to the same security and access controls as other Platform data.
  • Users may request that their data be excluded from AI-driven analytics by writing to contact@bharattender.ai.

12. Children's Privacy

The Platform is designed exclusively for businesses and professionals. We do not knowingly collect personal data from individuals under the age of 18. If you believe a minor has provided us with personal data, please contact us at contact@bharattender.ai and we will take appropriate action to delete such data.

13. Grievance Officer and Contact Information

In accordance with the Information Technology Act, 2000 and the DPDPA 2023, the following officer is designated to address data-related grievances:

Grievance Officer: Rankit Singh

Designation: Co-Founder, Acquorum Technologies Private Limited

Email: contact@bharattender.ai

Postal Address: P No 56, Sector 12-A, Dwarka, New Delhi – 110078

We will acknowledge grievances within 48 business hours and endeavour to resolve them within 30 days of receipt.

14. Cross-Border Data Transfers

BharatTender's primary data infrastructure is located within India. Where data is processed by third-party service providers whose servers may be located outside India (including analytics and communication tools), we ensure that such transfers are governed by standard contractual clauses or equivalent safeguards and comply with applicable Indian data protection laws.

15. Amendments to This Policy

We reserve the right to modify this Privacy Policy at any time. Significant changes will be communicated to registered users via email to the address on file and/or via a prominent notice on the Platform at least 14 days before the change takes effect. Continued use of the Platform after the effective date of any change constitutes acceptance of the updated policy.

The current version of this Privacy Policy is always available at: bharattender.ai/privacy-policy

16. Governing Law and Jurisdiction

This Privacy Policy is governed by the laws of India. Any disputes arising under or in connection with this Privacy Policy shall be subject to the exclusive jurisdiction of the courts in New Delhi, India.

© 2026 Acquorum Technologies Private Limited. All rights reserved. | bharattender.ai

← Back to Home