Legal

Privacy Policy

Last updated: August 14, 2026

1. Who is responsible

The controller of the personal data described in this policy is Invictus Development BV, trading as Tenderlist, Witherendreef 20, 3090 Overijse, Belgium, company number (KBO/BCE) 0749.451.296, VAT BE 0749.451.296. For any privacy request or question, contact contact@tenderlist.eu.

2. What we collect and why

Account data — name, email address, and a hashed password (we never store the password itself). Used to provide the Service and secure your account. Legal basis: performance of the contract.

Company profile data — company name, a free-text description of your business, target countries, budget range, and similar matching preferences you enter, plus up to five additional email addresses you may add as alert recipients (see Section 7). Used to power search, alerts, and AI matching. Legal basis: performance of the contract.

Billing data — subscriptions are processed by Stripe. We store your subscription status and Stripe customer reference; your card or bank details never touch our servers and are held by Stripe. Legal bases: performance of the contract and our legal obligations (tax and accounting).

Usage and security data — a log entry per sign-in, your search queries and filters, and a log of emails we sent you (including their content). Used for security, abuse prevention, support, and improving the Service. Legal basis: our legitimate interest in running the Service securely and reliably.

AI feature inputs — when you use AI features, the text you enter (such as search criteria or custom notes) is processed as described in Section 6.

Contact form — name, email, and message, used solely to answer you. Legal basis: our legitimate interest in responding to enquiries.

We send you transactional emails (verification, password reset, team invitations) and the alert digests you configure. We may occasionally email account holders about significant product changes; you can opt out of those at any time. We do not run advertising and do not sell or share personal data for marketing.

3. Where your data lives

The Service runs on dedicated infrastructure at Hetzner (EU data centers: Helsinki, Finland, with encrypted backups in Falkenstein, Germany). Our email is sent from our own mail server (box.tenderlist.eu) — no third-party email marketing platform sees your address. Data is encrypted in transit (TLS).

4. Processors we use

  • Hetzner Online GmbH (Germany/Finland, EU) — hosting and backups.
  • Stripe Payments Europe / Stripe, Inc. — payment processing and invoicing. Stripe processes your payment details as described in its own privacy policy; transfers to the US are covered by the EU–US Data Privacy Framework and standard contractual clauses.
  • Anthropic (US) — provides the AI model behind our AI features (see Section 6). Transfers are covered by Anthropic’s data processing agreement, including standard contractual clauses. API data is not used to train Anthropic’s models.

We use no analytics providers, advertising networks, or tracking services of any kind.

5. Data from public procurement notices

The tender data in the Service comes from TED (Tenders Electronic Daily), the official EU publication for public procurement, © European Union. It concerns organizations — contracting authorities and winning suppliers — not individuals, and we deliberately do not ingest the contact-person names, email addresses, or phone numbers that appear in some notices. Incidentally, organization data can still identify a person (for example a sole trader whose business name is their own name, or a name appearing in a notice’s free-text description). We process such data on the basis of our legitimate interest in providing procurement transparency, drawing on information the EU has already made public; every tender in the Service links to the original notice on ted.europa.eu. If you are such a person and want data about you corrected or removed, or object to its processing, email contact@tenderlist.eu — we respond within one month.

6. AI features

Our AI features (tender matching, machine translation, market-intelligence summaries) are powered by Anthropic’s Claude models via API. When you use them, the relevant inputs — your company profile text, search criteria, custom notes, and tender text — are sent to Anthropic for processing under a data processing agreement. Anthropic does not use this data to train its models. AI-generated content is labeled in the app and can contain errors; it is decision support, not advice, and no decision with legal or similarly significant effect on you is made solely by automated means.

7. Alert recipients you add

Account holders can add up to five email addresses of colleagues to receive alert digests. If you received a digest without having an account, that is because an account holder at your organization added your address. Every digest links to alert management, and you can have your address removed at any time by emailing contact@tenderlist.eu. If you add recipients, make sure they are within your organization and expect these emails.

8. Cookies

We use exactly one cookie: a session cookie that keeps you logged in (strictly necessary, expires after about 30 days). Your theme preference is stored locally in your browser and never sent to us. Because we use no tracking, analytics, or advertising cookies, no cookie consent banner is required — there is nothing to consent to.

9. How long we keep data

  • Account and profile data: for as long as your account exists.
  • Sent-email log: 90 days.
  • Sign-in log and search queries: 12 months.
  • Billing records: as long as required by Belgian tax and accounting law (in general 7 years), held by Stripe and in our accounting.

Deleting your account (Settings → Data & Privacy) permanently removes your account and its associated data from the live database; already-issued invoices are retained as required by law.

10. Your rights

Under the GDPR you can request access to, rectification or erasure of, or a portable copy of your personal data, ask us to restrict processing, and object to processing based on legitimate interest. Self-service export and deletion are available in Settings → Data & Privacy; for anything else, email contact@tenderlist.eu. You also have the right to lodge a complaint with the Belgian Data Protection Authority (Autorité de protection des données / Gegevensbeschermingsautoriteit, Rue de la Presse 35, 1000 Brussels, www.dataprotectionauthority.be) or your local supervisory authority.

11. Security

Passwords are stored hashed (bcrypt), data is encrypted in transit, access to production systems is restricted, and the database is not reachable from the public internet. No system is perfectly secure; if a breach ever puts your rights at risk, we will notify the supervisory authority within 72 hours and affected users without undue delay, as the GDPR requires.

12. Changes to this policy

We will announce material changes to this policy by email and/or in the app before they take effect. The date at the top tells you when it last changed.

Tenderlist is a product of Invictus Development BV · BE 0749.451.296 · Overijse, Belgium

Contains public procurement data from TED (Tenders Electronic Daily), © European Union, ted.europa.eu. Tenderlist is not affiliated with or endorsed by the institutions of the European Union.

© 2026 Invictus Development BV. All rights reserved.