Privacy Policy
Last updated: 16 July 2026
TenderMatch ("we", "us") is the data controller for personal data processed via the Service. We are based in Ireland and process data primarily in the EU (Hetzner, Falkenstein); some processors named in Section 3 operate outside the EU under the transfer safeguards listed there. This policy explains what we collect, why, how long we keep it, and your rights under GDPR.
1. Data we collect
From you directly
- Account details: name, work email, company name, password hash.
- Company profile: sector, CPV codes, annual contract value, past-work description.
- Billing data: Stripe customer ID, subscription ID. We never see full card numbers.
- Preferences and interactions: which matches you save, dismiss, mark as "bidding".
- Bid Review uploads: if you use Bid Review, the draft tender application you upload (PDF/DOCX), its extracted text, the AI-generated review, and the tender it relates to. Bid documents may contain personal data about third parties (e.g. CVs and references of key personnel) — see "Third-party personal data in bids" below.
- AI chat and research messages: messages you send to tender chat or the research assistant, and the AI's responses. These may contain personal data if you include it in your message.
From public sources
- Tender and award data from eTenders.gov.ie, TED, the Irish Companies Registration Office. This is public-record data.
- For outreach prospecting: company name, registered email (from CRO / public tender records), past award history.
Automatically
- Server logs (IP address, user-agent, URL, timestamp) for 30 days for security + debugging.
- Error reports via Sentry (includes request metadata and the exception stack trace).
- Email-lifecycle events (sent / bounced) via Resend webhooks, and first-party click tracking on links in our own emails (Resend's own open/click-pixel tracking is switched off — we do not receive an "opened" signal from Resend).
- With your consent (cookie banner): usage analytics (pages visited, scroll depth) and session replay — a visual recording of how you navigate the app. Anything you type into form fields is masked and never recorded. If you are logged in, analytics and session-replay events are linked to your account by your email address (identified analytics), not tracked anonymously.
2. Why we use it
| Purpose | Lawful basis |
|---|---|
| Provide the Service (matching, alerts, chat) | Contract |
| Billing + invoicing | Contract |
| Cold outreach to prospect companies | Legitimate interest — promoting B2B service to entities with an established public-procurement footprint. You can opt out via the unsubscribe link in any message. |
| Error monitoring + fraud prevention | Legitimate interest |
| Product analytics + session replay | Consent (cookie banner) |
| Grade your uploaded draft bid against the tender's award criteria and show you the review | Contract — you request this by uploading (Art. 6(1)(b)) |
| Link submissions to published award outcomes (won/lost) and analyse submissions in aggregate to improve the Service and build statistical insight into what wins tenders | Legitimate interest (Art. 6(1)(f)) — improving and developing the Service. Stated plainly as a condition of the feature in our Terms (§6A); if you don't want this, don't upload. Individual bid content is never shown to other users; outputs of this analysis are aggregate/statistical only. You can delete a submission's content at any time. |
| Process third-party personal data contained in bid documents (e.g. key-personnel CVs) to generate your review | Legitimate interest (Art. 6(1)(f)); we instruct uploaders to minimise it and it is used for no other purpose in identifiable form |
3. Sub-processors
We use the following providers, all bound by GDPR-compliant data processing agreements:
- Hetzner Online GmbH — hosting (Falkenstein, Germany). DB + app storage, and private object storage for Bid Review uploads (Nuremberg/Falkenstein, Germany).
- Resend — transactional email delivery + webhook lifecycle (US-incorporated, AWS us-east-1; DPA includes 2021 EU SCCs; Resend is certified under the EU-US Data Privacy Framework).
- Stripe, Inc. — payment processing (Ireland + US).
- Sentry — error tracking (sentry.io, US, standard contractual clauses).
- Hugging Face — embedding inference (serverless API, EU region when available).
- Google Cloud (Google LLC / Google Ireland Ltd) — Vertex AI: AI-assisted matching rerank, tender summaries/copywriting, tender chat and research-assistant responses, and AI grading of Bid Review submissions. Transfer safeguards: Google's Cloud Data Processing Addendum incorporating the 2021 EU SCCs; Google LLC is certified under the EU-US Data Privacy Framework. Google does not use Vertex AI customer prompts to train its models. Processing region: tender chat, the research assistant, and Bid Review grading run on an EU Vertex AI endpoint (europe-west1); match reranking, tender-summary generation, and internal quality checks currently run on a US endpoint (us-central1) — moving these to the EU is planned.
- Groq, Inc. — LLM inference (US), used as a fallback provider in our free-tier LLM routing chain for chat/summarisation tasks if our primary providers are unavailable.
- Anthropic, PBC — Claude models, used by our internal automation (tender enrichment, matching, and outreach-drafting assistants) and may process tender data and, for outreach drafting, prospect company names and contact details.
- GitHub (OpenAI via Copilot API) — LLM calls for match explanations and tender summaries.
- PostHog (Cloud EU) — web analytics, product analytics + session replay (Frankfurt, Germany). Loaded only after consent; form inputs are masked; logged-in users are identified by email address.
4. How long we keep data
- Account data: for the life of your account, plus 30 days grace after deletion.
- Server logs + Sentry errors: 30 days.
- Cold outreach records: until the recipient unsubscribes or 18 months, whichever is shorter.
- Invoices + tax records: 6 years (Irish Revenue Commissioner requirement).
- Bid Review uploads: kept while your account is active, until you delete the submission. Deleting a submission immediately removes the stored file, extracted text, and review content; we keep a minimal record (submission existed, tender, won/lost outcome, dates) for aggregate statistics. Deleting your account removes everything, including that record.
5. Your GDPR rights
You can at any time:
- Access the data we hold about you — email us.
- Correct inaccurate data — via settings or by email.
- Delete your account and associated personal data — via Settings → Delete account, or by email. Deletion is processed within 30 days.
- Port your data — we will provide a machine-readable export on request.
- Object to processing, including opting out of cold outreach at any time.
- Complain to the Irish Data Protection Commission (dataprotection.ie).
- Bid Review submissions can be deleted self-serve from My submissions (immediate), in addition to the account-level rights above. Access/portability requests include your submissions' extracted text and reviews.
- Objection (Art. 21): you may object to the aggregate-analysis processing of a specific submission by deleting it, or by emailing [email protected]; we will assess objections case-by-case as Art. 21(1) requires.
5A. Third-party personal data in bids
Bid documents often include personal data about people other than you — key personnel CVs, referee names, client contacts. For that data, your company is responsible for having the right to share it with service providers (this is normally covered by your staff privacy notice). We process it only to generate your review and within the aggregate analysis described above; we never use it to contact those individuals, never show it to other users, and delete it with your submission. Please minimise or redact third-party personal details before uploading — the grader does not need them. Individuals who believe their data appears in an upload can contact [email protected]; we will inform the uploader and delete content where required (Art. 14(5)(b) is relied on for not notifying such individuals directly, as we generally cannot identify or contact them proportionately).
6. Cookies
We set only essential cookies (session, CSRF) by default. Analytics cookies — and session replay — only start after you accept them in the banner on first visit. No third-party advertising cookies are ever set.
7. Changes
We'll post changes here and, for material changes, email you in advance.
8. Contact
Data-protection queries: [email protected].
9. Data controller / company information
The data controller is:
- Cú Chulainn Tech Limited, trading as TenderMatch.
- Company registered in the Republic of Ireland.
- Company Registration Office (CRO) number: 812722.
- Registered office: Farrannamoreen, Glasson, Athlone, Co. Westmeath, N37 W215, Ireland.
- Director: William O'Meara.
- Data-protection contact: [email protected].
Supervisory authority: Data Protection Commission, 21 Fitzwilliam Square South, Dublin 2, D02 RD28. You have the right to lodge a complaint with the DPC at any time.