The question you’d ask us.
A straight answer about where information goes, without the marketing.
What we monitor is public
The Gazette and tender portal are published by government. No client name of yours is sent anywhere to obtain it — matching happens inside our own database.
What you give us stays isolated
Held in an EU-hosted database, with row-level security scoping every query to the account that owns the row — enforced by the database, not application code.
We never contact your clients
There is no send path. You send it yourself, from your own address.
GDPR, and a DPA you can read now
Published, not sent on request. Both say plainly they are our own template and have not been through external counsel yet.
The fields, named
Not a category list. The actual columns.
About your firm
Firm name, the email addresses of your users, plan and seat count, and the industry you selected at onboarding.
About your clients
Company name, registration number, sector, and any note you typed. Nothing else — no financials, no documents, no correspondence.
What we generated
The summaries, the levels, the extracted dates, which alerts matched which client, and when each was delivered and read.
What we never hold
Your clients’ contact details. We have no reason for them, because we never contact your clients.
One EU database, isolated per firm
Row-level isolation
Every table carrying your data has a policy scoping each query to the account that owns the row — enforced by the database itself, not by application code. It was verified by observation: a second account calling the same function against another firm’s row writes nothing.
EU-hosted
The database sits inside the EU, under the same regulation you operate under.
The one exception
The optional assistant passes your own data to our AI provider when you use it. The privacy policy says exactly what and when. Don’t use it and nothing leaves.
Deletion
Remove any client yourself, instantly. For the whole account, or a copy of everything, email us and a person does it — we’ll be straight that a self-serve button for those two does not exist yet.
What we cannot claim
No external certification
No ISO, no SOC 2. We are not going to imply otherwise with a badge.
Templates, not counsel
The data processing agreement and privacy policy are published and readable now — and both say plainly they are our own template and have not been through external counsel.
Backups unproven
Everything lives in one database with one provider. Backups exist; independent verification of their coverage does not yet.