Privacy Policy
This policy explains how Tenqual Software AS processes personal data when you visit tenqual.com, receive a business communication from us, or use Tenqual’s tender discovery, alert, delivery, API, webhook, and MCP services.
1. Controller and contact
Tenqual Software AS is the data controller. We are registered in Norway under organization number 938 164 428 at Fløenbakken 50, 5009 Bergen, Norway. Contact support@tenqual.com for privacy questions or requests.
2. Data we process
- Account and workspace data: name, email, Firebase identity, company, workspace role, and versioned legal acceptance.
- Discovery configuration: company website, business description, alert terms, filters, fit criteria, recipients, and delivery preferences.
- Agent connection data: MCP client name, approved workspace and scopes, connection status, authorization and last-use times, and the explicit tool inputs needed to perform your request. When you approve identity scopes, Tenqual sends your verified account email and verification status to the connected MCP client through OAuth UserInfo so the client or its workspace can apply account-domain restrictions. Tool responses may contain public tender data, workspace alert definitions, qualification matches and reasons, usage totals, available-document metadata, and integration status. Tenqual does not request or receive your full conversation history, unrelated local files, or credentials from the MCP client.
- Service and security data: searches, API-key metadata, webhook configuration, delivery attempts, usage records, IP address, device information, logs, and support correspondence.
- First-party measurement: page and section views, named button clicks, bounded scroll milestones, tender opens, and workspace-level product activity. Tender-search phrases are normalized into daily audience totals and removed from raw events.
- Billing data: Stripe customer and subscription references, plan quantity, status, and billing events. Tenqual does not store complete card details.
- Public procurement data: source notices, award notices, buyers, suppliers, public contact information, and tender documents made available by procurement sources.
- Business prospect data: award-winning company name, country, official website, publicly posted business email address, award evidence, relevant public tender matches, delivery history, CRM suppression state, and opt-out status. We do not generate or guess email addresses.
3. Why we process data
We process account, workspace, alert, and billing data to perform our contract with you under GDPR Article 6(1)(b). We process security, reliability, abuse prevention, product measurement, business support, and relevant business-to-business outreach for our legitimate interests under Article 6(1)(f). Prospect outreach is limited to public business contacts at companies that have won procurement contracts and includes tender opportunities that may be relevant to that company. We process accounting records and lawful requests under Article 6(1)(c). We rely on consent where the law requires it.
You may object to prospect outreach at any time by using the unsubscribe link in the email or contacting us. We retain a minimal suppression record so we can honor that choice.
4. AI processing
Tenqual uses Google Vertex AI and Gemini for features such as alert drafting, tender fit classification, optional notice translation, and bounded business-prospect research. Translation applies only to notice titles and descriptions when enabled; Tenqual does not translate tender documents. Prompts may include approved fit criteria, company context, public award evidence, and source notice text. We do not use customer content to train our own models.
If you provide a company website, Tenqual may retrieve its public pages to help prepare an alert draft. You review the resulting search scope and all fit criteria before activation. For award-winning business prospects, Gemini may use Google Search grounding to identify an official company website. Tenqual accepts the site only when the cited domain and the site’s own content corroborate the award winner.
5. Service providers and integrations
We use providers including Google Cloud Platform for infrastructure and AI, Firebase for authentication, Stripe for billing, and SendGrid for transactional email. When you configure a webhook, API client, CRM, MCP client, or another external system, data is sent to that destination at your direction and its own privacy terms apply.
6. International transfers
We prefer EU regions for Tenqual’s application data. Some providers or customer-configured destinations may process data outside the EEA. Where GDPR requires it, we use an adequacy decision, Standard Contractual Clauses, or another lawful transfer mechanism.
7. Retention
We retain account, workspace, alert, search, integration, and delivery configuration while the account or workspace is active. MCP tool inputs are not kept as a separate conversation history; an input is retained only when it becomes service configuration, an auditable action record, or part of a security log. MCP authorization and browser-handoff requests expire after 10 minutes, access tokens after one hour, and rotating refresh tokens after no more than 30 days. Disconnecting an agent revokes its active tokens immediately. Revoked MCP grant records are removed through bounded rolling maintenance after 12 months. Product action or configuration records that used a grant may remain under the applicable retention period, but their grant reference is cleared when the grant is removed.
Raw first-party behavior events expire after 90 days. Daily aggregate search-term and acquisition records expire after 25 months. Prospect engagement events expire after 12 months. Prospect qualification, delivery, and suppression records are retained while needed to document lawful business outreach and prevent renewed contact, and are reviewed when the relationship ends or you object. Application and security logs are retained for 30 days. Billing and accounting records are retained for five years after the end of the relevant financial year, or longer when law requires it.
After a verified account-deletion request, we promptly revoke active sessions and delete or anonymize customer account and configuration data within the time required by applicable law, unless a legal obligation requires retention. Cloud SQL point-in-time logs are retained for no more than seven days and seven daily database backups are retained, so deleted data may remain in an encrypted backup for approximately seven additional days and is not restored except for disaster recovery.
Public tender and award records may remain in the discovery database to maintain procurement history, source auditability, and stable public links. We correct or remove personal data from those records where required by law.
8. Security and credentials
Tenqual uses encryption in transit and at rest, least-privilege service identities, managed secrets, access controls, and audit logging. API keys are stored as one-way hashes. Webhook signing secrets are encrypted. You are responsible for protecting credentials and promptly revoking any credential you believe is exposed.
9. Cookies and first-party measurement
Tenqual does not use advertising cookies or third-party analytics. Public-site measurement uses a random identifier held only in the current page runtime; it is not written to a cookie or browser storage and disappears when the page reloads. We do not use this measurement for cross-session profiles, advertising, fingerprinting, or session replay. We honor browser Do Not Track and Global Privacy Control signals. Authentication and security technologies required to provide the service may still be used.
10. Your rights
Under GDPR, you may request access, correction, deletion, restriction, portability, or object to certain processing, including business prospecting. You may withdraw consent at any time. Every prospect email includes an unsubscribe link. You can also contact support@tenqual.com. You may complain to the Norwegian Data Protection Authority, Datatilsynet.
11. Changes
We may update this policy when the product, providers, or legal requirements change. We will publish the new effective date and provide reasonable notice of material changes.