Privacy Policy
Last Updated: 2026-07-26
Version: 1.0
RFPBench (“RFPBench,” “we,” “us,” or “our”) provides a business-to-business platform that helps organizations create, issue, respond to, evaluate, and manage requests for proposals, requests for information, security questionnaires, vendor questionnaires, and related procurement or sales-response workflows.
This Privacy Policy explains how we collect, use, disclose, retain, and protect personal information when you visit our website, request early access, communicate with us, or use our platform and related services.
This Privacy Policy is intended to apply to users in Canada, the United States, the European Economic Area, the United Kingdom, Switzerland, and other jurisdictions where our services may be made available.
1. Who we are
Company: Sama Ventures Inc.
Product: RFPBench
Jurisdiction: Burnaby, BC, Canada
Privacy contact: Privacy Officer ([email protected])
For customers located in the European Economic Area or the United Kingdom, we will provide additional data-processing terms, including appropriate international-transfer terms, where required.
2. Scope of this Privacy Policy
This Privacy Policy applies to personal information we process in connection with:
- our website;
- early-access, beta, pilot, waitlist, newsletter, and demo forms;
- account registration and user administration;
- customer support, sales, marketing, and product communications;
- the RFPBench platform;
- uploaded RFPs, questionnaires, answers, policy documents, security materials, templates, scoring rubrics, comments, and related customer content;
- AI-assisted drafting, search, summarization, comparison, scoring support, and review workflows;
- analytics, security monitoring, fraud prevention, and service improvement.
This Privacy Policy does not apply to third-party websites, services, or integrations that we do not control.
3. Our role: controller/business and processor/service provider
Depending on the context, RFPBench may act in different privacy roles.
3.1 Information we process for our own business purposes
We act as an independent controller, business, or similar responsible party when we process information for purposes such as operating our website, managing early-access requests, marketing, sales, account administration, billing, security, analytics, and customer communications.
3.2 Customer content we process on behalf of customers
When a customer uploads, submits, or stores RFPs, RFI documents, vendor responses, policy documents, security questionnaires, prior answers, scoring comments, internal notes, user assignments, and related files in the platform, we generally process that content on behalf of the customer.
In that context, the customer is usually responsible for determining what personal information is included in the content, why it is processed, who may access it, and how long it should be retained. RFPBench processes that information to provide the service, support the customer, secure the platform, comply with law, and perform other activities authorized by the customer agreement or data-processing agreement.
4. Personal information we collect
We may collect the following categories of personal information.
4.1 Account and contact information
This may include:
- name;
- business email address;
- phone number;
- company name;
- job title;
- department;
- business address;
- username;
- password or authentication credentials;
- account preferences;
- communication preferences.
4.2 Early-access, demo, and sales information
This may include:
- information submitted through waitlist, demo, contact, or early-access forms;
- information about whether you issue RFPs, respond to RFPs, or both;
- business needs, use cases, procurement workflows, sales-response workflows, and pain points;
- company size, industry, and region;
- communications with our sales or support team.
4.3 Platform usage and workflow information
This may include:
- account activity;
- login records;
- project, workspace, team, and role information;
- RFP creation activity;
- vendor invitation and submission activity;
- responder workflow activity;
- review, approval, assignment, scoring, and commenting activity;
- document upload and processing activity;
- search queries entered into the platform;
- AI-drafting, comparison, summarization, or scoring-support activity;
- timestamps, audit logs, and security logs.
4.4 Customer content
Customers and users may upload, submit, create, or process content in RFPBench, including:
- RFPs, RFIs, RFQs, questionnaires, and similar documents;
- vendor responses and proposal materials;
- security questionnaires and due-diligence materials;
- policy documents, compliance documents, certifications, reports, and templates;
- previous RFP answers and approved answer libraries;
- scoring matrices, evaluation comments, and internal notes;
- source documents used to generate or support draft answers;
- files, spreadsheets, documents, and metadata.
Customer content may contain personal information if the customer or user includes it.
Customers should not upload sensitive personal information unless it is necessary for the RFP or response workflow and permitted under applicable law and the customer’s agreement with us.
4.5 Device, technical, and analytics information
We may collect:
- IP address;
- browser type;
- device type;
- operating system;
- pages visited;
- referring URLs;
- timestamps;
- approximate location derived from IP address;
- cookie identifiers;
- session activity;
- error logs;
- diagnostic information;
- security and fraud-prevention signals.
4.6 Communications information
If you contact us, we may process:
- email messages;
- support tickets;
- chat messages;
- call notes;
- meeting notes;
- feedback;
- survey responses;
- product-interview notes.
If calls or meetings are recorded, we will provide notice where required.
4.7 Billing and commercial information
For paid tiers, free trials, promotional plans, and self-serve subscriptions, we may process billing contact details, account plan, package or subscription tier, seat count, usage limits, purchase history, invoice records, receipts, payment status, tax information, renewal dates, cancellation status, upgrade and downgrade history, and related commercial records.
We use one or more third-party payment processors, subscription-management providers, tax providers, or billing platforms to process payments and manage billing. These providers may collect, process, and store payment information, including payment method details, cardholder name, billing address, partial card number, card expiration date, transaction details, invoices, receipts, tax information, subscription package details, and payment history.
RFPBench does not intend to store full credit card numbers, bank account numbers, or card security codes on its own systems. Payment information is processed by third-party providers that are responsible for protecting payment card data in accordance with applicable payment-card security requirements. Our payment processor may be Stripe or another comparable provider. The payment processor’s own terms and privacy policy may also apply to its handling of payment information.
4.8 Sensitive personal information
RFPBench is not designed to collect sensitive personal information from ordinary website visitors. However, customer content may sometimes include sensitive information if a customer uploads it.
Depending on jurisdiction, sensitive information may include government identifiers, precise location, financial account details, health information, biometric information, racial or ethnic origin, religious or philosophical beliefs, union membership, sexual orientation, criminal-offense information, or similar categories.
Customers are responsible for ensuring that they have the right to upload and process such information through the platform. We will process sensitive customer content only as necessary to provide the service, comply with the customer agreement, protect the platform, or comply with law.
5. Sources of personal information
We may collect personal information from:
- you directly;
- your employer or organization;
- other users in your workspace;
- buyers that invite vendors to respond to an RFP;
- responders that upload or submit responses;
- customer administrators;
- uploaded documents and files;
- third-party authentication providers;
- CRM, email, analytics, hosting, security, support, and infrastructure providers;
- public business sources, where permitted;
- event, referral, or partner sources, where permitted.
6. How we use personal information
We use personal information for the following purposes.
6.1 To provide and operate the service
We use information to:
- create and manage accounts;
- authenticate users;
- provide workspaces and projects;
- create, issue, respond to, compare, and manage RFPs and related documents;
- support buyer-side and responder-side workflows;
- process uploads and documents;
- generate searchable knowledge bases;
- draft, summarize, compare, classify, or organize content;
- display sources, confidence indicators, comments, and review history;
- support human review, approval, and finalization workflows;
- manage roles, permissions, and access controls;
- provide exports, reports, and audit history.
6.2 To provide AI-assisted features
RFPBench may use AI-assisted functionality to help users draft answers, compare responses, summarize documents, identify relevant source material, organize prior answers, suggest scoring support, or assist with RFP creation. To provide these features, RFPBench may transmit customer content, user prompts, document excerpts, metadata, and related information to third-party AI, machine-learning, document-processing, or natural-language-processing providers acting on our behalf.
Unless we state otherwise in a separate customer agreement, data-processing agreement, or product setting:
- we do not use customer content to train public AI models;
- we do not allow AI providers to use customer content to train their general models;
- AI-generated outputs should be reviewed by a human before use;
- users remain responsible for verifying accuracy, completeness, confidentiality, and appropriateness of AI-assisted outputs;
- AI outputs may be based on customer-provided documents, prior answers, policies, templates, metadata, and user prompts;
- AI-generated drafts may include errors or omissions and should not be treated as legal, procurement, compliance, security, or professional advice.
If we later offer optional model-training, benchmarking, or product-improvement programs using customer content, we will provide additional notice and, where required, obtain consent or contractual authorization.
6.3 To improve and develop the service
We may use information to:
- debug and improve product functionality;
- understand usage patterns;
- improve user experience;
- develop new features;
- measure performance;
- improve document parsing, search, classification, workflow design, and user interfaces;
- conduct internal analytics.
Where practical, we use aggregated, de-identified, or anonymized information for product improvement.
6.4 To communicate with you
We may use information to:
- respond to questions;
- provide support;
- send administrative notices;
- provide onboarding materials;
- send security or service alerts;
- communicate about beta access or pilots;
- request feedback;
- send product updates, newsletters, or marketing communications where permitted.
You may opt out of marketing emails at any time. You may still receive non-marketing service, security, account, legal, or transactional messages.
6.5 To secure the platform
We use information to:
- detect, prevent, and investigate unauthorized access;
- monitor abuse, fraud, and security incidents;
- maintain audit logs;
- protect customer content;
- enforce access controls;
- troubleshoot technical issues;
- maintain platform availability and integrity.
6.6 To comply with law and enforce rights
We may use information to:
- comply with legal obligations;
- respond to lawful requests;
- enforce agreements;
- protect our rights, users, customers, and the public;
- establish, exercise, or defend legal claims;
- conduct compliance, accounting, audit, and recordkeeping activities.
7. Legal bases for processing under European and UK privacy law
Where the GDPR, UK GDPR, or similar law applies, we rely on one or more of the following legal bases:
Where we rely on legitimate interests, we consider the nature of the information, the impact on individuals, and whether safeguards are appropriate.
8. How we disclose personal information
We may disclose personal information to the following categories of recipients.
8.1 Service providers and subprocessors
We may use third parties that help us operate the website, platform, and business, including providers of:
- cloud hosting and infrastructure;
- database and storage services;
- authentication and identity management;
- email delivery;
- CRM and sales tools;
- customer support tools;
- analytics;
- security monitoring;
- logging and error tracking;
- payment processing;
- AI, machine learning, document parsing, or natural-language processing services;
- professional services, such as legal, accounting, audit, and compliance advisors.
We require service providers to protect personal information and use it only for authorized purposes.
8.2 Customer organizations and workspace users
If you use RFPBench through your employer or organization, information associated with your account and activity may be available to that organization’s administrators and authorized users.
For example, administrators may see your name, email address, role, permissions, activity logs, document activity, comments, assignments, approvals, submissions, and other workspace activity.
8.3 Buyers, responders, and invited parties
RFPBench is designed to support interactions between buyers and responders. Depending on the workflow:
- a buyer may invite vendors or responders to view and respond to an RFP;
- a responder may submit answers, files, and related information to a buyer;
- buyer-side users may view vendor submissions and compare responses;
- responder-side users may collaborate internally before submitting answers;
- customer-configured permissions may determine which users can view, edit, approve, score, or export information.
Users should not submit information they are not authorized to share.
8.4 Business transfers
We may disclose or transfer information in connection with a merger, acquisition, financing, reorganization, sale of assets, bankruptcy, due diligence process, or similar business transaction, subject to appropriate confidentiality and legal protections.
8.5 Legal and safety disclosures
We may disclose information if we believe it is reasonably necessary to:
- comply with law, regulation, legal process, or governmental request;
- enforce our agreements;
- protect the security or integrity of the service;
- investigate fraud, abuse, or security incidents;
- protect the rights, property, or safety of RFPBench, our customers, users, or others.
9. Selling or sharing personal information
We do not sell personal information for money.
Unless we update this Privacy Policy and provide required choices, we do not “sell” personal information or “share” personal information for cross-context behavioral advertising as those terms are defined under California privacy law.
If we use advertising or analytics technologies that may be considered a sale, sharing, or targeted advertising under applicable law, we will provide any required notices and opt-out mechanisms.
10. Cookies and similar technologies
We may use cookies, pixels, local storage, and similar technologies to:
- operate the website and platform;
- keep users signed in;
- remember preferences;
- secure accounts;
- measure site performance;
- understand usage;
- improve the product;
- support marketing, where permitted.
Some cookies are necessary for the service. Others may be optional. Where required by law, we will request consent before using non-essential cookies or similar technologies.
You can manage cookies through your browser settings. If we provide a cookie banner or preference center, you may also manage choices there.
11. Data retention
We keep personal information only as long as reasonably necessary for the purposes described in this Privacy Policy, unless a longer period is required or permitted by law.
Retention periods may depend on:
- the type of information;
- the customer agreement;
- account status;
- workspace settings;
- legal, tax, accounting, and audit requirements;
- security and fraud-prevention needs;
- dispute-resolution needs;
- backup and disaster-recovery schedules.
Typical retention practices may include:
When information is no longer needed, we delete, anonymize, aggregate, or securely retain it only where legally permitted.
12. Security
We use administrative, technical, and organizational safeguards designed to protect personal information and customer content. These may include:
- access controls;
- authentication controls;
- role-based permissions;
- encryption in transit;
- encryption at rest where appropriate;
- logging and monitoring;
- vulnerability management;
- backup and recovery controls;
- confidentiality obligations;
- internal access restrictions;
- security review of vendors;
- incident-response procedures.
No system is completely secure. Customers and users are responsible for using strong passwords, protecting login credentials, configuring permissions carefully, and ensuring they have authority to upload and share content.
13. Confidential customer content
RFPs, proposals, vendor questionnaires, pricing materials, security documents, policies, certifications, product roadmaps, and similar business documents may be confidential.
We treat customer content as confidential and use it only to provide, secure, support, maintain, and improve the service as permitted by the customer agreement and this Privacy Policy.
We do not intentionally make customer content public. Customers control who has access to their workspaces, projects, documents, invitations, and submissions.
14. International transfers
We may process and store information in Canada, the United States, the European Economic Area, the United Kingdom, and other locations where we or our service providers operate.
If personal information is transferred across borders, it may be subject to the laws of the jurisdiction where it is processed. Where required, we use appropriate safeguards, which may include contractual protections, data-processing agreements, standard contractual clauses, adequacy mechanisms, or other legally recognized transfer tools.
15. Your privacy rights
Depending on where you live and the nature of our relationship with you, you may have rights to:
- access personal information;
- confirm whether we process personal information;
- correct inaccurate or incomplete information;
- delete personal information;
- restrict processing;
- object to processing;
- withdraw consent;
- receive a portable copy of personal information;
- opt out of marketing communications;
- opt out of certain targeted advertising, sale, or sharing, where applicable;
- appeal a denied privacy request, where applicable;
- complain to a privacy regulator.
Some rights may be limited by law, customer instructions, security requirements, confidentiality obligations, or our need to retain information for legitimate business or legal purposes.
To exercise rights, contact us at: PrivacyOfficer@rfpbench.com
If your information is contained in customer content that we process on behalf of a customer, we may direct your request to that customer or ask you to contact the customer directly.
16. Canadian privacy rights
If Canadian privacy law applies, you may request access to personal information we hold about you and request correction if it is inaccurate or incomplete.
We may ask you to verify your identity before responding. We may refuse access or correction in limited circumstances permitted by law, such as where disclosure would reveal another person’s personal information, confidential commercial information, privileged information, or information that cannot be disclosed for legal or security reasons.
If you have a privacy concern, you may contact our Privacy Officer at PrivacyOfficer@rfpbench.com. You may also have the right to contact the Office of the Privacy Commissioner of Canada or a provincial privacy regulator.
17. European Economic Area, United Kingdom, and Swiss rights
If the GDPR, UK GDPR, or similar law applies, you may have the right to:
- be informed about processing;
- access your personal data;
- correct inaccurate personal data;
- request erasure;
- restrict processing;
- object to processing based on legitimate interests;
- object to direct marketing;
- request data portability;
- withdraw consent where processing is based on consent;
- not be subject to a decision based solely on automated processing that produces legal or similarly significant effects, subject to applicable exceptions;
- complain to a supervisory authority.
RFPBench’s AI-assisted features are intended to support human review and workflow efficiency. They are not intended to make solely automated decisions with legal or similarly significant effects about individuals.
18. U.S. state privacy rights
Residents of certain U.S. states may have privacy rights under state laws, depending on whether those laws apply to RFPBench and the relevant processing activity.
These rights may include the right to:
- know or confirm whether we process personal information;
- access personal information;
- correct personal information;
- delete personal information;
- obtain a portable copy of personal information;
- opt out of targeted advertising;
- opt out of sale of personal information;
- opt out of certain profiling;
- limit use or disclosure of sensitive personal information, where applicable;
- appeal a denied request.
To exercise these rights, contact us at PrivacyOfficer@rfpbench.com.
We will not discriminate against you for exercising privacy rights.
19. California notice at collection
This section applies to California residents where the California Consumer Privacy Act, as amended, applies.
The following table describes categories of personal information we may collect, the sources, purposes, disclosure categories, and general retention approach.
We do not knowingly collect sensitive personal information for the purpose of inferring characteristics about individuals.
We do not sell personal information for money. Unless we update this Privacy Policy and provide required choices, we do not share personal information for cross-context behavioral advertising.
20. How to submit a privacy request
You may submit a privacy request by emailing:
Please include enough information for us to understand and process your request. We may need to verify your identity and your authority to make the request.
If you are making a request on behalf of someone else, we may ask for proof of authorization.
If your request concerns information controlled by one of our customers, we may refer the request to that customer.
21. Marketing communications
You may unsubscribe from marketing emails by clicking the unsubscribe link in the email or contacting us.
Even if you unsubscribe from marketing communications, we may still send service, security, legal, billing, and transactional messages.
22. Children
RFPBench is a business-to-business service and is not intended for children. We do not knowingly collect personal information from children under 16. If you believe a child has provided personal information to us, contact us, and we will take appropriate steps.
23. Automated processing and AI-assisted outputs
RFPBench may use AI-assisted tools to support RFP drafting, answer retrieval, summarization, comparison, scoring support, classification, and workflow automation.
These tools are intended to assist users, not replace professional judgment. Users should review AI-assisted outputs before relying on them, submitting them, or sharing them externally.
We do not intend to use AI-assisted features to make decisions about individuals that produce legal or similarly significant effects without appropriate human involvement and safeguards.
24. De-identified, aggregated, and anonymized information
We may create and use aggregated, anonymized, or de-identified information for analytics, benchmarking, product improvement, security, research, and business purposes.
We will not attempt to re-identify information that has been anonymized or de-identified, except where permitted by law for testing, security, or compliance purposes.
25. Third-party integrations
RFPBench may integrate with third-party services, such as identity providers, document storage tools, CRM systems, email tools, calendar tools, collaboration tools, or customer systems.
If you connect a third-party integration, we may exchange information with that service as authorized by you or your organization. Third-party services are governed by their own terms and privacy policies.
26. Data-processing agreements
For business customers, we may provide a data-processing agreement that describes how we process customer personal information, subprocessors, confidentiality, security measures, international transfers, assistance with data-subject requests, deletion or return of customer content, and audit-related commitments.
If there is a conflict between this Privacy Policy and a signed customer agreement or data-processing agreement, the signed agreement will govern to the extent of the conflict.
27. Security incidents
If we become aware of a security incident involving personal information, we will assess the incident and take appropriate steps. Where required by law or contract, we will notify affected customers, individuals, regulators, or other parties.
Customers are responsible for notifying affected individuals or regulators where they are the controller or legally responsible organization, unless the customer agreement states otherwise.
28. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. The “Last Updated” date shows when it was most recently revised.
If we make material changes, we will provide notice as required by law, such as by posting a notice on our website, notifying account administrators, or sending an email.
Your continued use of the website or service after an updated Privacy Policy becomes effective means that you acknowledge the updated policy, where permitted by law.
29. Contact us
If you have questions, requests, or complaints about this Privacy Policy or our privacy practices, contact:
RFPBench Privacy Officer
Company: Sama Ventures Inc.
Jurisdiction: Burnaby, BC, Canada
Email: [email protected]
If you are not satisfied with our response, you may have the right to contact your local privacy regulator.