Tenderax

Privacy Policy

Last updated 16 July 2026  ·  Operated by Klokk Nettablering
policy_version: 2026-07-16.1

This Privacy Policy explains how Klokk Nettablering ("Tenderax", "we", "us") collects, uses, and protects personal data when you use tenderax.com and the Tenderax application. It is written to comply with the EU General Data Protection Regulation (GDPR).

1. Data controller

Klokk Nettablering, a Norwegian enkeltpersonforetak, is the data controller for personal data processed through the Tenderax website and account system. For data you upload about your own customers or business contacts as part of using the service, you are the controller and Klokk Nettablering acts as processor — see our Data Processing Agreement.

2. What we collect

3. Legal basis for processing

4. Sub-processors

We use the following sub-processors to deliver the service. Each is bound by a data processing agreement consistent with GDPR Article 28.

Sub-processorPurposeLocation
Amazon Web Services (AWS SES)Transactional email deliveryEU (eu-north-1, Stockholm)
StripePayment processing and billingUnited States
Anthropic (Claude API)AI relevance scoring and document analysisUnited States
ip-api.comIP-based country detection for currency display (Redis-cached, 1 hour)United States
Hetzner Online GmbHApplication hostingGermany (EU)

5. International transfers

Where personal data is transferred to sub-processors located outside the EU/EEA (Stripe, Anthropic, ip-api.com — all United States), the transfer is safeguarded by the European Commission's Standard Contractual Clauses (SCCs), supplemented by additional technical and organisational measures as required. A copy of the applicable transfer safeguards is available on request to [email protected].

6. Retention

Account and billing data is retained for the duration of your subscription plus the period required by Norwegian bookkeeping law (generally 5 years for accounting records). Uploaded documents and AI analysis results are retained until you delete them or close your account, after which they are permanently deleted within 30 days. Usage logs are retained for up to 12 months for security and product-improvement purposes.

7. Your rights

Under GDPR you have the right to:

You can submit a Data Subject Access Request (DSAR) directly from your account settings in the app, or by emailing [email protected]. We respond within 30 days.

8. Cookies

Tenderax uses only essential cookies required for authentication and session management — no advertising or tracking cookies. The application interface loads Google Fonts, which may result in your browser making a request to Google's servers when the page loads; no Tenderax account data is shared with Google as part of this.

9. AI processing transparency

Tender scoring and document analysis are performed by the Anthropic Claude API. Public tender notice data and your company profile are sent to Anthropic solely to generate your results; this data is not used by Anthropic to train its models under our commercial API terms. Full methodology and disclosure under the EU AI Act is published at /legal/ai-transparency.

10. Security

We apply encryption in transit (TLS) and at rest, access controls limiting data access to authorised personnel, and regular review of our infrastructure and sub-processor agreements. No system is completely secure, and we encourage you to use a strong, unique password for your account.

11. Children

Tenderax is a B2B service not directed at or intended for use by individuals under 16. We do not knowingly collect data from children.

12. Changes to this policy

We may update this Privacy Policy to reflect changes in our processing activities or legal requirements. Material changes will be notified by email or in-app notice at least 14 days before taking effect.

13. Contact

Data protection queries can be sent to [email protected].

← Back to Tenderax