Security & data practices

How we handle data

Short version: the opportunity data is public by law, your account data is minimal, the database lives in the EU where we control it, and we never claim certifications we do not hold.

Where the opportunity data comes from

Everything on the radar derives from official public procurement sources: TED (the EU's publication platform), TenderNed (the Dutch national platform), Germany's Bekanntmachungsservice (oeffentlichevergabe.de) and Austria's Kerndaten, published as open data under the BVergG. These notices are published by law for transparency. We do not scrape private systems, buy contact databases, or use any non-public source.

Facts (buyer, supplier, value, dates, contact details on the notice) come straight from those notices and link back to the source. Renewal timing is our inference and is always labeled as an estimate.

What personal data we process

For your account: name, work email, and authentication data. For billing: handled by Stripe; we never see card numbers. For the product: the pipeline state, notes and tasks your team enters. That is the list. We do not sell data, run ads, or enrich your people from third-party sources.

Buyer contact persons shown on dossiers are professional contact details published by the contracting authority itself on the official notice, provided for exactly this purpose.

Infrastructure

The database (procurement data and your account and pipeline data) runs on Neon in the EU (Frankfurt). The application runs on Vercel. Data is encrypted in transit (TLS) and at rest by our infrastructure providers. Access to production is limited to the founder.

Subprocessors

ProviderPurposeRegion
VercelApplication hosting and deliveryEU/US (global edge)
NeonDatabase (all procurement + account data)EU (Frankfurt)
ClerkAuthentication (sign-in, sessions)Per Clerk DPA
StripePayments and billingPer Stripe DPA
ResendTransactional email (digests, alerts)Per Resend DPA
AnthropicMachine enrichment of notice text; excluded from verdict calculationPer Anthropic DPA

Access, retention and deletion

Your team's data is visible to your team only. If you cancel, your account and pipeline data are deleted on request; ask by email and it happens. We keep operational logs briefly for debugging and abuse prevention.

Compliance posture, honestly

We operate GDPR-aligned practices: minimal data, EU hosting, transparent subprocessors, deletion on request, and a DPA available for customers who need one. We do not currently hold a SOC 2 or ISO 27001 certification and will not pretend otherwise; if your procurement process requires one, tell us and it moves up the roadmap.

Reporting a concern

Found a vulnerability or have a data question? Email ravid@tendervane.com and you will hear back from the founder, fast.

Security & data · Tendervane