Privacy Policy
This Privacy Policy explains how personal data is processed when you visit the TenderDesk website, create or use an account, upload documents, request support, or use analysis and workflow features provided through the TenderDesk platform.
1. Controller
Avagliano Unternehmergesellschaft (haftungsbeschränkt)
Otto-Heilmann-Str. 18 A
82031 Grünwald
Germany
Email: connect@avagliano.com
Phone: +49 (0)30 223 995 0815
If a data protection officer is appointed or additional privacy contact details are required by law, such details will be published here or in the legal notice.
2. Scope of this Privacy Policy
This Privacy Policy applies to personal data processed by us in connection with:
- the TenderDesk website;
- account creation, account administration, and authentication;
- customer communication and support;
- billing, service administration, and security;
- the use of the TenderDesk platform.
Where organizational customers use TenderDesk to upload and process case materials, we may process personal data contained in such materials on behalf of the respective customer. In such cases, the customer is generally responsible for the underlying case-related processing, and we process such data as a service provider in accordance with the applicable customer agreement and, where required, a data processing agreement.
3. Categories of Personal Data
We may process the following categories of personal data:
- identity and account data, such as name, email address, tenant association, user role, and login credentials or authentication-related information;
- contract and billing data, such as subscription plan, billing contact details, invoices, payment status, and transaction-related records;
- document and case data uploaded to the platform, including uploaded files, extracted text, generated summaries, line items, reports, tasks, reminders, audit trails, and workflow metadata;
- communication and support data, such as inquiries, support requests, and related correspondence;
- technical and usage data, such as IP addresses, timestamps, browser or device information, request metadata, system logs, security events, and platform activity records.
4. Purposes of Processing
We process personal data for the following purposes:
- to provide and operate the TenderDesk website and platform;
- to create, manage, and secure user accounts;
- to authenticate users and manage access rights;
- to process uploaded documents and generate platform outputs and workflow artifacts;
- to provide customer support and respond to inquiries;
- to administer subscriptions, billing, and contractual relationships;
- to maintain platform security, integrity, availability, and abuse prevention;
- to log system events, maintain auditability, and investigate incidents;
- to comply with legal, regulatory, tax, accounting, and contractual obligations;
- to enforce our legal rights and defend against legal claims.
5. Legal Bases for Processing
Depending on the specific context, we process personal data on one or more of the following legal bases:
- performance of a contract or steps prior to entering into a contract;
- compliance with legal obligations;
- our legitimate interests in operating, securing, improving, and administering TenderDesk and related services;
- consent, where processing is based on consent and such consent is required by law.
Where consent is used as the legal basis, you may withdraw it at any time with effect for the future.
6. Platform Processing of Uploaded Materials
TenderDesk is designed to process tender-related documents, case materials, and related workflow data. Uploaded documents and related case materials may contain personal data, business data, project-specific information, and other sensitive operational content.
We process such materials in order to provide platform functionality, including structured extraction, summaries, reports, line items, tasks, reminders, audit trails, and related workflow outputs.
Users and customer organizations are responsible for ensuring that they are authorized to upload and process such materials and that there is a valid legal basis for doing so.
7. Use of OpenAI
Certain TenderDesk features use the OpenAI API to process content and generate analysis results. For these features, relevant portions of uploaded content, extracted text, prompts, instructions, and processing metadata may be transmitted to OpenAI for the sole purpose of providing the requested TenderDesk functionality.
We use such third-party services only as required to provide the service. According to OpenAI’s published business and API documentation, business and API data is not used for model training by default unless the customer or organization explicitly opts in.
Where required, processing by service providers is governed by appropriate contractual safeguards, including data processing terms where applicable.
8. Hosting, Infrastructure, Security, and Log Files
We process technically necessary data in order to deliver and secure the website and platform, detect misuse, monitor system integrity, investigate incidents, and defend against malicious or unauthorized access attempts.
This may include server logs, IP addresses, request metadata, authentication logs, audit events, and other security-relevant system information.
9. Cookies and Similar Technologies
TenderDesk does not use Google Analytics, Google Tag Manager, Meta Pixel, or comparable marketing or profiling technologies for behavioral advertising.
Where cookies or similar storage technologies are used, they are limited to what is technically necessary for the operation, authentication, security, and core functionality of the website or platform, unless otherwise stated.
10. Recipients and Categories of Recipients
Personal data may be disclosed to or processed by the following categories of recipients where necessary:
- hosting and infrastructure providers;
- authentication, email delivery, and communications providers;
- payment, billing, and accounting service providers;
- OpenAI and other technical processors used to provide TenderDesk functionality;
- legal, tax, compliance, or professional advisers where necessary;
- courts, authorities, regulators, or other third parties where disclosure is required by law or necessary to establish, exercise, or defend legal claims.
11. International Data Transfers
Where personal data is transferred to recipients outside the European Union or the European Economic Area, such transfers will be carried out only where there is an appropriate legal basis and suitable safeguards under applicable data protection law, such as adequacy decisions, standard contractual clauses, or other recognized transfer mechanisms.
12. Retention
We retain personal data only for as long as necessary for the purposes described in this Privacy Policy, for the duration of the contractual relationship, and for any additional period required for legal, regulatory, tax, accounting, security, backup, dispute-resolution, or evidentiary purposes.
Retention periods may vary depending on the nature of the data, the account status, applicable statutory obligations, and operational necessity.
13. Provision of Data
Where personal data is required to create an account, provide platform access, perform contractual services, process billing, or ensure secure operation, failure to provide such data may mean that we are unable to provide all or part of the TenderDesk services.
14. Data Subject Rights
Subject to the applicable legal requirements, you may have the right to:
- request access to your personal data;
- request rectification of inaccurate or incomplete data;
- request erasure of personal data;
- request restriction of processing;
- object to processing based on legitimate interests;
- receive personal data in a portable format, where applicable;
- withdraw consent at any time where processing is based on consent;
- lodge a complaint with a competent supervisory authority.
15. No Solely Automated Legal Decision-Making
TenderDesk provides operational support, analysis assistance, and workflow outputs. Users remain responsible for reviewing and validating outputs before relying on them. Platform outputs are not intended to replace human review or professional judgment.
16. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect legal, technical, operational, or organizational changes. The version published on this page is the currently applicable version.
17. Contact
For privacy-related questions or requests regarding this Privacy Policy or the processing of personal data in connection with TenderDesk, please contact:
Avagliano Unternehmergesellschaft (haftungsbeschränkt)
Email: connect@avagliano.com
Phone: +49 (0)30 223 995 0815
Address: Otto-Heilmann-Str. 18 A, 82031 Grünwald, Germany