Privacy notice
How Biddable handles personal data.
Who we are, what we collect and why, where it is processed, how long we keep it, how it is protected, and your rights. Written for website visitors, applicants and the people who use a customer's space.
Last updated 5 October 2026.
This notice explains how Toga EMEA FZC LLC (we, us), the company that owns and operates Biddable, handles personal data when you visit biddable.ae, apply for access, or use the Biddable service at app.biddable.ae and in its phone and tablet apps. Biddable is a hosted service for bid teams and freelance bid writers: it reads a tender pack against a customer's own rules, gives a bid or no-bid view, and drafts the response in the customer's templates. It is a business service, not a consumer one.
It is written to meet the UAE Personal Data Protection Law and, for people in the European Economic Area and the United Kingdom, the GDPR and the UK GDPR (section 2). Where they differ we apply the stricter standard to your data.
1. Who we are and how to reach us
1.1 Toga EMEA FZC LLC is a free zone limited liability company incorporated in the Sharjah Publishing City Free Zone, Sharjah, United Arab Emirates, licence number 4311946.01. Our address is Business Centre, Sharjah Publishing City Free Zone, Sharjah, United Arab Emirates. You can reach us at hello@biddable.ae or by post there.
1.2 We are the controller of the personal data described in sections 3 and 4: the data of people who visit this website, apply for access, use Biddable as a member of a customer's space, or deal with us as a customer or supplier contact.
1.3 For the content a customer puts into its Biddable space (tender documents, drafts, CVs, pricing, correspondence and the customer's own rules), the customer decides what is processed and why. For that content the customer is the controller and we are its processor, under the Biddable Data Processing Addendum. Section 5 describes that processing so that you can see the whole picture, but the customer's own privacy notice governs it.
1.4 We have not appointed a data protection officer. The director responsible for data protection can be reached at hello@biddable.ae.
2. Which laws apply
2.1 Our home law is the United Arab Emirates' Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (the PDPL). This notice is our statement under it.
2.2 If you are in the European Economic Area, the General Data Protection Regulation (EU) 2016/679 (the GDPR) also applies to our processing of your data. If you are in the United Kingdom, the UK GDPR and the Data Protection Act 2018 apply. Section 12 lists the rights each of these laws gives you and how to use them.
2.3 Under the GDPR and UK GDPR, the legal bases we rely on are named beside each purpose in section 3. Under the PDPL we rely on the corresponding grounds it permits: processing necessary for a contract with you or at your request before one, processing required by law, and the other grounds the PDPL allows without consent. Where the PDPL requires your consent for a particular activity we ask for it first, and you may withdraw it at any time.
3. What we collect about you, why, and on what basis
We collect only what each purpose needs. Nothing on this list is sold or used for advertising.
- A visitor to biddable.ae
What we collect: Server request logs: your network (IP) address, the time, the page requested, your browser type and, if your browser sends one, the page that linked to us. No cookies, no analytics, no tracking.
Why: To run and secure the website, diagnose faults and defend against abuse.
Legal basis (GDPR / UK GDPR): Legitimate interests (Article 6(1)(f)): keeping the site available and secure. - An applicant for access
What we collect: What you type into the application form: your name, work email, role, company, company type, team size, what you bid for, an optional note, your consent to be contacted, and the date and source of the application.
Why: To consider your application, reply to you and, if we accept it, set up your space and your sign-in.
Legal basis (GDPR / UK GDPR): Steps at your request before a contract (Article 6(1)(b)); legitimate interests in choosing pilot customers. - A user of a customer's space (owner, writer or reviewer)
What we collect: Your name, work email and role in the space; how you sign in: a password (stored only as a salted hash), emailed one-time codes, an authenticator-app seed (stored encrypted), a passkey's public key, hashed recovery codes, or your organisation's single sign-on identity (your email and its domain); a sign-in history (time, method, browser and platform, network address, success or failure); the account's audit log (members added or removed and by whom, second factors reset, sign-in settings changed); your sessions; the emails we send you about your account; and which bids your space has used against its plan.
Why: To provide the service under our contract with your organisation, to keep your account secure, to tell you about security events on it, and to bill your organisation correctly.
Legal basis (GDPR / UK GDPR): Performance of a contract (Article 6(1)(b)); legitimate interests (Article 6(1)(f)) in account security; legal obligation (Article 6(1)(c)) for billing records. - A customer, supplier or business contact
What we collect: Your name, role, employer, contact details, the contents of our correspondence, and the contract, order, invoice and payment records of your organisation. We do not collect card details today; if we add a payment provider it will handle them and be added to our processor list first.
Why: To negotiate, sign and perform contracts, to invoice and be paid, to answer you, and to keep the records the law requires.
Legal basis (GDPR / UK GDPR): Performance of a contract (Article 6(1)(b)); legal obligation (Article 6(1)(c)) for tax and commercial records; legitimate interests (Article 6(1)(f)) in running our business. - Anyone who emails us
What we collect: Your email address, what you write, and our replies.
Why: To answer you and keep a record of what was agreed.
Legal basis (GDPR / UK GDPR): Legitimate interests (Article 6(1)(f)); performance of a contract where you are a customer.
We do not ask for, and do not want, special categories of personal data (health, beliefs, biometrics used to identify you, and so on) or criminal-record data about you. Passkeys use your device's own fingerprint or face check; the biometric never leaves your device and we never receive it.
4. What we do not do
- This website sets no cookies and uses no analytics, advertising or tracking. It loads nothing from third parties.
- We do not sell personal data, share it for marketing, or build profiles of you.
- We do not send marketing email. If we ever ask to, we will ask for your consent first and every message will have an unsubscribe link.
- We make no decision about you by automated means alone that has a legal or similarly significant effect. Biddable's bid or no-bid view and its drafts are about tenders, not about people, and a person in the customer's team decides what to do with them.
5. Content in a customer's space: what we do as processor
5.1 A customer's space may contain personal data the customer puts there: the names and contact details of people at the buying organisation named in a tender pack, the CVs and rates of the customer's own staff or candidates, the customer's team's names and roles, and correspondence. The customer is responsible for having the right to use that data in Biddable and for telling the people concerned.
5.2 We process it only to do the customer's work: to store it in that customer's own space, to read it and produce the outputs the customer asks for (a bid or no-bid view, a brief, a draft response, a costing, an audit), to back it up, and to support the customer. Producing an output means sending the relevant text to a cloud AI model provider under enterprise terms (section 7).
5.3 Each customer's space has its own database and file store on our server. Content is never shared with another customer, never used to improve the service for anyone else, never copied to our own document stores, and never used to train any model, by us or by our providers.
5.4 Named members of our staff operate the service and can open a customer's space to set it up, to help when the customer asks, and to investigate a fault or a security event. They are bound by confidentiality, use only the access the task needs, and never take content out of the space. The Data Processing Addendum and the Terms of Service say so in binding terms.
5.5 For anything about your data inside a customer's space, ask that customer first. We help customers answer such requests, and we will point you to the right organisation if you contact us directly.
6. Who receives personal data
We use a small number of service providers (processors) to run Biddable. On this page we describe them by category. The current list of their names and locations is in Annex 3 of our Data Processing Addendum and is available to any customer or prospective customer on request at hello@biddable.ae.
- Hosting provider
What they do for us: Runs the server that hosts the website, the service and every customer space. Keeps our encrypted nightly backups on a separate storage service.
Where: Data centre in Nuremberg, Germany; backup storage in the European Union.
Safeguard: A European company under European data protection law and its processor terms. - Business email and productivity provider
What they do for us: Delivers the emails Biddable sends (sign-in codes, security notices, notifications) and hosts our own mailbox and calendar.
Where: Processing may take place in the European Union and elsewhere, including the United States.
Safeguard: The provider's data processing terms, which include the EU standard contractual clauses. - Cloud AI model provider (customers on the Standard plan)
What they do for us: Receives the text of the documents a run needs and returns the model's output. Under its enterprise terms it does not use that content to train models and keeps it only as those terms allow. We may change provider or model without changing anything for the customer.
Where: Served from a global endpoint, so processing may take place in data centres outside the European Union and the United Arab Emirates, including the United States.
Safeguard: Enterprise terms with a data processing addendum and the EU standard contractual clauses. - The customer's own AI provider account (customers on the Own Key plan)
What they do for us: A customer who chooses Own Key stores a key for its own account with a supported AI model provider. Runs go to that account under the customer's own contract with the provider, which is then the customer's processor, not ours. We store the key encrypted and never show it back.
Where: As agreed between the customer and its provider.
Safeguard: The customer's own agreement with the provider. - Payment provider (none today)
What they do for us: We invoice by email and are paid by bank transfer. If we add a card payment provider it will be named on the processor list before it is used.
Where: To be confirmed.
Safeguard: The provider's terms; card data would never reach our server. - Professional advisers, auditors and insurers
What they do for us: Advise us and check our books. They see personal data only where a matter needs it.
Where: United Arab Emirates and, for some, elsewhere.
Safeguard: Professional duties of confidence. - Public authorities and courts
What they do for us: Only where the law requires it or to establish or defend a legal claim.
Where: Where the authority sits.
Safeguard: The legal duty itself, and disclosing no more than is required. - A buyer of our business
What they do for us: If Biddable or our company is sold or reorganised, the buyer receives the records that go with it. We would tell customers first and the buyer would be bound by this notice.
Where: To be confirmed at the time.
Safeguard: Contractual undertakings in the sale.
7. How the AI processing works, in plain words
7.1 When a customer asks Biddable to read a tender pack, give a view, draft a response or audit a bid, the service sends the relevant parts of the customer's documents, with the customer's own rules, to a cloud AI model and receives text back. The service then turns that text into the customer's documents.
7.2 The model provider is chosen by us for the Standard plan, under enterprise terms that forbid training on the content. On the Own Key plan the customer chooses and pays its own provider. In both cases the content is sent for that run only.
7.3 The output is a draft. It can be wrong, incomplete or out of date, and it must be read and approved by a person in the customer's team before it is used. Biddable is built so that a person signs off every output, and the Terms of Service make the customer responsible for what it submits.
7.4 We do not use the content or the outputs to build profiles of anyone, and no output is a decision about a person.
7.5 Biddie on this website. The chat bubble on biddable.ae lets you ask Biddie, the assistant, questions about Biddable. What you type there is sent to our AI model provider only to answer it, together with the text of this website. We do not keep the conversation and do not link it to you; it lives in your browser tab until you close it. Please do not share personal or confidential information in the chat: the application form is the place for your details.
8. Where data is processed and how transfers are protected
8.1 Our company is in the United Arab Emirates and our staff work from there. Our server is in Germany and our backups are stored in the European Union. Our customers may be anywhere.
8.2 From the EEA or the UK to the UAE. If you are in the EEA or the UK, your data is held in Germany and seen by our staff in the UAE. The UAE is not covered by an adequacy decision, so this is a restricted transfer. We rely on the EU standard contractual clauses (and the UK International Data Transfer Addendum) in our Data Processing Addendum with customers, and on the security measures in section 11.
8.3 To the United States and elsewhere. Our email provider and, for Standard-plan runs, our AI model provider may process data outside the EU and the UAE. Each is bound by data processing terms that include the EU standard contractual clauses and, where the provider is certified, the EU-US Data Privacy Framework.
8.4 From the UAE. Personal data leaves the UAE when it is stored on our German server and processed by our providers. The PDPL allows this to countries with adequate protection and otherwise under contractual safeguards, which is how we do it. If a customer or a person asks, we will describe the safeguards in force.
9. Cookies and similar technologies
9.1 biddable.ae sets no cookies. The one thing it keeps in your browser is a question you have typed to Biddie but not yet sent, so that it is still there when you move to another page; it stays in that browser tab only and is gone when you close it or send the question. Nothing is sent to us until you send it. There is no cookie banner because nothing here needs your consent.
9.2 app.biddable.ae sets one cookie after you sign in, which holds your session. It is strictly necessary to keep you signed in, is marked so that scripts and other sites cannot read it, and expires after thirty days without use or when you sign out. The phone and tablet apps hold an equivalent session token on the device. No cookie is used for analytics or advertising, and no third party sets any.
9.3 If a customer uses Biddable on its own web address (a white-label domain), the same single session cookie is set on that address.
10. How long we keep personal data
- Website server logs
How long: No more than thirty days.
Why that long: Long enough to investigate a fault or an attack. - Applications for access
How long: Twelve months after we decide, unless we set up your space, when the data becomes account data.
Why that long: So that we can reply to a follow-up and pick up a conversation that was paused. - Account data of a space's users
How long: For as long as the customer's space exists, then deleted with the space (section 10, next row).
Why that long: The account is needed while the service is. - A customer's space and its content
How long: Kept for thirty days after the contract ends so the customer can export it, then deleted within a further thirty days. A customer can ask for earlier deletion.
Why that long: The Terms of Service and the Data Processing Addendum set this out. - Sign-in history and account audit log
How long: Twelve months, rolling.
Why that long: To investigate a security event; the law does not require longer. - Encrypted backups
How long: Backups rotate: seven daily, four weekly and six monthly copies are kept, so deleted data leaves the last backup within about six months of deletion.
Why that long: To recover from a fault or an attack. Backups are restored only in whole, never to read one record. - Contracts, invoices and payment records
How long: Seven years after the financial year they belong to.
Why that long: UAE tax and commercial law require it. - Correspondence
How long: Twenty-four months after the matter closes, or longer while a contract or claim needs it.
Why that long: To know what was said and agreed.
11. How we protect it
Biddable is built to hold commercially sensitive documents. In summary:
- Every connection is encrypted (HTTPS, with HTTP Strict Transport Security), and the app's pages carry a strict content security policy.
- Every user signs in with two steps: a password or an emailed code, then an authenticator app, a passkey or a second emailed code. Organisations can use single sign-on with their own identity provider instead. Passwords are stored only as salted hashes.
- Stored secrets (authenticator seeds, customers' own model keys, our providers' credentials) are encrypted with a key kept apart from the data.
- Each customer's space has its own database and file store, and the service runs in a sandbox that cannot reach our other systems.
- Nightly encrypted backups go to a separate location, with a restore check.
- Sign-in attempts are rate-limited; every user has a sign-in history; each account has an audit log; security events are emailed to the user concerned.
- We hold no security certification yet and do not claim one. If your organisation needs a questionnaire answered, email hello@biddable.ae.
If a personal data breach affects you, we will tell the customer whose space is affected without undue delay, and tell you and the regulator where the law requires it.
12. Your rights and how to use them
12.1 You have the right to ask us for a copy of your personal data, to correct it, to have it deleted, to restrict or object to our processing of it, to receive the data you gave us in a portable form, to withdraw any consent you gave, and not to be subject to a decision based solely on automated processing. The PDPL, the GDPR and the UK GDPR each give these rights with some differences; we honour them for everyone.
12.2 To use a right, email hello@biddable.ae from the address we hold for you, or tell us how to check that the request is yours. We answer within one month, and tell you if the law allows us longer for a complex request. We do not charge unless a request is plainly unfounded or repeated.
12.3 If your data is in a customer's space, the customer decides on your request and we help it; we will tell you who to contact.
12.4 Some rights have limits: we may have to keep a record the law requires us to keep, or one we need to defend a legal claim. If we refuse a request in whole or in part we will explain why.
12.5 You may complain to a supervisory authority: in the UAE, the UAE Data Office; in the EEA, the authority of the country where you live or work; in the UK, the Information Commissioner's Office. We would rather you gave us the chance to put things right first.
13. Children
Biddable is for organisations and the adults who work for them. We do not knowingly collect personal data from anyone under eighteen. If you think we hold such data, tell us and we will delete it.
14. Changes to this notice
We will post any new version here with its date and version number. If a change affects how we use the data of a customer's users in a way that matters, we email the owners of every space at least thirty days before it applies. The version history is available on request.
15. Contact
Toga EMEA FZC LLC, Business Centre, Sharjah Publishing City Free Zone, Sharjah, United Arab Emirates. Email hello@biddable.ae. Please put "Privacy" in the subject line.
Last updated 5 October 2026. Questions: hello@biddable.ae.