PRIVACY & DATA PROTECTION POLICY
This section should be published as a standalone Privacy Policy and incorporated into the Terms.
1. Data PROQ May Process
Business identity and registration data: company name, CR/licence information, address, business activity and verification documents.
Authorized-user data: name, work email, telephone, role, department, authority/permission data and authentication information.
Procurement data: RFQs, quotations, prices, attachments, POs, approvals, messages, supplier/buyer records and transaction history.
Technical/security data: IP address, device/browser identifiers, login records, timestamps, security events and audit logs.
Support and subscription data: service requests, billing contacts, subscription records and communications.
1.1 Purpose limitation. PROQ should process personal data only for disclosed legitimate purposes such as account administration, procurement workflows, security, fraud prevention, support, compliance, analytics/service improvement and legal obligations.
1.2 Transparency. Before processing, PROQ should provide the information required by applicable Qatar data-protection law regarding the controller/processor context, purposes and other required matters.
1.3 Security. PROQ should implement appropriate administrative, technical and physical safeguards, including access control, authentication, encryption where appropriate, backups, logging, vulnerability management and incident response.
1.4 Minimization. Organizations should avoid uploading unnecessary personal data, national IDs, sensitive records or unrelated personal information into RFQs/quotations.
1.5 Processors. PROQ may appoint service providers to process data on its behalf under appropriate contractual and security controls.
1.6 International transfers. If data is hosted, backed up or accessed outside Qatar, PROQ must assess and implement any requirements applicable to cross-border processing/transfers before launch.
1.7 Rights requests. PROQ should maintain a process for legally applicable access, correction, deletion/erasure, objection/withdrawal or other individual rights, subject to lawful retention and B2B recordkeeping needs.
1.8 Breach response. PROQ should maintain an incident-response procedure addressing containment, investigation, remediation, documentation and legally required notifications.
1.9 Retention. Retention periods should be documented by data category. Transaction/audit records may need longer retention than ordinary account-profile data because of commercial, legal, audit and dispute requirements.
1.10 Marketing. Direct marketing should be separated from necessary transactional communications and managed in accordance with applicable consent/opt-out requirements.
2. Buyer and Supplier Data Responsibilities
2.1 Independent responsibilities. Each Buyer/Supplier remains responsible for personal data it uploads or instructs PROQ to process, including having an appropriate legal basis and providing required notices to its personnel or contacts.
2.2 DPA. Enterprise customers may require a Data Processing Agreement defining controller/processor roles, security measures, subprocessors, assistance obligations, retention/deletion and incident cooperation.
2.3 Confidential business data. Commercial confidentiality is distinct from personal-data privacy; PROQ should protect both through contractual and technical controls.
ACCEPTABLE USE & PROCUREMENT INTEGRITY POLICY
PROQ is designed to create reliable procurement records. Users must not use the platform to create misleading competition, bypass corporate controls or corrupt the integrity of a sourcing event.
3. Zero-Tolerance Categories
Forgery or falsification of company/legal documents.
Unauthorized quotation access, bid leakage or disclosure of competitor pricing.
Bid-rigging, collusion, sham bids or coordinated market allocation.
Bribery, kickbacks or improper inducements.
Account impersonation or use of another person’s approval authority.
Backdating or secret alteration of procurement records.
Malware, exploitation, unauthorized penetration/security testing or deliberate service disruption.
Use of PROQ for illegal products, services or transactions.
3.1 Enforcement. PROQ may warn, restrict, suspend, terminate, preserve evidence or refer matters to competent authorities as appropriate and lawful.
3.2 No retaliation through platform. Users must not misuse ratings, access, RFQs or account reporting to retaliate against another user for raising a genuine compliance concern.
4. Conflict of Interest and Related Parties
4.1 Disclosure. Organizations should require their users to disclose material conflicts of interest affecting a procurement decision where required by their policies or law.
4.2 Related suppliers. PROQ may provide tools to flag related parties or common ownership, but the organization remains responsible for investigation and approval.
4.3 No false independence. Users must not present related companies as independent competing bidders for the purpose of creating artificial competition.
SUBSCRIPTION, BILLING & ACCOUNT POLICY
5. Subscription Administration
5.1 Plan. Features, user limits, storage, support and subscription period are defined in the selected plan/order.
5.2 Payment. PROQ subscription invoices are payable according to the PROQ commercial order. Non-payment may result in restriction/suspension after applicable notice.
5.3 Cancellation. Cancellation rules, effective date and any refund entitlement should be stated in the order form/pricing terms. Unless required by law or expressly promised, unused portions of a B2B subscription should not automatically create a refund.
5.4 Data export. PROQ should define a reasonable post-termination export window for customer-controlled data, subject to legal holds, security and retention obligations.
5.5 Deletion. After the applicable export/retention period, PROQ may delete or anonymize data in accordance with its retention schedule, except data that must or may lawfully be retained.
6. CR / Licence Monitoring Workflow — Product Requirement
| Remaining validity | Recommended status | User experience | Legal effect |
|---|---|---|---|
| > 90 days | Active | Normal access | No special restriction |
| 90–61 days | Renewal required | Persistent alert + admin reminders | PROQ may restrict designated high- risk actions |
| 60–31 days | Renewal critical | Escalated alerts | PROQ may restrict new sourcing participation |
| 30–1 days | Renewal critical | Strong warning / controlled access | MOCI renewal window is already relevant; PROQ may restrict further |
| Expired | Inactive / suspended | No new transactional activity | Existing obligations and records survive |
Implementation control: The exact restriction level at 90/60/30 days should be configurable by document type. The Terms preserve PROQ’s contractual right to restrict at 90 days, while the UI can use staged enforcement.
DEVELOPER IMPLEMENTATION REQUIREMENTS
7. Mandatory Acceptance Screens
Registration: checkbox — “I confirm I am authorized to act for this organization and agree to the PROQ Terms of Use and Privacy Policy.”
Supplier quotation submission: confirmation that the quotation is authorized, accurate and will lock at the Bid Closing Date if not withdrawn.
Supplier pre-closing withdrawal: explicit confirmation + timestamp + immutable audit event.
Supplier post-closing release request: reason field; status must be “Requested”, not “Withdrawn”, until Buyer approves.
Buyer award/PO: confirmation that the Buyer is authorized and that the PO reflects the accepted commercial terms or clearly identifies agreed amendments.
Material RFQ amendment after supplier participation: versioning, notification to affected suppliers and extension/cancellation controls as appropriate.
CR/legal-document expiry: automated reminders and restriction rules tied to verified expiry dates.
8. Required Audit Events
Account creation, organization verification and changes to legal identity.
User invitations, role/permission changes and deactivation.
RFQ creation, publication, amendments, clarifications, deadline changes, cancellation and closure.
Quotation creation, version, submission, replacement, pre-close withdrawal and post-close release request/decision.
Bid opening/access events for sensitive quotations where technically feasible.
Evaluation approvals, award, rejection/disregard, PO issuance and PO amendments.
Document upload, verification, expiry alerts, restriction, suspension and reinstatement.
Security-relevant events and administrative overrides.
9. Controls PROQ Should Not Allow
Deleting a submitted quotation without an audit trace.
Editing a quotation after closing as though it were the original submission.
Changing the RFQ closing timestamp retroactively without a visible event.
Issuing a PO from an expired quotation without an explicit exception/renewal or Supplier confirmation.
Changing agreed payment terms silently after award.
Allowing a suspended/expired-document account to bypass restrictions through another ordinary user role.
Administrators secretly changing commercial records without a reason, timestamp and privileged-action log.
10. Recommended Transaction Status Model
| Stage | Supplierposition | Buyerposition |
|---|---|---|
| RFQ Open | May submit/replace/withdraw before closing | May clarify/amend subject to transparent rules |
| RFQ Closed | Quotation locked; post-close release only by request | May evaluate; cannot secretly rewrite bid basis |
| Award PendingPO | Must remain available within validity period | Complete approvals and issue conformingPO |
| PO Issued / Contracted | Perform accepted obligations | Perform payment/cooperation obligations |
| Release Agreed | Released to agreed extent | Quotation disregarded/released |
| Dispute | Preserve performance/evidence subject to contract/law | Preserve payment/evidence subject to contract/law |
RISK REGISTER FOR LEGAL REVIEW
This table identifies high-priority legal/product risks that should be closed before production launch.
| Risk | Potential harm | Draft/control response | Pre-launch action |
|---|---|---|---|
| Ambiguous contract formation | Supplier argues quotation was non- binding or Buyer PO changed terms | Lock at closing + defined validity + conforming award/PO model | Qatar counsel confirm exact formation language and UI |
| Supplier pricing mistake | Refusal to perform / dispute | Supplier accuracy duty + controlled release request | Create documented exception workflow |
| Buyer late/non-payment | Supplier loss / platform reputational risk | Buyer payment commitment; PROQ not guarantor | Add payment dispute and performance-history policy if desired i |
| Expired/near-expiry CR | Trading/compliance exposure | 90-day platform threshold + staged restrictions i | Confirm which documents are mandatory by supplier category |
| Fake documents/identity | Fraud / invalid contracting authority | Verification rights + suspension + evidence preservation | Define KYC/KYB vendor/process |
| Bid leakage/collusion | Procurement corruption / claims | Confidentiality + access controls + logs + prohibited conduct | Technical penetration/access review |
| Admin override abuse | Internal PROQ manipulation | Privileged logs + no silent edits | Maker-checker for sensitive admin actions |
| Personal-data breach | Regulatory/reputational exposure | Privacy policy + security + processor controls | Complete data map, DPA, incident plan and hosting review i |
| Cross-border hosting | Data compliance uncertainty | Transfer assessment clause | Confirm hosting/backup/support countries |
| Platform outage at closing | Bid fairness dispute | Outage/extension rule | Define measurable incident threshold and authority to extend |
| Liability clause unenforceable l | Unexpected PROQ exposure | Cap + carve-outs subject to law | Qatar counsel validate cap/indemnity |
| Arabic/English conflict | Interpretation dispute | Language precedence placeholder | Counsel choose authoritative version |
11. Items That Must Be Filled Before Publication
Full legal name of the PROQ operating company, CR number, registered office and official support/legal email.
Final subscription fees, billing cycle, renewal/cancellation/refund rules.
Exact hosting locations, subprocessors and cross-border data flows.
Final retention schedule for RFQs, quotations, POs, audit logs, user profiles and verification documents.
Formal security and incident-response standards.
Whether PROQ will provide supplier ratings, payment-performance indicators, AI recommendations, automated award scoring or document verification.
Whether any government entity will use PROQ; government electronic transactions can have additional consent/requirements.
Final Arabic version and language-precedence clause.
Final dispute clause (Qatar courts versus any chosen arbitration mechanism) after counsel review.