Tenderbox

Legal

Privacy Policy

Effective date: 20 April 2026

1. About This Policy

TenderBox is a tender management platform operated by Beyond Condition Pty Ltd (ABN 33 139 306 360), registered office Toowong QLD Australia, as trustee for the Beyond Condition Unit Trust (“we”, “us”, “our”). TenderBox is accessible at tenderbox.au and tenderbox.beyondcondition.com.

This Privacy Policy explains how we collect, use, disclose, and manage personal information. We comply with the requirements of the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), and we intend to incorporate the standards set forth in the European Union General Data Protection Regulation (GDPR) where applicable.

Beyond Condition reserves the right to modify this Privacy Policy at any time. Changes will be communicated electronically to all relevant parties. The current version will always be available at tenderbox.beyondcondition.com/privacy.

By using TenderBox, you acknowledge and agree that you have had sufficient opportunity to read and understand this policy and you agree to be bound by it. If you do not agree, please do not use the platform.

If a provision of this policy is invalid or unenforceable it is to be read down or severed to the extent of the inconsistency without affecting the validity or enforceability of the remaining provisions.

2. Who This Policy Applies To

This policy applies to:

  • Project managers and other professionals who create and manage tender exercises on TenderBox (Users);
  • Tenderers or Bidders who receive an invitation link and submit bids through TenderBox (Tenderers); and
  • Visitors to the TenderBox website.

Tenderers interact with TenderBox without creating an account. Their personal information is collected and held only for the duration of the tender exercise in which they participate.

3. What Personal Information We Collect

We collect personal information from you for the exclusive purpose of providing the TenderBox platform and its services. If you do not provide us with certain information, you may not be able to enjoy the full functionality of the platform.

3.1 From Users (Project Managers)

  • Name and email address (collected at account registration)
  • Password (stored as a one-way hash; we cannot retrieve it)
  • Professional or organisational details you voluntarily provide
  • Payment information — processed by Stripe; we do not store card details on our systems
  • Usage data: tenders created, actions taken, exports generated
  • IP address and browser/device information collected automatically on login

3.2 From Tenderers

  • Name and email address (provided by the inviting User when setting up the tender)
  • Bid submissions: price, notes, and any attachments uploaded through the bidder portal
  • Questions submitted during the Q&A period
  • IP address and browser information collected automatically on portal access

3.3 Information We Do Not Collect

We do not knowingly collect sensitive information as defined under the Privacy Act (including health information, financial account details beyond payment processing, or government identifiers) unless you voluntarily include such information in uploaded tender documents or bid submissions.

We do not collect information from individuals under the age of 18. If you believe we have inadvertently collected such information, please contact us immediately.

4. Cookies

TenderBox collects session cookies from your browser, which enable us to maintain your login state and operate the platform. We do not use advertising cookies, cross-site tracking, or third-party analytics that collect personal information.

Your browser settings allow you to control or delete cookies, though disabling essential cookies may impair platform functionality.

5. How We Use Personal Information

Beyond Condition will not share, rent, trade, or sell your personal information to third parties. Personal information is used only for the purposes for which it was collected, including:

  • Providing and operating the TenderBox platform
  • Processing tender exercises, including sealed bid management, Q&A broadcasts, and evaluation workflows
  • Sending transactional emails (tender invitations, bid confirmations, Q&A notifications, opening summaries) via SMTP2GO
  • Generating evaluation reports and audit logs for export by the User
  • Processing payments and managing billing via Stripe
  • Responding to support enquiries
  • Improving platform functionality and resolving technical issues
  • Complying with legal obligations

You may correct, update, or request deletion of your personal information by contacting us at [email protected].

6. Disclosure to Third Parties

We disclose personal information to the following third parties only to the extent necessary to operate the platform:

6.1 Anthropic (AI Co-Evaluator — opt-in only)

TenderBox includes an optional AI co-evaluator feature powered by Claude, an AI model operated by Anthropic, PBC (United States). When a User activates this feature, the contents of uploaded tender documents and bid submissions are transmitted to Anthropic’s API for processing.

Users and Tenderers should be aware that:

  • Document and bid content may include commercially sensitive pricing and project information;
  • Anthropic’s processing occurs on infrastructure located in the United States;
  • Anthropic’s data handling is governed by their Privacy Policy and API Terms of Service, available at anthropic.com. Anthropic holds ISO 27001 and SOC 2 Type II certifications;
  • The AI co-evaluator is an opt-in feature. If it is not activated by the User, no tender documents or bid content are ever transmitted to Anthropic.

By activating the AI co-evaluator, Users acknowledge and accept that tender content will be processed by Anthropic for the purpose of generating evaluation scores and observations.

6.2 SMTP2GO (Email Delivery)

Transactional emails are delivered via SMTP2GO Pty Ltd, an Australian-based email delivery service. SMTP2GO receives recipient email addresses and transactional message content for the sole purpose of delivery. Their privacy practices are available at smtp2go.com.

6.3 Stripe (Payment Processing)

Payments are processed by Stripe. We do not store credit card or bank account details on our systems. Stripe’s privacy practices are available at stripe.com/privacy.

6.4 Legal Disclosure

We may disclose personal information if required to do so by law, court order, or regulatory authority, or where we reasonably believe disclosure is necessary to protect the rights, property, or safety of Beyond Condition, our users, or the public. We do not disclose personal information to any other third parties without your consent, unless permitted or required by law.

7. Data Security

Beyond Condition restricts access to your personal information within our organisation to specific personnel who require it to perform their job function. We maintain appropriate physical, electronic, and procedural safeguards to protect your information, including:

  • Encryption of data in transit (TLS)
  • Sealed bid architecture that prevents tender content from being accessed before the tender close time
  • Append-only audit logging of all platform events

No method of electronic transmission or storage is completely secure. While we take reasonable precautions, we cannot guarantee absolute security. To report a security concern, please contact [email protected].

8. Data Retention and Deletion

8.1 Active Tenders

Personal information associated with an active tender exercise (including bidder details, submitted bids, Q&A records, and the audit log) is retained for the duration of the tender and for a reasonable period thereafter to allow for export, review, and any disputes.

8.2 Completed and Cancelled Tenders

When a User deletes a completed or cancelled tender, the platform prompts the User to download the evaluation report and audit log before deletion proceeds. Upon confirmed deletion:

  • Tender content, bid submissions, and bidder personal information are deleted from our active database;
  • Residual copies may persist in encrypted backups for up to 120 days, after which they are permanently purged.

8.3 User Accounts

Personal information associated with a User account is retained for as long as the account remains active. Users may request deletion of their account and associated personal information by contacting us at the address below. Account deletion will be completed within 30 days of a verified request, subject to any legal retention obligations.

8.4 Legal Retention

We may retain certain personal information for longer periods where required by law (for example, for tax, audit, or legal compliance purposes).

9. Transfer of Data Outside Australia

TenderBox is hosted on servers located in North America. We select providers who maintain appropriate data security standards. By continuing to use TenderBox, you consent to the transfer of your data to our hosting infrastructure.

Beta note: TenderBox is in active development. Following beta testing, our roadmap includes migrating to AWS servers hosted in Australia.

Additionally, by activating the AI co-evaluator feature, you acknowledge that tender content will be transmitted to Anthropic in the United States for the purpose of generating AI evaluations. User activation of the AI co-evaluator constitutes informed consent for that specific disclosure in accordance with APP 8.

10. Your Rights

Under the Privacy Act 1988 (Cth) and applicable law, you have the right to:

  • Access — request access to the personal information we hold about you. We will respond within 30 days.
  • Correction — request correction of inaccurate, out-of-date, or incomplete information. We will take reasonable steps to correct it within 30 days of a verified request.
  • Deletion — request deletion of your personal information, subject to legal retention obligations (see §8).

If you believe we have breached the Australian Privacy Principles, you may contact us directly — we will respond within 30 days. If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.

11. Law and Jurisdiction

Beyond Condition Pty Ltd is registered in Australia and complies with Australian state and Commonwealth law. This policy is governed by the laws of Queensland, Australia.

12. Contact Us

For privacy enquiries, access requests, correction requests, or complaints, please contact:

Beyond Condition Pty Ltd
Privacy Officer: Ben Ihle
Email: [email protected]
Postal address: PO Box 2601 New Farm QLD 4006