Privacy policy
1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
Philipp Dylka
Lokstedter Weg 39, 20251 Hamburg, Germany
Email: datenschutz@tender-scope.de
2. Hosting
This website is hosted on a server operated by IONOS SE, Elgendorfer Str. 57, 56410 Montabaur, Germany. The servers are located in Germany. When you visit our website, IONOS, as a processor, records various technical data in the course of providing the service. The legal basis is our legitimate interest in providing our offering securely and efficiently (Art. 6(1)(f) GDPR). A data processing agreement (DPA) is in place with IONOS.
3. Server log files
Each time our website is accessed, information transmitted by your browser is automatically stored in so-called server log files. These are in particular:
- IP address
- date and time of the request
- page / file accessed
- browser and operating system used
- referrer URL
The processing is carried out to ensure trouble-free operation and the security of our systems (Art. 6(1)(f) GDPR). The log files are deleted after a short time.
4. Getting in touch / demo request
When you request a demo via our form, we process the data you provide (name, email address, company website, described service) in order to handle your request and get in touch with you. The legal basis is Art. 6(1)(b) GDPR (pre-contractual measures) and our legitimate interest in responding to enquiries (Art. 6(1)(f) GDPR). The data is deleted as soon as it is no longer required for the purpose, unless statutory retention obligations apply.
5. Email delivery (Resend)
To send emails (e.g. the tender digest, invitations and notifications about enquiries) we use the service Resend provided by Resend, Inc. (USA). The data required for delivery (in particular email addresses and content) is transmitted to Resend. The transfer to the USA takes place on the basis of appropriate safeguards (standard contractual clauses). The legal basis is our legitimate interest in reliable email delivery (Art. 6(1)(f) GDPR).
6. AI-assisted processing (Anthropic)
To score and analyse tenders, to automatically generate the tender digest and - depending on the feature used - to create short overviews and detail summaries, to generate bidder questions, to check eligibility, to create bid drafts, to prepare submission documents and to create and calibrate the search profile (including suggestions for sharpening the search profile), we use the application programming interface (API) of Anthropic PBC (USA, “Claude”). Depending on the feature used, the following are transmitted: the stored company profile and search configuration, an uploaded service catalogue, answers and feedback provided within the service (e.g. from the Eligibility Check), publicly accessible content of the company website during profile creation, tender data, tender documents downloaded within the service, as well as - on the Professional plan, after separate activation - the voluntarily stored company master data (including the names of authorised representatives and business contact details). The transfer to the USA takes place on the basis of appropriate safeguards (standard contractual clauses). According to Anthropic, data transmitted via the API is not used to train models. The legal basis is the performance of the contract (Art. 6(1)(b) GDPR).
7. Overview of processors used
To provide our service, we use carefully selected service providers as processors. Data processing agreements pursuant to Art. 28 GDPR are in place with all of them; transfers to third countries (USA) are safeguarded by appropriate guarantees (standard contractual clauses).
- IONOS SE(Germany) - hosting & storage. Data processed: all data stored within the service. Server location Germany.
- Resend, Inc. (USA) - sending emails (digest, invitations, notifications). Data processed: recipients' email addresses and email content.
- Anthropic PBC (USA) - AI-assisted scoring and document analysis. Data processed: company profile (incl. service catalogue), answers and feedback provided within the service, tender data, tender documents and (on the Professional plan) company master data. No training with the transmitted data.
8. Cookies and login
In the protected area (login) we use technically necessary cookies that are required for signing in and maintaining your session. We also store your language choice in a technically necessary cookie. These cookies are strictly necessary for the operation of the application; the legal basis is § 25 (2) TDDDG and Art. 6(1)(b) GDPR. Cookies are not used for analytics or marketing purposes.
9. Password security check
When you set a password, we check whether it appears in known data breaches. For this we use the service “Have I Been Pwned” (haveibeenpwned.com). Only the first five characters of the SHA-1 hash of the password are transmitted (k-anonymity method); neither the password itself nor your email address or any other identifying data leaves our server. The legal basis is our legitimate interest in the security of user accounts (Art. 6(1)(f) GDPR).
10. Your rights
Within the scope of the statutory provisions, you have the right to:
- access to the data stored about you (Art. 15 GDPR)
- rectification of inaccurate data (Art. 16 GDPR)
- erasure (Art. 17 GDPR)
- restriction of processing (Art. 18 GDPR)
- data portability (Art. 20 GDPR)
- objection to the processing (Art. 21 GDPR)
You also have the right to lodge a complaint with a data protection supervisory authority about the processing of your personal data.
11. Currency of this notice
This privacy policy is currently valid. As our website develops further or due to changed statutory requirements, it may become necessary to amend this notice.