Legal

Privacy Policy

Last updated: 12 August 2026Version: 1.0 (draft)

This policy explains what personal data weTender.ai processes, why, on what legal basis, who else is involved, and what rights you have. It covers people who use the service and people whose contact details appear in it — including supplier contacts we or our customers put into a case.

Draft for review. This text describes how the service actually works, but it has not been reviewed by a lawyer and the highlighted fields still need real values. It is not yet a binding agreement.

Who is responsible

The controller for the data described here is [COMPANY LEGAL NAME], [REGISTERED ADDRESS], IČO [IČO]. For privacy questions and to exercise your rights, write to [PRIVACY CONTACT E-MAIL][, DPO CONTACT IF APPOINTED].

For part of the data — the supplier records and correspondence inside a customer's workspace — our customer is the controller and we act as their processor. Section 13 explains what that means for you.

Data we process about users

When you register and use the service we process:

  • Registration details — first and last name, e-mail address, phone number, country and city.
  • Company details — company name, registration number (IČO), tax number (DIČ), address and the details of the person acting for the company.
  • Account and sign-in data — a password stored only as a hash, e-mail verification status, and sign-in events.
  • Usage and technical data — actions taken in a case, timestamps, IP address, browser and device information, and error logs.
  • Anti-abuse data — the result of the reCAPTCHA check performed during registration.

Case content and supplier correspondence

A procurement case contains what you wrote, files you attached, the specification derived from them, the suppliers who were contacted, and the full e-mail exchange with them, including their offers and any follow-ups. Where a supplier signs an e-mail with a person's name, position or direct phone number, that message contains personal data and is stored with the case.

Outgoing inquiries are sent from our infrastructure on behalf of the buying organisation, and replies are received into a mailbox operated for that purpose and attached to the case they belong to.

Supplier contact details found on the web

To be able to send an inquiry to a supplier that a customer does not already have in their directory, the service visits that supplier's own public website and collects business contact details published there — typically an e-mail address and a phone number, together with the page they were found on. Only publicly accessible pages are read; nothing behind a login is accessed.

Where such an address identifies a person, for example firstname.lastname@supplier.example, we process it on the basis of legitimate interest under Article 6(1)(f) GDPR: putting a genuine purchase inquiry in front of the business that published the address for exactly that purpose. We keep these details so that a later inquiry does not require crawling the site again, and we refresh them when they become stale.

If you are a supplier contact: you can object to this processing at any time at [PRIVACY CONTACT E-MAIL] and ask us to erase your details and stop contacting you. Every inquiry we send also tells you how to do that, and we act on such a request without needing a reason.

Processing by AI models

The service sends content to AI model providers in order to write specifications, evaluate whether search results match a specification, draft inquiry and follow-up e-mails, read supplier replies into structured offers, and suggest categories for supplier records. The content sent can include your case description, files you attached, and the text of supplier correspondence.

Our AI providers process this content on our instructions in order to return a result, and are contractually required not to use it to train their models. The current provider is [AI PROVIDER AND PROCESSING REGION].

Decisions that matter — which suppliers to contact, what to send, which offer to accept — are taken or approved by a person in your organisation. The service does not make decisions producing legal effects about an individual within the meaning of Article 22 GDPR.

Why we process it, and on what basis

  • To provide the service you asked for — running cases, sending and receiving supplier correspondence, keeping the case record. Basis: performance of a contract, Article 6(1)(b).
  • To reach suppliers with a genuine inquiry — collecting and using published business contact details. Basis: legitimate interest, Article 6(1)(f).
  • To keep the service secure and prevent abuse — logs, rate limits, the registration reCAPTCHA. Basis: legitimate interest, Article 6(1)(f).
  • To meet legal obligations — accounting and tax records. Basis: legal obligation, Article 6(1)(c).
  • To send product news, if you asked for it. Basis: consent, Article 6(1)(a), withdrawable at any time.

Who else sees the data

We do not sell personal data. We share it only with providers who process it for us under a data processing agreement, and with suppliers to the extent an inquiry you send necessarily reveals who is asking. Our processors are:

  • Hosting and infrastructure[PROVIDER, REGION].
  • AI model provider[PROVIDER, REGION].
  • Web search provider, used to find candidate products and suppliers — [PROVIDER, REGION].
  • E-mail sending and receiving[PROVIDER, REGION].
  • Bot protection — Google reCAPTCHA, used on the registration form.
  • Error monitoring and analytics[PROVIDER, OR "NONE"].

We may also disclose data where the law requires it, or to establish or defend legal claims.

Transfers outside the EEA

Some of the providers above may process data outside the European Economic Area. Where that happens, the transfer is covered by an adequacy decision or by the European Commission's Standard Contractual Clauses together with additional safeguards. You can ask us for a copy of the safeguards that apply at [PRIVACY CONTACT E-MAIL].

How long we keep it

  • Account data — while the account exists, and [PERIOD] after it is closed.
  • Cases and supplier correspondence — while the account exists, so the record of a purchase stays available; then [PERIOD].
  • Supplier contact details — until they are no longer useful, refreshed when stale, and erased on objection.
  • Technical logs[PERIOD].
  • Accounting records — for the period required by law, currently [PERIOD].

Your rights

Under the GDPR you can ask us for access to your data, for it to be corrected or erased, for processing to be restricted, and for a copy in a portable format. You can object to processing based on legitimate interest — including the supplier contact details described in section 4 — and withdraw any consent you have given, without affecting processing that already happened.

Write to [PRIVACY CONTACT E-MAIL] and we will respond within one month. If you are not satisfied, you can complain to the Office for Personal Data Protection of the Slovak Republic (Úrad na ochranu osobných údajov SR, Hraničná 12, 820 07 Bratislava) or to the supervisory authority where you live.

Cookies and similar technologies

We use storage in your browser for what the service needs to work: keeping you signed in, remembering your language, and the reCAPTCHA check on the registration form. These are necessary for a service you asked for and do not require consent. [IF ANALYTICS OR MARKETING COOKIES ARE ADDED, A CONSENT BANNER IS REQUIRED — DESCRIBE THEM HERE.]

Security

Access to the service requires authentication, traffic is encrypted in transit, passwords are stored only as hashes, and access to production data is limited to staff who need it. Each customer's cases and supplier directory are separated from other customers'. No system is perfectly secure; if a breach affects your data and is likely to present a risk to you, we will notify you and the supervisory authority as the GDPR requires.

When we act for our customer

For supplier records a customer imports and for the correspondence inside their workspace, that customer decides what is processed and why — they are the controller and we act on their instructions as their processor. If you are a supplier contact and your details are in a customer's workspace, we will pass your request on to that customer and help them act on it, and we will still act on an objection to any processing we do in our own right.

Changes and contact

We update this policy when the service or the law changes, and publish the new version here with a new "last updated" date. For anything in this document, write to [PRIVACY CONTACT E-MAIL].