Legal
Privacy
Short version: browsing this site is anonymous, and the only personal data we hold about you is an email address you chose to give us.
This is a draft.
The operating entity behind EuProcure has not been settled, so this page does not yet name a legal counterparty or a governing law. Everything else on it describes what the site actually does today. It is excluded from search results until it is complete.
Who is responsible
The operating entity has not been settled yet, so it is not named here. We would rather leave this blank than print something that is not true. It will be filled in before the site is promoted to real users. In the meantime every request reaches us at privacy@euprocure.com and is answered under the same 72-hour commitment.
Reading the site
No account, no analytics, no tracking. Loading a page on this site makes requests to this domain and to nothing else — no fonts from a CDN, no analytics script, no embedded widgets, no advertising network. Nobody else learns that you were here.
Two cookies are set, both strictly necessary:
-
euprocure-session— keeps a session so forms work across a page load. -
XSRF-TOKEN— protects the forms against cross-site request forgery.
Neither is used to profile you or to follow you anywhere, which is why this site has no cookie banner: consent under the ePrivacy Directive is required for storage that is not strictly necessary, and we do not use any.
What we store, and why
| What | Why | Kept |
|---|---|---|
| Early-access signup: your email, which page you signed up from, whether you asked for alerts | Consent — to tell you when access opens | Until you ask us to delete it |
| Removal or correction request: your email, the category, an optional link, and what you wrote | Legal obligation — we have to be able to show a request was handled | Kept as a record of the request |
| Server access logs, which include your IP address | Legitimate interest — keeping the service up and defending it against abuse | Held by the hosting stack; not used for analytics or profiling |
| Error reports when something breaks | Legitimate interest — fixing faults | Sent to Sentry with personal data collection switched off |
We never sell or rent any of it, and we do not send marketing to addresses given to us for a removal request.
Data about people in the tender notices
This is the part most likely to concern you. We republish public procurement notices from the EU's TED portal, in the public interest and as permitted reuse of open data. Those notices are about organisations, but they can contain personal data — most often a named award winner who is a sole trader rather than a company.
Contact-person details are never extracted into our database. Names that look like an individual's are replaced automatically before publication. Both of those, the limits of the automatic check, and how to have something removed are set out on the data removal page.
Who else touches the data
- Hetzner (Germany) — hosts the server. Everything lives there.
- Cloudflare — runs the domain's DNS and forwards mail sent to our contact address.
- Sentry — receives error reports, with personal data collection disabled.
That is the complete list. No data is sold, shared for advertising, or used to train anything.
Your rights
Under the GDPR you can ask for a copy of the data we hold about you, have it corrected or erased, object to how we use it, or ask for it in a portable form. The fastest route for all of these is the removal and correction form, or email privacy@euprocure.com. We answer within 72 hours.
You can also complain to a data protection authority in the EU country where you live or work.