Security & data practices
How we handle data
Short version: the opportunity data is public by law, your account data is minimal, the database lives in the EU where we control it, and we never claim certifications we do not hold.
Where the opportunity data comes from
Everything on the radar derives from official public procurement sources: TED (the EU's publication platform), TenderNed (the Dutch national platform), Germany's Bekanntmachungsservice (oeffentlichevergabe.de) and Austria's Kerndaten, published as open data under the BVergG. These notices are published by law for transparency. We do not scrape private systems, buy contact databases, or use any non-public source.
Facts (buyer, supplier, value, dates, contact details on the notice) come straight from those notices and link back to the source. Renewal timing is our inference and is always labeled as an estimate.
What personal data we process
For your account: name, work email, and authentication data. For billing: handled by Stripe; we never see card numbers. For the product: the pipeline state, notes and tasks your team enters. That is the list. We do not sell data, run ads, or enrich your people from third-party sources.
Buyer contact persons shown on dossiers are professional contact details published by the contracting authority itself on the official notice, provided for exactly this purpose.
Infrastructure
The database (procurement data and your account and pipeline data) runs on Neon in the EU (Frankfurt). The application runs on Vercel. Data is encrypted in transit (TLS) and at rest by our infrastructure providers. Access to production is limited to the founder.
Subprocessors
| Provider | Purpose | Region |
|---|---|---|
| Vercel | Application hosting and delivery | EU/US (global edge) |
| Neon | Database (all procurement + account data) | EU (Frankfurt) |
| Clerk | Authentication (sign-in, sessions) | Per Clerk DPA |
| Stripe | Payments and billing | Per Stripe DPA |
| Resend | Transactional email (digests, alerts) | Per Resend DPA |
| Anthropic | Machine enrichment of notice text; excluded from verdict calculation | Per Anthropic DPA |
Access, retention and deletion
Your team's data is visible to your team only. If you cancel, your account and pipeline data are deleted on request; ask by email and it happens. We keep operational logs briefly for debugging and abuse prevention.
Compliance posture, honestly
We operate GDPR-aligned practices: minimal data, EU hosting, transparent subprocessors, deletion on request, and a DPA available for customers who need one. We do not currently hold a SOC 2 or ISO 27001 certification and will not pretend otherwise; if your procurement process requires one, tell us and it moves up the roadmap.
Reporting a concern
Found a vulnerability or have a data question? Email ravid@tendervane.com and you will hear back from the founder, fast.