Bidwise is designed to support GDPR-aligned handling of personal data by minimizing stored information, protecting access, and giving users a clear path to exercise privacy rights.

Legal Basis

Bidwise processes personal data where necessary to provide the service, secure accounts, enforce plan access, comply with legal obligations, and pursue legitimate interests in service reliability and fraud prevention. For UK and EU users, the UK GDPR and EU GDPR apply in addition to local member-state rules.

Data Subject Rights

Users may request access, correction, deletion, restriction, objection, or portability of personal data, subject to applicable law and reasonable verification of identity. In the UK, the ICO framework applies; in the EU, supervisory authorities apply under the GDPR.

International Transfers

Depending on infrastructure choices, data may be processed outside the European Economic Area. Deployment operators should ensure appropriate contractual and technical safeguards are in place with their vendors, including SCCs or equivalent UK transfer mechanisms where required.

India and Other Markets

For users in India, the Digital Personal Data Protection Act, 2023 requires a lawful basis for processing, including valid consent where appropriate. For users in Australia, Canada, New Zealand, and the United States, applicable local privacy laws continue to apply alongside these controls.

Data Minimization

Bidwise should be configured to retain only the data necessary for account access, feature enforcement, fraud prevention, and limited operational troubleshooting.

Breach Response

Deployment operators should maintain an incident response plan so unauthorized access, service compromise, or material data exposure can be investigated, contained, and disclosed where legally required.