Privacy policy
Introduction
Bidbot is committed to protecting your privacy and ensuring transparency in how we handle your personal data. This Privacy Policy explains how we collect, use, and safeguard your information when you use our services.
Bidbot is an AI-powered platform that scans thousands of EU tenders and delivers only the most relevant opportunities to our customers. Our service is designed to help businesses identify and respond to procurement opportunities efficiently.
We comply with the General Data Protection Regulation (EU) 2016/679 (GDPR), the United Kingdom General Data Protection Regulation (UK GDPR), and other applicable data protection laws.
1. Data Controller
The data controller responsible for your personal data is:
Intelligent Response Limited
The Black Church, St. Mary’s Place, Dublin 7, D07 P4ax, Ireland
For any privacy-related inquiries, you can contact our Data Protection Officer (DPO) at privacy@bidbot.eu.
2. What Personal Data We Collect
When you use Bidbot, we may collect the following types of data:
2.1 Data Provided by Users
Account Information: Name, email address, company name, phone number, and billing details.
Subscription & Payment Details: Transaction records for premium services.
Preferences & Settings: User-defined filters for tender searches.
2.2 Automatically Collected Data
Usage Data: Log files, IP addresses, browser type, and interaction logs.
Device & Technical Information: Operating system, referral URLs, and session times.
Analytics Data: Behavioral tracking through cookies and analytics tools (e.g., Google Analytics).
2.3 Tender Data Processing
Publicly Available Tender Data: We scan and analyse publicly available procurement tenders across the EU and provide summaries to users.
User Uploaded Data: If users submit data for customized tender matching, we process it only for this purpose.
3. How We Use Your Data
We process your personal data for the following purposes:
| Purpose | Legal Basis |
| To provide access to Bidbot services | Performance of a contract (Art. 6(1)(b) GDPR) |
| To personalize and improve tender recommendations | Legitimate interest (Art. 6(1)(f) GDPR) |
| To process payments and invoices | Legal obligation & contract (Art. 6(1)(c) & (b) GDPR) |
| To send important service updates | Legitimate interest (Art. 6(1)(f) GDPR) |
| To send marketing communications (if opted-in) | Consent (Art. 6(1)(a) GDPR) |
| To prevent fraud and enhance security | Legitimate interest (Art. 6(1)(f) GDPR) |
4. Data Sharing & Transfers
We do not sell your personal data. However, we may share data in the following cases:
4.1 Third-Party Service Providers
We work with trusted data processors to enhance our services. These include:
Hosting & Infrastructure: Cloud service providers.
Analytics & Performance: Google Analytics, Hotjar.
Payment Processors: Stripe, PayPal.
All third parties are contractually obligated to handle your data in compliance with GDPR.
4.2 Legal Compliance & Law Enforcement
We may disclose your data if required to comply with legal obligations or law enforcement requests.
4.3 International Transfers
Some of our service providers may be located outside the EU/EEA. When transferring data internationally, we ensure:
EU Standard Contractual Clauses (SCCs) are in place.
The recipient country has an adequate level of protection per GDPR.
Additional security measures such as encryption and pseudonymization are applied.
5. Data Retention
We retain personal data only for as long as necessary:
| Data Type | Retention Period |
| Account data | Until account deletion |
| Payment records | 5 years (legal requirement) |
| Tender interaction logs | 12 months |
| Marketing preferences | Until consent is withdrawn |
After these periods, data is securely deleted or anonymized.
6. Your GDPR Rights
Under GDPR, you have the following rights:
Right to Access – Request a copy of your personal data.
Right to Rectification – Request corrections to inaccurate data.
Right to Erasure – Request deletion of your data (“right to be forgotten”).
Right to Restrict Processing – Limit how we process your data.
Right to Data Portability – Receive your data in a machine-readable format.
Right to Object – Opt out of processing for marketing or legitimate interest.
Right to Withdraw Consent – Withdraw consent at any time for optional data processing.
To exercise your rights, contact privacy@bidbot.eu.
If you believe your rights have been violated, you can lodge a complaint with the relevant Data Protection Authority in your country.
7. Cookies & Tracking
We use cookies and tracking technologies to improve user experience. For our cookie policy, please visit our separate Cookie policy page.
8. Automated Decision-Making & AI
Bidbot uses AI algorithms to analyse and recommend relevant tenders. These AI-driven processes do not involve fully automated decision-making that significantly affects users.
If AI-based tender recommendations impact your business decisions, you can request manual review by contacting privacy@bidbot.eu.
9. Security Measures
We implement strict security controls to protect your data:
Encryption: All data is encrypted in transit and at rest.
Access Controls: Role-based access to sensitive data.
Regular Audits: Internal security reviews and penetration testing.
Incident Response Plan: In case of a data breach, we will notify affected users within 72 hours.
10. Changes to this Privacy Policy
We may update this policy from time to time. Users will be notified of significant changes via email or in-app notifications.
11. Contact Us
For any privacy-related concerns, you can reach us at:
Email: privacy@bidbot.eu
Address: The Black Church, St. Mary’s Place, Dublin 7, D07 P4ax, Ireland