1. Scope
This Policy applies when you:
- visit the TenderVerity website;
- create or use an account;
- join an organization workspace;
- configure a company profile;
- review or manage procurement opportunities;
- use saved searches, alerts, APIs, feeds or integrations;
- subscribe to a paid plan;
- contact support;
- receive service or marketing communications; or
- otherwise interact with TenderVerity.
This Policy does not govern third-party procurement portals, external websites or services that have their own privacy policies.
2. Our role
TenderVerity generally acts as a data controller for account administration, billing, security, product analytics, communications and operation of the Service.
A Customer may act as the controller of personal data that its users enter into private notes, comments, assignments, workflows or integrations. In those circumstances, TenderVerity may act as a processor or service provider on the Customer’s behalf.
Requests concerning Customer-controlled workspace data may need to be directed to the relevant Customer or organization administrator.
3. Personal data we collect
3.1 Account and identity data
This may include:
- name;
- professional email address;
- job title;
- profile image;
- password-related authentication records;
- identity-provider identifiers;
- email-verification status;
- preferred language; and
- account and organization identifiers.
When you sign in through Google or another provider, we receive the information authorized through that provider.
3.2 Organization and company-profile data
This may include:
- organization name;
- business contact information;
- website and country;
- services, sectors and capabilities;
- preferred procurement classifications;
- target countries and contract preferences;
- organization members and roles;
- qualification criteria; and
- matching configuration.
Information concerning a company is not always personal data. It becomes personal data where it identifies or relates to an individual.
3.3 Workspace and collaboration data
This may include:
- saved opportunities and searches;
- qualification status;
- assignments and ownership;
- due dates;
- notes and comments;
- watchers;
- decisions and reasons;
- submission or outcome status;
- activity history;
- feedback; and
- files or information transmitted through enabled features.
3.4 Procurement-source data
We process information obtained from public procurement sources. This may include professional names, roles, business contact details, contracting-authority contacts, supplier or awardee information and other information published in official notices.
TenderVerity does not control the original publication of that information.
3.5 Subscription and transaction data
This may include:
- plan and subscription status;
- billing contact details;
- customer and transaction identifiers;
- invoices;
- payment status;
- tax country;
- refunds and chargebacks; and
- payment-provider events.
TenderVerity does not normally receive complete payment-card numbers. Payment information is handled by the applicable payment provider or merchant of record.
3.6 Technical and usage data
This may include:
- IP address;
- browser and device information;
- operating system;
- approximate location derived from IP address;
- login date and time;
- pages and features used;
- searches, clicks and interactions;
- referral information;
- session identifiers;
- cookie identifiers;
- error reports;
- performance information;
- API activity;
- security events; and
- audit logs.
3.7 Communications and support data
This may include:
- support requests;
- email correspondence;
- survey answers;
- product feedback;
- meeting notes;
- notification preferences; and
- records of service communications.
3.8 Integration data
When an organization enables an integration, we may process:
- integration account identifiers;
- workspace or channel identifiers;
- access tokens or credentials;
- webhook endpoints;
- API keys;
- delivery status; and
- content selected for transmission.
Integration secrets are protected and used only to operate the requested integration, maintain security and comply with law.
4. How we obtain personal data
We obtain personal data:
- directly from you;
- from your employer or organization administrator;
- through your use of the Service;
- from identity providers;
- from payment and subscription providers;
- from enabled integrations;
- from public procurement portals and official data feeds;
- from public professional sources; and
- from service providers that help us detect fraud, secure or operate the Service.
5. Purposes and lawful bases
Where the GDPR, UK GDPR or similar law applies, we process personal data under the following lawful bases.
Providing the Service
We process account, organization, workspace, matching and integration data to create accounts, operate workspaces, generate results, provide notifications and deliver requested features.
Lawful basis: performance of a contract or steps requested before entering a contract.
Account and organization administration
We process membership, role, permission and administrative data to manage access and organization settings.
Lawful basis: performance of a contract and our legitimate interest in administering the Service.
Billing and subscription management
We process subscription and transaction information to manage plans, payments, invoices, taxes, refunds and financial records.
Lawful basis: performance of a contract and compliance with legal obligations.
Security and abuse prevention
We process logs, account information and technical data to authenticate users, investigate incidents, prevent fraud, enforce restrictions and protect the Service.
Lawful basis: our legitimate interests in maintaining a secure and reliable service and, where applicable, compliance with legal obligations.
Matching and procurement intelligence
We process company profiles, configuration and public procurement information to rank opportunities, calculate scores and display evidence.
Lawful basis: performance of a contract and our legitimate interest in providing and improving procurement-intelligence functionality.
Service communications
We send account verification, password, billing, security, digest, alert and administrative communications.
Lawful basis: performance of a contract, legitimate interests and legal obligations.
Product improvement and analytics
We analyze usage, performance, errors and feedback to understand how the Service works and improve its relevance and reliability.
Lawful basis: legitimate interests. Consent will be requested where applicable law requires it for cookies or similar technologies.
Support
We process communications and relevant account information to answer questions, diagnose problems and resolve requests.
Lawful basis: performance of a contract and legitimate interests.
Marketing
We may send product news, offers or invitations where permitted.
Lawful basis: consent or legitimate interests, depending on the jurisdiction, recipient and communication.
You may opt out of marketing at any time. Opting out does not stop essential service messages.
Legal compliance and claims
We may process information to comply with law, respond to lawful requests, enforce agreements and establish, exercise or defend legal claims.
Lawful basis: legal obligation and legitimate interests.
6. Public procurement and professional information
TenderVerity indexes and normalizes information published by Official Sources.
Where that information identifies a person, we process it to:
- display the relevant notice;
- identify the contracting authority or awarded supplier;
- provide source attribution;
- support search, matching and procurement intelligence; and
- maintain an accurate history of public notices.
Our lawful basis is generally our legitimate interest and that of our business users in accessing, organizing and understanding publicly available procurement information.
We consider the professional nature of the information, its public availability, user expectations and the limited procurement-related purpose.
You may contact us to object, request correction or raise a concern. We may be unable to alter an authoritative source record, but may correct our normalized data, limit display or direct you to the original publisher where appropriate.
7. Cookies and similar technologies
TenderVerity may use:
- essential cookies for authentication, security and session management;
- preference cookies for language and interface settings;
- analytics technologies for performance and product usage; and
- communication identifiers for measuring delivery and interactions.
Where required, non-essential cookies will be used only after consent.
A separate Cookie Notice or consent interface should identify the active cookies, providers, purposes and durations.
You may manage cookies through the available consent controls and browser settings. Disabling essential cookies may prevent the Service from working.
8. Automated processing
TenderVerity uses automated processing to rank procurement opportunities and produce relevance scores, classifications, signals and recommendations.
The processing generally evaluates the fit between an organization profile and a procurement opportunity. It is not intended to evaluate an individual’s creditworthiness, employment, eligibility for public services or other personal characteristics.
The outputs do not by themselves produce legal or similarly significant effects concerning individuals.
Users must review the underlying evidence and make their own decisions.
9. How we disclose personal data
We may disclose personal data to:
Your organization
Organization owners, administrators and authorized team members may access information according to their permissions.
Service providers
We may use providers for:
- hosting and cloud infrastructure;
- database and object storage;
- authentication;
- email delivery;
- payment and subscription administration;
- security;
- logging, monitoring and error reporting;
- customer support;
- analytics;
- backups; and
- technical operations.
Current or expected providers may include Lemon Squeezy, Resend, Google authentication services, Sentry and infrastructure providers. The active provider list should be maintained on a subprocessor page or made available on request.
Integrations selected by the Customer
When a Customer enables Slack, Telegram, email, webhook, API or similar integrations, selected information is disclosed to the relevant service.
Professional advisers
We may disclose information to lawyers, accountants, auditors, insurers and other professional advisers subject to confidentiality duties.
Authorities and legal recipients
We may disclose information where reasonably recipients
We may disclose information where reasonably necessary to comply with law, a court order or valid governmental request, or to protect rights, safety and security.
Corporate transactions
Information may be transferred during a financing, reorganization, merger, acquisition, sale of assets or similar transaction, subject to appropriate confidentiality and legal safeguards.
We do not sell personal data for money.
We do not currently share personal data for cross-context behavioral advertising. This Policy and the relevant opt-out mechanisms must be updated before introducing such activity.
10. International data transfers
TenderVerity and its service providers may process personal data outside your country.
Where personal data protected by European or UK data-protection law is transferred to a country not recognized as providing adequate protection, we will use an approved transfer mechanism where required, such as:
- European Commission Standard Contractual Clauses;
- the applicable United Kingdom transfer addendum or agreement; or
- another legally recognized safeguard.
We may also rely on an adequacy decision or a permitted legal exception.
Information about applicable safeguards may be requested through the privacy contact address.
11. Data retention
We retain personal data only for as long as reasonably necessary for the stated purposes, including contractual, security, accounting, dispute-resolution and legal requirements.
Unless a longer period is necessary:
- account and workspace information is retained while the account is active;
- deleted account data is generally removed from active systems within 30 days;
- deleted information may remain in protected backups for up to 90 days;
- routine security and operational logs may be retained for up to 12 months;
- support records may be retained for up to three years after resolution;
- transaction, invoice and tax records are retained for the legally required period;
- unresolved disputes or security records may be retained until resolution; and
- minimal opt-out or suppression information may be retained to respect communication preferences.
Customer-controlled retention settings or a separate agreement may apply to certain enterprise accounts.
Aggregated or irreversibly anonymized information may be retained for longer because it no longer identifies an individual.
12. Security
We use reasonable technical and organizational safeguards appropriate to the nature of the information and risks involved.
Measures may include:
- encryption in transit;
- access controls;
- role-based permissions;
- credential protection;
- logging and monitoring;
- secure backups;
- environment separation;
- vulnerability management;
- provider assessments; and
- incident-response procedures.
No method of transmission or storage is completely secure. You are responsible for protecting your credentials, devices, API keys and integration secrets.
13. Your privacy rights
Depending on your location and applicable law, you may have the right to:
- obtain information about our processing;
- access your personal data;
- correct inaccurate information;
- request deletion;
- restrict processing;
- object to processing based on legitimate interests;
- object to direct marketing;
- withdraw consent;
- receive portable data;
- lodge a complaint with a data-protection authority; and
- receive information about applicable automated processing.
Withdrawal of consent does not affect processing performed before withdrawal.
Rights may be subject to legal limitations and exceptions.
To submit a request, contact [email protected]. We may need to verify your identity and authority. An authorized agent may submit a request where permitted by law.
You will not be discriminated against for exercising a legally protected privacy right.
14. California and other United States privacy disclosures
This section applies only where the relevant state privacy law applies to TenderVerity and the individual concerned.
During the preceding twelve months, TenderVerity may have collected the following categories:
- identifiers;
- professional or employment-related information;
- commercial and subscription information;
- internet or electronic activity;
- approximate geolocation;
- customer communications;
- inferences relating to organizational procurement preferences; and
- account credentials or integration information that may qualify as sensitive personal information under some laws.
These categories are used for the purposes described in this Policy and may be disclosed to service providers, organization administrators, selected integrations, advisers, authorities and transaction counterparties.
Subject to applicable law, residents may have rights to know, access, correct, delete or obtain a copy of their information and to opt out of certain sales, sharing, targeted advertising or profiling.
TenderVerity does not currently sell personal information or share it for cross-context behavioral advertising.
TenderVerity does not use sensitive personal information to infer characteristics about individuals.
Requests may be submitted to [email protected].
15. Marketing communications
You may unsubscribe from marketing emails through the link in the message or by contacting us.
We may retain limited suppression information so that we do not contact you again contrary to your preference.
Account, security, billing, tender-alert and other service communications are not marketing and may continue while the relevant Service remains active.
16. Children
TenderVerity is a professional B2B service and is not directed to children.
You must be at least 18 years old, or the applicable age of legal capacity in your country, to create an account.
We do not knowingly collect personal data from children through the Service. Suspected child data may be reported to [email protected].
17. Changes to this Policy
We may update this Policy to reflect changes in law, the Service, providers or data practices.
Material changes will be communicated through the Service, by email or through another appropriate method.
The date at the top identifies the current version.
18. Complaints
You may contact us first at [email protected] so that we can investigate your concern.
Where applicable, you may also complain to the data-protection authority in your country of residence, place of work or location of the alleged violation.
19. Contact
General support: [email protected] Privacy requests: [email protected]