Privacy Policy - przetarg.eu
1. Data controller
Marcin Kisieliński, MADD Marcin Kisieliński, ul. Kajki 10-12, 10-547 Olsztyn, Poland, VAT ID (NIP) 7422297084. Data matters: kontakt@przetarg.eu.
2. What data we process in przetarg.eu
- Account data - e-mail, password (hash) - stored in a separate przetarg.eu account database; the account is independent of a DomaAI account, even with the same e-mail address.
- Monitor configuration - CPV codes, keywords, locations.
- Company profile - the business description and references you provide (used to compute the fit-score).
- Working content - AI analyses, document drafts, pipeline notes, AI Assistant conversations.
- Billing data - handled by Stripe (we do not store card numbers); invoice data processed to issue invoices.
- Public market database - data on awarded public contracts from BZP (contractor and buyer names, tax ID/NIP, values) - see section 4c.
- Account security data - an account activity log (logins and logouts, monitor creation and deletion, analysis runs, account changes) together with the IP address and browser information; with two-factor authentication enabled, also the 2FA secret and the list of remembered devices (a hash of the device secret, the browser family, a shortened IP prefix). You can see the log in your account settings and you receive it in the data export.
- Team - if you use a team account: the e-mail address of the invited person, their role and the invitation status. A team member sees the account owner data within the granted role; we do not create a separate data set for them.
- Calendar subscription (ICS) - a random token in the calendar feed URL. The calendar returns only the proceeding title, the buyer, the deadline and a link - no analyses, notes or prices. You can rotate the token with one click, which invalidates earlier subscriptions. The feed URL works without logging in, so treat it like a password.
- Mobile App (iOS) - if you sign in with Apple: your Apple user identifier and the e-mail address passed on by Apple (including a relay address if you choose to hide yours). The App contains no ads, analytics or tracking; we collect no advertising identifiers and no location data in it.
- "Leave your number - we'll call back" form data - phone number and optionally name, company and call topic, provided voluntarily by people interested in the offer (also without an account). We process them solely to call you back at your request, based on consent (Art. 6(1)(a) GDPR). You may withdraw consent at any time by writing to kontakt@przetarg.eu.
3. Purposes and legal bases
- providing the service (Art. 6(1)(b) GDPR) - monitoring, analyses, documents, chat;
- billing and accounting (Art. 6(1)(c) GDPR);
- security and abuse prevention (Art. 6(1)(f) GDPR) - including the account activity log, request limits and detection of unusual logins;
- developing and maintaining service quality (Art. 6(1)(f) GDPR) - we count product events (for example "analysis started"), always without the content of documents or conversations; we build no marketing profiles and send these data to no external analytics tools;
- establishing, pursuing or defending claims and handling complaints (Art. 6(1)(f) and (b) GDPR).
4. AI and processors
Analyses, briefs, the document generator, file editing and the AI Assistant run on OpenAI models (the only model provider that receives data from przetarg.eu - verified in the code on 27 August 2026). The model receives the notice content, the company profile, the selected document and your question - only to the extent needed to generate the answer. Data sent through the API is not used to train models - OpenAI does not train on API data, as stated in its policy for API customers. Should another model provider be added, we will name it here and on the sub-processor list before it goes live.
Other sub-processors: payments - Stripe; VAT invoices - inFakt (Infakt sp. z o.o.); outgoing e-mail - OVH (servers in the EU); technical error collection - Sentry (technical event data: error type, stack trace, account identifier - without the content of documents or conversations). Hosting: OVH, infrastructure in the European Union. Full platform sub-processor list: madd.im/podprocesorzy.
4a. Transfers outside the EEA
The AI model providers and Stripe are established in the USA. Transfers are based on the European Commission's adequacy decision for entities certified under the EU-U.S. Data Privacy Framework (Art. 45 GDPR) and, supplementarily, on standard contractual clauses (Art. 46(2)(c) GDPR). We transfer only the data necessary for the given operation.
4b. Automated processing (fit-score)
Fit-scores and AI analyses are produced automatically from the notice content and the company profile. They are auxiliary - we do not take automated decisions producing legal effects concerning you within the meaning of Art. 22 GDPR; the decision to participate in a proceeding is always yours.
4c. Public market database and the "Check NIP" tool (Art. 14 GDPR notice)
The service presents - also without logging in (Contractor database, buyer pages, the "Check NIP" tool) - information on awarded public contracts from official public sources: the Public Procurement Bulletin (e-Zamówienia API) and public registers (the Ministry of Finance VAT white list, KRS).
- Data categories: business name of the contractor or contracting authority, tax ID (NIP), city, subject, value and date of the award, number of bids. For sole proprietorships the business name contains the owner's full name - to that extent it is personal data and we act as its controller.
- Source: public award notices published in BZP (openness of procurement proceedings - Art. 18 and 74 of the Polish Public Procurement Law) and public business registers.
- Purpose and legal basis: presenting public procurement market information in a searchable, analytical form - legitimate interest (Art. 6(1)(f) GDPR).
- Period: pages cover awards from up to the last 24 months and are refreshed weekly; older data is removed automatically.
- Your rights: you may object (Art. 21 GDPR), request rectification or restriction - write to kontakt@przetarg.eu with the NIP and the page address. We will correct or remove the page. We have no control over the source notices in BZP.
- "Check NIP": the number you enter is used solely for a one-off query of the registers and our database; queries are not stored (beyond standard, short-term server logs kept for security and rate limiting).
4d. Team accounts
In a team account we remain the data controller, but it is the account owner who decides whom to share their data with: when inviting someone to the team they grant the role of "viewer" or "bid handling" and may revoke access at any time. For an invited person we process the e-mail address, the role and the invitation status and - once the invitation is accepted - the log of their actions in the owner account. A team member receives no monitors or analyses of their own; they use the owner data within their role. If you invite an employee to your team, make sure they have a basis on your side to access those data.
4e. Calendar subscription (ICS)
The deadline calendar can be subscribed to in Outlook, Google Calendar or on iOS. A calendar client polls the address periodically and cannot log in, which is why the secret lives in the feed URL - anyone who knows that address will see the list of proceedings you track (title, buyer, deadline, link). The feed contains no analyses, notes or bid prices. Treat the address like a password; in the settings you can rotate it, which immediately invalidates all earlier subscriptions. Our server records standard access logs for these requests (the calendar client IP address).
5. Retention
We keep data for as long as you hold the account. You can delete the account and data yourself in the settings - deletion covers monitors, analyses, documents, the company profile, files and chat history. Billing data is kept for the period required by tax law. "Leave your number" form data is kept for a maximum of 12 months from submission or until consent is withdrawn - whichever comes first.
Backups: the database is archived once a day; backups are encrypted and kept for 14 days, after which they are deleted automatically. Data removed from an account may therefore persist in backups for up to 14 more days. Backups are never used for day-to-day operations or analytics - only to restore the service after a failure.
Specific periods: account activity log - 365 days from the event; technical server logs (including IP addresses) - up to 14 days, solely for security and diagnostics; AI model call metadata (model, latency, status - no content) - 30 days; award data in the public market database - up to 24 months from publication (section 4c); billing data and invoices - 5 years from the end of the tax year, as required by tax law.
6. Your rights
You have the right of access, rectification, erasure, restriction of processing, data portability and objection, as well as the right to lodge a complaint with the President of the Polish DPA (UODO). Data export is available in the account settings.
7. Cookies and localStorage
We use only essential cookies (login, security) and browser storage (localStorage) to remember preferences: the selected site language, theme and the state of the contact widget. We use no advertising or tracking cookies and no external analytics tools - the przetarg.eu site loads no resources from third-party servers, which is why there is no consent banner: there is nothing to consent to. In the Mobile App the equivalent is the system secure storage (Keychain), which holds the session token.
8. Mobile App
The przetarg.eu app for iOS uses the same account and the same data as the web panel; it collects nothing beyond what is described above. It contains no ads, no analytics and no cross-app tracking (we do not ask for App Tracking Transparency permission because we do not track), and collects no advertising identifiers or location data. Signing in with Apple gives us your Apple user identifier and an e-mail address (or a relay address if you hide yours). You can delete your account inside the app: Account → Privacy and AI → Delete account; deletion works exactly as in the web panel and covers all data described in section 5.
9. Contact, data protection officer and complaints
For data protection matters write to kontakt@przetarg.eu. We have not appointed a data protection officer - none of the conditions in Art. 37 GDPR applies (we are not a public authority, our core activity does not consist of large-scale monitoring of individuals or of processing special categories of data); we repeat this assessment whenever the scale of processing changes materially. If you believe we process your data unlawfully, you may lodge a complaint with the President of the Personal Data Protection Office in Poland (ul. Stawki 2, 00-193 Warsaw, uodo.gov.pl) or with the supervisory authority in your country of habitual residence.
Providing account data (e-mail address) is voluntary but necessary to conclude and perform the contract - without it you cannot create an account. Providing invoice data is a statutory requirement under tax law when purchasing a paid Plan. Other data (company profile, phone number in the contact form) are provided voluntarily.