Privacy Policy
This policy covers the GovBuyX platform, including FedBidX and Sovereign Express. It describes what we hold, why we hold it, who can see it, and how long it stays. We have written it against what the software actually does rather than against what a template says, so where a section looks unusually specific, that is deliberate.
1. Who we are
GovBuyX is an independent company and software product, and a subsidiary of Wakaga Economic Development Group. GovBuyX is the data controller for the information described here.
Contact for privacy questions: PRIVACY CONTACT EMAIL. Postal address: REGISTERED ADDRESS.
2. Access is by invitation
There is no public sign-up. Accounts are created either by a GovBuyX administrator or by an administrator at your own company. If you submitted the “Request an invite” form, we hold what you typed into it — company name, your name, business email, any phone number, any UEI, and your description of what your company does — together with the IP address the form was sent from, which we keep to stop the form being abused. Submitting that form does not create an account or a company; it creates a message that a person reads.
3. What we hold about you
- Who you are
- Your name, your email address (which is also your sign-in), and optionally a job title, a job role, a phone number and a small profile picture. The picture is stored with your profile record, not on a separate file server.
- How you sign in
- A cryptographic hash of your password — never the password itself — and, if you turn on two-factor authentication, the shared secret your authenticator app uses. We cannot read your password, and neither can a GovBuyX administrator.
- When and where you signed in
- The time, the IP address, the browser’s self-reported description of itself, and which method you used. You can see this yourself on your Profile page. We keep the most recent fifty sign-ins per person.
- What you did
- An audit record of significant actions: signing in and out, password changes, permission and role changes, company profile edits, credit purchases and limit changes, project creation, and moving work through preparation, review and submission. Each record names who acted, which company they were acting in, what was acted on, and when.
- What your company is
- Its legal name, registered address, website, phone and email, UEI, CAGE code, DUNS, NAICS codes, business type and certifications, SAM.gov registration status and expiry, primary contact details, and its logo. Some of this is required before federal contracting workflows will run at all.
- What your company sells
- If you maintain a price list: products, SKUs, units, prices, service rates, locations and notes, plus who last confirmed each price and when.
- What you used
- A ledger of chargeable actions — searches, briefs, drafts — recording which person ran what, when, and what it cost in credits, together with compute usage such as model tokens.
- The work itself
- Opportunities you track, bids and grant applications, their stages and history, assignments, budgets, notes, and any documents you upload.
4. Who can see it
This is the part most policies leave vague, so we will be specific.
People at your own company
GovBuyX is workplace software, and your colleagues can see your activity in it according to their access level:
- Owners and Executives can see the full activity history of their company, including financial activity.
- Managers can see their people’s activity and compute usage, but not payment details, credit purchases or permission changes.
- Staff and everyone else can see their own activity only.
- Everyone can see who else is in their company and what work is assigned to whom.
Belonging to a company that owns or is owned by another company does not give anyone at either company access to the other. Access comes from your membership of a specific company, never from corporate ownership.
GovBuyX staff
A small number of GovBuyX platform administrators can see data across all companies in order to run and support the service.
They can also view the application as you. This exists so that support can see what you are seeing when something goes wrong. It does not use or reveal your password. When it happens, it is recorded: the start, the end, which administrator, which account, which company, and every change made during it, filed under the administrator’s name as well as yours. A GovBuyX administrator cannot be viewed-as by another administrator.
Nobody else, unless
We do not sell your data, and we do not share it for anyone else’s advertising. We disclose it outside GovBuyX only where we are legally required to, where it is necessary to protect the service or someone’s safety, or to service providers acting on our instructions and bound to protect it — see section 6.
5. Artificial intelligence
GovBuyX uses language models to summarise opportunities, prepare briefs and draft proposal text.
These models run on hardware GovBuyX controls, reached over a private encrypted link. Your solicitations, drafts and company information are not sent to a third-party AI provider, are not used to train anyone else’s model, and do not leave our infrastructure for that purpose. We record how much model time each action used so that we can meter it.
Model output is a draft. It can be wrong, and it must be read and corrected by a person before it is relied on or submitted anywhere.
6. Other services we rely on
- SAM.gov and Grants.gov. We retrieve public federal opportunity and grant data from these sources into our own database. We do not send them your information.
- Microsoft Entra and Google sign-in. Available as optional ways to sign in. If you use one, that provider tells us who you are; we do not receive your password.
- Hosting. The platform runs on Amazon Web Services infrastructure in the United States.
- Email. NAME THE MAIL PROVIDER ONCE CHOSEN — at the time of writing no email provider is configured and the platform sends no email at all.
7. Payment information
The platform does not take card details. Credit purchases are recorded as orders and invoiced separately; no card number is ever entered into GovBuyX, and none is stored. Nothing recharges automatically.
8. Cookies and measurement
One cookie, for your sign-in session. It cannot be read by scripts in the page, is not sent to other sites, and expires after eight hours. There are no advertising or analytics cookies, and no third-party trackers.
We do measure how the platform is used, and we do it on our own servers rather than by putting somebody else's script in the page. There is nothing to block and nothing that follows you anywhere else. For each request we record the kind of page or action, whether it succeeded, how long it took, which company the request belonged to, and the access level involved.
We do not record who you are in that measurement. No name, no email address, no identifier for you personally, and no addresses of individual records — a request for one bid is counted as "a bid", not as that bid. Where the question genuinely is "who did this", the answer lives in the audit trail described in section 4, which exists for that purpose and is visible under the rules set out there. Measurement data is kept for 90 days and then deleted.
9. How long we keep it
- Your account and profile: for as long as your company keeps you on it.
- Sign-in history: the most recent fifty sign-ins per person.
- The audit trail: retained, and deliberately not editable or deletable through the product by anyone, including us. A record of who changed a permission is worth nothing if it can be tidied away afterwards.
- Work, projects and documents: until your company deletes them or the account is closed.
- Declined or blocked invite requests: retained so that a decision does not have to be made twice.
- Usage measurement: 90 days, then deleted automatically.
- After an account is closed: RETENTION PERIOD.
10. Keeping it safe
Passwords are stored as salted hashes. Two-factor authentication is available to every account. Traffic is encrypted in transit. Access inside the product is decided per request against the current permissions, so a change to what you may do takes effect on your next click rather than whenever a token happens to expire. Changing or resetting a password ends every other session for that account immediately.
No system is perfectly secure, and we do not claim otherwise. If we discover a breach affecting your data we will tell you and any regulator we are required to tell, WITHIN THE PERIOD COUNSEL SPECIFIES.
11. Your choices
From your Profile you can change your name, job title, phone number, picture and notification preferences, change your password, turn on two-factor authentication, and see your recent sign-ins.
Your email address is also your sign-in and the address a contracting officer would use, so changing it needs an Owner or Executive at your company to agree.
To ask what we hold about you, to correct it, or to ask us to delete it, contact PRIVACY CONTACT EMAIL. Note that where the data belongs to your employer’s account rather than to you personally, we may need to refer the request to them. COUNSEL: STATE THE APPLICABLE RIGHTS AND RESPONSE TIMES — e.g. CCPA/CPRA, and GDPR if there will be EU users.
12. Children
GovBuyX is business software and is not intended for anyone under 18. We do not knowingly collect information about children.
13. Changes
If we change this policy we will update the date at the top and, where the change is significant, tell you in the application.