TenderFlare.com
Search Buyers Resources Pricing
Login

Privacy Policy

Last updated: 21 July 2026

1. Who We Are

TenderFlare is a public procurement intelligence platform based in Ireland, operated by Blue Dot Consulting Limited t/a TenderFlare, an Irish company (CRO: 769206). Registered office: The Rubicon Centre, Bishopstown, Cork, Ireland, T12 Y275.

TenderFlare is a product of Blue Dot Consulting Limited. For personal data collected through our corporate website rather than the TenderFlare platform, see the Blue Dot Consulting privacy policy.

We aggregate publicly available tender data from Irish and EU sources. For details on how we protect your data, see our Security & Trust page.

For privacy-specific queries or data subject rights requests, email privacy@tenderflare.com, or contact us via our general form.

2. What Data We Collect

When you create an account, we collect:

  • Email address - used for account login and service communications
  • Full name - used for display within the platform
  • Company name (optional) - used for display within the platform
  • Password - stored as a secure hash; we never store your plain-text password

When you use the platform, we also store:

  • Saved search criteria
  • Pipeline entries (tenders you track)
  • Basic usage logs for service operation and security

When you subscribe to a paid plan, we also process:

  • Billing details - billing name and address, and a VAT registration number if you provide one
  • Subscription data - your plan, subscription status, and renewal date
  • Your payment card details, which are collected and stored directly by Stripe, our payment processor - these never reach or pass through our own servers

3. Why We Collect Your Data (Legal Basis)

We process your personal data on the following legal bases under GDPR:

  • Contract performance (Article 6(1)(b)) - to provide the TenderFlare service you signed up for, including account management, saved searches, pipeline tracking, and paid subscription billing.
  • Legitimate interests (Article 6(1)(f)) - for service security, fraud prevention, and improving the platform.
  • Legal obligation (Article 6(1)(c)) - to retain billing and invoice records for the period required under Irish tax law.
  • Consent (Article 6(1)(a)) - when you voluntarily submit our contact form. You may withdraw consent at any time by contacting us.

4. How We Use Your Data

  • To provide and maintain your account
  • To deliver the procurement search and tracking features
  • To send essential service communications (e.g. password resets)
  • To monitor and ensure security of the platform

We do not sell your personal data to third parties. We do not use your data for advertising.

5. Data Retention

We retain your account data for as long as your account is active. If you delete your account, we will remove your personal data within 30 days, except where retention is required by law.

Usage logs are retained for up to 12 months for security and operational purposes.

Billing and invoice records (billing name/address, VAT details, amounts and dates) are retained for as long as necessary to comply with our legal, tax and accounting obligations under Irish law, regardless of your account's status.

Contact-form submissions (name, email, message) are retained for up to 2 years, then deleted.

6. Data Sharing & Sub-Processors

We may share data with:

  • Amazon Web Services (AWS) - database hosting and compute infrastructure (EU-West-1, Ireland)
  • Cloudflare - frontend hosting and content delivery network
  • Resend - transactional email delivery (e.g. password resets)
  • Stripe - payment processing, subscription billing, and VAT calculation for paid plans
  • Sentry - error monitoring and crash reporting, to help us find and fix bugs
  • Web3Forms - relays messages submitted via our Contact page to us by email
  • Legal authorities - if required by law or valid legal process

Our processors are subject to contractual and/or statutory data protection obligations consistent with GDPR.

7. Your Rights Under GDPR

As a data subject, you have the right to:

  • Access - request a copy of the personal data we hold about you
  • Rectification - ask us to correct inaccurate data
  • Erasure - ask us to delete your data ("right to be forgotten")
  • Data portability - receive your data in a structured, machine-readable format; saved searches and pipeline entries can also be exported directly, at any time, from your account settings
  • Restriction - ask us to restrict processing of your data
  • Objection - object to processing based on legitimate interests

To exercise any of these rights, please email privacy@tenderflare.com or contact us. We will respond within 30 days.

You also have the right to lodge a complaint with the Irish Data Protection Commission.

8. Cookies

TenderFlare uses essential browser storage (localStorage) to maintain your login session. We do not use tracking cookies or third-party advertising cookies.

9. AI & Automated Processing

TenderFlare does not use artificial intelligence or machine learning to process your personal data. Your data is never used to train AI models. Search functionality is keyword-based and analytics are statistical.

No automated decisions are made about you based on your personal data (Article 22 GDPR does not apply).

Blue Dot Consulting Limited uses AI tools internally for business productivity (e.g., software development, research). These tools are governed by our internal PII & LLM Usage Policy, which prohibits sending third-party personal data to AI providers that lack a Data Processing Agreement.

10. International Data Transfers

TenderFlare's primary infrastructure is hosted in the EU (AWS EU-West-1, Ireland). However, some sub-processors may process data in the United States or other jurisdictions:

  • Cloudflare - content delivery may route through non-EU edge servers. Covered by EU-US Data Privacy Framework and SCCs.
  • Resend - email delivery infrastructure. Covered by SCCs.
  • Stripe - payment processing infrastructure. EEA merchants (including us) contract with Stripe Payments Europe Limited; billing and payment data may also be processed in the US, covered by Stripe's Standard Contractual Clauses.
  • Sentry - error-monitoring infrastructure, based in the US. Covered by SCCs.
  • Web3Forms - contact-form message relay; servers in the US, parent entity based in India.

Where data is transferred outside the EEA, appropriate safeguards are in place under Chapter V GDPR, including Standard Contractual Clauses (SCCs) approved by the European Commission.

11. Changes to This Policy

We may update this privacy policy from time to time. We will notify registered users of material changes via email. The "last updated" date at the top of this page indicates when the policy was last revised.

© 2026 TenderFlare. All rights reserved.

A product of Blue Dot Consulting (CRO: 769206) · Cork, Ireland

Privacy Policy · Terms of Service · About · Security · Contact ·

Contains Irish Public Sector Data licensed under CC BY 4.0. Sources: Office of Government Procurement (data.gov.ie), TED (EU Publications Office)

Session Expired

Your session has expired. Sign in again to continue.