Last Updated: July 6, 2025
1. Introduction and Data Controller
The data controller responsible for the processing of your personal data is:
Tendery UG (haftungsbeschränkt)
Kreuzbergstraße 42a
10965 Berlin
Germany
Email: [email protected]
2. Information We Collect and Legal Basis
We collect and process personal data to provide and improve our services. The legal basis for our processing is primarily the performance of our contract with you (Art. 6(1)(b) GDPR) and our legitimate interests (Art. 6(1)(f) GDPR).
- Account Information: When you create an account, we collect your name, email address, and company information. This is necessary to create and manage your account and fulfill our contractual obligations.
- Payment Information: For paid subscriptions, we collect billing details. These are processed securely by our payment provider ([e.g., Stripe]) and are necessary for contract performance. We do not store your credit card details on our servers.
- Usage Data: We may collect data on how you interact with our platform, such as searches performed and features used. We process this data based on our legitimate interest to analyze and improve the performance and usability of our service. This data is aggregated and anonymized wherever possible.
- Communications: If you contact us via email or our support channels, we will collect your contact information and the content of your message to respond to your inquiry.
3. Cookies and Similar Technologies
We use cookies and similar technologies to operate our website, secure our services, and, with your consent, to analyze and improve our platform. Cookies are small text files stored on your device.
When you first visit our site, we will ask for your consent to use non-essential Analytics Cookies via a cookie banner. You can find more details on each category below.
- Necessary Cookies: These cookies are essential for the site to function correctly. Some of these cookies are placed automatically on all pages for basic security and usability, such as the cookie that stores your consent preferences. Others are placed only when you request a specific feature; for example, when you navigate to our sign-in page, we place the necessary authentication cookies from our provider, Clerk, to allow you to log in. Because this functionality is explicitly requested by you, these cookies do not require prior consent.
- Analytics Cookies (with consent): This is the only category of cookies that requires your explicit consent. These cookies help us understand how visitors interact with our public pages by collecting information anonymously. We use tools like Google Analytics and PostHog for this purpose. These cookies will only be placed on your device if you accept them in our cookie banner. You can withdraw your consent at any time via the "Cookie Settings" link in our website footer.
4. Data Sharing and Third-Party Processors
We do not sell your personal data. We share your data only with trusted third-party service providers (data processors) who are essential for us to operate and provide our services. We have signed Data Processing Agreements (DPAs) with all of them to ensure your data is protected in accordance with GDPR.
Our key data processors include:
- Infrastructure and Hosting: To host our platform and user data, we use services from Google Cloud Platform (GCP), Amazon Web Services (AWS), and DigitalOcean. Data is primarily processed within their data centers in the European Union. (Providers: Google Ireland Ltd., Amazon Web Services EMEA SARL, Digital Ocean, LLC)
- Authentication and User Management: To securely manage user sign-up, login, and session management, we use Clerk. (Provider: Clerk, Inc.)
- AI Copilot Features: To provide our semantic search and copilot functionalities, we send query data to OpenAI's API. We do not permit OpenAI to use this data to train their models. (Provider: OpenAI, L.L.C.)
- Payment Processing: For handling subscriptions, we use Stripe. We do not store your credit card information on our servers. (Provider: Stripe, Inc.)
- Transactional Emails: To send essential service-related communications, such as account notifications and tender recommendations, we use Resend. (Provider: Resend, Inc.)
- Marketing and Newsletters: For sending marketing communications and newsletters, which you will only receive with your explicit consent, we use Mailchimp. You can withdraw your consent at any time by clicking the "unsubscribe" link in any of these emails. (Provider: The Rocket Science Group LLC d/b/a Mailchimp)
- Analytics and Product Improvement: To understand how users interact with our platform and to improve our service, we use Google Analytics and PostHog. We only use these services if you provide your explicit consent. (Providers: Google Ireland Ltd., PostHog, Inc.)
- Support Communications: When you contact us via email, your data is processed by Google Workspace. (Provider: Google Ireland Ltd.)
Some of these providers are based outside the European Economic Area (EEA). In such cases, we ensure that data is transferred securely and that an adequate level of data protection is guaranteed through legal mechanisms such as the EU-U.S. Data Privacy Framework or by executing EU Standard Contractual Clauses (SCCs).
5. Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected. This includes the duration of your account's existence and any period required by law (e.g., for tax and commercial law purposes regarding invoices).
6. Data Security
We implement appropriate technical and organizational security measures to protect your personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access.
7. Your Rights Under GDPR
As a data subject, you have the following rights:
- Right of Access (Art. 15 GDPR): To request information about the personal data we hold about you.
- Right to Rectification (Art. 16 GDPR): To have inaccurate personal data corrected.
- Right to Erasure ('Right to be Forgotten') (Art. 17 GDPR): To have your data deleted.
- Right to Restriction of Processing (Art. 18 GDPR): To limit how we use your data.
- Right to Data Portability (Art. 20 GDPR): To receive your data in a machine-readable format.
- Right to Object (Art. 21 GDPR): To object to the processing of your data based on legitimate interests.
- Right to Lodge a Complaint: You have the right to lodge a complaint with a supervisory authority.
To exercise these rights, please contact us at [email protected]
8. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any significant changes by posting the new policy on this page and, where appropriate, through email notification.