tenderguru.io
Legal Document

Privacy Policy

Effective date: [EFFECTIVE DATE]  ·  Version: 1.0  ·  Jurisdiction: GDPR (EU) / EEA
Summary. TenderGuru processes data you upload (CVs, company profiles, documents) and data about your usage of the Platform to provide its services. We do not sell your data. We do not use your content to train AI models. BYOK users control how their data reaches Anthropic directly. You have full GDPR rights: access, rectification, erasure, portability, and objection.
Table of Contents
  1. Data Controller
  2. What We Collect
  3. How We Use Your Data
  4. Legal Basis (GDPR)
  5. AI Processing Modes: BYOK vs TG Key
  6. Data Sharing & Sub-processors
  7. International Transfers
  8. Data Retention
  9. Security
  10. Your Rights (GDPR)
  11. Cookies
  12. Children's Privacy
  13. Changes to This Policy
  14. Contact & DPA

01 Data Controller

The data controller for personal data processed through the TenderGuru Platform is:

TenderGuru OÜ (Estonian entity, upon registration) / MakeIT SRL (Moldovan entity, prior to Estonian registration)
Email: privacy@tenderguru.io
Website: tenderguru.io

If your organisation has signed an Enterprise Agreement with TenderGuru, please refer to the Data Processing Agreement (DPA) annexed to that contract, which governs processing of your organisation's data and supersedes this Policy to the extent of any conflict.

02 What We Collect

2.1 Account & Registration Data

2.2 User Content (uploaded by you)

Sensitive data notice: CVs and professional profiles may contain data that is sensitive in some jurisdictions (nationality, age, languages). We process this data solely for the purpose of matching experts to ToR requirements as instructed by you, our Customer. You are responsible for ensuring lawful collection of your experts' personal data before uploading it.

2.3 Platform Usage Data

2.4 Communications

03 How We Use Your Data

PurposeData Used
Providing the Services (scoring, generation, matching, monitoring)User Content, account data, usage data
Billing and payment processingAccount data, usage data (coins/operations count)
Security and fraud preventionIP address, login logs, access patterns
Platform improvement and bug fixingUsage data, anonymised error logs
Customer supportAccount data, content you share in support tickets
Legal complianceAccount data, billing records
Transactional emails (invoices, alerts, security notices)Email address

We do not: sell personal data to third parties, use User Content to train AI models, process data for advertising profiling, or share data with tendering authorities without your explicit instruction.

05 AI Processing Modes: BYOK vs TG Key

TenderGuru offers two modes for AI processing. The mode you select determines how your data is routed for AI operations:

BYOK ModeTG Key Mode
Who provides the API key You (Customer) TenderGuru
Where data goes for AI processing Directly to Anthropic under your own account and API agreement To Anthropic via TenderGuru's API key
TenderGuru's role for AI data TenderGuru does not receive or store AI input/output; your Anthropic ToS governs TenderGuru is processor; data temporarily processed, not retained for training
Data sovereignty Maximum — you control the Anthropic relationship directly Standard — TenderGuru DPA applies
Billing Direct Anthropic billing; TenderGuru flat subscription fee TG Coins deducted per operation
Enterprise clients on on-premise deployments: your data does not leave your infrastructure. TenderGuru's AI models run within your server environment. No data is transmitted to TenderGuru or Anthropic (subject to BYOK configuration in the on-premise licence).

06 Data Sharing & Sub-processors

TenderGuru does not sell personal data. We share data only with:

All sub-processors are bound by data processing agreements and required to process data only as instructed by TenderGuru.

We may disclose data to law enforcement or regulatory authorities when required by applicable law, subject to validating the legal basis of any such request.

07 International Data Transfers

If your data is transferred outside the European Economic Area (EEA), TenderGuru ensures appropriate safeguards are in place:

You may request a copy of the applicable transfer mechanism by emailing privacy@tenderguru.io.

08 Data Retention

Data CategoryRetention Period
Account data (active accounts)Duration of account + 90 days after closure
User Content (CVs, documents)Duration of account + 30-day export window + deletion within 90 days of account closure
Billing records and invoices7 years (legal / tax obligation)
Usage logs (AI operations, approvals)2 years (audit purposes)
Security logs (access, IP)12 months
Support communications3 years from last interaction
Marketing consent recordsUntil withdrawal + 3 years

You may request early deletion of your data at any time (see Section 10 — Your Rights), subject to legal retention obligations.

09 Security

TenderGuru implements industry-standard security measures, including:

In the event of a personal data breach likely to result in a risk to individuals, TenderGuru will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, and affected data subjects without undue delay, in accordance with GDPR Article 33–34.

10 Your Rights (GDPR)

If you are in the EEA or otherwise covered by GDPR, you have the following rights:

Access

Request a copy of the personal data we hold about you (Art. 15).

Rectification

Request correction of inaccurate or incomplete data (Art. 16).

Erasure

Request deletion of your data ("right to be forgotten") where no legal basis persists (Art. 17).

Portability

Receive your data in a structured, machine-readable format (Art. 20).

Restriction

Request restriction of processing in certain circumstances (Art. 18).

Objection

Object to processing based on legitimate interests (Art. 21).

Withdraw Consent

Withdraw consent at any time for consent-based processing (e.g., marketing emails).

Complain

Lodge a complaint with your local data protection authority (e.g., Estonian Inspectorate: aki.ee).

To exercise any right, email privacy@tenderguru.io with "Data Rights Request" in the subject line. We will respond within 30 days. We may need to verify your identity before processing the request.

Note for Enterprise clients: If your organisation's data was uploaded by your employer, please direct rights requests to your employer (as data controller for that data) in the first instance.

11 Cookies

TenderGuru uses cookies and similar technologies for:

We do not use third-party advertising cookies. You can manage cookie preferences through your browser settings or our in-app cookie preferences panel.

12 Children's Privacy

The Platform is intended for professional use by adults (18+). TenderGuru does not knowingly collect personal data from individuals under 18. If you believe a minor has provided us with personal data, contact privacy@tenderguru.io and we will delete it promptly.

13 Changes to This Policy

We may update this Privacy Policy to reflect changes in our practices or applicable law. Material changes will be notified by email at least 30 days before taking effect. The "Effective date" at the top of this document reflects the most recent revision.

14 Contact & DPA

For privacy-related enquiries, data rights requests, or to obtain a copy of our Data Processing Agreement:

Enterprise clients may request a countersigned DPA (covering EU SCCs, sub-processor list, breach notification, and audit rights) by emailing legal@tenderguru.io.

TenderGuru OÜ / MakeIT SRL · tenderguru.io
This Policy was last updated on [EFFECTIVE DATE].