Privacy Policy
Last updated 21 August 2026
This is our standard template and has not yet been reviewed by external counsel. We would rather tell you that than imply a legal review that has not happened. It is an accurate description of what the system does today, written by the people who built it. If you need reviewed wording before signing, say so and we will get it reviewed first.
GovAlert AI monitors publicly available Cyprus government publications and tells you when one of them concerns a company on your register. This page explains exactly what we hold to do that, where it sits, and who else touches it.
Who we are
GovAlert AI is operated from Nicosia, Cyprus. For anything in this policy — access, correction, deletion, or a question you would rather ask a person — write to dropshipingonline81@gmail.com.
What we collect
Your account
- Email address — how you sign in and where alerts are sent.
- Firm name and industry — the industry choice tailors which sources are highlighted and the vocabulary the interface uses.
- Content language — English, Greek or Russian.
- A WhatsApp number, only if you enter one. This field exists but the delivery channel behind it is not currently operational, so a number entered today is stored and not used.
Your client register
This is the substantive data you give us, and the reason the product works. For each company you add we store:
- the company name, as you type it;
- a registration number, if you provide one;
- a sector label, if you provide one;
- free-text notes, if you write any;
- a normalised form of the name, derived automatically so that spelling variants (Ltd, Limited, ΛΤΔ, Λίμιτεδ) resolve to the same company when we compare it against a published notice.
The notes field is free text and we do not inspect it. Whatever you type there is what we hold. If you would rather not place personal or confidential information in our system, do not put it in that field.
Usage
- which alerts you have opened, so unread ones can be marked;
- a count of assistant messages per hour, used solely to enforce a rate limit;
- a Stripe customer identifier and your subscription status. We do not receive or store card details.
What we do not collect
- Nothing confidential from your files. We do not read your documents, your accounting system, or your correspondence. Inbox monitoring is not part of the product you can buy today.
- Nothing from non-public sources. Everything we monitor — the Official Gazette, the government eProcurement board, CySEC and the Cyprus Bar Association — is published by a public body for anyone to read.
- Nothing about your clients is disclosed in order to monitor them. We do not query any registry, government body or third party using your client names. Matching happens inside our own database, by comparing the names you gave us against the text of publications we have already downloaded.
Where it is held
All customer data is stored in a PostgreSQL database operated by Supabase and hosted on AWS in eu-west-1 (Ireland), inside the EU. Every table in that database has row-level security enabled — 22 of 22 at the time of writing — so a query can only return rows belonging to the account that issued it. That is enforced by the database, not by application code that could be bypassed.
Sub-processors
These are the only third parties that process customer data on our behalf. If we add one, we will update this list.
| Provider | What it does | What it sees |
|---|---|---|
| Supabase (AWS eu-west-1, Ireland) | Database and authentication | All stored account and client-register data |
| Vercel | Hosting and delivery of the web application | Data in transit while you use the site, plus standard request logs |
| Anthropic | Summarising publications; the optional assistant | Public publication text always. Your own alerts, deadlines, firm name and client names only when you use the assistant — see below |
| Google (Gmail SMTP) | Sending alert emails | Your email address and the alert content sent to you |
| Stripe | Payments and subscription billing | Your email and billing details. Card data goes to Stripe directly and never reaches us |
We do not use Twilio, and no WhatsApp messages are sent, despite the settings field mentioned above.
When your client names leave our database
This deserves stating plainly rather than burying, because it is the one case where data you gave us is sent to a third party.
- Monitoring and matching: never. We download public publications, then compare them against your register inside our own database. No client name is transmitted anywhere.
- Summarising publications: no customer data. The text we send to Anthropic to be summarised is the government publication itself, which is already public. Your register is not part of that request.
- The assistant: yes, while you use it. If you ask the in-product assistant a question, we send Anthropic the context needed to answer it — your firm name, your alerts and deadlines, and up to 30 of your client names. That happens only on a message you send, and only for your own data. If you would prefer that never to happen, do not use the assistant; every other part of the product works without it.
We do not train any model on your data, and we do not sell, rent or share it with anyone for their own purposes.
How long we keep it, and how to have it deleted
We keep your account and register for as long as your account is open, because the product cannot work without them.
- You can delete any client from your register yourself, at any time, from the client's page. That removes the record and the matches derived from it.
- To delete your whole account and everything in it, email dropshipingonline81@gmail.com.We will do it and confirm when it is done. We are being straight with you: there is not yet a self-serve “delete my account” button, and there is not yet a self-serve export. Both are on the list. Until they exist, ask us and a person will do it.
- Publications themselves — Gazette issues and the notices in them — are public records and are not deleted, because they are not your personal data. What is removed is your register, your account, and the links between them.
Your rights
Under the GDPR you can ask us for a copy of your data, ask us to correct it, ask us to delete it, ask us to restrict how we use it, or object to our using it. Write to dropshipingonline81@gmail.com and we will respond within 30 days. If you are not satisfied, you can complain to the Office of the Commissioner for Personal Data Protection in Cyprus.
If you are a firm using this for clients
Where you upload a register of companies you act for, you are the controller of that data and we are your processor. Our data processing agreement sets out that relationship, including the Article 28 terms and the same sub-processor list as above.
Changes
If we change what we collect, where it is held, or who processes it, we will update this page and change the date at the top.