Privacy Policy - przetarg.eu

version 2.0 · effective 27 August 2026 · wersja polska

Language note: this English translation is provided for convenience; the Polish version is binding. przetarg.eu runs on the DomaAI platform - the full DomaAI Privacy Policy applies to all account data. Below we describe what is specific to przetarg.eu.

1. Data controller

Marcin Kisieliński, MADD Marcin Kisieliński, ul. Kajki 10-12, 10-547 Olsztyn, Poland, VAT ID (NIP) 7422297084. Data matters: kontakt@przetarg.eu.

2. What data we process in przetarg.eu

3. Purposes and legal bases

4. AI and processors

Analyses, briefs, the document generator, file editing and the AI Assistant run on OpenAI models (the only model provider that receives data from przetarg.eu - verified in the code on 27 August 2026). The model receives the notice content, the company profile, the selected document and your question - only to the extent needed to generate the answer. Data sent through the API is not used to train models - OpenAI does not train on API data, as stated in its policy for API customers. Should another model provider be added, we will name it here and on the sub-processor list before it goes live.

Other sub-processors: payments - Stripe; VAT invoices - inFakt (Infakt sp. z o.o.); outgoing e-mail - OVH (servers in the EU); technical error collection - Sentry (technical event data: error type, stack trace, account identifier - without the content of documents or conversations). Hosting: OVH, infrastructure in the European Union. Full platform sub-processor list: madd.im/podprocesorzy.

4a. Transfers outside the EEA

The AI model providers and Stripe are established in the USA. Transfers are based on the European Commission's adequacy decision for entities certified under the EU-U.S. Data Privacy Framework (Art. 45 GDPR) and, supplementarily, on standard contractual clauses (Art. 46(2)(c) GDPR). We transfer only the data necessary for the given operation.

4b. Automated processing (fit-score)

Fit-scores and AI analyses are produced automatically from the notice content and the company profile. They are auxiliary - we do not take automated decisions producing legal effects concerning you within the meaning of Art. 22 GDPR; the decision to participate in a proceeding is always yours.

4c. Public market database and the "Check NIP" tool (Art. 14 GDPR notice)

The service presents - also without logging in (Contractor database, buyer pages, the "Check NIP" tool) - information on awarded public contracts from official public sources: the Public Procurement Bulletin (e-Zamówienia API) and public registers (the Ministry of Finance VAT white list, KRS).

4d. Team accounts

In a team account we remain the data controller, but it is the account owner who decides whom to share their data with: when inviting someone to the team they grant the role of "viewer" or "bid handling" and may revoke access at any time. For an invited person we process the e-mail address, the role and the invitation status and - once the invitation is accepted - the log of their actions in the owner account. A team member receives no monitors or analyses of their own; they use the owner data within their role. If you invite an employee to your team, make sure they have a basis on your side to access those data.

4e. Calendar subscription (ICS)

The deadline calendar can be subscribed to in Outlook, Google Calendar or on iOS. A calendar client polls the address periodically and cannot log in, which is why the secret lives in the feed URL - anyone who knows that address will see the list of proceedings you track (title, buyer, deadline, link). The feed contains no analyses, notes or bid prices. Treat the address like a password; in the settings you can rotate it, which immediately invalidates all earlier subscriptions. Our server records standard access logs for these requests (the calendar client IP address).

5. Retention

We keep data for as long as you hold the account. You can delete the account and data yourself in the settings - deletion covers monitors, analyses, documents, the company profile, files and chat history. Billing data is kept for the period required by tax law. "Leave your number" form data is kept for a maximum of 12 months from submission or until consent is withdrawn - whichever comes first.

Backups: the database is archived once a day; backups are encrypted and kept for 14 days, after which they are deleted automatically. Data removed from an account may therefore persist in backups for up to 14 more days. Backups are never used for day-to-day operations or analytics - only to restore the service after a failure.

Specific periods: account activity log - 365 days from the event; technical server logs (including IP addresses) - up to 14 days, solely for security and diagnostics; AI model call metadata (model, latency, status - no content) - 30 days; award data in the public market database - up to 24 months from publication (section 4c); billing data and invoices - 5 years from the end of the tax year, as required by tax law.

6. Your rights

You have the right of access, rectification, erasure, restriction of processing, data portability and objection, as well as the right to lodge a complaint with the President of the Polish DPA (UODO). Data export is available in the account settings.

7. Cookies and localStorage

We use only essential cookies (login, security) and browser storage (localStorage) to remember preferences: the selected site language, theme and the state of the contact widget. We use no advertising or tracking cookies and no external analytics tools - the przetarg.eu site loads no resources from third-party servers, which is why there is no consent banner: there is nothing to consent to. In the Mobile App the equivalent is the system secure storage (Keychain), which holds the session token.

8. Mobile App

The przetarg.eu app for iOS uses the same account and the same data as the web panel; it collects nothing beyond what is described above. It contains no ads, no analytics and no cross-app tracking (we do not ask for App Tracking Transparency permission because we do not track), and collects no advertising identifiers or location data. Signing in with Apple gives us your Apple user identifier and an e-mail address (or a relay address if you hide yours). You can delete your account inside the app: Account → Privacy and AI → Delete account; deletion works exactly as in the web panel and covers all data described in section 5.

9. Contact, data protection officer and complaints

For data protection matters write to kontakt@przetarg.eu. We have not appointed a data protection officer - none of the conditions in Art. 37 GDPR applies (we are not a public authority, our core activity does not consist of large-scale monitoring of individuals or of processing special categories of data); we repeat this assessment whenever the scale of processing changes materially. If you believe we process your data unlawfully, you may lodge a complaint with the President of the Personal Data Protection Office in Poland (ul. Stawki 2, 00-193 Warsaw, uodo.gov.pl) or with the supervisory authority in your country of habitual residence.

Providing account data (e-mail address) is voluntary but necessary to conclude and perform the contract - without it you cannot create an account. Providing invoice data is a statutory requirement under tax law when purchasing a paid Plan. Other data (company profile, phone number in the contact form) are provided voluntarily.