Legal

Privacy Policy

Draft — under legal review. This document describes the product accurately but has not yet been approved by counsel.

This document is currently provided in English.

Last updated: 2026-08-12 (draft)

1. Who we are

TenderLab ("TenderLab", "we", "us") is a procurement-intelligence service operated by [LEGAL ENTITY NAME — pending owner input, Decision D4], registered at [REGISTERED ADDRESS — pending owner input, Decision D4]. This policy explains what personal data we process when you visit tenderlab.ai or use the TenderLab application at app.tenderlab.ai, and why.

Contact for all privacy matters: [email protected].

2. What we collect

  • Account data — name, email address, and password hash, processed by our authentication provider Clerk when you create an account or sign in. We never see or store your plaintext password.
  • Workspace and profile data — the organization you create and the procurement profile you fill in (countries of operation, sectors, contract types, budget range, keywords, company capabilities). This is business data you provide so that matching can work; it is stored in our production database.
  • Usage data — if product analytics are enabled, we record product events (for example: page viewed, signup completed, tender opened) associated with a pseudonymous identifier, so we can understand where the product works and where it fails. We do not sell this data or use it for third-party advertising.
  • Technical data — server logs and error reports (via Sentry) may include your IP address, browser type, and the URL where an error occurred, used solely to operate and debug the service.

3. What we do NOT collect

  • No payment or card data — TenderLab is free during Early Access and requests no payment details.
  • No government identifiers.
  • No data about you from third-party data brokers.

4. Why we process it (legal bases)

  • To provide the service (contract): authentication, workspaces, matching your procurement profile against tender notices, alerts you configure.
  • To operate and secure the service (legitimate interest): error monitoring, abuse prevention, service logs.
  • To improve the product (legitimate interest / consent where required): pseudonymous product analytics.
  • To communicate with you (contract / legitimate interest): transactional email such as email verification, workspace invitations, and the tender alerts you set up.

5. Where your data lives and who processes it

We use a small set of processors, each bound by its own data-processing terms:

  • Clerk — authentication and user management.
  • Neon — our production Postgres database, hosted in AWS us-east-1 (United States).
  • Vercel — application hosting and delivery.
  • Railway — background processing (tender ingestion and analysis).
  • Sentry — error monitoring.
  • PostHog (EU region) — product analytics, when enabled.
  • OpenAI — tender documents and notices (not your personal data) may be processed to generate summaries and analysis.

Your account and workspace data are stored in the United States. If you are in a jurisdiction that restricts international transfers, transfers rely on the processors' standard contractual clauses or equivalent safeguards.

6. Cookies

  • Authentication cookies (Clerk) — strictly necessary to keep you signed in.
  • Locale cookie (tl_locale) — remembers your language choice on the public website.
  • Analytics — when enabled, analytics are configured cookieless on the public website; in the application a first-party identifier may be used.

7. Retention

Account and workspace data are kept while your account is active. If you ask us to delete your account, we delete or irreversibly anonymize your personal data within 30 days, except where a longer period is required by law. Error logs and analytics events are retained on the processors' standard rolling windows.

8. Your rights

Depending on your jurisdiction, you may have rights to access, correct, export, restrict, object to processing of, or delete your personal data. Write to [email protected] and we will respond within the statutory period. You may also lodge a complaint with your supervisory authority.

9. Tender data is not personal data

The tender notices in TenderLab originate from official public procurement portals and are public information about organizations, not about you. Buyer contact details that appear inside official notices are reproduced as published by the source portal.

10. Changes to this policy

We will post any changes on this page and update the date above. For material changes affecting registered users we will notify you by email before the change takes effect.

Privacy Policy — TenderLab