1. Who we are
TenderLock is provided and operated by Leonova Technologies Ltd, registered in England and Wales (company number 17038635), One Kingdom Street, Paddington Central, London W2 6BD, United Kingdom (TenderLock, we, us). The platform is built and owned by COGNIVO FZ-LLC (Dubai, United Arab Emirates), which licenses it to us and supports it as our sub-processor.
- Controller: we are the controller for personal data used to run our website, user accounts, security, support and billing.
- Processor: for personal data contained in tenders, bids, contacts, emails and evaluation records, we act as a processor for the customer organisation that uses TenderLock. See our Data processing terms.
- Contact: [email protected]
2. What we collect
- Account data: name, email address, job title, phone number, address, organisation and role.
- Sign-in data: if you sign in with Microsoft, Google or your organisation's single sign-on, we receive your name and email address from that provider. We do not receive your password.
- Security and audit data: sign-in times, IP address, approximate location derived from the IP address, device and browser, two-factor settings, and a record of significant actions taken in your account.
- Customer content: tenders, documents, bids, clarifications, scores, notes, contacts, companies, call and message logs, and emails sent or received through TenderLock.
- Connected mailbox data: if you choose to connect your own Microsoft 365 or Google mailbox, see section 5.
- Email engagement data: for emails sent through TenderLock we record delivery, and may record when an email is opened or a link is clicked, using a small image or tracked link in the email.
- Company data: information about organisations from public registers (Companies House) and, where a customer orders a credit check, from our credit reference provider (Creditsafe). This may include the names of company officers.
- Billing data: plan, invoices, payment status and billing contact. Card details are collected and held by Stripe, not by us.
- Preferences: notification settings, sound, theme (light, dark or system) and the account you last used.
- Website data: strictly necessary cookies, described in our Cookie policy, and messages sent through our contact form.
3. How we use it and our lawful bases
- To provide the Service and your account: performance of our contract with you or your organisation.
- To secure accounts, prevent fraud and keep audit records: our legitimate interests in protecting the Service, and our customers' legal and procurement obligations.
- To send service and transactional emails (sign-in, invitations, notifications, billing): performance of contract.
- To bill, collect payment and keep financial records: performance of contract and legal obligation.
- To provide support, including temporary support access where a customer grants it: performance of contract and legitimate interests.
- To improve the Service: legitimate interests, using aggregated or de-identified information where possible.
We do not use personal data for advertising, and we do not sell personal data.
4. AI processing
AI features process tender, bid and related content only to carry out the action a user requested, such as drafting, reviewing or summarising. We do not use customer content to train AI models, and our AI provider is contractually prevented from using it for training. AI suggestions are reviewed and decided on by people. See our AI use policy.
5. Connected mailboxes (Microsoft 365 and Google)
Any user can choose to connect their own work mailbox from My profile. This is optional and can be disconnected at any time.
- What we access: permission to send email as you, and to read messages in your inbox so that replies to emails you sent from TenderLock can be shown in TenderLock.
- What we store: only emails you send from TenderLock and the replies to those emails. We check recent incoming messages to find those replies, and do not store any other message.
- Tokens: access tokens are stored encrypted and deleted when you disconnect.
- No other use: mailbox data is not used for advertising, is not sold, is not used to train AI models, and is not read by people except where you ask us for support, where needed for security, or where the law requires it.
Google user data: TenderLock's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
6. Who we share it with
We share personal data only with service providers that help us run TenderLock (listed in our Data processing terms), with the customer organisation that controls the relevant account or content, with our professional advisers, and where required by law. When you take part in a tender, the buyer running it will see the information you submit to it.
7. International transfers
Our main hosting is in London, United Kingdom. Some providers, and our own operations in the United Arab Emirates, process data in other countries. Where personal data is transferred outside the UK or EEA, we rely on adequacy decisions or appropriate safeguards such as the UK International Data Transfer Agreement or Addendum and the EU Standard Contractual Clauses.
8. Retention
- Account data: kept while the account is active, then deleted or anonymised within 12 months of closure unless we need it for a legal claim or obligation.
- Tender and audit records: kept for as long as the customer organisation needs them to evidence its procurement decisions. Audit records are append-only.
- Billing records: kept for as long as tax and accounting law requires, normally six years.
- Backups: backups are overwritten on a rolling basis.
9. Security
We use encryption in transit, encrypted storage of secrets and tokens, role-based access, two-factor authentication, logging of sensitive actions and regular backups. No system is perfectly secure, and we will notify affected customers and regulators of a personal data breach where the law requires it.
10. Your rights
Depending on where you are, you may have the right to access, correct or erase your personal data, restrict or object to its use, and receive it in a portable format. Email [email protected]. Where we act as a processor, we will pass your request to the relevant organisation. You can complain to the UK Information Commissioner's Office (ico.org.uk) or your local data protection authority.
11. Changes
We will update this policy as the Service changes, and will tell account owners about material changes by email or in the Service.
