Enterprise Confidentiality & Zero AI Training Pledge

Privacy Policy

This Privacy Policy applies to BID, a product operated by Eventro Technologies Limited. We treat competitive intelligence, internal business profiles, and executive queries with the highest level of commercial confidentiality and cryptographic isolation.

Effective Date: September 5, 2026 Version: 3.2 Eventro Technologies Limited
Our Unconditional Four-Point Privacy Guarantee
1. Zero Model Training: Your internal documents and queries are never fed into public AI foundation models.
2. Multi-Tenant Wall: Row-level isolation ensures no competitor or other organization can ever view your intelligence.
3. No Ad Retargeting: We do not sell, license, or monetize your corporate data with advertising networks.
4. Instant Data Purge: You maintain full sovereignty to export and permanently erase your organization's entire database.

1. Scope & Commitment

This Privacy Policy describes how Eventro Technologies Limited ("Eventro", "BID", "we", "our", or "us") collects, secures, processes, and disposes of information collected from users, organizations, and visitors across the Business Intelligence Desk website, applications, APIs, and progressive web apps.

We operate in accordance with global data protection frameworks, including the Nigeria Data Protection Act (NDPA), General Data Protection Regulation (GDPR), and the California Consumer Privacy Act (CCPA).

2. Information We Collect

We collect only information necessary to deliver autonomous intelligence workflows and maintain secure access to your organization's desk:

A. Account & Contact Credentials

Name, corporate email address, encrypted authentication hashes (Argon2/bcrypt), and designated team role (Owner, Analyst, Member).

B. Business Profile & Organizational Context

Company legal name, commercial focus, target customer personas, operational geographies, tracked competitors, key regulatory agencies, and strategic keywords entered during onboarding.

C. Generated Intelligence Records & Action Playbooks

Verified facts, confidence scores, custom bookmarks, Business Pulse health metrics, ACT decision matrices, and task assignments generated within your tenant.

D. Operational Telemetry & Audit Logs

Timestamps of crawler runs, search queries dispatched to external search providers, IP addresses, browser user-agents, and session identifiers used for anomaly detection and IDOR defense.

E. Payment & Billing Details

Subscription plan selections and transaction tokens. All payment processing is handled directly by PCI-DSS Level 1 compliant gateways (Paystack and Stripe). BID never stores raw payment card numbers or CVVs.

// Contractual Clause: Zero Foundation Model Training

Eventro Technologies Limited contractually guarantees that no data provided by Customer or retrieved on Customer's behalf—including internal corporate profiles, tracked entity parameters, search prompts, synthesized intelligence items, or decision artifacts—shall be utilized by BID or its external inference sub-processors to train, fine-tune, improve, evaluate, or contribute to any public or commercial artificial intelligence models.

3. How We Process Your Information

Your data is processed strictly to execute the operational purposes of the platform:

  • Autonomous Web Monitoring: Running scheduled crawlers that monitor news, tenders, and regulatory disclosures relevant to your configured subjects.
  • Entity Disambiguation & Fact Cross-Verification: Extracting verifiable factual claims and assigning empirical confidence scores.
  • Business Pulse Calculation: Computing your organization's 0–100 health index based on recent verified developments.
  • ACT Engine Execution: Producing decision options and actionable playbooks for internal operational task management.
  • Ask BID Synthesis: Formulating citation-backed answers grounded strictly in your tenant's library using PromptDefense™.
  • Platform Security & Abuse Prevention: Auditing access patterns, blocking malicious prompt injection attempts, and enforcing multi-tenant isolation boundaries.

4. Multi-Tenant Data Isolation Architecture

BID enforces strict row-level isolation at the database tier. All domain records (including subjects, monitors, intelligence items, alerts, and decisions) are tied directly to an immutable organization_id foreign key.

Every web request sets a secure tenant context (Current.organization). The application controller systematically forbids direct ID lookups without tenant scoping, making cross-tenant data leakage or Insecure Direct Object References (IDOR) impossible.

5. Authorized Third-Party Sub-Processors

We partner exclusively with enterprise infrastructure and service providers bound by strict confidentiality and data protection agreements:

Sub-Processor Category Role & Data Safeguard
PostgreSQL Infrastructure Database Hosting Encrypted at rest with AES-256; automated daily transactional backups.
Google Cloud / OpenAI / Anthropic Enterprise AI Inference Stateless enterprise API calls under zero-data-retention agreements; no model training permitted.
SerpApi / Tavily / Brave Search Web Search & Harvesting Dispatches anonymized public search queries; no corporate tenant identities are transmitted.
Paystack / Stripe Payment Processing PCI-DSS Level 1 certified billing infrastructure.
Postmark / SendGrid Transactional Email Delivers email confirmations, security notices, and critical intelligence alerts.

6. Cryptographic & Technical Safeguards

We implement rigorous technical controls to protect your data against unauthorized access or compromise:

  • Encryption in Transit: Mandatory TLS 1.3 encryption with strict HTTP Strict Transport Security (HSTS) headers.
  • Encryption at Rest: High-performance AES-256 volume and database encryption across all storage tiers.
  • PromptDefense™ Quarantine: All third-party web content retrieved by crawlers is filtered and quarantined to prevent prompt injection or exfiltration attacks.
  • Role-Based Access Control (RBAC): Granular operational permissions separating Owner, Analyst, and Member capabilities.

7. Data Retention, Sovereignty & Erasure

You maintain full sovereignty over your organizational data. You may at any time export your verified intelligence items, custom tags, monitor rules, and ACT decision matrices in machine-readable JSON or CSV formats.

If your organization cancels its subscription or requests tenant deletion, your data enters a 30-day export grace period, after which all database records, cached brief summaries, and operational logs are permanently and cryptographically purged from our primary clusters and backups within sixty (60) days.

8. Cookies & Local Storage

BID uses only strictly necessary session cookies to maintain your authenticated state and CSRF protection tokens. We do not use third-party analytics trackers, advertising cookies, or behavioral retargeting scripts.

Our Progressive Web App (PWA) utilizes standard browser Service Worker Cache Storage to cache the visual application shell for fast, reliable offline rendering.

9. Data Protection Officer (DPO) Contact

For questions regarding this Privacy Policy, to exercise your rights of access, rectification, or erasure, or to execute an enterprise Data Processing Addendum (DPA), please contact our Data Protection Officer:

Data Protection & Privacy Office:

Eventro Technologies Limited

Email: privacy@bid.desk

Security Incidents: security@bid.desk

Address: Victoria Island Commercial Corridor, Lagos, Nigeria