Privacy
Privacy policy
Draft — not yet binding
This document is pending legal review. It describes what the system actually does today, which is why it is published, but it is not a contract and the operating entity is not yet named.
1. Who is responsible
The controller is [PLACEHOLDER-LEGAL-ENTITY], [PLACEHOLDER-ADDRESS]. Data protection enquiries: privacy@[PLACEHOLDER-DOMAIN].
2. What we collect
Three things, and nothing else:
- Your account. Email address and session records, handled by Clerk. We never receive your password.
- Your matching profile. The sub-niche, cantons, CPV codes and contract-value range you configure, so we know which awards to send you.
- Your lead interactions. Which awards you marked as called, won or dismissed. This exists so the product is useful to you across sessions.
We do not run advertising trackers, we do not sell or share your data with anyone for their own purposes, and we do not build profiles of you for resale.
3. The award data is public
Contract awards come from the public SIMAP API. They concern companies and public bodies, not private individuals, and they are published by law. Where an award names a natural person, that name was already published by the procuring office; we do not enrich it.
4. What the language model sees
Awards are classified by a language model via OpenRouter. It receives only published award text. It does not receive your email, your profile, or your activity.
5. Where it is stored
In Convex, in eu-west-1 (Ireland). Sub-processors are listed in full on the Security & data page.
6. Retention
Award records are retained indefinitely as public record. Account data is retained while your subscription is active and deleted on request afterwards.
7. Your rights
You can ask for a copy of your data, ask us to correct it, or ask us to delete it. Write to privacy@[PLACEHOLDER-DOMAIN] and we will confirm in writing when it is done. The applicable law and supervisory authority are [PLACEHOLDER-JURISDICTION].
Last updated: [PLACEHOLDER-DATE]