Effective 11 August 2026

Privacy Policy

This policy explains how Tenqual Software AS processes personal data when you visit tenqual.com, receive a business communication from us, or use Tenqual’s tender discovery, alert, delivery, API, webhook, and MCP services.

1. Controller and contact

Tenqual Software AS is the data controller. We are registered in Norway under organization number 938 164 428 at Fløenbakken 50, 5009 Bergen, Norway. Contact support@tenqual.com for privacy questions or requests.

2. Data we process

3. Why we process data

We process account, workspace, alert, and billing data to perform our contract with you under GDPR Article 6(1)(b). We process security, reliability, abuse prevention, product measurement, business support, and relevant business-to-business outreach for our legitimate interests under Article 6(1)(f). Prospect outreach is limited to public business contacts at companies that have won procurement contracts and includes tender opportunities that may be relevant to that company. We process accounting records and lawful requests under Article 6(1)(c). We rely on consent where the law requires it.

You may object to prospect outreach at any time by using the unsubscribe link in the email or contacting us. We retain a minimal suppression record so we can honor that choice.

4. AI processing

Tenqual uses Google Vertex AI and Gemini for features such as alert drafting, tender fit classification, optional notice translation, and bounded business-prospect research. Translation applies only to notice titles and descriptions when enabled; Tenqual does not translate tender documents. Prompts may include approved fit criteria, company context, public award evidence, and source notice text. We do not use customer content to train our own models.

If you provide a company website, Tenqual may retrieve its public pages to help prepare an alert draft. You review the resulting search scope and all fit criteria before activation. For award-winning business prospects, Gemini may use Google Search grounding to identify an official company website. Tenqual accepts the site only when the cited domain and the site’s own content corroborate the award winner.

5. Service providers and integrations

We use providers including Google Cloud Platform for infrastructure and AI, Firebase for authentication, Stripe for billing, and SendGrid for transactional email. When you configure a webhook, API client, CRM, MCP client, or another external system, data is sent to that destination at your direction and its own privacy terms apply.

6. International transfers

We prefer EU regions for Tenqual’s application data. Some providers or customer-configured destinations may process data outside the EEA. Where GDPR requires it, we use an adequacy decision, Standard Contractual Clauses, or another lawful transfer mechanism.

7. Retention

We retain account, workspace, alert, search, integration, and delivery configuration while the account or workspace is active. MCP tool inputs are not kept as a separate conversation history; an input is retained only when it becomes service configuration, an auditable action record, or part of a security log. MCP authorization and browser-handoff requests expire after 10 minutes, access tokens after one hour, and rotating refresh tokens after no more than 30 days. Disconnecting an agent revokes its active tokens immediately. Revoked MCP grant records are removed through bounded rolling maintenance after 12 months. Product action or configuration records that used a grant may remain under the applicable retention period, but their grant reference is cleared when the grant is removed.

Raw first-party behavior events expire after 90 days. Daily aggregate search-term and acquisition records expire after 25 months. Prospect engagement events expire after 12 months. Prospect qualification, delivery, and suppression records are retained while needed to document lawful business outreach and prevent renewed contact, and are reviewed when the relationship ends or you object. Application and security logs are retained for 30 days. Billing and accounting records are retained for five years after the end of the relevant financial year, or longer when law requires it.

After a verified account-deletion request, we promptly revoke active sessions and delete or anonymize customer account and configuration data within the time required by applicable law, unless a legal obligation requires retention. Cloud SQL point-in-time logs are retained for no more than seven days and seven daily database backups are retained, so deleted data may remain in an encrypted backup for approximately seven additional days and is not restored except for disaster recovery.

Public tender and award records may remain in the discovery database to maintain procurement history, source auditability, and stable public links. We correct or remove personal data from those records where required by law.

8. Security and credentials

Tenqual uses encryption in transit and at rest, least-privilege service identities, managed secrets, access controls, and audit logging. API keys are stored as one-way hashes. Webhook signing secrets are encrypted. You are responsible for protecting credentials and promptly revoking any credential you believe is exposed.

9. Cookies and first-party measurement

Tenqual does not use advertising cookies or third-party analytics. Public-site measurement uses a random identifier held only in the current page runtime; it is not written to a cookie or browser storage and disappears when the page reloads. We do not use this measurement for cross-session profiles, advertising, fingerprinting, or session replay. We honor browser Do Not Track and Global Privacy Control signals. Authentication and security technologies required to provide the service may still be used.

10. Your rights

Under GDPR, you may request access, correction, deletion, restriction, portability, or object to certain processing, including business prospecting. You may withdraw consent at any time. Every prospect email includes an unsubscribe link. You can also contact support@tenqual.com. You may complain to the Norwegian Data Protection Authority, Datatilsynet.

11. Changes

We may update this policy when the product, providers, or legal requirements change. We will publish the new effective date and provide reasonable notice of material changes.