Privacy Notice
Version 1.0 · Effective 2026-09-25
This notice explains how ACCER INFORMATION TECHNOLOGY LIMITED, trading as Tender Preflight ("we", "us"), uses personal data about the people who register for and use the Tender Preflight service, and about people who contact us. For this processing we are the controller.
Documents you upload are covered separately. Tender documents and submissions uploaded to the Service (for example CVs, references and signed forms) are processed by us on behalf of your organisation, as its processor or sub-processor, under the Data Processing Agreement. Your organisation decides how that data is used. If your personal data appears in such documents, contact the organisation that uploaded them.
1. Contact
- Controller: ACCER INFORMATION TECHNOLOGY LIMITED, trading as Tender Preflight, a private company limited by shares incorporated in Ireland, registered number 804260.
- Registered office and postal address: 6 Fern Road, Sandyford, Dublin, D18 FP98, Ireland
- Privacy questions and requests: [email protected]
We are not required to appoint a Data Protection Officer (Article 37 GDPR). The contact above handles all data protection matters.
2. What we collect and why
| Data | Why we use it | Lawful basis (GDPR) |
|---|---|---|
| Account details: name, work e-mail, job title (optional), organisation name, type and country; password (stored only as a salted Argon2 hash) | To create and run your account and provide the Service to your organisation | Performance of our contract with your organisation (Art. 6(1)(b)). Where you act for your employer, our legitimate interest in administering the business relationship (Art. 6(1)(f)) |
| E-mail confirmation and password-reset links: a random token (not your password), when it was requested, its expiry, and the requesting IP address | To confirm you control your e-mail address before the account can be used, and to let you regain access if you forget your password | Performance of our contract (Art. 6(1)(b)) and security of the account (Art. 6(1)(f)) |
| Acceptance records: who accepted which version of the Terms and DPA, on behalf of which organisation, when, the document fingerprint (SHA-256), IP address and browser | To prove that the contract was concluded and on which terms, and to defend legal claims | Legitimate interests (Art. 6(1)(f)) and compliance with legal obligations (Art. 6(1)(c)) |
| Activity records within your organisation's tenders: which account uploaded, deleted, accepted or dismissed something, and when | To show your organisation an audit trail of decisions in its preflight reports | Performance of contract (Art. 6(1)(b)) |
| Security and server logs: IP address, time, requested page, status code, sign-in events | To keep the Service secure, detect abuse and fix faults | Legitimate interests (Art. 6(1)(f)) |
| Marketing preference: whether you opted in to product e-mails, with the wording and time of your choice | To send occasional product news, only if you asked for it | Consent (Art. 6(1)(a)), which you can withdraw at any time |
| Correspondence with us | To answer your questions and requests | Legitimate interests (Art. 6(1)(f)) or, for data-protection requests, legal obligation (Art. 6(1)(c)) |
We do not use your personal data for profiling or for automated decisions that have legal or similarly significant effects. We do not sell it, and we do not use it to train AI models.
Providing account details is necessary to open an account. Everything marked optional can be left blank.
3. How long we keep it
| Data | Retention |
|---|---|
| Account details | While the account exists. Deleting your account removes them immediately from active systems. |
| Confirmation / reset links | Each link works once. Unused links expire after a few hours to two days depending on their purpose, and are deleted automatically within a week either way. |
| Acceptance records | 6 years after the account is closed, the period in which contract claims can be brought under the Statute of Limitations Act 1957. They are then deleted automatically. |
| Activity records within tenders | Deleted together with the tender: by you, or automatically when the tender has not been checked for 90 days. Only an entry without content remains, recording that a deletion took place. |
| Security and server logs | 30 days, unless they are needed to investigate a specific incident. |
| Marketing preference | Until you withdraw consent or close your account. |
| Backups | Deleted data can remain in encrypted backups for up to 35 days before the backups expire. |
4. Who receives it
- Service providers acting for us, bound by data processing contracts. They are listed in the Sub-processor List, together with where they process data.
- Professional advisers (lawyers, accountants, auditors), under a duty of confidentiality, where needed.
- Authorities, courts or regulators, where we are legally required to disclose data, or where disclosure is needed to establish, exercise or defend legal claims.
- A purchaser or successor of our business, subject to this notice.
5. Where it is processed
Your data is stored on our own servers in Ireland (European Union).
The Service is reached through Cloudflare, a content delivery network that sits in front of our server (see the Sub-processor List) to hide it from the open internet and absorb attacks. This means traffic to the Service — including the data you submit — passes through Cloudflare's global network before it reaches us, and Cloudflare, Inc. is a United States company. This is a transfer of personal data outside the European Economic Area for the purposes of Chapter V GDPR. It is covered by Cloudflare's Data Processing Addendum, which applies the European Commission's Standard Contractual Clauses. Cloudflare does not receive a separate copy of the files or database records stored in the Service; it processes traffic in transit and, like any content delivery network, keeps its own standard connection and security logs.
We do not use any other service that would move your data outside the EEA. If that changes, we will update this notice first.
6. Cookies and similar technologies
We use a single cookie, tp_session. It keeps you signed in and protects forms against cross-site request
forgery. It is strictly necessary for the Service, so it does not require consent (Regulation 5(5) of the ePrivacy
Regulations, S.I. No. 336 of 2011). It expires after 14 days, or when you sign out.
We use no analytics, advertising or tracking cookies. The Service loads no scripts, fonts or images from third-party servers.
7. Your rights
Under the GDPR you have the right to:
- access your personal data and receive a copy;
- rectify inaccurate data (you can edit your profile in Account & data);
- erase your data (you can delete your account in Account & data); acceptance records are kept as described in section 3, because they are needed to establish and defend legal claims;
- restrict processing, or object to processing based on legitimate interests;
- data portability, for data you provided under contract or consent; and
- withdraw consent to marketing at any time, in Account & data or through the link in any marketing e-mail. Withdrawal does not affect processing that took place before it.
To exercise a right, e-mail [email protected]. We will reply within one month. We may need to confirm your identity first.
You also have the right to lodge a complaint with the Data Protection Commission, 21 Fitzwilliam Square South, Dublin 2, D02 RD28, Ireland (www.dataprotection.ie), or with the supervisory authority where you live or work. We would appreciate the chance to address your concern first.
8. Security
How we protect data is described in our Security Measures.
9. Changes
When we change this notice, we publish the new version at Legal, keep the previous versions, and inform signed-in users in the Service.