TenderProc processes your personal data in compliance with the EU General Data Protection Regulation (GDPR). This notice explains what personal data TenderProc collects, why, and what rights you have over it under GDPR and Belgian data protection law. It applies to visitors of our website and users of the TenderProc app.
1. Who is responsible for your data
The data controller is Nokhbat Al Mutakamilah lil Khadamaat atTijaria, VAT number (Saudi Arabia) 3123756993100003. For any question about this notice or to exercise your rights, contact us at contact@tenderproc.com.
We’re established outside the European Union but offer the Service to businesses in Belgium and the EU, so this notice, and GDPR itself, still applies to how we handle your data (GDPR Art. 3(2)).
2. What we collect
Account data: your email address and password (stored hashed by our authentication provider, Supabase — we never see the plaintext password).
Company profile: company name, address, size, sectors, description, website, employee count, regions served and languages served — collected at signup and editable on your Company page.
Company knowledge base: the services you offer, certifications, past references (which may include contract values), and supporting documents you upload. This is used to generate match scores and eligibility checks, and — only where you choose to — as source material for AI-drafted bid responses.
Tenders and bids: tenders you upload or track, the requirements and award criteria we extract from them, your bid workspace data (status, checklists, uploaded bid documents, AI-drafted response text), and — if you record it — the outcome of a bid, which may include competitively sensitive figures like winning price or your own score.
Technical data: standard request data (IP address, browser user-agent) generated by using a web app, session cookies used to keep you signed in, and a cookie storing your language preference. If you consent via the cookie banner, we also use Google Analytics to understand how visitors use the site — see Section 8.
3. Why we process it, and on what legal basis
- Providing the Service — creating your account, matching tenders to your profile, running eligibility checks, generating draft bid responses, and running your bid workspace. Legal basis: performance of our contract with you (Art. 6(1)(b) GDPR).
- Billing — processing your subscription via Paddle, and keeping records required for accounting and tax law. Legal basis: contract performance and legal obligation (Art. 6(1)(b) and (c) GDPR).
- Service notifications — sending the tender digest email for sectors you’ve selected. Legal basis: legitimate interest in operating the feature you configured (Art. 6(1)(f) GDPR); you can turn this off in your preferences at any time.
- Security and abuse prevention — protecting accounts and the Service from unauthorized access. Legal basis: legitimate interest (Art. 6(1)(f) GDPR).
- Legal compliance — responding to lawful requests, tax and accounting record-keeping. Legal basis: legal obligation (Art. 6(1)(c) GDPR).
- Analytics, only with your consent — understanding how visitors use the site (via Google Analytics), so we can improve it. Legal basis: consent (Art. 6(1)(a) GDPR); you can withdraw it at any time via “Cookie preferences” in the footer.
AI-assisted outputs (match scores, eligibility checks, drafted text) are generated to help you, not to make decisions about you — TenderProc doesn’t use automated processing to make decisions that produce legal or similarly significant effects concerning you within the meaning of Art. 22 GDPR. A human — you — always reviews and decides before anything is submitted to a contracting authority.
4. Who we share it with
We share personal data with the following processors, each bound by a data processing agreement, and only to the extent needed to provide the Service:
- Supabase — hosts our database, authentication and file storage. Project region: Paris, France (AWS eu-west-3).
- Anthropic — processes tender and company text you submit to generate match scores, eligibility checks, and draft bid responses. Anthropic is based in the United States; transfers are covered by Standard Contractual Clauses or an equivalent safeguard.
- Resend — delivers the tender-digest email and other transactional emails.
- Paddle — processes payments and acts as Merchant of Record for paid subscriptions; Paddle receives the billing details needed to process your payment (Paddle, not us, holds your card details).
Tender and award data flowing the other way — from the EU’s TED database and Belgium’s e-Procurement/BOSA platform into TenderProc — is public procurement data, not your personal data; we don’t send your data to these sources.
We don’t sell personal data, and we don’t share it with third parties for their own marketing purposes.
5. International transfers
Our database and file storage (Supabase) are hosted in Paris, France (AWS eu-west-3), within the EU/EEA. Two other parts of how we operate still send your data outside the EU/EEA, though, and we want to be direct about that rather than bury it: our AI processing provider (Anthropic) is based in the United States, and Nokhbat Al Mutakamilah lil Khadamaat atTijaria itself, as controller, is established outside the EU/EEA. For each of these transfers, we rely on the European Commission’s Standard Contractual Clauses or another lawful transfer mechanism recognized under GDPR Chapter V to protect your data. You can ask us for a copy of the relevant safeguard by contacting us at contact@tenderproc.com.
6. How long we keep it
We keep your account and workspace data for as long as your account is active. If you delete your account, we delete or anonymize your personal data within a reasonable period, except data we’re required to keep for longer — for example, billing and invoice records, which we retain for the period required by Belgian accounting and tax law.
7. Your rights
Under GDPR, you have the right to:
- Access the personal data we hold about you;
- Correct inaccurate data;
- Ask us to delete your data (subject to our legal retention obligations, e.g. for invoices);
- Restrict or object to certain processing;
- Receive your data in a portable format;
- Withdraw consent at any time, where processing is based on consent;
- Lodge a complaint with the Belgian Data Protection Authority (Gegevensbeschermingsautoriteit / Autorité de protection des données) or your own EU supervisory authority.
To exercise any of these rights, contact us at contact@tenderproc.com. We may need to verify your identity before acting on a request.
8. Cookies
We use strictly necessary cookies — one to keep you signed in (set by Supabase authentication) and one to remember your language preference. These don’t require consent because the Service can’t function without them.
With your consent, given via the cookie banner shown on your first visit, we also use Google Analytics to understand how visitors use the site (pages viewed, approximate location from IP, device type); IP addresses are anonymized before being stored. Declining doesn’t affect your ability to use the Service, and you can change your choice at any time via “Cookie preferences” in the footer.
9. Security
Data in transit is encrypted (HTTPS). Access to your data within the Service is scoped to your own account through row-level security enforced at the database layer — by default, no other customer’s account can query your data. Access by TenderProc staff is limited to what’s needed for support and operating the Service.
10. Children
TenderProc is a business-to-business service and isn’t directed at, or knowingly used by, children.
11. Changes to this notice
We may update this notice from time to time. If a change is material, we’ll make reasonable efforts to notify you before it takes effect.