Privacy Policy

Last updated: 25 March 2026

1. Who we are

Tendrex ("we", "our", "us") operates the Tendrex platform at app.tendrex.co.uk and the marketing site at www.tendrex.co.uk. We are the data controller for the personal data we process.

If you have questions about this policy or your data, contact us at privacy@tendrex.co.uk.

2. What data we collect

Account data

When you sign in via Microsoft Entra ID (Azure AD) SSO, we receive and store:

  • Your name and email address
  • Your Microsoft tenant identifier
  • Your organisation name

Usage data

We collect information about how you use the platform, including:

  • Tenders created, questions processed, and answers reviewed
  • Documents uploaded to your organisation's knowledge base
  • Audit log entries (actions taken, timestamps)

Technical data

We automatically collect:

  • IP address and browser user agent
  • Pages visited and features used
  • Error and performance logs

3. How we use your data

We process your personal data to:

  • Provide the service — authenticate you, manage your account, and deliver platform functionality (legal basis: contract performance).
  • Improve the platform — analyse usage patterns to fix bugs and improve features (legal basis: legitimate interest).
  • Send service communications — notify you about assignments, reviews, and account changes (legal basis: contract performance).
  • Ensure security — detect and prevent fraud, abuse, and unauthorised access (legal basis: legitimate interest).

4. AI processing

Tendrex uses large language models (LLMs) to generate draft answers to tender questions. When processing questions:

  • Your documents and questions are sent to the configured LLM provider (e.g. OpenAI, Anthropic) for answer generation.
  • We do not use your data to train AI models.
  • LLM providers process data under their data processing agreements and do not retain your inputs for training.

5. Data sharing

We do not sell your personal data. We share data only with:

  • Infrastructure providers — Microsoft Azure for hosting and storage.
  • LLM providers — for AI answer generation (as described above).
  • Law enforcement — if required by law or to protect our legal rights.

6. Data retention

We retain your data for as long as your organisation has an active account. When an organisation's account is closed, we delete all associated data within 90 days. Audit logs are retained for 12 months after account closure for compliance purposes.

7. Data security

We implement appropriate technical and organisational measures to protect your data, including:

  • Multi-tenant data isolation at the organisation level
  • Encrypted data in transit (TLS) and at rest
  • Role-based access control
  • Comprehensive audit logging

8. Your rights

Under UK GDPR, you have the right to:

  • Access — request a copy of the personal data we hold about you.
  • Rectification — ask us to correct inaccurate data.
  • Erasure — ask us to delete your data (subject to legal obligations).
  • Portability — receive your data in a structured, machine-readable format.
  • Object — object to processing based on legitimate interest.
  • Restrict — ask us to limit how we process your data.

To exercise any of these rights, email privacy@tendrex.co.uk. We will respond within 30 days.

9. Cookies

The Tendrex platform uses a session cookie for authentication. We do not use third-party tracking cookies on the marketing site or the application.

10. Changes to this policy

We may update this policy from time to time. We will notify you of significant changes via the platform or by email. The "last updated" date at the top of this page indicates when the policy was last revised.

11. Complaints

If you are not satisfied with our response to a data protection concern, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.