1. Information We Process
- Account and billing information, including purchaser name and email, company name when supplied, authentication state, subscription status, legal-consent records, and Stripe customer and subscription references. GovBiz does not store full card numbers.
- Inbound and outbound email metadata, including sender, recipient agent identity, timestamp, subject, message type, generated short summary, delivery and processing status, and conversation and correlation identifiers.
- Customer email content when needed to provide the service, plus attachment names, types, sizes, hashes, securely stored originals, extracted text, and processing or malware-scan status.
- Versioned company knowledge, including customer-provided facts, agent inferences, preferences, evidence, confidence, confirmation state, corrections, and superseded or rejected items.
- Internal search plans, filters, semantic-query snapshots, search-execution telemetry, recommendation reasons and score components, feedback events, and learned preference signals.
- Service feedback reports, including the report body, category, severity, status, attachments, customer-visible activity, and resolution information. Service feedback is kept separate from recommendation ratings and does not silently alter company knowledge or search plans.
- Security, device, connection, audit, support-access, source-health, and service-reliability records.
2. How We Use Information
- To provision and authenticate your company agent; route authorized email; validate, scan, store, and extract documents; learn your company; ask clarifying questions; build and refine an internal search plan; search SAM.gov; compose and deliver briefs; process feedback; bill the subscription; prevent abuse; support customers; and operate, secure, and improve the service.
- Email and document text is treated as untrusted customer data, not as system instructions. Agent inferences remain labeled and are not silently converted into confirmed facts.
- GovBiz does not sell personal information or share it with advertisers.
3. Service Providers and Public Data
- Stripe processes checkout and subscription payments. Resend processes inbound and outbound service email. Hosting, storage, security, malware-scanning, monitoring, and model providers process only the data needed for their contracted function.
- The opportunity agent searches public SAM.gov records. Recommendations retain authoritative SAM.gov links and source identifiers where available.
- A current subprocessor list and additional data-processing information are available from hello@govbiz.ai.
4. Isolation, Security, and Support Access
- Tenant and company-profile controls isolate customer memory, messages, documents, search plans, executions, recommendations, and feedback. Sensitive message and extracted-document content is encrypted at rest and is excluded from ordinary operational logs.
- Full email, service-feedback, or attachment content is not the default support view. Access is tenant-scoped, reason-bound, time-limited, and audited. Ordinary content-access grants require approval from a second platform administrator; emergency break-glass access expires within 30 minutes.
- Tenant administrators can review all service feedback reported by their tenant, customer-visible activity, and the tenant support-access grant history. Protected content access is also recorded in the platform audit trail.
- We use signed provider webhooks, authorized-sender checks, attachment type and size limits, malware scanning, rate limits, managed secrets, signed and expiring feedback actions, backups, and deletion workflows.
5. Retention and Deletion
- We retain account, subscription, consent, audit, security, and transaction records as needed to provide the service, satisfy legal obligations, prevent fraud, and resolve disputes. Company messages, documents, extracted text, knowledge, plans, execution records, and feedback are retained while the service is active and for a limited recovery and compliance period after cancellation.
- Deletion requests remove or de-identify customer content according to the applicable retention schedule, except where law, security, fraud prevention, backup rotation, or dispute preservation requires temporary retention.
- You may request access, correction, export, or deletion by contacting hello@govbiz.ai. Identity verification may be required.
6. Contact
- For privacy questions, support-access questions, or data requests, contact hello@govbiz.ai.