Pre-release policy draft

Privacy policy

How ContractPulsar is designed to collect, use, protect, and remove account, company, pursuit, and product-usage information.

Last updated August 1, 2026

This policy is a transparent product implementation draft. It must be reviewed against the final operating entity, vendors, data flows, jurisdictions, retention schedule, and customer agreements before ContractPulsar accepts production customer data.

1. Scope

This draft describes the intended privacy practices for ContractPulsar, a proposal operating system developed by Federal Bid Partners. It covers the public website, account experience, organization workspaces, pursuit vaults, AI-assisted workflows, and support interactions.

It does not govern third-party procurement portals, government websites, BidPulsar, online notary providers, or other services that have their own privacy terms. ContractPulsar and BidPulsar are designed as separate data systems; a future connector will transfer only the data a user explicitly authorizes.

2. Information we process

Depending on the feature used, information may include:

  • Account information: name, email address, authentication events, account status, and workspace membership.
  • Company information: legal name, address, website, logos, UEI, CAGE, NAICS, certifications, registrations, and points of contact.
  • Company evidence: resumes, past performance, policies, rate information, tax and incorporation documents, and other files a user chooses to store.
  • Pursuit information: opportunity URLs, solicitations, amendments, questions, working documents, pricing, reviews, forms, signatures, submission records, and related metadata.
  • Product and device data: feature interactions, timestamps, browser and device characteristics, diagnostics, security events, and approximate network information.
  • Support information: messages and troubleshooting details shared with the support team.

Users control what they upload. ContractPulsar should not be used to store classified information, export-controlled technical data, health records, payment-card data, account passwords, private keys, or other data that the applicable agreement does not expressly authorize.

3. How information is used

Information may be used to:

  • create, secure, and administer accounts and organizations;
  • import, organize, extract, compare, and monitor solicitation materials;
  • support compliance analysis, authoring, pricing, review, artifact generation, signature routing, and submission preparation;
  • provide product support, service notices, security alerts, and requested communications;
  • diagnose errors, prevent abuse, maintain audit history, and improve reliability and accessibility; and
  • meet contractual, legal, and regulatory obligations.

ContractPulsar does not sell pursuit files or company-vault content. Any future advertising or cross-product use would require a clear policy update and, where required, a separate choice.

4. AI processing

ContractPulsar is designed to send selected instructions, excerpts, structured fields, and approved company evidence to AI service providers when needed for a requested feature. AI may assist with extraction, classification, drafting, comparison, research synthesis, pricing advice, review, and question answering.

AI output may be incomplete or incorrect. It remains advisory until required schemas, citations, calculations, validation, and human review have passed. AI is not authorized to sign, approve pricing, communicate externally, or submit a response without explicit user approval.

Final provider terms, retention settings, regional processing, and model-training controls will be documented before production launch.

5. Service providers and sharing

Information may be disclosed only as needed to:

  • infrastructure, storage, authentication, observability, email, document-processing, and AI providers supporting the service;
  • external services a user intentionally invokes, such as procurement portals, calendar tools, email providers, or online notarization;
  • authorized members and collaborators of the user's organization;
  • professional advisers or authorities when required by law, legal process, safety, fraud prevention, or protection of rights; and
  • a successor in a merger, financing, reorganization, or sale, subject to applicable confidentiality and notice requirements.

Vendor access is intended to be contractually limited to providing the relevant service. The final production subprocessors list will be published when vendor scope is complete.

6. Retention and deletion

Different records require different retention periods. The intended schedule distinguishes account data, company evidence, source revisions, working artifacts, audit events, signed packages, submission receipts, support records, and backups.

A verified deletion request will remove or de-identify eligible information after applicable workspace, backup, fraud-prevention, contractual, audit, legal-hold, and regulatory periods. Some immutable audit or submission records may need to remain when law or a customer agreement requires preservation.

Final retention periods and self-service export/deletion behavior will be published before production use.

7. Security

ContractPulsar is designed around private storage, organization isolation, server-only privileged credentials, immutable source history, untrusted-input handling, and explicit approval gates. No security program eliminates all risk.

See the security overview for the current architecture and assurance status. Do not email passwords, access tokens, or sensitive proposal packages to support.

8. Your choices

Subject to the final agreement and applicable law, users may be able to access, correct, export, or request deletion of personal information; manage organization membership; control selected communications; and choose whether to invoke optional integrations.

Authorized workspace administrators may control company and pursuit records on behalf of their organization. If an employer or client provided your account, direct workspace-record requests to that organization first.

ContractPulsar is intended for business users and is not directed to children under 18.

9. Contact

Questions or privacy requests may be sent to contact@federalbidpartners.com. Please use the subject “ContractPulsar privacy request” and avoid including sensitive files in the initial message.

Policy changes will be dated on this page. Material changes will use additional notice when required.