Data Handling & Retention Policy
This Data Handling & Retention Policy outlines how RFP Auto-Filler collects, processes, and stores data provided by its users. Our commitment is to ensure the highest level of security and privacy for your enterprise documentation.
1. Data Collection and Usage
We collect data necessary to provide our RFP automation services, including uploaded SOC 2 reports, internal policies, and compliance documentation. This data is used solely to populate security questionnaires via our browser extension and to improve the self-learning capabilities of your private instance.
2. Data Security
All data is encrypted at rest and in transit using industry-standard protocols. We implement strict access controls and regular security audits to maintain the integrity of your information. RFP Auto-Filler does not train global models on your private company data.
3. Data Retention
We retain your data only for as long as your account remains active or as needed to provide you with our services. Upon termination of service, all knowledge base documents and logging data are permanently deleted within 30 days, unless otherwise required by law.
4. Compliance
Our procedures are designed to meet SOC 2 and ISO 27001 requirements. We provide users with the tools necessary to manage their data footprints and ensure compliance with their own internal governance standards.
We may update this policy from time to time to reflect changes in our practices or regulatory requirements. Users will be notified of significant changes via email or through the platform interface.