Effective Date: August 12, 2026
Owner: RYMYS Technology Consultants, LLL
Enterprise Policy Notice. This document is part of the REP Enterprise Application Legal Policies framework and applies specifically to GovIntel. It should be read with any applicable order form, enterprise agreement, data-processing terms, and other posted RYMYS policies.
1. Scope
This Privacy Policy explains how RYMYS Technology Consultants, LLC (“RYMYS,” “we,” “us,” or “our”) collects, uses, discloses, protects, and retains information when you access or use GovIntel, an AI-enabled government contracting intelligence, opportunity, capture, proposal, agency, market, award, grant, and procurement intelligence platform, including associated websites, applications, APIs, mobile experiences, support services, and authorized integrations (collectively, the “Service”). This Policy applies to information processed by RYMYS as a business or controller. When RYMYS processes information solely on behalf of an organizational customer, that customer’s instructions and applicable agreement may control.
2. Information We Collect
We may collect account and identity information such as name, username, business email address, organization, role, and authentication records. We may also collect subscription, entitlement, order, and billing-related records; organization profile and configuration data; content, files, documents, prompts, messages, records, and other information submitted to the Service; technical and usage data such as IP address, device and browser information, timestamps, logs, feature usage, diagnostics, and security events; communications and support records; and information received through customer-authorized third-party systems, APIs, connectors, public data sources, or identity providers.
3. How We Use Information
We use information to provide, administer, secure, support, personalize, and improve the Service; authenticate users and manage organizations, memberships, roles, and entitlements; process customer requests and transactions; operate AI-enabled features; synchronize authorized data sources; generate reports and intelligence; communicate service, security, billing, and administrative notices; prevent fraud and abuse; maintain audit records; comply with law; enforce agreements; and protect RYMYS, customers, users, and the public.
4. AI and Automated Processing
The Service may use artificial intelligence, machine learning, retrieval, classification, summarization, recommendation, and other automated techniques. User-provided content may be processed to produce requested outputs, identify relevant information, support workflows, or improve the customer’s experience. AI output can be incomplete, outdated, or incorrect and should be reviewed by an authorized human before material decisions are made. RYMYS does not use customer confidential content to train a generally available RYMYS model unless expressly disclosed and authorized under the applicable agreement or settings.
5. Sources and Connectors
Customers may authorize the Service to access third-party services, public sources, procurement systems, cloud services, identity providers, or other connectors. Data obtained through a connector is processed to provide the requested functionality and remains subject to applicable source restrictions, customer permissions, and third-party terms. Customers are responsible for ensuring they have authority to connect accounts and provide credentials or data.
6. How We Disclose Information
We may disclose information to service providers and subprocessors that support hosting, infrastructure, communications, security, analytics, payment, customer support, and AI functionality; to an organization that administers your account; to third parties you direct us to integrate with; in connection with a corporate transaction; or when reasonably necessary to comply with law, legal process, enforce rights, investigate abuse, or protect safety and security. We do not sell personal information for money. We do not sell customer conversation or document content to advertisers.
7. Security
RYMYS uses administrative, technical, and organizational safeguards designed to protect information, including access controls, authentication, encryption where appropriate, logging, monitoring, vulnerability management, backup and recovery practices, and least-privilege principles. No system can be guaranteed completely secure, and customers remain responsible for securing their accounts, endpoints, credentials, authorized users, and connected systems.
8. Retention
We retain information for as long as reasonably necessary to provide the Service, maintain security and audit records, satisfy contractual obligations, resolve disputes, enforce agreements, and comply with legal, tax, accounting, or regulatory requirements. Retention periods vary by data type, customer configuration, legal requirements, and the status of the account. Backup copies may persist for a limited period after deletion.
9. Your Choices and Rights
Depending on your location and applicable law, you may have rights to request access, correction, deletion, portability, restriction, or other treatment of personal information. Organizational users may need to direct requests to their organization administrator when the organization controls the data. You may also manage certain profile, notification, security, and account settings through the Service. We may verify identity before fulfilling a request.
10. Account and Data Deletion
Users may request deletion through available account controls or by contacting RYMYS. Deletion may be subject to organization-admin authority, active subscriptions, legal holds, security needs, contractual retention requirements, transaction-record obligations, and data that must be retained to establish or defend legal rights. Deleting an account may permanently remove access to associated content and product entitlements.
11. Cookies and Similar Technologies
RYMYS may use cookies, local storage, session technologies, and similar tools that are necessary for authentication, security, preferences, performance, and service operation. Where required by law, additional consent mechanisms may be provided for non-essential technologies.
12. Children
The Service is intended for business, professional, organizational, or authorized educational use and is not directed to children under 13. RYMYS does not knowingly collect personal information from children under 13 through the Service without appropriate authorization and legal basis.
13. International Processing
Information may be processed in the United States and other locations where RYMYS or its service providers operate. Where required, RYMYS uses appropriate contractual or legal mechanisms for cross-border transfers.
14. Changes to This Policy
We may update this Privacy Policy to reflect changes in law, technology, security practices, or the Service. The revised policy will identify its effective date. Material changes may be communicated through the Service or other reasonable means.
15. Contact
Privacy questions and requests may be sent to privacy@rymys.com or through the RYMYS contact page at https://www.rymys.com/contact-us/. Security vulnerabilities should be reported to security@rymys.com.

