How a customer document moves
- An authorized user uploads a PDF over TLS and confirms upload authority.
- The customer workspace stores it privately in Cloudflare R2; project metadata and audit events live in Cloudflare D1.
- When analysis is requested, BidPilot creates a temporary OpenAI File and sends it to the Responses API with response storage disabled.
- BidPilot saves the reviewable output in the customer workspace and deletes the temporary OpenAI File after processing.
- The customer’s estimator reviews, accepts, adjusts, or rejects conditions before pricing and export.
Historical demo boundary
The public demo does not add the PDF or result to BidPilot R2 or D1. It records only company, work email, file size, consent version, processing status, and result counts. The PDF is sent temporarily to OpenAI and the temporary File object is deleted after the response. Standard OpenAI abuse-monitoring retention of up to 30 days may still apply.
Subprocessors
- Cloudflare: hosting, security, access, Workers, D1, R2, Turnstile.
- OpenAI: API document analysis.
- Resend: transactional email.
- Wave: invoicing; no project PDFs are intentionally sent to Wave.
Retention
- Demo PDF and result: not persisted in BidPilot storage.
- Workspace PDFs and output: during the service term; deletion on verified request or within 30 days after account closure, subject to legal holds and agreed export.
- Demo consent metadata and leads: up to 24 months after last activity.
- Security, consent, invoice, and audit records: only as needed for security, authorization, disputes, or law.
Deletion procedure
The Privacy Officer verifies authority, records scope and legal holds, provides an agreed export, deletes matching R2 objects and D1 records, checks for orphaned objects or failed jobs, and confirms completion. Limited provider security logs and controlled backups expire under their own cycles.
Incident response
BidPilot records and triages suspected events, contains access, preserves necessary evidence, assesses affected systems and information, eradicates the cause, restores verified service, and notifies affected customers without undue delay after confirmation. The Privacy Officer assesses whether personal information is involved and whether PIPEDA’s real-risk-of-significant-harm threshold is met. Required regulator and individual notices are made as soon as feasible, and records are kept for every personal-information breach.
Documents available during pilot review
Qualified prospects receive the Pilot and Data Processing Agreement, complete retention policy, upload authorization wording, and incident-response procedure before submitting live confidential work. Contact admin@tbaytechservice.com.