Privacy Policy

This policy was last updated on September 28, 2026.

PRIVACY & DATA PROTECTION POLICY

This section should be published as a standalone Privacy Policy and incorporated into the Terms.

1. Data PROQ May Process
  • Business identity and registration data: company name, CR/licence information, address, business activity and verification documents.

  • Authorized-user data: name, work email, telephone, role, department, authority/permission data and authentication information.

  • Procurement data: RFQs, quotations, prices, attachments, POs, approvals, messages, supplier/buyer records and transaction history.

  • Technical/security data: IP address, device/browser identifiers, login records, timestamps, security events and audit logs.

  • Support and subscription data: service requests, billing contacts, subscription records and communications.

  • 1.1 Purpose limitation. PROQ should process personal data only for disclosed legitimate purposes such as account administration, procurement workflows, security, fraud prevention, support, compliance, analytics/service improvement and legal obligations.

  • 1.2 Transparency. Before processing, PROQ should provide the information required by applicable Qatar data-protection law regarding the controller/processor context, purposes and other required matters.

  • 1.3 Security. PROQ should implement appropriate administrative, technical and physical safeguards, including access control, authentication, encryption where appropriate, backups, logging, vulnerability management and incident response.

  • 1.4 Minimization. Organizations should avoid uploading unnecessary personal data, national IDs, sensitive records or unrelated personal information into RFQs/quotations.

  • 1.5 Processors. PROQ may appoint service providers to process data on its behalf under appropriate contractual and security controls.

  • 1.6 International transfers. If data is hosted, backed up or accessed outside Qatar, PROQ must assess and implement any requirements applicable to cross-border processing/transfers before launch.

  • 1.7 Rights requests. PROQ should maintain a process for legally applicable access, correction, deletion/erasure, objection/withdrawal or other individual rights, subject to lawful retention and B2B recordkeeping needs.

  • 1.8 Breach response. PROQ should maintain an incident-response procedure addressing containment, investigation, remediation, documentation and legally required notifications.

  • 1.9 Retention. Retention periods should be documented by data category. Transaction/audit records may need longer retention than ordinary account-profile data because of commercial, legal, audit and dispute requirements.

  • 1.10 Marketing. Direct marketing should be separated from necessary transactional communications and managed in accordance with applicable consent/opt-out requirements.

2. Buyer and Supplier Data Responsibilities
  • 2.1 Independent responsibilities. Each Buyer/Supplier remains responsible for personal data it uploads or instructs PROQ to process, including having an appropriate legal basis and providing required notices to its personnel or contacts.

  • 2.2 DPA. Enterprise customers may require a Data Processing Agreement defining controller/processor roles, security measures, subprocessors, assistance obligations, retention/deletion and incident cooperation.

  • 2.3 Confidential business data. Commercial confidentiality is distinct from personal-data privacy; PROQ should protect both through contractual and technical controls.

ACCEPTABLE USE & PROCUREMENT INTEGRITY POLICY

PROQ is designed to create reliable procurement records. Users must not use the platform to create misleading competition, bypass corporate controls or corrupt the integrity of a sourcing event.

3. Zero-Tolerance Categories
  • Forgery or falsification of company/legal documents.

  • Unauthorized quotation access, bid leakage or disclosure of competitor pricing.

  • Bid-rigging, collusion, sham bids or coordinated market allocation.

  • Bribery, kickbacks or improper inducements.

  • Account impersonation or use of another person’s approval authority.

  • Backdating or secret alteration of procurement records.

  • Malware, exploitation, unauthorized penetration/security testing or deliberate service disruption.

  • Use of PROQ for illegal products, services or transactions.

  • 3.1 Enforcement. PROQ may warn, restrict, suspend, terminate, preserve evidence or refer matters to competent authorities as appropriate and lawful.

  • 3.2 No retaliation through platform. Users must not misuse ratings, access, RFQs or account reporting to retaliate against another user for raising a genuine compliance concern.

  • 4.1 Disclosure. Organizations should require their users to disclose material conflicts of interest affecting a procurement decision where required by their policies or law.

  • 4.2 Related suppliers. PROQ may provide tools to flag related parties or common ownership, but the organization remains responsible for investigation and approval.

  • 4.3 No false independence. Users must not present related companies as independent competing bidders for the purpose of creating artificial competition.

SUBSCRIPTION, BILLING & ACCOUNT POLICY

5. Subscription Administration
  • 5.1 Plan. Features, user limits, storage, support and subscription period are defined in the selected plan/order.

  • 5.2 Payment. PROQ subscription invoices are payable according to the PROQ commercial order. Non-payment may result in restriction/suspension after applicable notice.

  • 5.3 Cancellation. Cancellation rules, effective date and any refund entitlement should be stated in the order form/pricing terms. Unless required by law or expressly promised, unused portions of a B2B subscription should not automatically create a refund.

  • 5.4 Data export. PROQ should define a reasonable post-termination export window for customer-controlled data, subject to legal holds, security and retention obligations.

  • 5.5 Deletion. After the applicable export/retention period, PROQ may delete or anonymize data in accordance with its retention schedule, except data that must or may lawfully be retained.

6. CR / Licence Monitoring Workflow — Product Requirement
Remaining validityRecommended statusUser experienceLegal effect
> 90 daysActiveNormal accessNo special restriction
90–61 daysRenewal requiredPersistent alert + admin remindersPROQ may restrict designated high- risk actions
60–31 daysRenewal criticalEscalated alertsPROQ may restrict new sourcing participation
30–1 daysRenewal criticalStrong warning / controlled accessMOCI renewal window is already relevant; PROQ may restrict further
ExpiredInactive / suspendedNo new transactional activityExisting obligations and records survive

Implementation control: The exact restriction level at 90/60/30 days should be configurable by document type. The Terms preserve PROQ’s contractual right to restrict at 90 days, while the UI can use staged enforcement.

DEVELOPER IMPLEMENTATION REQUIREMENTS

7. Mandatory Acceptance Screens
  • Registration: checkbox — “I confirm I am authorized to act for this organization and agree to the PROQ Terms of Use and Privacy Policy.”

  • Supplier quotation submission: confirmation that the quotation is authorized, accurate and will lock at the Bid Closing Date if not withdrawn.

  • Supplier pre-closing withdrawal: explicit confirmation + timestamp + immutable audit event.

  • Supplier post-closing release request: reason field; status must be “Requested”, not “Withdrawn”, until Buyer approves.

  • Buyer award/PO: confirmation that the Buyer is authorized and that the PO reflects the accepted commercial terms or clearly identifies agreed amendments.

  • Material RFQ amendment after supplier participation: versioning, notification to affected suppliers and extension/cancellation controls as appropriate.

  • CR/legal-document expiry: automated reminders and restriction rules tied to verified expiry dates.

8. Required Audit Events
  • Account creation, organization verification and changes to legal identity.

  • User invitations, role/permission changes and deactivation.

  • RFQ creation, publication, amendments, clarifications, deadline changes, cancellation and closure.

  • Quotation creation, version, submission, replacement, pre-close withdrawal and post-close release request/decision.

  • Bid opening/access events for sensitive quotations where technically feasible.

  • Evaluation approvals, award, rejection/disregard, PO issuance and PO amendments.

  • Document upload, verification, expiry alerts, restriction, suspension and reinstatement.

  • Security-relevant events and administrative overrides.

9. Controls PROQ Should Not Allow
  • Deleting a submitted quotation without an audit trace.

  • Editing a quotation after closing as though it were the original submission.

  • Changing the RFQ closing timestamp retroactively without a visible event.

  • Issuing a PO from an expired quotation without an explicit exception/renewal or Supplier confirmation.

  • Changing agreed payment terms silently after award.

  • Allowing a suspended/expired-document account to bypass restrictions through another ordinary user role.

  • Administrators secretly changing commercial records without a reason, timestamp and privileged-action log.

StageSupplierpositionBuyerposition
RFQ OpenMay submit/replace/withdraw before closingMay clarify/amend subject to transparent rules
RFQ ClosedQuotation locked; post-close release only by requestMay evaluate; cannot secretly rewrite bid basis
Award PendingPOMust remain available within validity periodComplete approvals and issue conformingPO
PO Issued / ContractedPerform accepted obligationsPerform payment/cooperation obligations
Release AgreedReleased to agreed extentQuotation disregarded/released
DisputePreserve performance/evidence subject to contract/lawPreserve payment/evidence subject to contract/law

RISK REGISTER FOR LEGAL REVIEW

This table identifies high-priority legal/product risks that should be closed before production launch.

RiskPotential harmDraft/control responsePre-launch action
Ambiguous contract formationSupplier argues quotation was non- binding or Buyer PO changed termsLock at closing + defined validity + conforming award/PO modelQatar counsel confirm exact formation language and UI
Supplier pricing mistakeRefusal to perform / disputeSupplier accuracy duty + controlled release requestCreate documented exception workflow
Buyer late/non-paymentSupplier loss / platform reputational riskBuyer payment commitment; PROQ not guarantorAdd payment dispute and performance-history policy if desired i
Expired/near-expiry CRTrading/compliance exposure90-day platform threshold + staged restrictions iConfirm which documents are mandatory by supplier category
Fake documents/identityFraud / invalid contracting authorityVerification rights + suspension + evidence preservationDefine KYC/KYB vendor/process
Bid leakage/collusionProcurement corruption / claimsConfidentiality + access controls + logs + prohibited conductTechnical penetration/access review
Admin override abuseInternal PROQ manipulationPrivileged logs + no silent editsMaker-checker for sensitive admin actions
Personal-data breachRegulatory/reputational exposurePrivacy policy + security + processor controlsComplete data map, DPA, incident plan and hosting review i
Cross-border hostingData compliance uncertaintyTransfer assessment clauseConfirm hosting/backup/support countries
Platform outage at closingBid fairness disputeOutage/extension ruleDefine measurable incident threshold and authority to extend
Liability clause unenforceable lUnexpected PROQ exposureCap + carve-outs subject to lawQatar counsel validate cap/indemnity
Arabic/English conflictInterpretation disputeLanguage precedence placeholderCounsel choose authoritative version
11. Items That Must Be Filled Before Publication
  • Full legal name of the PROQ operating company, CR number, registered office and official support/legal email.

  • Final subscription fees, billing cycle, renewal/cancellation/refund rules.

  • Exact hosting locations, subprocessors and cross-border data flows.

  • Final retention schedule for RFQs, quotations, POs, audit logs, user profiles and verification documents.

  • Formal security and incident-response standards.

  • Whether PROQ will provide supplier ratings, payment-performance indicators, AI recommendations, automated award scoring or document verification.

  • Whether any government entity will use PROQ; government electronic transactions can have additional consent/requirements.

  • Final Arabic version and language-precedence clause.

  • Final dispute clause (Qatar courts versus any chosen arbitration mechanism) after counsel review.