Privacy notice
What we collect, why, and what you can do about it. Written to be read, not to be survived.
Who is responsible
Bidsight is the controller of the data described here. For anything on this page, write to privacy@bidsight.be.
What we collect
- Account details you give us: username, email address, company name and VAT number.
- A description of what your business does, which you write or we read from your website. This is what tenders are matched against.
- How you use the service: which searches ran, which tenders were shown, and the decisions your team recorded.
We do not use analytics or advertising trackers, we do not profile you, and we do not sell or share data for anyone else's marketing.
Why we are allowed to
- To provide the service you signed up for — running your searches and sending you results (contract).
- To keep the service secure and stop the free trial being taken repeatedly by the same company (legitimate interest).
- To send occasional product news, only if you switch it on (consent, withdrawable at any time).
- To keep invoices for seven years (legal obligation under Belgian bookkeeping law).
How the matching works
Tender notices are read and scored by a language model running on our own hardware in Belgium. Nothing about you or your business is sent to a third-party AI provider, and the model is not trained or fine-tuned on your data — it is given your description at the moment a notice is screened, and nothing is retained by it afterwards. The scoring decides which public tenders you are shown; it produces no legal effect concerning any individual, and every result carries the reason it matched and a link to the official notice so you can check it.
Who else sees it
| Recipient | What they do | Where |
|---|---|---|
| Hosting (self-managed server) | Runs the application and the database. All of it. | Belgium |
| SMTP provider | Delivers result emails, invitations and password resets. Email address, name, the contents of the message. | EU |
| Stripe | Takes payment. Billing name, email, VAT number, payment details. Card numbers never reach us. | EU/US - Data Privacy Framework |
| VIES (European Commission) | Confirms a VAT number is real. The VAT number only. Sent at signup, not stored by us in readable form afterwards. | EU |
| TED (EU Publications Office) | Source of tender notices. None. We read from it; we send it nothing about our customers. | EU |
How long we keep it
Account data for as long as you have an account. Search results for the history window on your plan. Sessions, invitations and reset links expire in hours or days. An account with no sign-in for two years is warned and then deleted. Invoices are kept for seven years because the law requires it.
Your rights
You can get a copy of your data, correct it, delete it, pause our processing of it, object to it, and take it elsewhere. All of these work from your account page without asking us, and take effect immediately. Where a request does need us, we answer within one month.
How it is protected
Passwords are stored as scrypt hashes and can never be recovered, only replaced. Invitation and reset links are stored hashed, so a stolen backup contains no working links. Changing your password signs out every other session. Data is separated by account at every point where it is read.
If you are not happy
You can complain to the Belgian Data Protection Authority (Autorité de protection des données / Gegevensbeschermingsautoriteit), Rue de la Presse 35, 1000 Brussels.
This notice describes what the software actually does. Have it reviewed by a lawyer before launch and complete the company details.