DRAFT - SUBJECT TO PROFESSIONAL LEGAL REVIEW

Privacy Policy

Version: 1.0.0-draftLast Updated: 2026-09-12

This document is a draft. It must not be relied upon as a final legal document. All provisions are subject to legal review and approval.

Table of Contents

  1. 1.Overview
  2. 2.Information Provided During Registration
  3. 3.Organization Information
  4. 4.Contact Details
  5. 5.Opportunity and Tender Information
  6. 6.Uploaded Documents
  7. 7.Bid Information
  8. 8.Communications and Engagement Data
  9. 9.Acquisition Intelligence
  10. 10.Official Source and Prospect Research Data
  11. 11.Audit and Security Logs
  12. 12.Authentication Data
  13. 13.Cookies and Technical Data
  14. 14.Purposes of Processing
  15. 15.Data Sharing Within Authorized Workflows
  16. 16.Service Providers and Infrastructure
  17. 17.Retention
  18. 18.Security Safeguards
  19. 19.User Rights
  20. 20.International Data Considerations
  21. 21.Policy Updates
  22. 22.Contact Details
1

Overview

BuildExchange is a private global construction and infrastructure procurement exchange. This Privacy Policy describes how BuildExchange collects, uses, stores, and protects information when users interact with the platform. BuildExchange is the marketplace infrastructure provider. It is not a contractor, developer, employer, insurer, or legal adviser.

2

Information Provided During Registration

When a user registers, BuildExchange collects the email address and password. Users may also register via Google OAuth, in which case Google provides the email address and basic profile information. Authentication data is managed by the platform authentication service.

3

Organization Information

When a user creates an Organization, BuildExchange collects the legal name, display name, country, registration number, website, industry, description, address, city, established year, primary contact email, and primary contact phone. This information is used to identify and verify the organization within the Exchange.

4

Contact Details

BuildExchange collects contact names, titles, email addresses, phone numbers, and roles for individuals associated with an Organization. This includes primary marketplace contacts, tender contacts, commercial contacts, and technical contacts.

5

Opportunity and Tender Information

Opportunity Owners submit project information including titles, descriptions, locations, project scale, deadlines, procurement models, confidentiality levels, and rescue project details where applicable. This information is shared with invited participants according to the configured access rules.

6

Uploaded Documents

Users may upload project documents, bid attachments, and other files. Documents are stored in platform-managed storage. Access to documents is controlled server-side based on the document access scope, organization membership, NDA status, and Data Room permissions.

7

Bid Information

Bidders submit commercial details including pricing, schedules, mobilization plans, supply chain items, guarantees, warranties, and attachments. Bid information is visible only to the bidding organization and the Opportunity Owner, subject to the configured bidding visibility mode and identity release stage.

8

Communications and Engagement Data

BuildExchange records engagement data including invitation status, expression of interest status, shortlist status, NDA status, Data Room access status, bid status, and contact history. This data supports the tender administration workflow.

9

Acquisition Intelligence

BuildExchange maintains research data about potential marketplace participants through OutreachProspect records. This includes company names, countries, websites, capability assessments, verification status, and acquisition status. Acquisition intelligence data is accessible only to platform administrators.

10

Official Source and Prospect Research Data

BuildExchange ingests and references official public sources, such as government lists, regulatory publications, and parliamentary research. OfficialSource records preserve provenance, including source organization, publication date, retrieval date, and status (current, historical, or superseded). Historical authorization is never displayed as current authorization.

11

Audit and Security Logs

BuildExchange maintains audit logs of significant platform events, including organization creation, opportunity lifecycle changes, bid submissions, verification decisions, commercial obligation calculations, and access events. Audit logs are used for security, compliance, and dispute resolution.

12

Authentication Data

Authentication credentials are managed by the platform authentication service. Passwords are not stored in plaintext. Session tokens are used to maintain authenticated sessions.

13

Cookies and Technical Data

BuildExchange uses essential technical mechanisms to maintain user sessions and platform functionality. The platform does not use third-party advertising cookies. Language preference is stored in the browser local storage.

14

Purposes of Processing

BuildExchange processes information for the following purposes: platform operation, organization verification, tender administration, matching of opportunities to qualified participants, security, fraud and abuse prevention, service communications, and legal and compliance purposes.

15

Data Sharing Within Authorized Workflows

Information is shared between organizations only within authorized marketplace workflows. Opportunity Owners can see bids submitted to their opportunities. Bidders can see only information they have been explicitly authorized to access. A bidder cannot access another bidder identity, bid, price, documents, or metadata unless explicitly permitted by the configured release rules.

16

Service Providers and Infrastructure

BuildExchange operates on cloud infrastructure providers that host the application, database, and file storage. Specific infrastructure providers are determined by the platform operator. BuildExchange does not sell user data to third parties.

17

Retention

BuildExchange retains information for as long as the organization account is active or as necessary to provide services, comply with legal obligations, resolve disputes, and enforce agreements. Audit logs may be retained for an extended period for security and compliance purposes.

18

Security Safeguards

BuildExchange implements organization-level isolation, row-level security, server-side authorization checks, NDA gates, Data Room access controls, sealed bidding, bid anonymity masking, signed download URLs, and audit logging. These safeguards are designed to protect information from unauthorized access. No system can guarantee complete security.

19

User Rights

Users may request access to their personal data, request corrections, or request deletion of their account. Organization-level data may be subject to retention requirements. Users can contact BuildExchange using the contact details provided in this policy.

20

International Data Considerations

BuildExchange serves participants across multiple countries. Information may be processed and stored in data centers located outside the user country of residence. By using the platform, users acknowledge that their information may be transferred to and processed in countries with different data protection regulations.

21

Policy Updates

BuildExchange may update this Privacy Policy. Updates will be versioned. Where a material change affects user rights, users may be required to accept the updated version. The effective date and version are displayed at the top of this document.

22

Contact Details

For privacy inquiries, contact: Haim Etkin, Founder, BuildExchange. Email: haimetkin@gmail.com. WhatsApp: +972-52-3728828.