Privacy Policy
This Privacy Policy explains how NullLogic s. r. o. ("we") processes personal data when you visit https://tendersignal.eu, create a TenderSignal workspace, or receive our e-mails. We are the data controller for this processing under the EU General Data Protection Regulation (GDPR) and Slovak Act No. 18/2018 Coll.
English is the contract language; Slovak law governs. Version 1.0 (5 September 2026). Effective: 5 September 2026.
1. Controller and contact
NullLogic s. r. o., IČO 56 906 439, DIČ 2122501667, VAT ID SK2122501667, registered seat Novozámocká 1347/69, 960 01 Zvolen, Slovak Republic, registered in the Commercial Register of the District Court Banská Bystrica, section Sro, file no. 52083/S.
Privacy requests: hello@tendersignal.eu. We have not appointed a data protection officer.
2. What we process and why
Account data — company name, your name if you give it, work e-mail address, a salted hash of your password, account role, time of signup and of acceptance of the Terms. Purpose: to create and secure your account and to conclude the contract. Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
Billing data — subscription status, Stripe customer and subscription identifiers, invoices. Card details are entered on Stripe's pages and never reach our servers. Purpose: charging the subscription and keeping accounts. Legal basis: contract (Art. 6(1)(b)) and legal obligations in tax and accounting law (Art. 6(1)(c)).
Workspace data — scoring profile (keywords, CPV codes, countries, value band), pursue / skip decisions and notes, digest recipient addresses, digest delivery log. Purpose: providing the Service. Legal basis: contract (Art. 6(1)(b)). Recipient addresses you enter must belong to people in your organisation who expect the digest; you are responsible for informing them.
Technical data — IP address, browser type, requested pages, timestamps, in server logs. Purpose: security, abuse prevention (rate limiting), troubleshooting. Legal basis: legitimate interest (Art. 6(1)(f)) in running a secure service.
Public procurement data — notices and award records published by public authorities may contain names of contact persons at buyers or of sole-trader suppliers. We copy these records from the official sources listed in the Service and show them unchanged to customers. Legal basis: legitimate interest (Art. 6(1)(f)) in providing procurement intelligence based on information that the law requires to be public. You may object (section 7).
Correspondence — e-mails you send us. Purpose: support. Legal basis: contract and legitimate interest.
We do not use advertising trackers, analytics cookies or profiling, and we do not send marketing e-mails without your consent. Service e-mails (digest, billing, security notices) are part of the contract.
3. Recipients and processors
We share personal data only with providers that help us run the Service, under data-processing agreements, and with authorities where the law requires it:
- Stripe Payments Europe, Ltd. (Ireland) — payments, invoices, subscription management. Stripe may transfer data to Stripe, Inc. (USA) under the EU-US Data Privacy Framework and standard contractual clauses.
- netcup GmbH (Karlsruhe, Germany) — hosting of the application and databases (EU data centre).
- Websupport, s.r.o. (Bratislava, Slovakia) — delivery of the digest and account e-mails.
- Websupport, s.r.o. (Slovakia) — domain registration and DNS.
There are no other recipients. We do not sell personal data.
4. International transfers
Data is stored in the European Union. Where a processor (currently Stripe) transfers data outside the EEA, the transfer is covered by an adequacy decision or standard contractual clauses.
5. Retention
- Account and workspace data: for the life of the account and 90 days after the subscription or trial ends, then deleted. Deleted earlier on request.
- Billing records and invoices: 10 years, as required by Slovak accounting and tax law.
- Server logs: 30 days.
- Public procurement data: retained as part of the Service's historical dataset; personal data in it is removed on justified objection.
- Support e-mails: 2 years.
6. Security
TLS on every connection, passwords stored only as salted PBKDF2 hashes, one isolated database per customer, application reachable only through the reverse proxy, access to servers restricted to the operator. No system is perfectly secure; tell us immediately if you suspect a breach.
7. Your rights
You have the right to access your data, to have it corrected or deleted, to restrict or object to processing based on legitimate interest, to data portability, and to withdraw any consent you have given. Write to hello@tendersignal.eu; we answer within one month. You may also complain to the Slovak Office for Personal Data Protection (Úrad na ochranu osobných údajov Slovenskej republiky, Hraničná 12, 820 07 Bratislava, www.dataprotection.gov.sk) or to the supervisory authority of your own EU country.
8. Cookies
The Service uses one strictly necessary cookie, signal_session, which keeps you signed in for up to 30 days. It is not used for tracking and requires no consent. The public pages set no cookies.
9. Children
The Service is for businesses and is not directed at persons under 18.
10. Changes
We may update this Policy; the current version is always at /legal/privacy. Material changes are announced by e-mail to account holders.