BidBetter Security and Data Handling
Your tender information should remain your business.
See how BidBetter handles account, workspace, tender and document information — where it is processed, which service providers support the platform, who may access it and which limitations currently apply.
This page provides a plain-language summary of BidBetter's current practices. The Privacy Policy, Terms of Use and applicable agreements remain authoritative.
Private BidBetter workspace
Tenders, tasks, notes, dates, documents
Base44 infrastructure
US region · Encrypted at rest and in transit
File storage
Uploaded documents
Optional — AI Tender Analysis
Base44 AI service
Selected document text sent · Model-training position under review
Email delivery
Alerts and service emails
PayFast (ZA)
Subscription payments
Public tender data
Government sources
BidBetter currently operates using third-party infrastructure and service providers. Security certifications or controls held by those providers do not automatically mean that BidBetter itself holds the same certification. This page distinguishes provider-level controls from BidBetter-specific controls.
At a glance
The information buyers usually ask for first.
| Control or question | Current BidBetter position | Managed by | Status | Detail |
|---|---|---|---|---|
| Application infrastructure | Base44 (cloud platform) | Provider | Provider managed | See section |
| Current storage region | United States (Base44 default production region) | Provider | Provider managed | See section |
| Data encrypted in transit | HTTPS / TLS enforced | Provider | Provider managed | See section |
| Data encrypted at rest | Encrypted by infrastructure provider | Provider | Provider managed | See section |
| End-to-end encryption | Not end-to-end encrypted | N/A | Not available | See section |
| Organisation workspace separation | Row-level security rules enforced per workspace | BidBetter | Available | See section |
| Row-level permissions | Configured and tested per entity | BidBetter | Available | See section |
| Field-level permissions | Selective field restrictions configured | BidBetter | Available | See section |
| Email verification | Required at registration | BidBetter / Provider | Available | See section |
| Multi-factor authentication | Not currently available in the BidBetter application | N/A | Not available | See section |
| Single sign-on (SSO) | Not currently available | N/A | Not available | See section |
| BidBetter independent security certification | No BidBetter-owned SOC 2 or ISO 27001 certificate | N/A | Not available | See section |
| Infrastructure provider certifications | Base44 platform holds provider-level certifications | Provider | Provider managed | See section |
| AI provider | Base44-integrated AI services | Provider | Provider managed | See section |
| AI model-training position | Under review — contractual position not yet fully confirmed | Under review | Under review | See section |
| Data export | Supported for tender register | BidBetter | Available | See section |
| Account deletion | Supported via request process | BidBetter | Available | See section |
| Uploaded-document deletion | Supported where files are user-uploaded | BidBetter | Available | See section |
| Security incident contact | Available via contact form | BidBetter | Available | See section |
| Last workspace permission review | July 2026 | BidBetter | Available | See section |
| Last independent penetration test | No independent penetration test completed | N/A | Not available | See section |
Status codes: Available — implemented and tested. Provider managed — controlled by the infrastructure or service provider. Customer configurable — adjustable within BidBetter. Not available — not currently implemented. Under review — being confirmed.
Information categories
Different information is handled for different purposes.
Public tender information
- Tender title and number
- Issuing organisation
- Public closing date
- Public briefing information
- Public tender documents
- Published award outcomes
Purpose
Help users search, match and manage public opportunities.
Visibility
May be visible publicly or to registered users depending on the feature.
Account information
- Name
- Email address
- Login information
- Organisation membership
- Account status
Purpose
Create accounts, authenticate users and manage workspace access.
Visibility
Visible to the account holder and authorised BidBetter administrators.
Organisation profile information
- Organisation name
- Services and industries
- Matching keywords
- Province or operating areas where supported
Purpose
Configure tender matching and the organisation workspace.
Visibility
Within the organisation workspace only.
Private tender workspace information
- Saved tenders and bid decisions
- Internal deadlines and tasks
- Assigned responsibilities
- Notes and submission details
- Validity and evaluation records
Purpose
Allow the organisation to manage its tender process.
Visibility
Within the authorised organisation workspace only.
Uploaded documents
- Tender source documents
- Supporting company documents
- Technical responses
- Compliance records
- Extension correspondence
Purpose
Support tender analysis, preparation or record keeping.
Visibility
Within the organisation workspace. May be sent to the AI service during analysis.
AI analysis information
- Tender documents selected for analysis
- Extracted tender text
- Generated analysis
- Identified requirements and risks
Purpose
Provide AI-assisted tender-analysis functionality.
Visibility
Within the organisation workspace. See AI Data Handling section.
Technical and security information
- IP address
- Browser and device details
- Login events
- Error information
- Security events
Purpose
Operate, secure, troubleshoot and improve the service.
Visibility
Accessible to authorised technical personnel. Not visible to other users.
Communication and billing information
- Demo and support requests
- Email-alert preferences
- Subscription status
- Invoice information
- Payment transaction reference
Purpose
Deliver communications, manage subscriptions and process payments.
Visibility
Payment card details are handled by the payment provider — BidBetter does not store full card numbers.
Not all tender information has the same sensitivity
Separate public opportunity information from your organisation's internal work.
Sourced from public procurement notices. May be visible to registered platform users.
Published tender notices
Tender titles and numbers
Government organisations
Closing dates and briefing dates
Public tender documents
Published award information
Created by your team. Visible only within your authorised workspace.
Which tender the organisation is pursuing
Internal bid or no-bid decisions
Assigned team members and tasks
Internal deadlines and preparation progress
Commercial notes and pricing discussions
Uploaded supporting records and submission evidence
Important: The decisions, notes, assignments and records created by your organisation should remain within the authorised workspace. Public tender information is visible as part of the platform's matching and directory features.
Tender documents and supporting files may contain personal or commercially sensitive information. Upload only information your organisation is authorised to process and that is necessary for the tender workflow.
Where the platform runs
See which provider hosts BidBetter and where production data is stored.
Application platform
Base44 (cloud application infrastructure)
Region: United States
Application database
Base44 managed database
Region: United States
File storage
Base44 managed file storage
Region: United States
Authentication
Base44 managed authentication
Region: United States
AI processing
Base44-integrated AI services (external AI providers)
Region: Provider-determined
Email delivery
Base44 / third-party email provider
Region: Provider-determined
Payment processing
PayFast (South African payment provider)
Region: South Africa
Analytics and monitoring
Internal usage tracking and error monitoring
Region: Provider-determined
Current data storage region
Production application data is currently stored in the United States using Base44's default production infrastructure. BidBetter has not configured a separate data region.
Cross-border processing
Some information is transferred or processed outside South Africa, including to the United States and other locations where AI and supporting providers operate. BidBetter reviews contractual safeguards under its applicable provider agreements and POPIA obligations.
Provider certifications
Base44 states that its platform holds provider-level security certifications. These certifications apply to Base44's infrastructure platform and do not mean that BidBetter has completed its own independent security certification.
Base44 Security Trust CentreNo end-to-end encryption: BidBetter data is not end-to-end encrypted. Authorised infrastructure-provider personnel may have technical access where required to operate, secure or support the platform, subject to the provider's controls and terms.
Who supports the service
BidBetter relies on selected providers to operate specific parts of the platform.
| Provider | Service | Information involved | Purpose | Region | Provider information |
|---|---|---|---|---|---|
| Base44 | Application infrastructure, database, authentication, file storage, backend functions | Account data, workspace data, tender records, documents, technical logs | Core platform operation | United States | View |
| Base44 AI services | AI Tender Analysis processing | Selected tender text and documents during analysis | AI-assisted analysis | Provider-determined | View |
| PayFast | Payment processing | Subscription transaction reference, billing status | Subscription billing | South Africa | View |
| Email provider (Base44) | Transactional and alert emails | Account email address, notification content | Deliver service emails and tender alerts | Provider-determined | View |
Who can see the workspace
Access should follow the organisation — not a public shared link.
Mahlangu Facilities Services
Naledi Mahlangu
naledi@mahlangu.co.za
Sipho Dlamini
sipho@mahlangu.co.za
Thandi Nkosi
thandi@contractor.com
Former Employee
former@mahlangu.co.za
Organisation membership
Users can only access the organisation workspace to which they have been invited. Access from another organisation's workspace is prevented by row-level security rules configured on every data entity.
Row-level security
BidBetter configures row-level access rules on every main data entity. Records are filtered by the user's confirmed workspace before being returned. Last reviewed: July 2026.
Team-member removal
When a workspace member is removed, their access to the workspace is revoked immediately. Records they created during their membership remain in the workspace. Their account is not automatically deleted.
BidBetter administrator access
Authorised BidBetter administrators may access organisation data where necessary to provide support, investigate a technical issue or meet a legal requirement. This access is controlled and not routine.
Base44 infrastructure access
Base44, as the infrastructure provider, may have technical-level access to application data where required to operate and secure the platform. This is governed by Base44's terms and Data Processing Agreement.
Security controls
Separate BidBetter controls from infrastructure-provider controls.
BidBetter application controls
Authentication requirement
All private workspace routes require a verified login.
Email verification
Required at account registration.
Organisation membership
Workspace access requires explicit invitation.
Row-level data rules
Enforced server-side on all main entities.
User-removal process
Workspace owners and admins can remove members at any time.
Server-side functions
Sensitive operations run server-side, not in the browser.
Secret management
API keys and credentials are stored as platform secrets, not in code.
Input validation
Enforced on entity schemas and backend functions.
Security scans
Periodic application-level security reviews using available tools.
Error monitoring
Application errors are monitored and reviewed.
Infrastructure-provider controls (Base44)
Encryption in transit
HTTPS and TLS enforced across the platform.
Encryption at rest
Data encrypted at rest within the hosting infrastructure.
Platform availability
Managed by Base44 infrastructure.
Platform monitoring
Infrastructure-level monitoring managed by provider.
Infrastructure backups
Managed by Base44. Backup schedule and retention are provider-controlled.
Platform vulnerability management
Infrastructure vulnerabilities managed by provider.
Provider penetration testing
Provider-level testing. No BidBetter-specific independent test completed.
Provider certifications
Base44 holds provider-level certifications. These do not extend to BidBetter independently.
Provider incident management
Infrastructure incidents managed according to Base44 procedures.
AI data handling
What happens when you analyse a tender with AI?
User selects tender
Documents or notice selected in workspace
Content is prepared
Text extracted from documents
Sent for analysis
Content sent to Base44 AI service
Analysis generated
AI output returned — requires human review
Result stored
Analysis saved to organisation workspace
| Question | Current position |
|---|---|
| Information sent to AI service | Selected tender text and document content chosen by the user |
| AI provider | Base44-integrated AI services (provider identity managed by Base44) |
| Processing region | Provider-determined — may include locations outside South Africa |
| Provider retention | Governed by Base44 and the underlying AI-service-provider terms. Review Base44's Data Processing Agreement. |
| Model-training use | Under review — the contractual position regarding use of customer content for model training or service improvement has not yet been fully confirmed across every provider in the processing chain. |
| Analysis storage in BidBetter | Analysis outputs are stored in the organisation workspace. |
| Source-document storage | Documents uploaded by the user are stored in BidBetter file storage. |
| Deletion options | Uploaded documents can be deleted where the document was user-uploaded. Analysis records can be removed from the workspace. |
| User opt-out | Users can choose not to use the AI Tender Analysis feature. |
| Human review | AI-generated analysis may be accessed by authorised support personnel where required to investigate a technical issue. |
AI model-training position — under review
BidBetter does not currently claim that uploaded information is excluded from every provider's service-improvement or model-training processes. The contractual position is under review. Users should be aware of this limitation when uploading commercially sensitive documents.
AI analysis is decision support
BidBetter's AI-assisted analysis contains errors and requires human review. Always confirm dates, mandatory requirements and submission instructions against the original tender documents before acting.
How long information is kept
Information should not be retained indefinitely without a defined reason.
Some information may need to be retained for contract administration, financial records, dispute resolution, fraud prevention, security investigation or compliance with legal obligations. These exceptions do not justify indefinite retention.
| Information category | Current retention | Purpose | User action available |
|---|---|---|---|
| Account information | For the duration of the account and as required by law | Account administration | Deletion request |
| Trial-workspace information | Retention period not yet formally documented | Trial administration | Closure request |
| Active subscription workspace | For the duration of the subscription | Service delivery | Managed by account holder |
| Cancelled workspace information | Retention period not yet formally documented | Legal and contractual obligations | Deletion request |
| Tender records and workspace data | While the workspace is active | Service delivery | Delete individual records or request workspace closure |
| Uploaded documents | Until deleted by the user or workspace closure | Tender preparation and analysis | Delete from workspace |
| AI analysis outputs | Stored in workspace until removed | Analysis access | Delete from workspace |
| Technical logs | Provider-determined | Security, troubleshooting, performance | No direct user action |
| Support messages | As required to resolve the support request | Customer support | Request deletion |
| Billing and invoice records | As required by financial, tax and legal obligations | Financial compliance | Request where permitted |
| Backup copies | Provider-determined backup schedule and retention | Platform recovery | Individual records cannot be removed from backups |
Backups
Deleted records may remain temporarily in infrastructure backups. Backup retention and overwrite schedules are managed by the infrastructure provider. Individual records cannot be selectively removed from provider backups. When a workspace is fully deleted, records will be removed as backups cycle.
Your control
Understand what can be exported, corrected or deleted.
Export
Tender-register records can be exported in Excel (.xlsx) and CSV (.csv) formats.
Exported data includes structured tender fields. Documents and activity logs are not included in the register export.
Only the account holder and authorised workspace users can initiate an export.
Correct
Account name, email preferences and workspace profile information can be updated within the application.
Incorrect tender records can be edited directly within the workspace.
To request correction of personal information held by BidBetter, submit a privacy request.
Delete
Individual tender records and uploaded documents can be deleted from the workspace.
Team members can be removed by workspace administrators.
To close a workspace or delete an account, submit a deletion request to BidBetter support.
Removing a user's access is not the same as deleting all information associated with that user.
Information retained for legal or contractual purposes may not be immediately deleted.
Backup copies cycle over time but cannot be individually overwritten on request.
South African privacy rights
How to ask about personal information held by BidBetter.
Supported request types
Confirm whether BidBetter holds personal information about you
Request access to your personal information
Request correction of inaccurate information
Request deletion where applicable
Object to certain processing where applicable
Raise a privacy or data-handling complaint
Ask about cross-border processing
How to submit a request
Submit a request using the verified privacy-request form on the Contact page.
Provide enough information to locate the account (email address, workspace name).
Complete proportionate identity verification.
BidBetter reviews the request and applicable legal requirements.
BidBetter responds through a secure channel.
Privacy contact
Submit via Contact page →South African Information Regulator
inforegulator.org.zaWhen something goes wrong
How BidBetter handles a suspected security compromise.
Receive or detect a report
Security concerns may be reported directly or detected through monitoring.
Preserve relevant information
Relevant system information is preserved to support assessment.
Contain the issue where possible
Steps are taken to limit the impact while the issue is assessed.
Assess affected systems and information
The nature, scope and potential impact of the issue are evaluated.
Coordinate with relevant providers
Where the issue involves the infrastructure provider, coordination occurs under their incident process.
Determine notification requirements
Legal and contractual notification obligations are assessed and fulfilled where required.
Notification approach
Where there are reasonable grounds to believe that personal information has been accessed or acquired by an unauthorised person, BidBetter will assess and manage notifications in accordance with applicable legal requirements.
Security reporting
If you believe you have identified a security concern in BidBetter, contact us using the form below. Do not include passwords, payment-card information, confidential tender documents or unnecessary personal information in the report.
Report a Security ConcernCurrent limitations
Security disclosure should include what is not yet available.
These limitations are disclosed to support informed evaluation. None of the items below are currently planned for a specific delivery date.
| Not currently available | Practical impact | Available alternative |
|---|---|---|
BidBetter-owned SOC 2 report | Enterprise buyers may require vendor certification | Request the Base44 platform documentation via the security contact. |
BidBetter-owned ISO 27001 certificate | Enterprise buyers may require this certification | Request the Base44 platform documentation via the security contact. |
Independent BidBetter penetration test | No external security assessment of the BidBetter application layer | BidBetter uses platform security scans and periodic internal review. |
End-to-end encryption | Infrastructure provider personnel may have technical platform access | Data is encrypted in transit and at rest at the infrastructure level. |
Customer-managed encryption keys | Customers cannot manage their own encryption keys | Infrastructure provider manages encryption. |
Multi-factor authentication | Login protection relies on password and email security | Use a unique password. Protect the registered email account. Remove users who no longer require access. |
Enterprise single sign-on (SSO) | Not available for enterprise identity providers | Email and password login only. |
IP allowlisting | Access cannot be restricted to specific IP ranges | Use workspace membership controls to limit access. |
Immutable audit log | Detailed tamper-proof event history not available | Workspace changes are tracked where supported by BidBetter features. |
Customer-selectable South African data region | Data is currently stored in the United States on Base44's default infrastructure | Cross-border transfer safeguards are reviewed under applicable provider agreements. |
Guaranteed zero-retention AI processing | AI model-training position not yet fully confirmed across every provider | Users can choose not to use the AI analysis feature. |
Formal public bug-bounty programme | No financial reward for external vulnerability reports | Security concerns can be reported via the security contact form. |
Security is shared
BidBetter can provide controls, but your organisation also determines how information is used.
Account security
Use unique passwords
Protect the registered email account
Do not share login credentials
Remove users who no longer need access
Workspace access
Invite only authorised contributors
Review workspace members regularly
Assign access according to job responsibilities
Document minimality
Upload only information needed for the tender process
Avoid uploading unnecessary identity or banking information
Confirm authority to process third-party personal information
Source verification
Confirm tender requirements against official documents
Do not rely solely on AI-generated outputs
Device security
Protect devices used to access BidBetter
Sign out of shared computers
Maintain browser and operating-system updates
Export security
Protect exported spreadsheets
Control who receives them
Remove local copies when no longer needed
This section describes shared risk management. It does not shift BidBetter's applicable legal responsibilities onto customers.
For procurement and IT review
Everything your organisation needs to evaluate BidBetter.
Privacy Policy
BidBetter privacy policy
Terms of Use
Platform terms and conditions
Data Policy
Data-processing and usage policy
Contact / Security request
Submit security or privacy questions
Base44 Trust Centre
Infrastructure provider security documentation
Base44 Data Processing Addendum
Provider DPA
Base44 Subprocessors
Infrastructure subprocessor list
Spreadsheet Import and Export
Data export capabilities
AI Tender Analysis
AI feature overview and data handling
Pricing
Plan details and included features
Security questionnaire
If your organisation requires a vendor-security questionnaire, infrastructure details, certification evidence, DPA review or AI processing information, contact BidBetter through the security form. BidBetter cannot guarantee that every requested control is available at its current plan and configuration.
Request a Security ReviewTransparency over time
Recent security and data-handling changes.
| Date | Change | Reason | Users affected | Action required |
|---|---|---|---|---|
| July 2026 | Security and Data Handling page published. | Initial disclosure | All users | No action required |
Security and data FAQ
Questions about how BidBetter handles information.
Have a security or privacy question?
Ask before uploading information your organisation considers sensitive.
Contact BidBetter for clarification about workspace access, data location, AI processing, retention, deletion or a vendor-security review.
Only contacts that are actively monitored are displayed here.
Review BidBetter with confidence
Understand the platform before bringing your tender process into it.
Review how BidBetter handles workspace information, ask security questions and see the current controls and limitations before starting your trial.
No credit card required · Guided setup included