TenderBuilder
Legal

Privacy Policy

Effective 3 June 2026

Who we are

TenderBuilder (Dublin, Ireland) operates this service. For most personal data processed through tenderbuilder.ie we are the data controller — we decide why and how it is processed. There is one important exception: for the CVs and personal details of your own staff that you upload into your company profile, you (our customer) are the controller and we act as your processor (see Customer-uploaded staff CVs below). For any privacy question, contact lewis@tenderbuilder.ie.

What we collect

Legal bases

We process account and tender data under the contract basis (Art. 6(1)(b) GDPR) — we need it to deliver the service you signed up for. Operational data is processed under our legitimate interest (Art. 6(1)(f)) in running and improving the service. Non-essential cookies, if any are added in the future, will only run with your explicit consent (Art. 6(1)(a)).

Where your data lives

All account, tender, profile, and operational data is stored in Supabase (Postgres + Storage) in the EU region (Frankfurt). When the harness drafts answers, your tender documents and a rendered company-profile bundle are sent to Anthropic (Claude API) as document blocks under Anthropic's processor terms. Anthropic does not train on data submitted via the API. Your tender drafts and company profile go only to Anthropic for drafting; the only other content that leaves our systems is email delivery — when we send transactional sign-in emails and tender-digest notifications, the recipient address (and the digest content) is routed through Resend, our email sub-processor (see below).

Sub-processors

We do not sell your data. We share it only with the service providers we need to run the service. Our complete current list, with each provider's location and the safeguard that protects any transfer out of the EEA, is:

International data transfers

Your stored data lives in the EU (Supabase, Frankfurt). Some processing involves transfers to the United States — to Anthropic (AI drafting), Stripe (payments), Vercel (app hosting), and Resend (email delivery). For those EU→US transfers we rely on EU Standard Contractual Clauses (SCCs)under Article 46 GDPR, supported where applicable by the providers' EU-US Data Privacy Framework self-certifications. For UK customers, the same transfers are covered by the UK Extension to the EU-US Data Privacy Framework(the "UK-US Data Bridge") and/or the UK International Data Transfer Agreement (IDTA) where a provider does not cover the UK Extension. You can request copies of the relevant transfer safeguards from us at lewis@tenderbuilder.ie.

Customer-uploaded staff CVs

When you upload your own staff's CVs and personal details into your company profile, you are the data controller for that personal data and TenderBuilder acts as your processor. That means you are responsible for telling those individuals that their details are being used in bids and for having a lawful basis to do so, and we only process that data on your documented instructions under the data processing agreement that forms part of your contract with us. If you are an individual whose CV was uploaded by your employer and you want it removed or corrected, please contact your employer (the controller) first; you can also contact us and we will help your employer action your request, or erase an individual's data on the customer's instruction.

Retention

We retain your data for as long as your account exists. Deleting your account deletes your tenant, all linked profile records, tenders, documents, drafts, and harness events within 30 days. Billing records are retained for 7 years as required by Irish tax law.

Your rights

Under the GDPR you can request access, correction, deletion, restriction, or portability of your personal data, and you can object to processing under legitimate interest. Email us at lewis@tenderbuilder.ie. You may also complain to the Irish Data Protection Commission (dataprotection.ie).

Security

Multi-tenant isolation is enforced at the database layer via Postgres Row Level Security on every table. Connections to Supabase and Anthropic are TLS-encrypted. Service-role keys are confined to the worker process and never exposed to the browser.

Changes

If we materially change this policy we will update the effective date above and notify active users by email at least 14 days before the change takes effect.


Terms of Service · Back to home