Legal
Privacy
Short version: browsing this site is anonymous, and the only personal data we hold about you is an email address you chose to give us.
This is a draft.
The operating entity behind EuProcure has not been settled, so this page does not yet name a legal counterparty or a governing law. Everything else on it describes what the site actually does today. It is excluded from search results until it is complete.
Who is responsible
The operating entity has not been settled yet, so it is not named here. We would rather leave this blank than print something that is not true. It will be filled in before the site is promoted to real users. In the meantime every request reaches us at privacy@euprocure.com and is answered under the same 72-hour commitment.
Reading the site
No account, no analytics, no tracking. Loading a page on this site makes requests to this domain and to nothing else — no fonts from a CDN, no analytics script, no embedded widgets, no advertising network. Nobody else learns that you were here.
Two cookies are set, both strictly necessary:
-
euprocure-session— keeps a session so forms work across a page load. -
XSRF-TOKEN— protects the forms against cross-site request forgery.
Neither is used to profile you or to follow you anywhere, which is why this site has no cookie banner: consent under the ePrivacy Directive is required for storage that is not strictly necessary, and we do not use any.
What we store, and why
| What | Why | Kept |
|---|---|---|
| Beta account: your email, your password stored as a hash we cannot read, and the searches you save | Contract — to give you the account you asked for | Until you delete it on your account page, or ask us to |
| Beta usage: which features your account uses and when — full records opened, searches saved and reopened, exports, alert requests — and the site that sent you when you signed up | Legitimate interest — deciding what to build and what it should cost from what people actually use | Deleted together with your account |
| Early-access signup: your email, which page you signed up from, the site that sent you to us, whether you asked for alerts | Consent — to tell you when access opens | Until you ask us to delete it |
| Removal or correction request: your email, the category, an optional link, and what you wrote | Legal obligation — we have to be able to show a request was handled | Kept as a record of the request |
| Server access logs, which include your IP address | Legitimate interest — keeping the service up, defending it against abuse, and counting, without IP addresses, how search engines crawl the site and which sites send visitors | Rotated automatically and overwritten: at most 300 MB, about two weeks at current traffic. The counts keep no IP addresses; nothing is used for profiling |
| Error reports when something breaks | Legitimate interest — fixing faults | Sent to Sentry with personal data collection switched off |
We never sell or rent any of it, and we do not send marketing to addresses given to us for a removal request.
Data about people in the tender notices
This is the part most likely to concern you. We republish public procurement notices from the EU's TED portal, in the public interest and as permitted reuse of open data. Those notices are about organisations, but they can contain personal data — most often a named award winner who is a sole trader rather than a company.
Contact-person details are never extracted into our database. Names that look like an individual's are replaced automatically before publication. Both of those, the limits of the automatic check, and how to have something removed are set out on the data removal page.
Who else touches the data
- Hetzner (Germany) — hosts the server. Everything lives there.
- Cloudflare — runs the domain's DNS and forwards mail sent to our contact address.
- Sentry — receives error reports, with personal data collection disabled.
That is the complete list. No data is sold, shared for advertising, or used to train anything.
Your rights
Under the GDPR you can ask for a copy of the data we hold about you, have it corrected or erased, object to how we use it, or ask for it in a portable form. The fastest route for all of these is the removal and correction form, or email privacy@euprocure.com. We answer within 72 hours.
You can also complain to a data protection authority in the EU country where you live or work.