Privacy Policy
Last updated: October 5, 2026
This policy explains how Licitora (licitora.eu) processes personal data under the EU General Data Protection Regulation (GDPR).
1. Who is responsible
The controller is Alina Kovtun, Gdansk 80-416, NIP 5842834961, REGON 525274099 ("we", "us"). For any privacy question or request, write to hello@licitora.eu. We have not appointed a data protection officer, as we are not required to.
For personal data that customers add to their workspace about their own team, we act as a processor on the customer's behalf under our Data Processing Agreement.
2. What we process and why
Visiting the website. Our hosting provider processes your IP address, browser details and the requested page to deliver the site and protect it from abuse (legitimate interest, Art. 6(1)(f) GDPR). We do not use advertising or tracking cookies and do not build visitor profiles.
Demo and CPV finder. When you enter a company website in the demo, we fetch the public pages of that website, extract the text and use AI to build a company profile and find matching tenders. We store the website address, the generated profile and results, and a one-way hash of your IP address (salted SHA-256, not your IP itself) to enforce usage limits. Cloudflare Turnstile checks that you are not a bot. Basis: legitimate interest in providing the demo and preventing abuse (Art. 6(1)(f)).
Your account. Email address, optional name, language, sign-in records (by Supabase Auth), workspace and team membership, and your plan. Basis: performance of the contract (Art. 6(1)(b)).
Using the Service. Company profiles (name, website, description, keywords, CPV categories, countries, value range), the website text used to build them, your saved tenders, statuses, feedback and settings such as digest time and time zone. To score and summarise tenders, we send the company profile and tender texts (never your email address) to our AI provider. Basis: contract (Art. 6(1)(b)).
Emails. We send sign-in links, the daily digest of matching tenders, deadline reminders, trial and account notices, team invitations and, where relevant, billing notices. We log which emails were sent to avoid duplicates. Each digest contains a one-click link to stop it. Basis: contract (Art. 6(1)(b)). We do not send marketing newsletters without your consent.
Payments. Paddle.com, our Merchant of Record, collects your payment and billing details and acts as an independent controller for them (see Paddle's privacy notice). We receive from Paddle your subscription status, plan, billing email and country, and invoice references. Basis: contract and legal obligations for accounting (Art. 6(1)(b) and (c)).
Product statistics and security. We record usage events (for example "tender opened" or "digest sent") linked to your workspace to understand how the Service is used and improve it, and technical logs and error reports to keep it secure and working. Error reports are configured not to include IP addresses, cookies or request bodies. Basis: legitimate interest (Art. 6(1)(f)).
Support. If you write to us, we process your message and contact details to answer it (Art. 6(1)(b) or (f)).
Business contacts from public award notices. To offer the Service to companies that take part in public tenders, we use company names and business contact details (company website, generic or business email address, country) published in contract award notices on TED. We may contact such companies about the Service where the law allows, and every message explains how to object. Basis: legitimate interest in B2B marketing (Art. 6(1)(f)). You can object at any time at hello@licitora.eu; we then mark the contact as "do not contact" and stop.
3. Where your data is processed
The main database runs in the EU (Frankfurt, Germany) and the application in Frankfurt. Some providers are based in, or may access data from, the United States or the United Kingdom. Transfers outside the EEA rely on an adequacy decision (including the EU–US Data Privacy Framework for certified providers, and the decision for the United Kingdom) or on the European Commission's Standard Contractual Clauses. The current list of providers, purposes and locations is on our Subprocessors page.
Our AI provider (Anthropic) does not use data sent through its API to train its models and keeps it only for a limited period under its commercial terms.
4. How long we keep data
- Account and workspace data: while your account exists. When you delete your workspace or account in Settings → Privacy, the data is deleted immediately from the live database and disappears from backups within 7 days. Usage statistics are kept afterwards only without a link to you.
- Demo runs (website, profile, results, hashed IP): 30 days.
- Rate-limit records: 1 day.
- Payment webhook records from Paddle: 90 days.
- Billing and accounting records: as long as tax law requires (in Poland, generally 5 years from the end of the year).
- Support emails: up to 3 years after the conversation ends.
- Business contacts from award notices: up to 24 months after our last contact, or until you object.
- Workspaces without a paid plan and without sign-in for 12 months may be deleted after an email notice at least 30 days in advance.
5. Cookies and local storage
We use only what is necessary for the Service to work, so no consent banner is needed:
| Name | Purpose | Duration |
|---|---|---|
sb-…-auth-token |
Keeps you signed in (Supabase Auth) | Session, refreshed while signed in |
demo_run_id |
Shows your demo result after you sign up | 7 days |
NEXT_LOCALE |
Remembers the site language | Session |
theme (local storage) |
Remembers light or dark mode | Until cleared |
| Cloudflare Turnstile | Bot check on the demo and tools | Session |
| Paddle checkout | Set by Paddle only when you open the checkout | See Paddle's notice |
6. Your rights
You have the right to access your data, to rectify it, to have it erased, to restrict processing, to data portability, and to object to processing based on legitimate interest, including direct marketing at any time. Many of these you can do yourself: Settings → Privacy offers a full data export and deletion of your workspace or account. For anything else, write to hello@licitora.eu; we answer within one month.
You may also lodge a complaint with a supervisory authority, in Poland the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warszawa, uodo.gov.pl), or with the authority in your EU country.
7. Security
Data is encrypted in transit (TLS) and at rest. Access to each workspace is enforced in the database (row-level security), administrative access is limited and protected with two-factor authentication, IP addresses are stored only as salted hashes, and websites are fetched through a filter that blocks internal network addresses.
8. Automated decisions
Relevance scores decide which tenders appear in your feed and digest. They only help you choose which public tenders to look at: they do not produce legal effects for you, and every tender remains available in full on TED. No decision with legal or similarly significant effect is made solely by automated means.
9. Changes
We update this policy when our processing changes and show the date at the top. For material changes we inform account owners by email.