# Privacy Notice

**Version 1.0** · Effective 2026-09-25

This notice explains how **ACCER INFORMATION TECHNOLOGY LIMITED**, trading as **Tender Preflight** (**"we"**, **"us"**), uses
personal data about the people who register for and use the Tender Preflight service, and about people who contact us.
For this processing we are the **controller**.

**Documents you upload are covered separately.** Tender documents and submissions uploaded to the Service (for
example CVs, references and signed forms) are processed by us **on behalf of your organisation**, as its processor
or sub-processor, under the [Data Processing Agreement](/dpa). Your organisation decides how that data is used. If
your personal data appears in such documents, contact the organisation that uploaded them.

## 1. Contact

- Controller: ACCER INFORMATION TECHNOLOGY LIMITED, trading as Tender Preflight, a private company limited by shares incorporated in Ireland,
  registered number 804260.
- Registered office and postal address: 6 Fern Road, Sandyford, Dublin, D18 FP98, Ireland
- Privacy questions and requests: **contact@accer.top**

We are not required to appoint a Data Protection Officer (Article 37 GDPR). The contact above handles all data
protection matters.

## 2. What we collect and why

| Data | Why we use it | Lawful basis (GDPR) |
|---|---|---|
| **Account details**: name, work e-mail, job title (optional), organisation name, type and country; password (stored only as a salted Argon2 hash) | To create and run your account and provide the Service to your organisation | Performance of our contract with your organisation (Art. 6(1)(b)). Where you act for your employer, our legitimate interest in administering the business relationship (Art. 6(1)(f)) |
| **E-mail confirmation and password-reset links**: a random token (not your password), when it was requested, its expiry, and the requesting IP address | To confirm you control your e-mail address before the account can be used, and to let you regain access if you forget your password | Performance of our contract (Art. 6(1)(b)) and security of the account (Art. 6(1)(f)) |
| **Acceptance records**: who accepted which version of the Terms and DPA, on behalf of which organisation, when, the document fingerprint (SHA-256), IP address and browser | To prove that the contract was concluded and on which terms, and to defend legal claims | Legitimate interests (Art. 6(1)(f)) and compliance with legal obligations (Art. 6(1)(c)) |
| **Activity records within your organisation's tenders**: which account uploaded, deleted, accepted or dismissed something, and when | To show your organisation an audit trail of decisions in its preflight reports | Performance of contract (Art. 6(1)(b)) |
| **Security and server logs**: IP address, time, requested page, status code, sign-in events | To keep the Service secure, detect abuse and fix faults | Legitimate interests (Art. 6(1)(f)) |
| **Marketing preference**: whether you opted in to product e-mails, with the wording and time of your choice | To send occasional product news, only if you asked for it | Consent (Art. 6(1)(a)), which you can withdraw at any time |
| **Correspondence** with us | To answer your questions and requests | Legitimate interests (Art. 6(1)(f)) or, for data-protection requests, legal obligation (Art. 6(1)(c)) |

We do not use your personal data for profiling or for automated decisions that have legal or similarly significant
effects. We do not sell it, and we do not use it to train AI models.

Providing account details is necessary to open an account. Everything marked optional can be left blank.

## 3. How long we keep it

| Data | Retention |
|---|---|
| Account details | While the account exists. Deleting your account removes them immediately from active systems. |
| Confirmation / reset links | Each link works once. Unused links expire after a few hours to two days depending on their purpose, and are deleted automatically within a week either way. |
| Acceptance records | **6 years after the account is closed**, the period in which contract claims can be brought under the Statute of Limitations Act 1957. They are then deleted automatically. |
| Activity records within tenders | Deleted together with the tender: by you, or automatically when the tender has not been checked for 90 days. Only an entry without content remains, recording that a deletion took place. |
| Security and server logs | 30 days, unless they are needed to investigate a specific incident. |
| Marketing preference | Until you withdraw consent or close your account. |
| Backups | Deleted data can remain in encrypted backups for up to 35 days before the backups expire. |

## 4. Who receives it

- **Service providers acting for us**, bound by data processing contracts. They are listed in the
  [Sub-processor List](/subprocessors), together with where they process data.
- **Professional advisers** (lawyers, accountants, auditors), under a duty of confidentiality, where needed.
- **Authorities, courts or regulators**, where we are legally required to disclose data, or where disclosure is needed
  to establish, exercise or defend legal claims.
- A **purchaser or successor** of our business, subject to this notice.

## 5. Where it is processed

Your data is stored on our own servers in **Ireland (European Union)**.

The Service is reached through **Cloudflare**, a content delivery network that sits in front of our server (see the
[Sub-processor List](/subprocessors)) to hide it from the open internet and absorb attacks. This means traffic to
the Service — including the data you submit — passes through Cloudflare's global network before it reaches us, and
Cloudflare, Inc. is a United States company. This is a transfer of personal data outside the European Economic Area
for the purposes of Chapter V GDPR. It is covered by Cloudflare's Data Processing Addendum, which applies the
European Commission's Standard Contractual Clauses. Cloudflare does not receive a separate copy of the files or database records
stored in the Service; it processes traffic in transit and, like any content delivery network, keeps its own
standard connection and security logs.

We do not use any other service that would move your data outside the EEA. If that changes, we will update this
notice first.

## 6. Cookies and similar technologies

We use a single cookie, **`tp_session`**. It keeps you signed in and protects forms against cross-site request
forgery. It is **strictly necessary** for the Service, so it does not require consent (Regulation 5(5) of the ePrivacy
Regulations, S.I. No. 336 of 2011). It expires after 14 days, or when you sign out.

We use no analytics, advertising or tracking cookies. The Service loads no scripts, fonts or images from third-party
servers.

## 7. Your rights

Under the GDPR you have the right to:

- **access** your personal data and receive a copy;
- **rectify** inaccurate data (you can edit your profile in *Account & data*);
- **erase** your data (you can delete your account in *Account & data*); acceptance records are kept as described in
  section 3, because they are needed to establish and defend legal claims;
- **restrict** processing, or **object** to processing based on legitimate interests;
- **data portability**, for data you provided under contract or consent; and
- **withdraw consent** to marketing at any time, in *Account & data* or through the link in any marketing e-mail.
  Withdrawal does not affect processing that took place before it.

To exercise a right, e-mail **contact@accer.top**. We will reply within one month. We may need to confirm your
identity first.

You also have the right to lodge a complaint with the **Data Protection Commission**, 21 Fitzwilliam Square South,
Dublin 2, D02 RD28, Ireland ([www.dataprotection.ie](https://www.dataprotection.ie)), or with the supervisory
authority where you live or work. We would appreciate the chance to address your concern first.

## 8. Security

How we protect data is described in our [Security Measures](/security).

## 9. Changes

When we change this notice, we publish the new version at [Legal](/legal), keep the previous versions, and inform
signed-in users in the Service.
