ZappRFP

Privacy Policy

Last updated: August 25, 2026. See also our Terms of Service.

1. Who we are

This Privacy Policy is issued by RG Novatech Private Limited, operating ZappRFP ("ZappRFP," "we," "us"), of New No. 8, II Cross Street, Ganesh Nagar, Adambakkam, Chennai – 600088, Tamil Nadu, India. For EU/UK data subjects, our processing is subject to the EU General Data Protection Regulation (GDPR) and equivalent UK GDPR. Given our current, limited scale of EU/UK processing, we haven't appointed a formal Article 27 EU or UK representative; if that changes, we'll appoint one and list their contact here. For India, we act as a Data Fiduciary (and, for Customer Content, as described in section 5, a Data Processor on behalf of the organization that owns it) under the Digital Personal Data Protection Act, 2023 ("DPDP Act"). For California residents, we act as a business (and, for Customer Content, a service provider) under the California Consumer Privacy Act, as amended by the CPRA ("CCPA").

2. Two kinds of data, two different rules

We draw a hard line between two categories, because they're treated very differently:

Account & usage data — information about the people and organizations using ZappRFP: names, work emails, roles, login activity, audit trail of who did what and when (not what the content said), and billing details.

Customer Content — everything your organization uploads, generates, or stores while using the product: RFPs/RFIs/RFQs and security questionnaires you upload, your knowledge base documents, your Company Profile (headcount, certifications, pricing, company overview), your canonical answer library, and every AI-drafted or human-written answer. This is the data most customers ask about, and section 5 below is the commitment that governs it.

3. What we collect

Account & usage data:

Name, work email, organization membership and role (admin/member), authentication records (including SSO/SAML assertions if your organization enables it), audit log entries (action type, timestamp, actor — see Settings → Audit for what your own organization can already see), device/log data such as IP address and browser type (used for security, rate-limiting, and abuse prevention, not tracking), and, if you contact support, the contents of that correspondence.

Customer Content, as described in section 2, exactly as your organization enters or uploads it.

Payment data: when self-serve billing is active, card numbers and billing details are collected and stored directly by our payment processor (Stripe) — they never touch our servers. We retain only the subscription status, plan, and non-sensitive billing metadata Stripe sends us. Where an organization is set up directly by our sales team instead, we collect only the billing contact and invoicing details needed for that arrangement.

Cookies: only the strictly necessary session cookie our authentication provider (Supabase Auth) sets to keep you signed in. It's httpOnly and isn't readable by page scripts. We don't use advertising, tracking, or third-party analytics cookies, so there's no cookie consent banner — there's nothing optional to consent to. We also honor Global Privacy Control (GPC) signals as a valid opt-out request, though as described in section 11, we don't sell or share personal information in the first place.

4. Why we process it, and on what legal basis

Running the Service you signed up for (account data + Customer Content) — performance of a contract under GDPR Art. 6(1)(b), legitimate use for a specified purpose you've consented to under the DPDP Act, and a business purpose under the CCPA. This includes sending relevant Customer Content to the AI Subprocessors listed in section 6 solely to generate your answers.

Security, abuse prevention, and keeping the audit trail — legitimate interest under GDPR Art. 6(1)(f), balanced against your rights (we log actions, not content, for this purpose).

Aggregated, de-identified performance analytics (response times, error rates, which features get used) to keep the product fast and reliable — legitimate interest under Art. 6(1)(f), scoped narrowly as described in section 5.

Billing and tax records — legal obligation under Art. 6(1)(c), and contract performance.

5. Our commitment on Customer Content

This is the core promise, stated plainly:

Your RFPs, product details, pricing, policies, and everything else in your knowledge base and answer library is never made public, never visible to any other organization on ZappRFP (enforced at the database level — see section 8), and never sold or shared for cross-context behavioral advertising, as those terms are defined under the CCPA.

We do not read, review, or use the substance of your Customer Content for any purpose except (a) generating the outputs you asked for, and (b) if you report a bug and it's genuinely necessary to reproduce it, with your permission.

The only other use is aggregated, de-identified backend analytics for performance optimization — for example, measuring how long document processing takes or how often a feature errors out, computed in a form that doesn't retain or expose the actual content of any single customer's documents or answers. This is operational telemetry about the system, not analysis of what your proposals say.

We do not use Customer Content to train AI models — ours or any third party's. Our model providers are contractually bound the same way (see section 6).

6. Who else processes your data (subprocessors)

We use a small number of subprocessors to run the Service; this list must match Terms of Service section 12. Each only receives the minimum data needed for its function:

Anthropic (Claude API) — receives the question/context text needed to draft an answer. Under Anthropic's commercial API terms, inputs and outputs are not used to train models by default.

Voyage AI (embeddings, for search/retrieval) — receives document and answer text to generate vector embeddings, under a zero-retention/no-training commitment on our account.

Supabase — our database, file storage, and authentication provider, hosted in the Asia Pacific (Tokyo) region. Holds SOC 2 Type II, ISO/IEC 27001, and GDPR certifications, and provides a Data Processing Addendum incorporating Standard Contractual Clauses for data transferred outside the EEA/UK.

Vercel — hosts and serves the application itself.

Google — if you choose to sign in with Google, Google processes your authentication on our behalf per its own terms.

Stripe — payment processing, when self-serve billing is active. PCI-DSS Level 1 certified, with its own GDPR data processing agreement. We never see or store full card numbers.

We'll update this list if it ever changes, and material changes will be flagged per section 15.

7. International data transfers

Our subprocessors may process data outside your country, including in the United States and Japan. Where that involves transferring personal data out of the EEA, UK, or Switzerland, we rely on Standard Contractual Clauses (and the UK International Data Transfer Addendum, where applicable) as the transfer mechanism, as provided in each subprocessor's own DPA.

8. Security

Every organization's data is isolated at the database level by row-level security policies keyed to organization membership — one organization's data is architecturally unreachable from another's account, not just hidden by the interface. Data is encrypted in transit (TLS) and at rest. Access within an organization is role-gated (admin vs. member), destructive and configuration-changing actions are admin-only, and sensitive actions are recorded in an audit trail your admins can review. Organizations that need it can enforce sign-in through their own identity provider (SAML SSO) instead of passwords. If we become aware of a data breach affecting your personal data, we'll notify affected organization admins and any regulator we're legally required to notify without undue delay.

9. How long we keep data

We retain Customer Content and account data for as long as your organization has an active account. If your subscription ends, we retain data for 30 days to allow reactivation, then delete it, except where we're legally required to keep billing/tax records longer. Any organization admin can request full erasure at any time — see section 10 — rather than waiting for that window.

10. Your rights

An organization admin can already exercise most of the rights below directly, for your organization's Customer Content and account data:

Access & export — Settings → "Export my organization's data" produces a full machine-readable copy of your account, company profile, knowledge base catalog, projects, questions, and answers.

Erasure — Settings → "Delete organization & all data" permanently removes your organization's records, uploaded files, and every member account from our systems. This is irreversible and requires typing your organization's name to confirm.

For anything those tools don't cover — an individual's own account data, correction of inaccurate data, a request that doesn't map to an admin action, or if you're a data subject mentioned in a customer's uploaded content rather than a ZappRFP user yourself — contact us using the details in section 16.

Depending on where you're located, these rights may include:

EU/UK (GDPR): the right to access, rectify, erase, or restrict your data; data portability; the right to object to processing based on legitimate interest; the right to withdraw consent where processing relies on it; and the right to lodge a complaint with your local data protection supervisory authority.

India (DPDP Act): as a Data Principal, the right to access a summary of your personal data and the processing activities involving it, correction and erasure, grievance redressal (see section 16 for our Grievance Officer), the right to nominate another individual to exercise your rights on your behalf in the event of death or incapacity, and the right to withdraw consent at any time.

California (CCPA/CPRA) and other US states with similar laws: the right to know what personal information we collect, use, and disclose; the right to delete; the right to correct inaccurate information; the right to opt out of the sale or sharing of personal information (see section 11 — we don't engage in either); the right to limit use of sensitive personal information; and the right not to be discriminated against for exercising these rights. You may designate an authorized agent to make a request on your behalf.

Brazil (LGPD), Canada (PIPEDA), and elsewhere: we extend the same core set of rights — confirmation of processing, access, correction, deletion, and the ability to object — to individuals in jurisdictions with comparable data protection frameworks, even where not separately itemized above.

We'll respond to verifiable rights requests within the time required by applicable law (for example, one month under GDPR, extendable by two further months for complex requests; 45 days under the CCPA, extendable once by 45 days; or the timeline prescribed under the DPDP Act once its grievance-redressal rules are in force).

11. California-specific disclosures

In the preceding 12 months, we have not sold or shared (as those terms are defined under the CCPA) any personal information, and we have no plans to. We collect the categories of personal information described in section 3 for the business purposes described in section 4. We don't use or disclose sensitive personal information for any purpose beyond what's necessary to provide the Service. California residents may also request, under California Civil Code § 1798.83 ("Shine the Light"), information about disclosures of personal information to third parties for their own direct marketing purposes — we don't make such disclosures, so there's nothing to report, but you can still ask.

12. Cookies and tracking technologies

As described in section 3, we use only the strictly necessary authentication session cookie — no advertising or analytics cookies, no third-party trackers, and no cross-site tracking of any kind.

13. Children's privacy

ZappRFP is a business tool restricted to organizational use by adults (see Terms of Service section 3) and isn't directed at, or knowingly used to collect data from, anyone under 18. If we learn we've inadvertently collected personal data from someone under that age, we'll delete it.

14. Automated decision-making

AI-generated draft answers (section 6 of our Terms of Service) are recommendations that a human at your organization must review and approve before they're used — we don't use automated processing to make any decision about you (for example, employment, credit, or eligibility decisions) without human review.

15. Changes to this policy

We'll post material changes here and update the "Last updated" date. Where a change is significant, we'll also notify organization admins directly.

16. Contact and grievance officer

Questions, rights requests, or to report a suspected breach: support@zapprfp.com, or by post at RG Novatech Private Limited, New No. 8, II Cross Street, Ganesh Nagar, Adambakkam, Chennai – 600088, Tamil Nadu, India. For grievances under India's DPDP Act and IT Rules, the same contact serves as our Grievance Officer until we designate a named individual. If we ever appoint a formal Data Protection Officer or EU/UK Article 27 representative, their contact will be listed here too.