Acceptable Use Policy
In short. Use Bidwhistle for your own business. Do not attack it, copy it wholesale, resell what is in it, or use it to bother the public-sector contacts named in tender notices. Check what is in a document before you upload it — tender packs often name other people’s staff. Do not pass AI output off as human, official or guaranteed.
1. Scope and how this policy works
1.1 This Acceptable Use Policy sets out what you may and may not do with the Service. It expands on the acceptable use clause of our Terms of Service and forms part of the Agreement, so breaking it is a breach of the Agreement.
1.2 It binds you — the customer — and every Authorised User on your account, including employees and contractors. You must make sure they know and follow it, and you are responsible for their acts and omissions as if they were your own.
1.3 It applies equally on a free trial, on beta features, and through any API we make available.
1.4 The examples here are illustrative, not exhaustive, and we apply the policy proportionately and in good faith. If you are unsure whether something is allowed, ask us first at support@bidwhistle.com — asking is free, and guessing wrong can cost you your account.
1.5 We may update this policy. Section 13 says how, and what notice you get.
2. Definitions used in this policy
Terms defined in the Terms of Service have the same meaning here. The ones used most are:
| Term | Meaning |
|---|---|
| Service | The Bidwhistle platform, website, applications, APIs and support |
| AI Features / Olivia | Any feature using generative AI or machine learning / our AI assistant with a synthetic voice and animated avatar |
| Response Workspace | The bid-writing surface of the Service, where you upload a tender pack and can have it read, have answers drafted, have a requirement explained and have a draft bid reviewed. It is an AI Feature |
| Input / Output | Content you submit to AI Features / content they generate |
| Procurement Data | Tender and award notices, buyer information and related procurement information we collect from public sources, with the structure and enrichment we add. Not Customer Data |
| Buyer Contact Data | The name, job title, employer and published work email address and telephone number of a person named as a contact in a notice. Part of Procurement Data; subject to section 9 |
| Authorised User | An individual authorised by you to use the Service under your account |
3. Prohibited content and conduct
You must not use the Service, or let anyone else use it, to:
3.1 Break the law — including competition law (no bid rigging, market sharing, price fixing or coordinating bidding with a competitor), anti-bribery, procurement law, sanctions, consumer law and data protection law.
3.2 Infringe third-party rights — copyright, database right, trade marks, trade secrets, confidence or privacy. Do not upload material you have no right to upload, such as another supplier’s confidential bid, and do not use our brand or any public body’s name, logo or crest to suggest an endorsement.
3.3 Harass or abuse anyone — our people, our suppliers, other customers, or the public-sector contacts named in notices. No threats, intimidation, stalking, defamation, or discriminatory, hateful or gratuitously offensive content, and no continuing to contact someone after they have asked you to stop (section 9).
3.4 Distribute malware — no viruses, ransomware or other harmful code, and no hosting phishing pages or attack infrastructure.
3.5 Commit fraud or misrepresent things — procurement and invoice fraud; false information to obtain a subscription, refund, trial or higher allowance; multiple accounts to evade limits or billing; misstating your identity, accreditations, capacity or eligibility to a buyer; and impersonating any person or organisation, including a public body.
3.6 Upload other people’s personal data without a lawful basis. Do not upload to the Response Workspace, or otherwise submit to AI Features, personal data about anyone that you have no lawful basis to share with us. Before you upload a document, check what is in it, and remove or redact the personal data we do not need in order to do what you are asking. When you upload a document you are disclosing its contents to us and to the model provider that reads it; you are the controller of that disclosure, and our Data Processing Agreement sets out our role as processor.
This matters more in procurement than in most sectors. Tender packs commonly contain schedules naming the incumbent supplier’s staff — TUPE schedules listing employees by name with their roles, salaries and length of service. Those people are not our customers, have no relationship with us, and will not be expecting their details to reach an AI provider. Take the same care with them that you would want taken with your own staff.
3.7 Upload special category data. Never upload or submit special category data as defined in Article 9 of the GDPR — data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric data used to identify someone, health data, or data about a person’s sex life or sexual orientation — or data about criminal convictions and offences under Article 10. The Service is not designed for it and we do not accept it. If a pack you need to work on contains any, redact it before you upload. On upload we show you a notice, list every file in the pack so that only the ones you leave ticked are read, and leave files whose names indicate a staff record unticked by default. That default is overridable, it reads file names rather than contents — so a schedule named “Appendix 7” is not recognised — and it works on whole files. The check remains yours to make.
3.8 Breach of clause 3.6 or 3.7 is a breach we treat as material, and the indemnity in our Terms of Service applies to claims arising from what you upload.
4. Security and integrity
4.1 Testing. Do not probe, scan, load test, fuzz or penetration test the Service or its infrastructure without our prior written permission. We do not refuse such requests as a matter of course — email security@bidwhistle.com and we will agree scope and timing in writing. Testing outside an agreed scope may be a criminal offence.
4.2 Access controls. Do not circumvent, disable or defeat authentication, seat or usage limits, rate limits, feature gates or billing controls, and do not access or try to access any account, data or system you are not authorised to reach, including another customer’s data.
4.3 Interference. Do not disrupt the Service or other customers’ use of it, whether by denial-of-service activity, deliberately abusive request patterns or content designed to corrupt our data, and do not remove, obscure or alter any security notice, provenance marking or AI labelling.
4.4 Reverse engineering. Do not copy, decompile, disassemble or reverse engineer the Service, or try to derive its source code, models, prompts, weights or scoring logic — except to the extent that this restriction is prohibited by applicable law, including interoperability rights under Directive 2009/24/EC and its national implementations. Where you have such a right, ask us first: it is usually quicker for us to give you the interface information.
4.5 Responsible disclosure. Report vulnerabilities to security@bidwhistle.com with what you found, how to reproduce it and how to reach you, and give us a reasonable chance to fix it before telling anyone else. If you report in good faith and follow clause 4.6, we will not bring or support a claim against you under the Agreement, and will not report you to law enforcement, for the research behind the report. We will acknowledge it, keep you informed, and credit you if you would like.
4.6 To stay within that: use only your own account and test data; do not access, alter or disclose anyone else’s data beyond what is needed to demonstrate the issue; do not degrade the Service; no social engineering, phishing or physical attacks; and do not demand payment for withholding a finding. We do not currently run a paid bug bounty programme — we would rather say so than imply otherwise.
5. Data extraction and redistribution
5.1 No scraping or bulk extraction, by automated or non-automated means. “Non-automated” is deliberate: systematically copying records by hand, by screenshot or by a team of people is caught just as much as a script. No headless browsers, extensions, macros or robotic process automation replicating an API we have not given you.
5.2 No resale or redistribution. Do not sell, resell, licence, rent, syndicate, republish or otherwise commercially redistribute Procurement Data or Outputs, in original or modified form — in particular as a tender alerting service, data feed, newsletter or lead-generation product — and do not use them to build or enrich a competing database.
5.3 What you may do. Use the Service and its Outputs freely for your own internal business purposes: researching opportunities, deciding whether to bid, briefing your team and preparing your own bid documents. Advisers and subcontractors working on a specific bid for you may use the material for that bid and nothing else. What you may not do is turn the Service into something you supply to the market.
5.4 APIs and credentials. We do not currently offer a public API. If we provide one, use it only in line with its documentation, authentication requirements and published limits. Do not share login credentials, session tokens or API keys with anyone who does not hold a seat, embed them client-side or publish them, and do not rotate one seat between people to avoid buying more. Reassigning a seat when someone leaves is fine.
5.5 Benchmarking. Evaluate the Service internally as much as you like, but do not publish benchmarking or comparison results without our prior written consent, which we will not unreasonably withhold where the testing is fair and the results accurate.
6. Fair use, rate limits and excessive load
6.1 Your plan sets your seats and allowances for searches, alerts, exports, AI Features usage and API calls, as shown when you choose your plan at sign-up. Beyond those limits, use is subject to fair use: a pattern of activity consistent with a business of your size using the Service for its own purposes.
6.2 If your usage exceeds a limit or becomes excessive, we normally act in this order: throttle the excess requests; notify you and ask you to come back within the limit; offer an overage charge or a plan that fits, never charging overage without telling you the rate first; and, if it continues, suspend the affected feature or the account under the Terms of Service. We may go straight to suspension where clause 12.3 applies.
6.3 Anti-abuse limits. We may apply technical rate limits, request quotas and other protective measures at any time and without notice where we reasonably believe they are needed to protect the security, stability or availability of the Service, or to stop abuse in progress. They are safeguards, not sanctions, and do not count as Downtime under our Service Level Agreement.
7. AI-specific restrictions
7.1 No reliance as professional advice. Do not treat Outputs as legal, procurement, bid-writing, tax, financial or eligibility advice, present them to anyone as such, or rely on them instead of reading the original notice. Check the material facts — dates, values, thresholds, eligibility, deadlines — against the notice published by the contracting authority before you act.
7.2 No solely automated decisions about people. Do not use AI Features or Outputs to make decisions producing legal effects concerning an individual, or similarly significantly affecting them, based solely on automated processing, without meaningful human review by someone able to reach a different conclusion.
7.3 No misrepresenting Outputs. Do not present an Output as human-generated where the law or basic honesty requires otherwise; as official government information or the text of a notice; or — a fit score especially — as a prediction or guarantee of a bid outcome, shortlisting, award or eligibility.
7.4 No attacks on the AI. Do not attempt prompt injection, jailbreaking, instruction extraction or any other technique intended to make AI Features act outside their intended purpose, ignore safeguards or reveal their configuration, and do not embed hidden instructions in material you submit in order to manipulate them.
7.5 No model extraction or competing training. Do not scrape, extract, distil or reconstruct any model, prompt, weight, embedding or scoring logic used in the Service, and do not use Inputs, Outputs or Procurement Data obtained through it to train any model that competes with the Service or with the models of the AI providers we use — Anam, Google (reached through Anam), Anthropic and Voyage AI. Our sub-processors list, available on request at privacy@bidwhistle.com, says which of them does what.
7.6 Practices prohibited by the EU AI Act. Do not use the Service, AI Features or Outputs for any practice prohibited by Article 5 of Regulation (EU) 2024/1689 (the EU AI Act) — social scoring, manipulative or exploitative techniques, predictive policing based on profiling alone, untargeted scraping of facial images, emotion inference at work or in education, biometric categorisation to deduce protected characteristics, and the other practices that Article bans. That is a summary, not a substitute for the Article. Where you deploy Outputs in your own systems, your obligations under the EU AI Act are yours, not ours.
8. Olivia and voice
How Olivia works, so that the rules below make sense. Olivia’s avatar, synthetic voice and speech-to-text are provided by Anam. What you say is transcribed, your profile context is added, and the reply is produced by a Google model that we reach through Anam, then spoken by the avatar. Anam keeps the session recording — your audio and the avatar video — and the transcript for 30 days, then deletes them automatically, and does not use them to train models. Our Privacy Notice and AI Use Disclosure set out where that processing happens and what we are doing about it. Everything you say to Olivia therefore leaves our systems and reaches those providers, which is why the rules in this section are about what you put into a conversation as much as what you do with the output.
8.1 No voice cloning or imitation. Do not use the Service to clone, synthesise, imitate or approximate the voice of any real, identifiable person, living or dead, whether or not you have their consent, and do not submit recordings of a person’s voice so that it can be reproduced or matched.
8.2 No deceiving people about what they are talking to. Do not use Olivia, or any Output, to make a person believe they are dealing with a human being when they are not. Do not remove, suppress, delay, obscure or talk over the disclosure identifying Olivia as an AI system, and do not instruct Olivia to deny that she is one.
8.3 If you expose Olivia or Outputs to third parties, you must (a) tell them clearly, before they engage, that they are dealing with an AI system and that the content was AI-generated; (b) keep any AI labelling and machine-readable marking intact; and (c) where you publish AI-generated text to inform the public on matters of public interest, disclose that it was artificially generated, unless it has had human review or editorial control and a natural or legal person holds editorial responsibility for it. These reflect Article 50 of the EU AI Act; our AI Use Disclosure explains how we meet our own side of it.
8.4 If outbound calling is ever enabled. Olivia makes no outbound telephone calls today. If we ever enable outbound calling and you use it, you must comply with all of the following. We will not enable it on any other basis.
| Requirement | In practice |
|---|---|
| Electronic communications and telemarketing law | The ePrivacy Directive as implemented in each country you call, PECR for UK calls, and the national direct marketing rules of the country called |
| Preference services and suppression | Screen every UK number against the TPS and CTPS, and against the equivalent register elsewhere; keep your own do-not-call list and add anyone who asks you to stop, immediately |
| Calling hours and identification | Only within the permitted calling hours where you are calling, using a valid, non-withheld caller line identity that reaches a monitored line |
| Disclosure and recording | Say at the start of the call that the caller is an AI system and, if the call is recorded, say so and obtain any consent local law requires |
| Consent evidence | Evidence of the lawful basis or consent for every number called — what, when, how and by whom — kept for the longer of the statutory minimum in that country and five years |
| Human escape route | Let the person ask for a human, and provide one |
8.5 You are the controller of the marketing you send and the calls you make. Our Data Processing Agreement governs our role as processor; it does not make your campaigns lawful.
9. Marketing and contact data
Read this section carefully. It is the one most likely to cost you your account.
9.1 Why it exists. Procurement notices name real people, and buyers publish their work contact details for one reason: so suppliers can ask questions about that tender. Those details are personal data, and do not stop being so because they were published. Our lawful basis for holding them is legitimate interests, and the balance that makes that lawful depends on the data being used for the purpose the buyer published it for. If customers use Buyer Contact Data as a marketing list, that balance collapses for everyone. These rules are strict on purpose.
9.2 Relevant and proportionate contact only. You may contact a person named in a notice about the procurement they are named in: a clarification question, a request for documents, or a proportionate follow-up while it is live. Your communication must be relevant, proportionate in length and frequency, professional in tone, and must clearly identify you and how to stop hearing from you. You must comply with the direct marketing and electronic communications law that applies to you, including the ePrivacy Directive as implemented locally, PECR in the UK, and the GDPR or UK GDPR.
9.3 Honour opt-outs, and keep a suppression list. If a person asks you to stop, in any form of words and through any channel, stop immediately — do not ask them to justify it or contact them again to confirm. Every communication using Buyer Contact Data must include a working way to opt out. Keep a suppression list of everyone who has asked you to stop, screen against it before every send, and make sure it survives changes to your CRM, your staff and your campaigns.
9.4 No bulk or unsolicited campaigns. Do not use Buyer Contact Data for bulk, generic, templated or automated communications, or for anything not tied to a specific procurement the recipient is named in — no cold outreach, prospecting, newsletters, event invitations, surveys or recruitment approaches. Do not enrich, append, guess or reconstruct contact details from it, for example by inferring a personal email address or matching a named contact to a social media profile.
9.5 No transfer out. Do not sell, share, licence, disclose or otherwise transfer Buyer Contact Data to any third party, and do not export, upload, sync or copy it into any other system — a CRM, marketing automation platform, sales engagement tool, spreadsheet, email list, data warehouse or AI tool of your own — other than for the specific, live procurement the contact is named in, and only while it is live.
9.6 We monitor, and we will act. We may monitor the volume and pattern of access to contact details in the Service: how many records are viewed or exported, how quickly, and whether the pattern looks like researching opportunities or like building a list. Where we see excessive or inappropriate access, or where someone named in a notice tells us they have received communications that breach this section, we may restrict or remove your access to contact details, or to the Service, at any time, including immediately and without prior warning. We will tell you what we did and why; clause 12.4 explains how to get it back. We may also suppress a person’s details across the Service and report the matter to the relevant supervisory authority and the buying organisation. Breach of this section is one we treat as material.
10. Third-party rights and law
10.1 Sanctions and export controls. Do not use, export or make the Service available in breach of EU, UK, UN or United States sanctions, export control or trade control law. You confirm that neither you nor your Authorised Users are in, or organised under the laws of, a comprehensively sanctioned country, and that none of you is on, or owned or controlled by anyone on, a restricted-party list. Tell us at legal@bidwhistle.com if that stops being true.
10.2 Local law. You are responsible for complying with the law that applies to you, wherever you use the Service — recording a conversation, contacting a public official and automated calling are treated very differently from country to country. If local law prohibits something this policy permits, local law wins.
10.3 Source licences. Procurement Data comes from public sources under open licences, including the Open Government Licence v3.0 for UK data and Commission Decision 2011/833/EU for EU data, so keep the attribution and non-endorsement requirements in our Terms of Service.
11. Reporting a violation
11.1 Report suspected breaches of this policy to abuse@bidwhistle.com; vulnerabilities to security@bidwhistle.com (clause 4.5); and privacy concerns, including unwanted contact you have received as a person named in a notice, to privacy@bidwhistle.com. You do not need a Bidwhistle account to report anything.
11.2 What to include: what happened; when, with dates and times where you can; who is involved; evidence such as screenshots, full email headers and text, URLs or notice references; how we can reach you; and whether you want to stay anonymous to the account concerned.
11.3 What we do. We aim to acknowledge reports within 2 business days for security reports and 3 business days for other reports. These are targets, not guarantees. We acknowledge sooner where the report suggests an urgent risk. We investigate proportionately, then tell you in general terms whether we found a breach and whether we acted; we will not disclose confidential details of another customer’s account. We do not tolerate retaliation against anyone who reports in good faith, and reports made in bad faith are themselves a breach of this policy.
12. Enforcement
12.1 Graduated by default. In most cases we work through these steps, giving you a reasonable chance to put things right at each one:
| Step | What it means |
|---|---|
| 1. Warning | We explain what we have seen and ask you to fix it by a stated date |
| 2. Throttle or limit | We slow, cap or queue the activity concerned |
| 3. Feature restriction | We disable the feature being misused — exports, API access, AI Features, contact details |
| 4. Suspension | We suspend the Authorised User or the account under the Terms of Service |
| 5. Termination | We terminate the Agreement for material breach |
12.2 We choose the step that fits the problem, do not have to start at step 1, and may use more than one. Where we act, we tell you what we did, why and what you need to do — before we act where practicable, otherwise as soon as we reasonably can afterwards.
12.3 When we act immediately. We may restrict, suspend or terminate immediately and without prior warning where we reasonably believe that (a) there is a real risk of harm to any person, their rights or their data; (b) continuing would be unlawful or put us in breach of a law, court order or source data licence; (c) the security or availability of the Service or another customer’s data is at risk; (d) an account has been compromised or used fraudulently; or (e) section 9, or clause 3.6 or 3.7, has been breached seriously or repeatedly. We act no more widely and for no longer than the circumstances reasonably require. A breach may also lead us to remove content, preserve evidence, notify affected individuals or a supervisory authority, or refer the matter to law enforcement, and we do not refund fees for a period during which the Service was suspended for your breach.
12.4 Getting reinstated. Email legal@bidwhistle.com with the subject line “Reinstatement request”, telling us what happened, what you have done to fix it and what you have changed so it does not recur. We aim to decide within 5 business days; a person makes that decision, not an automated system, and we will explain it. Where the breach was inadvertent, has been corrected and leaves no continuing risk, we will normally reinstate you; where it is serious or repeated we may decline, and we will say so plainly rather than leave you waiting. If you think we got it wrong, use our Complaints Policy.
13. Changes to this Acceptable Use Policy
13.1 The current version is always at Acceptable Use Policy, with its version number and effective date at the top.
13.2 If a change would, on balance, disadvantage you in a way that matters, we will give at least 30 days’ notice by email to your account’s administrative contact and in the Service before it takes effect, and you may terminate before then on the terms in our Terms of Service.
13.3 Clarifications, corrections and changes reflecting a new feature or a change in the law may take effect when published, and where the law requires different notice we follow the law. Continuing to use the Service after a change takes effect means you accept it.
| Version | Effective date | Changes |
|---|---|---|
| 1.0 | 27 September 2026 | First published version |
14. How to contact us
Bidwhistle OÜ · Registry code 17567745 · Sepapaja tn 6, 15551 Tallinn, Estonia · https://www.bidwhistle.com
| What you need | |
|---|---|
| Report misuse of the Service | abuse@bidwhistle.com |
| Report a vulnerability, or ask permission to test | security@bidwhistle.com |
| Privacy concerns, objections, unwanted contact | privacy@bidwhistle.com |
| Ask whether something is allowed, or general help | support@bidwhistle.com |
| Reinstatement requests and formal legal notices | legal@bidwhistle.com |
| Invoices, billing and refunds | billing@bidwhistle.com |
We answer during UK business hours, Monday to Friday, in line with the support targets in our Service Level Agreement.
Related documents: our Terms of Service, Privacy Notice, Data Processing Agreement, Service Level Agreement, AI Use Disclosure and Complaints Policy.