Privacy Policy
This Privacy Policy applies to BID, a product operated by Eventro Technologies Limited. We treat competitive intelligence, internal business profiles, and executive queries with the highest level of commercial confidentiality and cryptographic isolation.
1. Scope & Commitment
This Privacy Policy describes how Eventro Technologies Limited ("Eventro", "BID", "we", "our", or "us") collects, secures, processes, and disposes of information collected from users, organizations, and visitors across the Business Intelligence Desk website, applications, APIs, and progressive web apps.
We operate in accordance with global data protection frameworks, including the Nigeria Data Protection Act (NDPA), General Data Protection Regulation (GDPR), and the California Consumer Privacy Act (CCPA).
2. Information We Collect
We collect only information necessary to deliver autonomous intelligence workflows and maintain secure access to your organization's desk:
A. Account & Contact Credentials
Name, corporate email address, encrypted authentication hashes (Argon2/bcrypt), and designated team role (Owner, Analyst, Member).
B. Business Profile & Organizational Context
Company legal name, commercial focus, target customer personas, operational geographies, tracked competitors, key regulatory agencies, and strategic keywords entered during onboarding.
C. Generated Intelligence Records & Action Playbooks
Verified facts, confidence scores, custom bookmarks, Business Pulse health metrics, ACT decision matrices, and task assignments generated within your tenant.
D. Operational Telemetry & Audit Logs
Timestamps of crawler runs, search queries dispatched to external search providers, IP addresses, browser user-agents, and session identifiers used for anomaly detection and IDOR defense.
E. Payment & Billing Details
Subscription plan selections and transaction tokens. All payment processing is handled directly by PCI-DSS Level 1 compliant gateways (Paystack and Stripe). BID never stores raw payment card numbers or CVVs.
Eventro Technologies Limited contractually guarantees that no data provided by Customer or retrieved on Customer's behalf—including internal corporate profiles, tracked entity parameters, search prompts, synthesized intelligence items, or decision artifacts—shall be utilized by BID or its external inference sub-processors to train, fine-tune, improve, evaluate, or contribute to any public or commercial artificial intelligence models.
3. How We Process Your Information
Your data is processed strictly to execute the operational purposes of the platform:
- Autonomous Web Monitoring: Running scheduled crawlers that monitor news, tenders, and regulatory disclosures relevant to your configured subjects.
- Entity Disambiguation & Fact Cross-Verification: Extracting verifiable factual claims and assigning empirical confidence scores.
- Business Pulse Calculation: Computing your organization's 0–100 health index based on recent verified developments.
- ACT Engine Execution: Producing decision options and actionable playbooks for internal operational task management.
- Ask BID Synthesis: Formulating citation-backed answers grounded strictly in your tenant's library using PromptDefense™.
- Platform Security & Abuse Prevention: Auditing access patterns, blocking malicious prompt injection attempts, and enforcing multi-tenant isolation boundaries.
4. Multi-Tenant Data Isolation Architecture
BID enforces strict row-level isolation at the database tier. All domain records (including subjects, monitors, intelligence items, alerts, and decisions) are tied directly to an immutable organization_id foreign key.
Every web request sets a secure tenant context (Current.organization). The application controller systematically forbids direct ID lookups without tenant scoping, making cross-tenant data leakage or Insecure Direct Object References (IDOR) impossible.
5. Authorized Third-Party Sub-Processors
We partner exclusively with enterprise infrastructure and service providers bound by strict confidentiality and data protection agreements:
| Sub-Processor | Category | Role & Data Safeguard |
|---|---|---|
| PostgreSQL Infrastructure | Database Hosting | Encrypted at rest with AES-256; automated daily transactional backups. |
| Google Cloud / OpenAI / Anthropic | Enterprise AI Inference | Stateless enterprise API calls under zero-data-retention agreements; no model training permitted. |
| SerpApi / Tavily / Brave Search | Web Search & Harvesting | Dispatches anonymized public search queries; no corporate tenant identities are transmitted. |
| Paystack / Stripe | Payment Processing | PCI-DSS Level 1 certified billing infrastructure. |
| Postmark / SendGrid | Transactional Email | Delivers email confirmations, security notices, and critical intelligence alerts. |
6. Cryptographic & Technical Safeguards
We implement rigorous technical controls to protect your data against unauthorized access or compromise:
- Encryption in Transit: Mandatory TLS 1.3 encryption with strict HTTP Strict Transport Security (HSTS) headers.
- Encryption at Rest: High-performance AES-256 volume and database encryption across all storage tiers.
- PromptDefense™ Quarantine: All third-party web content retrieved by crawlers is filtered and quarantined to prevent prompt injection or exfiltration attacks.
- Role-Based Access Control (RBAC): Granular operational permissions separating Owner, Analyst, and Member capabilities.
7. Data Retention, Sovereignty & Erasure
You maintain full sovereignty over your organizational data. You may at any time export your verified intelligence items, custom tags, monitor rules, and ACT decision matrices in machine-readable JSON or CSV formats.
If your organization cancels its subscription or requests tenant deletion, your data enters a 30-day export grace period, after which all database records, cached brief summaries, and operational logs are permanently and cryptographically purged from our primary clusters and backups within sixty (60) days.
8. Cookies & Local Storage
BID uses only strictly necessary session cookies to maintain your authenticated state and CSRF protection tokens. We do not use third-party analytics trackers, advertising cookies, or behavioral retargeting scripts.
Our Progressive Web App (PWA) utilizes standard browser Service Worker Cache Storage to cache the visual application shell for fast, reliable offline rendering.
9. Data Protection Officer (DPO) Contact
For questions regarding this Privacy Policy, to exercise your rights of access, rectification, or erasure, or to execute an enterprise Data Processing Addendum (DPA), please contact our Data Protection Officer:
Eventro Technologies Limited
Email: privacy@bid.desk
Security Incidents: security@bid.desk
Address: Victoria Island Commercial Corridor, Lagos, Nigeria