Bidsight

Privacy notice

What we collect, why, and what you can do about it. Written to be read, not to be survived.

Who is responsible

Bidsight is the controller of the data described here. For anything on this page, write to privacy@bidsight.be.

What we collect

We do not use analytics or advertising trackers, we do not profile you, and we do not sell or share data for anyone else's marketing.

Why we are allowed to

How the matching works

Tender notices are read and scored by a language model running on our own hardware in Belgium. Nothing about you or your business is sent to a third-party AI provider, and the model is not trained or fine-tuned on your data — it is given your description at the moment a notice is screened, and nothing is retained by it afterwards. The scoring decides which public tenders you are shown; it produces no legal effect concerning any individual, and every result carries the reason it matched and a link to the official notice so you can check it.

Who else sees it

RecipientWhat they doWhere
Hosting (self-managed server)Runs the application and the database.
All of it.
Belgium
SMTP providerDelivers result emails, invitations and password resets.
Email address, name, the contents of the message.
EU
StripeTakes payment.
Billing name, email, VAT number, payment details. Card numbers never reach us.
EU/US - Data Privacy Framework
VIES (European Commission)Confirms a VAT number is real.
The VAT number only. Sent at signup, not stored by us in readable form afterwards.
EU
TED (EU Publications Office)Source of tender notices.
None. We read from it; we send it nothing about our customers.
EU

How long we keep it

Account data for as long as you have an account. Search results for the history window on your plan. Sessions, invitations and reset links expire in hours or days. An account with no sign-in for two years is warned and then deleted. Invoices are kept for seven years because the law requires it.

Your rights

You can get a copy of your data, correct it, delete it, pause our processing of it, object to it, and take it elsewhere. All of these work from your account page without asking us, and take effect immediately. Where a request does need us, we answer within one month.

Your data

How it is protected

Passwords are stored as scrypt hashes and can never be recovered, only replaced. Invitation and reset links are stored hashed, so a stolen backup contains no working links. Changing your password signs out every other session. Data is separated by account at every point where it is read.

If you are not happy

You can complain to the Belgian Data Protection Authority (Autorité de protection des données / Gegevensbeschermingsautoriteit), Rue de la Presse 35, 1000 Brussels.

This notice describes what the software actually does. Have it reviewed by a lawyer before launch and complete the company details.