Enterprise Privacy & Data Protection Policy
Effective Date: 1st January 2026 · Compliant with Digital Personal Data Protection (DPDP) Act, 2023
1. Information We Collect
Community of Employees ("COE") collects only necessary corporate procurement information to facilitate reverse auctions:
- Corporate Buyer Data: Authorized representative name, official corporate email, company name, office address, and contact numbers.
- Vendor Entity Data: Business name, registered entity type, GSTIN number, establishment address, contact person, and bank/invoicing coordinates.
- RFP & Auction Data: Headcount requirements, event dates, event category preferences, and itemized reverse quotations.
2. Purpose Limitation & Processing
Under Section 6 of the DPDP Act, 2023, data is processed strictly for the specified purpose of enabling B2B reverse auctions, vendor statutory KYC validation, and auction contract facilitation. We do not sell, rent, or trade corporate or vendor data to third-party advertisers.
3. How Bids Are Kept Confidential
While a requirement is open for bids, a vendor can see the requirement and their own quote and nothing else. Rival vendors' prices, terms and identities are never sent to a bidding vendor's browser, so they cannot be recovered from the page.
The employee who posted the requirement sees every quote, with vendor identities masked until they award — unless they chose open bidding when posting, which is shown on the requirement. Once awarded, identities are revealed to both sides so the work can be coordinated. Data is encrypted in transit (HTTPS) and at rest by our database provider; we do not claim any additional bid-level encryption beyond that.
4. Cookies, Sessions and Location
- Session cookie. Signing in sets one strictly-necessary cookie (
coe_session). It is HttpOnly and SameSite=Lax, holds a random token rather than any personal data, expires after 7 days, and is revoked server-side the moment you sign out, change your password, or an admin suspends the account. We set no advertising or analytics cookies. - Location. The vendor directory can sort by distance from you. Your browser is only asked for a location after you press the button that says so; the coordinates are used to sort that one list, are not written to our database, and are not shared with anyone. Declining simply shows the unsorted list.
- Passwords. Stored only as a bcrypt hash. Nobody at COE can read your password, and we will never ask you for it.
5. How Long We Keep Things
- Account and profile: for as long as the account is open.
- Closed accounts: the profile is anonymised immediately. Awarded requirements and their bids are retained, because they are the record of a transaction between two other parties and an audit trail we are obliged to keep.
- Email verification and password-reset links: 24 hours and 1 hour respectively, and single-use.
- Expired sessions: deleted.
- Admin audit log: retained for 24 months.
6. Your Rights, and Getting In Touch
Under the DPDP Act, 2023 you can review, correct, or ask us to delete your data. You can edit your profile yourself at any time, and close your account from your profile page — that anonymises it immediately, subject to the retention note above. For anything else, or to raise a grievance, write to our Data Protection Desk at privacy@communityofemployees.com.