BidCaliber Privacy Policy and Data Processing Addendum
Version 0.10, 3 October 2026. In force from 3 October 2026. Counsel review is pending; a revised version will be put to you for acceptance when it is ready. Part A is the Privacy Policy (how we handle personal data as the party in charge of it). Part B is the Data Processing Addendum (how we handle your workspace's data on your instructions). Square brackets mark facts to fill in. The India DPDP Act's operative rules are expected from 13 May 2027; this document is written to meet them and the GDPR now.
Part A. Privacy Policy
A1. Who we are
Webnotics Private Limited, CIN U72900UP2020PTC134552, GSTIN 09AACCW7481N1ZI, Unit No 307, Padam Corporate Park, Avas Vikas Colony, Sector 13, Sikandra, Agra, Uttar Pradesh 282007, India ("BidCaliber", "we"). Grievance Officer and data-protection contact: Lalit Yadav, [email protected], at the address above.
A2. What we collect and why
| Data | Where from | Why | Basis |
|---|---|---|---|
| Your name, work email, workspace name, and the mobile number (with country code) of the person who founds a workspace | You, at signup | To run your account; the mobile number for account and payment notices only (it is passed to Razorpay for payment notices when an Indian workspace buys a plan) and never shown to your team; you can change or remove it in My settings | Contract |
| Early-access request: your name, work email, agency name, the plan you clicked, your team size if you chose a team plan, and whether we have invited or declined you | You, on the request form | To send you a sign-in link when a workspace can be opened and to size your plan; nothing else, no marketing without your separate consent. Ask us and we delete the request | Steps before a contract, at your request (DPDP s.7(a) voluntary provision) |
| Acceptance record: version of each document, time, IP address | Your acceptance click | To prove the agreement | Contract, legal obligation |
| Sign-in data: session tokens, Google account id if you use Google sign-in | Sign-in | To keep you signed in | Contract |
| Your Upwork connection: tokens (encrypted), account id, org id | Upwork, when you connect | To fetch jobs and submit proposals on your instruction | Contract |
| Jobs and client details read from a marketplace: job text, budget, client country, spend, hire rate, feedback figures; screenshots you upload | You, or the marketplace on your click | To screen the job and draft the proposal | Legitimate interest of your workspace in evaluating a job it may bid on; see A4 |
| Your catalogue, profile, rules, notes, drafts, reviews, verdicts, outcomes | You, and the service as you use it | To run the service and keep your bid record | Contract |
| Workspace logo and name | Your organisation admin | Shown to your own people in the app, in invitation emails and on invoices | Contract; Terms section 6B |
| Bidder performance figures (speed, quality, process, selection scores) | Derived from the bid record | Coaching within your workspace; see A5 | Workspace's legitimate interest; your workspace is responsible for telling its people |
| Model usage: tokens and cost per call | The service | Billing and cost reporting | Contract |
| Forwarded job-alert emails: the job link, arrival time, and the lines the marketplace printed (title, budget, client country, payment status, spend, bid count, skills); the registered forwarding address; a received log of time, result and reason | Your admin forwards them | Pre-screening alerts; nothing is fetched until a person opens the row | Contract; the lines expire with the task or at 30 days, the raw email is discarded after parsing |
| Learnings you choose to send: your own comment text, verdict, rule names, review score, bid outcome, organisation label, an opaque sender id | A manager or bidder, by ticking the box on that item | Finding and fixing product problems; telling the sender the outcome | Our legitimate interest in improving the product; the sender's choice for their own words; see A5a |
| Billing: plan, seats, the name the invoice is made out to, billing address, city, postal code and country, state or GSTIN for India, the payment provider's customer and subscription ids, subscription status, invoices; card and UPI details are held by the payment provider, never by us | Organisation admin at purchase, and the provider's webhooks | Charging for the service, issuing the tax invoice the law requires, GST and export-of-services compliance | Contract, legal obligation |
| Server logs, audit log of fetches, overrides, submissions, deletions | The service | Security, proof of compliance | Legitimate interest, legal obligation |
We do not collect marketplace passwords, payment card details (until billing launches, when a payment provider will), or data about children.
A3. How long we keep it
| Data | Kept until |
|---|---|
| Marketplace-sourced job and client details, screenshots | The job's task ends (skip, or proposal closes), and never more than 30 days after fetch or upload |
| Your workspace's own records (verdicts, rule names, drafts, reviews, outcomes, notes, scores) | You delete the job or the workspace |
| Workspace logo | You replace or remove it, or delete the workspace |
| Account and acceptance records | Account deletion, then [1 year] for legal defence |
| Early-access request | 180 days while waiting, then deleted; 30 days after we invite or decline you; at once if you ask |
| Upwork tokens | You disconnect, or we detect revocation; then at once |
| Audit log | [1 year] minimum, then deleted; it holds no marketplace content |
| Billing records (invoices with the invoice name and address, charges, provider ids, billing country, state, GSTIN) | 8 years after the last charge (Companies Act s.128; CGST Act s.36), even if the workspace is deleted |
| Mobile number | Until you remove it in My settings or delete your account |
| Model usage records | 8 years, as billing records |
| Backups | Daily database backups kept 7 days; a purged or deleted record disappears from backups within 7 days |
A4. Data about people who are not our users
A job listing can name a client, their company and figures about their history on the marketplace. We hold that only to let your workspace decide whether to bid, for the time in A3, visible only to the workspace that brought it in. We never build a profile of a client across jobs or workspaces, never derive a client's hourly rate, and never contact a client. If you are such a client and want to know whether a workspace holds a job you posted, write to the Grievance Officer; we will ask the workspace and delete on request where the law requires.
A5. Bidder scores
If you bid through a workspace, your workspace owner can see your bids and your scores. The scores are computed by fixed rules in code, not by an AI model, and you can see your own scores and what went into them. BidCaliber does not make decisions about your work; your workspace does. Your workspace is responsible for telling you about this monitoring under its own law.
A5a. Learnings
A learning is de-identified before it leaves your workspace: no job text, client details, screenshots, links, and no name or id of the bidder whose bid was reviewed. The sender is known to us only by an opaque id, mapped back to a person only inside your workspace so they can see the outcome. We scan the comment text and remove names, links and addresses. Learnings are kept for [24 months], counted across organisations under labels, and never used to train an AI model. Your workspace is responsible for telling its people that managers may send learnings.
A6. Who else sees your data
| Provider | What | Where | Why |
|---|---|---|---|
| DigitalOcean, LLC | Hosting (App Platform) and managed Postgres database; Spaces object storage for screenshots, which we encrypt before storing so DigitalOcean holds only ciphertext | Hosting and database in Bangalore, India (blr1); screenshot storage in Singapore (sgp1). DigitalOcean is a US company; its Data Processing Agreement with Standard Contractual Clauses applies | Running the service |
| Microsoft Azure | Preview environments only; no customer data | [Region] | Testing before release |
| Anthropic | Job text, screenshots, catalogue facts and drafts sent for extraction, drafting and review | United States | AI model. Not retained by Anthropic by default on the models we use; never used to train |
| Resend, Inc. | Your email address, the sign-in link, invitation emails (workspace name, inviter's name, workspace logo) and support-session notices (support person's name, ticket id, reason); never marketplace content | United States | Sends the service's email from [email protected] |
| Microsoft 365 (Microsoft Corporation) | Email you send to [email protected] or [email protected], including grievances and security reports | [Region of the Microsoft 365 tenant] | Our mailbox for human correspondence |
| Your Google account id and email, only if you choose Google sign-in | United States | Sign-in | |
| Upwork | What you ask us to fetch or submit | United States | Your marketplace |
| Destinations you configure: a Teams or Slack channel by webhook, your email digest, browser push | Job title, budget line, marketplace name and link only | Wherever your own service runs | Alerting your team; these are your own providers, switched on by your admin |
| Stripe, Inc. | For workspaces billed outside India: the invoice name, organisation admin email, billing address, card details (held by Stripe), subscription and invoices | United States | Payments in US dollars |
| Razorpay Software Private Limited | For workspaces billed in India: the invoice name, organisation admin email and mobile number (for payment notices), GSTIN and state, card or UPI details and the recurring-payment mandate (held by Razorpay), subscription and receipts | India | Payments in rupees |
We do not sell personal data. Account, workspace, billing, early-access and marketplace data are never shared for advertising or used to build advertising audiences. Visits to our website bidcaliber.com are measured by advertising partners only with your consent, as A6a describes.
A6a. Advertising and website measurement (bidcaliber.com only)
We advertise BidCaliber on Meta (Facebook and Instagram), Google and LinkedIn. To measure those ads and to show them to people who visited our site, bidcaliber.com can load those partners' measurement tags (the Meta Pixel, the Google tag, the LinkedIn Insight Tag). They load only after you choose "Accept" in the banner on the site; choose "Reject" and nothing from these partners is requested, and the site works the same. You can change your choice at any time from "Cookie choices" in the site footer, and a browser Global Privacy Control signal is treated as "Reject".
| What | Detail |
|---|---|
| Where | bidcaliber.com only. No tag runs inside the app (app.bidcaliber.com, admin.bidcaliber.com), on sign-in, sign-up or legal pages, or in our emails |
| Data, after consent | The pages you view and the page that referred you, the click identifiers on an ad link (gclid, fbclid, li_fat_id), events such as "viewed pricing" and "signed up", and the partner's cookie identifiers; the partner itself records your IP address and browser details |
| Never | Your email address (plain or hashed), name, workspace or agency name, plan, payment, anything from inside the app, anything read from a marketplace |
| Partners | Meta Platforms Ireland Limited (EU/UK visitors) and Meta Platforms, Inc. (others); Google Ireland Limited (EU/UK) and Google LLC (others); LinkedIn Ireland Unlimited Company (EU/UK) and LinkedIn Corporation (others). For the collection on our site they act with us as joint controllers (EU/UK) or as independent controllers, under their own privacy policies; for what they do afterwards they are controllers in their own right |
| Purposes | Measuring whether an ad led to a visit or a sign-up; showing BidCaliber ads to people who visited the site; building similar audiences on the partner's side |
| Basis | Your consent (GDPR Art. 6(1)(a) and ePrivacy; DPDP Act s.6). Withdrawal takes effect from the next page load |
| Retention | Your consent choice is kept in your browser for up to twelve months. Partner cookies last up to thirteen months; the partners' own retention is in their policies |
| Opt out at the partner | Meta: Ad preferences in your Facebook or Instagram settings. Google: My Ad Center and the Google Analytics opt-out add-on. LinkedIn: Ads settings in your LinkedIn account |
We never upload customer lists to these partners and never match our users to their accounts.
A7. International transfers
We are in India and the service is hosted in India (DigitalOcean, Bangalore), with encrypted screenshot storage in Singapore. Data about people in the EU or UK that your workspace brings in is therefore transferred to India, and encrypted screenshots to Singapore. We rely on the EU Standard Contractual Clauses and the UK Addendum (with us, in Part B; with DigitalOcean and Anthropic, in their agreements) and on a transfer impact assessment we keep on file. India has no data-localisation requirement for this service.
A8. Security
Encryption in transit. Screenshots are encrypted by the application itself (AES-256-GCM) before they are stored, with a key held only in the application's environment, so the storage provider holds ciphertext; Upwork tokens, webhook addresses and alert tokens are encrypted or hashed with the same key material; the database runs under a least-privilege role; access by role; audit logging; daily backups kept 7 days. Report a security problem to [email protected].
A9. Your rights
Under the DPDP Act (India): access to a summary of your data, correction, erasure, a grievance route, the right to nominate someone to act for you. Under the GDPR/UK GDPR: access, rectification, erasure, restriction, portability, objection, and a complaint to your supervisory authority. For website advertising cookies, use the banner or the footer link to withdraw consent. Write to the Grievance Officer for anything else. We answer within [30 days]. Workspace owners can export and delete their workspace from Settings without asking us.
A10. Changes
We will ask you to accept a new version on sign-in when the change matters. The version you accepted is recorded.
Part B. Data Processing Addendum
B1. Roles
For the data your workspace puts into BidCaliber and what the service derives from it (jobs, screenshots, client details, catalogue, drafts, verdicts, records, bidder scores), you (the customer) are the controller (the Data Fiduciary under the DPDP Act) and BidCaliber is the processor (the Data Processor). For your account, acceptance and billing data, BidCaliber is the controller, as Part A describes.
B2. Our instructions
We process workspace data only to provide the service as the Terms and your settings instruct, and as the law requires. We will tell you if an instruction appears to break the law.
Two things sit outside these instructions and are processed on our own account as controller, as the Privacy Policy states: account, acceptance and billing data; and learnings a person in your workspace chooses to send (Terms section 6A, Privacy Policy A5a). Support staff access to your workspace happens only at your organisation admin's request with a ticket reference, as a time-limited "view as" session of one of your users: at most 30 minutes, with a stated reason, shown by a red bar, blocked from sending bids, fetching from any marketplace, connecting or disconnecting marketplace logins, accepting terms, and billing, role or invitation changes, and written to your organisation's own log, which the person viewed and your admin can read. At your organisation admin's request, with a ticket or reason, our console can add a person to your workspace, change a person's name, sign-in email, role or manager, or pause and resume their access; each such action is written to your workspace's audit trail as done by BidCaliber support, with the reason, and emailed to your organisation admins and the person; a sign-in email change, an invitation or a promotion to manager or admin takes effect only once one of your organisation admins confirms it. The console can also grant your workspace a plan at no charge. It has no other path into a workspace's bids, and it cannot delete a person or a record.
B3. People who work for us
Only staff and contractors who need access have it, under a duty of confidentiality.
B4. Security
As in A8. We review these measures at least yearly.
B5. Sub-processors
The providers in A6 are our sub-processors. We will give 30 days' notice before adding or replacing one, by email to the workspace owner. You may object on reasonable data-protection grounds; if we cannot resolve it you may end the service and we will delete your data.
B6. Helping you with people's rights
If someone exercises a right over data in your workspace, we will pass the request to you within [5 working days] and help you answer it, including finding and deleting every record about a named client across your workspace.
B7. Security incidents
We will tell the workspace owner without undue delay, and within 48 hours of confirming a personal-data breach affecting your workspace, with what we know, what we are doing, and what you may need to report. (India: a breach must be reported to affected people and the Data Protection Board without delay and in detail within 72 hours; EU/UK: to the supervisory authority within 72 hours. Those reports are yours to make for workspace data; ours for account data.) We also report security intrusions to Upwork as its terms require.
B8. Impact assessments
For bidder performance monitoring and for the use of marketplace client data, you may need an assessment under your law. We will give you the information you need, including a template for the bidder-scoring assessment.
B9. Deletion and return
You can export and delete your workspace at any time. On termination we delete workspace data within 30 days, except what the law requires us to keep (A3). Marketplace-sourced data follows the shorter A3 periods regardless. On request we certify deletion in writing.
B10. Audits
Once a year, on 30 days' notice, you may ask us for evidence of compliance with this addendum, and where that is not enough, for an audit at your cost by an auditor we do not reasonably object to.
B11. Transfers
Where this addendum involves transferring data about people in the EU/EEA, the UK or Switzerland to us in India, the EU Standard Contractual Clauses (Module Two, controller to processor), the UK International Data Transfer Addendum and the Swiss amendments are incorporated by reference, with you as data exporter and us as data importer. [Counsel: attach Annexes I to III (parties, description of processing, security measures) and decide the governing-law and forum options the clauses require.]
B12. DPDP-specific
Where the DPDP Act applies to your workspace, we process only under this contract (section 8(2)), delete when you ask or when the purpose is served, keep the logs the Rules require, and help you meet your notice, consent and grievance duties for the people whose data you bring in.
B13. Term and precedence
This addendum lasts as long as we hold workspace data for you. If it conflicts with the Terms on a data-protection point, this addendum wins; the Standard Contractual Clauses win over both.