01 Data Controller
The data controller for personal data processed through the TenderGuru Platform is:
Denis Tulum, acting as a natural person (sole trader / individual controller)
Trading as: TenderGuru (tenderguru.io)
Address: Str. Eufrosina Popescu nr. 61, Tronson Lama 3, sc. B, ap. 69, Sector 3, București, Romania (EU)
Email: privacy@tenderguru.io
Website: tenderguru.io
If your organisation has signed an Enterprise Agreement with TenderGuru, please refer to the Data Processing Agreement (DPA) annexed to that contract, which governs processing of your organisation's data and supersedes this Policy to the extent of any conflict.
02 What We Collect
2.1 Account & Registration Data
- Name, email address, job title, organisation name
- Billing address, VAT/tax number (for invoicing)
- Login credentials (password stored as bcrypt hash; we never store plaintext passwords)
2.2 User Content (uploaded by you)
- Expert/consultant CVs — name, professional history, education, skills, regions, languages, certifications
- Company profiles — sector expertise, past projects, geographic reach, staff bios
- Tender documents — ToR files, methodology drafts, LOIs, ESPDs uploaded for AI processing
- Other documents — work samples, reference letters, certificates uploaded for scoring improvement
2.3 Public CV-Formatting Tool (no account required)
TenderGuru offers a public page (/cv-format) where anyone can upload a CV and receive it back reformatted for a chosen donor template (World Bank, EBRD, ADB, etc.), without creating an account. This is a distinct flow from 2.2 and has its own rules:
- The uploaded CV is parsed by Anthropic's AI (see Section 5) to extract structured fields, and the reformatted file is generated and returned to you.
- Without an account, you get 1 free parse per UTC day, tracked by a signed, functional browser cookie that stores only a usage counter and the UTC date it belongs to — no name, email, IP address, or any other identifier is stored on our servers for this cookie. A free account gives the same 1 parse per UTC day for this tool; paid plans raise it (5 per UTC day on Analyst), and the top plans have no daily limit at all.
- Separately from the per-browser counter above, the page applies a coarse hourly and daily cap per IP address to stop automated abuse. That cap is the only use we make of your IP address on this page: it is held in the server's memory for no more than 24 hours, is never written to our database, and never appears in the usage analytics described below.
- The uploaded file and the parsed data are kept for 30 days, after which they are deleted automatically, so you can re-download without re-uploading. You can request deletion sooner at any time — see below.
- You can delete your data immediately, without an account or a support request — a "Delete my data" action is available directly on the result screen after your CV is processed. This erases the uploaded file from disk and the associated database records right away.
- The tool asks for up to three separate, independently-given permissions, each with its own checkbox: (1) none — processing and returning your file is a service you requested, not something we ask permission for; (2) showing your profile to companies searching for experts (a public showcase, opt-in, withdrawable at any time with immediate removal from the showcase); (3) sending you product and tender-related emails (opt-in, unchecked by default, unsubscribe link in every email). None of these are bundled — declining (2) or (3) never blocks getting your formatted file.
2.4 Platform Usage Data
- Tender searches, saved filters, alert subscriptions
- AI operations performed (scoring runs, document generations) — used for billing and feature improvement
- Document approval actions (who approved, when) — required for audit trail
- IP address, browser type, device information — collected at login for security
- Session data and access logs — retained for security monitoring
- Public CV-hook analytics only: country (derived at request time from a trusted reverse-proxy header, when configured — the raw IP address itself is never written to this analytics data), first browser-language tag, and a coarse device category (desktop / mobile / tablet). No raw IP, no city/coordinates, no full
User-Agentstring, and no third-party analytics or tracking scripts are used anywhere on this page.
2.5 Communications
- Emails and messages sent to our support team
- Survey responses and feedback you provide voluntarily
03 How We Use Your Data
| Purpose | Data Used |
|---|---|
| Providing the Services (scoring, generation, matching, monitoring) | User Content, account data, usage data |
| Formatting a CV through the public tool (with or without an account) | The uploaded CV file, parsed fields, usage-counter cookie or account ID, optional country/language/device analytics fields |
| Billing and payment processing | Account data, usage data (coins/operations count) |
| Security and fraud prevention, and enforcing the free-usage limit | IP address, login logs, access patterns; for the public CV tool, IP address is used only for short-lived rate-limiting (held in server memory for no more than 24 hours), never written to the database and never stored in analytics |
| Platform improvement and bug fixing | Usage data, anonymised error logs |
| Customer support | Account data, content you share in support tickets |
| Legal compliance | Account data, billing records |
| Transactional emails (invoices, alerts, security notices) | Email address |
| Marketing emails about the product to CV-hook users who opted in | Email address, marketing opt-in flag and timestamp |
We do not: sell personal data to third parties, use User Content to train AI models, process data for advertising profiling, run third-party analytics or trackers on the public CV-formatting page, or share data with tendering authorities without your explicit instruction.
04 Legal Basis for Processing (GDPR)
| Processing Activity | Legal Basis (GDPR Art.) |
|---|---|
| Providing the Services under a contract with you | Art. 6(1)(b) — Performance of contract |
| Parsing and returning a CV through the public tool (with or without account) | Art. 6(1)(b) — performing the request you made by clicking upload |
| Keeping the uploaded CV file for 30 days so you can re-download it | Art. 6(1)(f) — legitimate interest, time-boxed and stated on the page |
| Enforcing the free-usage limit (cookie / daily account counter / short-lived IP rate-limit) | Art. 6(1)(f) — legitimate interest in offering a fair free tier and preventing abuse |
| Showing your profile in the expert showcase | Art. 6(1)(a) — Consent, separate, withdrawable |
| Marketing emails (optional, opt-in) | Art. 6(1)(a) — Consent, separate, unbundled from the other two |
| Billing, invoicing, legal compliance | Art. 6(1)(c) — Legal obligation |
| Security monitoring, fraud prevention | Art. 6(1)(f) — Legitimate interests |
| Platform improvement (aggregated, anonymised) | Art. 6(1)(f) — Legitimate interests |
| Processing expert CVs on instruction of Customer (account-based flow) | Art. 6(1)(b) + Art. 28 (Processor relationship) |
Where TenderGuru processes personal data contained in expert CVs and professional profiles on your instruction, TenderGuru acts as a data processor and you (the Customer organisation) act as data controller for that data. The Data Processing Agreement (Schedule C of the Enterprise Agreement or available on request) governs this relationship. The public CV-formatting tool is different: there, the person uploading their own CV is both the data subject and the one requesting the service, so TenderGuru acts as controller for that processing.
05 AI Processing Modes: BYOK vs TG Key
TenderGuru offers two modes for AI processing on the main Platform. The mode you select determines how your data is routed for AI operations:
| BYOK Mode | TG Key Mode | |
|---|---|---|
| Who provides the API key | You (Customer) | TenderGuru |
| Where data goes for AI processing | Directly to Anthropic under your own account and API agreement | To Anthropic via TenderGuru's API key |
| TenderGuru's role for AI data | TenderGuru does not receive or store AI input/output; your Anthropic ToS governs | TenderGuru is processor; data temporarily processed, not retained for training |
| Data sovereignty | Maximum — you control the Anthropic relationship directly | Standard — TenderGuru DPA applies |
| Billing | Direct Anthropic billing; TenderGuru flat subscription fee | TG Coins deducted per operation |
/cv-format is sent to Anthropic using TenderGuru's own API key, regardless of the account's plan.
07 International Data Transfers
If your data is transferred outside the European Economic Area (EEA), TenderGuru ensures appropriate safeguards are in place:
- Transfers to the US (Anthropic) are covered by Standard Contractual Clauses (EU SCC Module 2, Controller-to-Processor) as approved by the European Commission. These clauses apply automatically under Anthropic’s Commercial Terms of Service; no separate signature is required.
- Cloud hosting is located within the EU (see Section 6): data stored on the Platform is not transferred outside the EU/EEA.
- Enterprise on-premise clients: no international transfer occurs — data stays within client infrastructure.
You may request a copy of the applicable transfer mechanism by emailing privacy@tenderguru.io.
08 Data Retention
| Data Category | Retention Period |
|---|---|
| Account data (active accounts) | Duration of account + 90 days after closure |
| User Content (CVs, documents) — account-based flows | Duration of account + 30-day export window + deletion within 90 days of account closure |
| Public CV-formatting tool — anonymous or free-account uploads | 30 days, automatically deleted from disk and database. You can delete sooner at any time from the result screen. (Enforced in code today.) |
| Talent-pool / expert profiles held by a customer account | Retained while the account holding them is active. There is no automatic time-based deletion today: profiles are deleted on request, and when the account is closed they follow the account-closure timeline above. |
| Billing records and invoices | Retained for as long as the accounting and tax law applicable to the controller requires — under Romanian accounting rules, 10 years from the end of the financial year concerned. |
| Usage logs (AI operations, approvals) | 2 years (audit purposes) |
| Security logs (access, IP) | 12 months |
| Support communications | 3 years from last interaction |
| Marketing consent records | Until withdrawal + 3 years |
You may request early deletion of your data at any time (see Section 10 — Your Rights), subject to legal retention obligations.
09 Security
TenderGuru implements industry-standard security measures, including:
- Encryption in transit (TLS 1.3) and at rest (AES-256)
- Bcrypt password hashing (passwords never stored in plaintext)
- Role-based access controls limiting who can access User Content within TenderGuru
- Regular automated backups with tested restore procedures
- Security monitoring and access logging
- Responsible disclosure policy for security vulnerability reports
In the event of a personal data breach likely to result in a risk to individuals, TenderGuru will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, and affected data subjects without undue delay, in accordance with GDPR Article 33–34.
10 Your Rights (GDPR)
If you are in the EEA or otherwise covered by GDPR, you have the following rights:
Request a copy of the personal data we hold about you (Art. 15).
Request correction of inaccurate or incomplete data (Art. 16).
Request deletion of your data ("right to be forgotten") where no legal basis persists (Art. 17). For the public CV-formatting tool, you can also erase your data instantly yourself — see below.
Receive your data in a structured, machine-readable format (Art. 20).
Request restriction of processing in certain circumstances (Art. 18).
Object to processing based on legitimate interests (Art. 21).
Withdraw consent at any time for consent-based processing (e.g., marketing emails, expert showcase).
Lodge a complaint with a data protection authority. Our lead supervisory authority is the Romanian ANSPDCP (Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal, dataprotection.ro). You may also complain to the authority in your own country of residence.
To exercise any other right, email privacy@tenderguru.io with "Data Rights Request" in the subject line. We will respond within 30 days. We may need to verify your identity before processing the request.
12 Children's Privacy
The Platform is intended for professional use by adults (18+). TenderGuru does not knowingly collect personal data from individuals under 18. If you believe a minor has provided us with personal data, contact privacy@tenderguru.io and we will delete it promptly.
13 Changes to This Policy
We may update this Privacy Policy to reflect changes in our practices or applicable law. Material changes will be notified by email at least 30 days before taking effect. The "Effective date" at the top of this document reflects the most recent revision.
14 Contact & DPA
For privacy-related enquiries, data rights requests, or to obtain a copy of our Data Processing Agreement:
- Email: privacy@tenderguru.io
- Website: tenderguru.io
Enterprise clients may request a countersigned DPA (covering EU SCCs, sub-processor list, breach notification, and audit rights) by emailing privacy@tenderguru.io.
Denis Tulum, individual data controller · tenderguru.io
This Policy was last updated on 21 August 2026.