Privacy Policy

Tendermark Ltd

Effective: 17 July 2026 Version: 1.3


Contents

  1. About this Policy
  2. Who we are and how to contact us
  3. Our role as controller and processor
  4. The personal data we handle
  5. How we use personal data, and our lawful bases
  6. The Benchmarking Commons
  7. Data about contractors
  8. The audit log
  9. Public sharing — share links and invitation links
  10. Artificial intelligence and our use of Anthropic
  11. Sub-processors and who we share data with
  12. International transfers
  13. Cookies and analytics
  14. Security
  15. How long we keep personal data
  16. Your rights under UK GDPR
  17. Children
  18. Changes to this Policy
  19. Complaints

1. About this Policy

1.1 This Privacy Policy explains how Tendermark Ltd handles personal data when you use the Tendermark website and platform (the "Services").

1.2 We are committed to protecting your privacy and handling personal data in line with the UK General Data Protection Regulation ("UK GDPR"), the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations 2003 ("PECR").

1.3 The Services are a business tool for UK-based RICS-certified building surveyors and surveying firms. We do not offer the Services to consumers or to anyone under 18.

1.4 This Policy should be read alongside our Terms of Service, including Schedule 1 (Data Processing Terms) which applies when we process personal data on your behalf as your processor.


2. Who we are and how to contact us

2.1 The data controller for personal data we hold about you (as our customer and user) is:

Tendermark Ltd (company number 17161246) 66 Paul Street London EC2A 4NA United Kingdom

Email: hello@tendermark.ai

2.2 We have not appointed a statutory Data Protection Officer, because we are not required to under UK GDPR Article 37. For all data protection questions, contact hello@tendermark.ai.


3. Our role as controller and processor

3.1 We act as controller in relation to personal data about you and your use of the Services — your name and firm name, your email address and login credentials, your subscription and billing identifiers, and data about how you use the Services.

3.2 We act as processor on your behalf in relation to personal data that is part of the tender content you upload, author or collect through the Services — personal data about your clients, your contractors, your projects, and the free-text material you or a contractor enter into the Services.

3.3 This dual role matters because different legal frameworks apply to each. Section 5 of this Policy describes what we do as controller. Sections 6–9 describe what we process as processor on your instructions. The full terms of our processor role are at Schedule 1 of the Terms of Service.

3.4 If you are a contractor who has received an invitation to price a tender through the Services, please see section 7 — which explains how your personal data is handled and how to contact the surveyor who invited you.


4. The personal data we handle

4.1 Account and profile data (controller):

4.2 Project, tender and client data (processor):

4.3 Contractor data (processor — personal data about third parties you introduce to the Services; see section 7):

4.4 Return content (processor — content of each tender return):

4.4A Valuation evidence data (processor — content you capture on site against a live contract's interim valuation, through the Tendermark mobile application):

This valuation evidence forms part of the tender and contract record and is processed on your instructions as part of the tender content. Photographs and location captured as evidence are stored as your evidence and are not sent to Anthropic or to any other AI provider (see section 10).

4.5 Usage data (controller):

4.6 Communications data (controller):

4.7 Anonymised commons data (no personal data): anonymised pricing signals are stored separately in the Benchmarking Commons — see section 6. This data contains no personal data and cannot be traced back to you, your clients or any contractor.

4.8 Incidental personal data in free text. Some fields in the Services — project notes, line-item descriptions, contractor notes, and raw text extracted from uploaded returns — accept free-text input. You or a contractor may include personal data in those fields (for example, a property address). We process that data as part of the tender content; it is your responsibility (as the surveyor) to manage what goes into those fields.

4.9 Newsletter and update subscription data (controller): if you subscribe to our newsletter or to compliance-pack updates — from our blog or our RICS compliance resources page — we collect your email address, which list you subscribed to, the exact wording you agreed to when you subscribed, and the date. You do not need a Tendermark account to subscribe, and many subscribers are not customers. See section 5A.


5. How we use personal data, and our lawful bases

5.1 As controller, we process personal data for the following purposes, on the lawful bases indicated:

PurposeLawful basis
Creating and managing your account; authenticating you when you sign inContract (UK GDPR Article 6(1)(b)) — performance of the Terms of Service
Providing the Services to you, including processing your tender content and generating outputsContract
Taking payment and issuing invoicesContract; legal obligation (Article 6(1)(c)) for statutory record-keeping
Sending you transactional emails (for example, password resets, tender status notifications)Contract
Sending you the newsletter or compliance-pack updates you have subscribed toConsent (Article 6(1)(a)); and Regulation 22 of PECR for the electronic marketing — see section 5A
Analysing how you use the Services to improve them (via PostHog)Legitimate interests (Article 6(1)(f)) — our interest in maintaining and improving a professional B2B service. Balanced against your rights; you can decline non-essential analytics cookies at the cookie banner (see section 13)
Maintaining security of the Services, investigating fraud, and keeping the audit logLegitimate interests — our interest, and your interest, in a secure and auditable platform (see section 8)
Contributing anonymised pricing signals to the Benchmarking Commons (subject to your opt-out)Legitimate interests (Article 6(1)(f)) — see section 6
Complying with legal and regulatory obligationsLegal obligation
Defending ourselves against legal claims, where necessaryLegitimate interests

5.2 As processor, we handle personal data in the tender content on your instructions — as documented in the Terms of Service and Schedule 1. Your legitimate use of the Services is treated as an instruction to process. You are the controller for that data and you are responsible for having a lawful basis to provide it to us.

5.3 We do not sell personal data. We do not use personal data for targeted advertising. We do not profile users for automated decisions that produce legal or similarly significant effects.


5A. Our newsletter and update emails

5A.1 What this covers. You can subscribe to receive email from us that is not tied to a tender or an account:

You do not need a Tendermark account to subscribe to either, and this section applies to any website visitor who subscribes, whether or not they are a customer.

5A.2 Lawful basis — consent. We send these emails on the basis of your consent (UK GDPR Article 6(1)(a)), and we treat them as electronic marketing under Regulation 22 of PECR. You give that consent by entering your email address and choosing to subscribe. We do not add anyone to these lists without that action, and we do not buy or rent email lists.

5A.3 What we record as your consent. When you subscribe we store your email address, which list you chose, the exact wording shown to you at the point you subscribed, and the date. We keep this so that we can evidence what you agreed to.

5A.4 These emails are separate from account email. Subscribing to the newsletter or to compliance-pack updates is separate from the transactional and service emails we send you as a customer (for example password resets or tender-status notifications, described in section 5). Unsubscribing from the newsletter does not stop the service emails your account needs, and having an account does not subscribe you to the newsletter.

5A.5 How to withdraw consent. You can withdraw your consent — unsubscribe — at any time, and just as easily as you gave it:

Unsubscribing takes effect promptly and stops all further emails on that list. Withdrawing consent does not affect the lawfulness of anything we sent before you withdrew.

5A.6 After you unsubscribe. When you unsubscribe we keep a minimal record — your email address and the fact that you unsubscribed — as a suppression record, so that we can honour your request and do not add you back. We do not use that record to send you anything. You can ask us to erase it entirely by emailing hello@tendermark.ai (see section 16).

5A.7 No sharing. We do not share these email addresses with third parties for their own marketing, and we do not sell them. The email itself is delivered by our email sub-processor, Resend (see section 11).


6. The Benchmarking Commons

6.1 The Benchmarking Commons is a shared dataset of anonymised pricing signals derived from the tenders you process, used to improve benchmarking for Tendermark users. Participation is optional. It is a core feature of the product and we want you to understand it fully.

6.2 Professional precedent. The Benchmarking Commons model is based on the approach used by the Building Cost Information Service (BCIS), which has operated a professional data commons for the surveying profession for more than 60 years with RICS backing. Under that long-established model, the surveyor contributing data is the participant and the data provider; the anonymised aggregate is made available to the profession. Tendermark applies that model to minor works, with one conservative refinement: contribution to our commons is opt-in, not assumed.

6.3 Two distinct processing activities. There are two things going on when you use the Services, and they are treated separately:

6.4 Your right to object. Because Activity 2 is based on legitimate interests, you have a right under UK GDPR Article 21 to object to it at any time. We operationalise this right through an opt-in/opt-out toggle in your account settings: toggling off stops all future contributions to the Benchmarking Commons from your account. The opt-in toggle is the primary way to exercise this right; you can also object by emailing hello@tendermark.ai.

6.5 No effect on service. Your opt-in status has no effect on:

6.6 What is stripped before anything is stored in the Commons. Before any record is written to the Benchmarking Commons, we remove:

6.7 What is retained. Only anonymised pricing signals are retained: trade category (normalised), a generalised description of the work (rewritten by AI to remove specifics), unit of measurement, unit rate, total, project type, broad region (broader than postcode area), and the quarter in which the contribution was made.

6.8 Contributions are irrevocable once anonymised. Because we strip all links back to you, your clients and the contractor before writing to the Commons, there is no personal-data record to retrieve once a contribution has been made. If you toggle off future contributions, the toggle takes effect immediately, but past anonymised records stay in the aggregate. This is unavoidable because those records contain no personal data that could be used to identify or locate your prior contributions.

6.9 This is explained at the point of opt-in. Our onboarding screen sets out, before you accept, exactly what is stripped, exactly what is retained, and exactly what toggling off does and does not do. This is a deliberate design choice that reflects ICO guidance on how irrevocable anonymised contributions should be communicated.

6.10 How to stop contributing. You can toggle off contributions at any time from the Pricing Commons section of your account settings. No justification is required. We will not nag you or prompt you to toggle back on.

6.11 Further questions about contributions. If you want to discuss your contribution history, or you believe you contributed data in error, email hello@tendermark.ai.


7. Data about contractors

7.1 Contractors named in tenders, and contractors who receive an invitation to price a tender via the Services, are data subjects under UK GDPR. They are not customers of Tendermark.

7.2 Our role. When you invite a contractor through the Services, or when you upload a return from a contractor:

7.3 What we collect about contractors:

(a) when you invite a contractor, we collect the name, email and (if you provide it) firm name you enter;

(b) when a contractor opens an invitation link, we capture their IP address (see section 8);

(c) when a contractor confirms their details on the gate screen, we collect the name, email and firm name they enter themselves;

(d) at each subsequent save and submit, we record a timestamp and the contractor's IP address in our append-only audit log.

7.4 Direct collection from the contractor. The identity gate — where the contractor types in their own name, email and firm name before they begin pricing — is a direct collection from the contractor to the Services. That collection is on the surveyor's instructions and for the surveyor's purposes; it records the contractor's accurate identity for the tender the surveyor has issued. We act as processor on the surveyor's behalf for that collection, not as a joint controller.

7.5 Information for contractors. A contractor who has received an invitation and who has questions about their personal data can:

7.6 No marketing to contractors. We do not use contractor email addresses or other contractor personal data to market Tendermark to contractors.


8. The audit log

8.1 The Services include a tamper-resistant audit log (tender_return_events) that records every state transition on every tender return, including:

8.2 What is captured. For each event: the event type, the type of actor (surveyor, contractor, or our system), the actor's user identifier (if the actor is a surveyor), the contractor's IP address (if the actor is a contractor), a timestamp, and event-specific metadata (for example, the deadline change or the number of responses saved).

8.3 Why this exists. The audit log:

8.4 Lawful basis. We process audit log data on the basis of our legitimate interests — and the legitimate interests of surveyors, contractors and the profession — in a secure, auditable platform. For contractor IPs specifically, the legitimate interests are fraud prevention, dispute resolution, and audit trail. These interests are balanced against the contractor's reasonable expectation that their interaction with a priced tender is recorded for the surveyor's professional record. The log is append-only — we do not edit or delete log entries in the ordinary course.

8.5 Retention. We retain audit log entries for the same period as the associated tender content (see section 15). The log is append-only — we do not edit or delete individual entries in the ordinary course of operations. If you request deletion of Customer Personal Data, or close your account, audit log entries for the affected tenders are deleted alongside the rest of your content, subject only to any retention required by law or by a live dispute, investigation or regulatory request.

8.6 Access. Audit log entries are visible in the application only to the surveyor who owns the tender the return belongs to. They are not public, not visible to other users, and not visible to contractors. They may be accessed by Tendermark personnel under strict access controls to investigate incidents or respond to a lawful request.

8.7 Valuation audit events. The on-site interim-valuation flow maintains its own append-only audit log (valuation_events), recording actions taken against a valuation — for example, when observed progress is set on a line, when photographs are attached, and when a site note is added. Each event is attributed to the signed-in surveyor who took the action; attribution comes from the authenticated account, never from a device-supplied name. Where an action is captured on site through the mobile application, the event records two timestamps: a device-claimed time (when it happened on site, according to the device) and a server-received time (when it reached our servers on sync). Both are retained, and the audit trail is honest about which is which — for example, "captured on device 24 June 14:06, received 24 June 18:22" — because a device clock is a claim, not a verified fact. This log is retained and deleted on the same basis as the associated valuation and tender content (see section 15).


9.1 The Services generate two kinds of token-based public link:

9.2 Share links.

(a) A share link renders the completed report in read-only form and displays your name and firm as the preparer of the report.

(b) A share link is valid until the share expiry you configure. After expiry, the link returns a generic "no longer valid" response and reveals nothing about the content.

(c) Anyone holding the share link can read the content. You are responsible for deciding with whom to share it.

9.3 Invitation links.

(a) An invitation link permits the invited contractor to enter their details, price line items, save progress and submit. It does not grant access to anyone else's data.

(b) Tokens are random 122-bit identifiers generated using crypto.randomUUID(). They are not guessable in any practical sense.

(c) Tokens are transmitted over HTTPS only, included in the email link to the contractor but never displayed in link text. Tokens are not stored in analytics (PostHog) or in application logs.

(d) Invitation links expire at the deadline you set, after which they return the same generic "no longer valid" response. All error states on invitation links — expired, revoked, already submitted, invalid — return the same generic message, to prevent probing of the token space.

(e) Per-token and per-IP rate limits apply to invitation endpoints.

9.4 A contractor who prices a tender through an invitation link can download a PDF copy of their submission at the time of submission and receives it by email.


10. Artificial intelligence and our use of Anthropic

10.1 The Services use large language models provided by Anthropic (via Anthropic's commercial API) to extract structured data from uploaded tender documents, to normalise line-item descriptions before contribution to the Benchmarking Commons, and to support report drafting.

10.2 What is sent to Anthropic. When we call Anthropic's API, we send the content we need to process to complete the task — for example, the text content of a Schedule of Works, the content of a contractor return, or a line-item description we need to normalise.

10.3 Anthropic does not use your data to train its models. Under Anthropic's commercial API terms as in force at the effective date of this Policy, the data we submit — including your tender content, contractor returns, and any derived analysis — is not used to train Anthropic's models. Your data is processed solely to provide you with the Tendermark Services. If Anthropic's commercial API terms change in a way that materially affects this statement, we will update this Policy in accordance with section 18.

10.4 What the AI does and does not do. The AI extracts, normalises and summarises information. It does not make professional judgements, give opinions, or take decisions on your behalf. All outputs are for you to review and verify — see the output-reliance clause in the Terms of Service (clause 12).

10.5 No automated decision-making with legal or similarly significant effects. We do not make automated decisions concerning you within the meaning of UK GDPR Article 22.

10.6 Valuation evidence is not sent to AI. The photographs and location data you capture on site as valuation evidence (see section 4.4A) are stored as your evidence and are not sent to Anthropic or to any other AI provider. This clarification applies only to that photographic and location evidence. It does not change the position for your tender content — Schedules of Works, contractor returns and line-item text — which is processed using AI as described in this section.


11. Sub-processors and who we share data with

11.1 We use the following sub-processors to provide the Services. Each has been chosen for its security posture and its compatibility with UK GDPR obligations. We have a written data processing agreement with each.

Sub-processorPurposeLocation of processingInternational transfer mechanism
SupabaseDatabase, authentication, file storageEuropean Union (EU region)Not required (UK adequacy regulations apply to EEA transfers)
AnthropicAI-powered extraction, normalisation and analysisUnited StatesUK Addendum to EU SCCs
StripePayment processingUnited StatesUK extension to the EU–US Data Privacy Framework, with UK Addendum to EU SCCs as backup
VercelApplication hosting, edge deliveryUnited StatesUK extension to the EU–US Data Privacy Framework, with UK Addendum to EU SCCs as backup
CloudflareDNS, CDN, DDoS protectionUnited StatesUK extension to the EU–US Data Privacy Framework, with UK Addendum to EU SCCs as backup
PostHogProduct analytics and feature flagsEuropean Union (EU Cloud)Not required
ResendTransactional email deliveryEuropean UnionNot required

11.2 We may also share personal data with:

11.3 We do not sell personal data, and we do not share it for marketing purposes with third parties.

11.4 We keep our sub-processor list current. If we add or change a material sub-processor, we will update this Policy and notify customers in line with section 18.


12. International transfers

12.1 Some of our sub-processors (marked in section 11 as requiring a transfer mechanism) process personal data outside the United Kingdom, principally in the United States.

12.2 Our transfer safeguards depend on the sub-processor:

12.3 For transfers to Anthropic, we have carried out a Transfer Risk Assessment in line with ICO guidance. For transfers to Stripe, Vercel and Cloudflare, we rely on the adequacy finding underlying the Data Privacy Framework and monitor each sub-processor's certification status; if any certification is suspended or withdrawn, our UK Addendum backup mechanism takes effect and a Transfer Risk Assessment is completed at that point.

12.4 You can request a copy of the transfer safeguards we rely on for any specific sub-processor by emailing hello@tendermark.ai.


13. Cookies and analytics

13.1 We use a small number of cookies and similar technologies on the Services.

13.2 Strictly necessary cookies are required for the Services to function — for example, to keep you signed in and to support secure payment. These cannot be disabled.

13.3 Analytics cookies (PostHog) help us understand how the Services are used. PostHog is hosted in the EU and acts as our processor. We use it solely to analyse aggregate usage of our own service and to improve it — we do not share analytics data with any third party for advertising, targeting, or any other purpose. Because the processing meets the "statistical purposes" exception under the Privacy and Electronic Communications Regulations 2003 (as amended by the Data (Use and Access) Act 2025, effective 5 February 2026), we do not require your consent to set these cookies. You can still turn analytics off at any time via the Cookie preferences link in the site footer; doing so does not affect your access to any feature of the Services.

13.4 Payment cookies (Stripe) are set by Stripe at the point of checkout to process your payment. They are necessary for that purpose.

13.5 How we inform you. On your first visit, a small notice at the bottom of the page summarises our use of cookies and links to this Policy and to the Cookie preferences page. The notice is informational — it does not ask for your consent, because none is required for the cookies we actually use. You can change your analytics preference at any time via the Cookie preferences link, which remains accessible from every page.

13.6 We do not use advertising cookies, tracking cookies for third-party advertising purposes, retargeting cookies, or any cross-site tracking technology.

13.7 On-device storage in the mobile application. The Tendermark mobile application stores certain data on your device — your sign-in session, and a durable queue of on-site actions and photographs waiting to sync — so that it works offline. This is described in section 13A.


13A. The mobile application

13A.1 What it is. We offer a native mobile application for iOS and Android — the on-site valuation companion — for recording observed progress and photographic evidence against the line items of a live interim valuation while you are on site. It is a capture surface in front of the same server-held valuation flow you use on the web. You sign in to the mobile application with your existing Tendermark account; accounts are created and managed on the web, not in the app.

13A.2 Device permissions. The mobile application asks for two device permissions, each only when needed and each explained on screen:

You can grant, change or withdraw these permissions at any time in your device settings. Declining the camera permission prevents photo capture; declining location does not block capture.

13A.3 On-device storage. To work offline, the application stores on your device: your sign-in session (held in the device's secure credential storage), and a durable queue of pending on-site actions and captured photographs that have not yet synced. Queued items are held only until they have synced to our servers, after which the local copy is removed. Photographs are compressed on the device before upload.

13A.4 Where evidence is stored. Photographs, site notes and location data captured through the application are transmitted over an encrypted connection to our storage in the European Union (provided by Supabase — see section 11) and stored as part of your tender and contract record. This evidence is not transferred outside the UK/EU for storage (see section 12) and is not sent to any AI provider (see section 10).

13A.5 Analytics. The mobile application does not currently include the product-analytics tooling (PostHog) used on our website, and does not include third-party crash-reporting or advertising technology.

13A.6 App-store distribution. The application is distributed through the Apple App Store and Google Play. Your download and use of the application is also subject to the relevant app store's own terms and privacy practices, over which we have no control. An app store may collect limited information about downloads and, where you enable it, diagnostic information — this is governed by that store's privacy policy, not this one.

13A.7 Account deletion from the application. You can reach account deletion from within the application. Because your account is created and managed on the web, the deletion link opens the Tendermark website, where you sign in and complete the deletion. What deletion erases and what it retains is described in section 16.6.

13A.8 Lawful basis. Valuation evidence and location captured through the application are processed as processor content on your instructions, as part of the tender content, on the lawful basis of our contract with you (see section 5.2). They are not contributed to the Benchmarking Commons and are not processed on a separate legitimate-interests basis.


14. Security

14.1 We take security seriously. Our technical and organisational measures include:

14.2 No system is perfectly secure, and we cannot guarantee the security of information transmitted to us over the internet. You are responsible for keeping your account credentials confidential.

14.3 We have carried out a Data Protection Impact Assessment for the on-site valuation-capture feature of the Tendermark mobile application (photographic evidence and location data). It is available on request by emailing hello@tendermark.ai.


15. How long we keep personal data

15.1 We keep personal data only as long as we need it for the purposes for which we collected it, and in line with legal and regulatory obligations.

15.2 Our current retention periods are:

CategoryRetentionReason
Account and profile dataLifetime of account + 6 months after closureAllows account reactivation; allows resolution of queries after closure
Tender content (SoWs, returns, line items, responses)Lifetime of account + 6 months after closureAs above
Valuation evidence (photographs, site notes, capture timestamps, location)Lifetime of account + 6 months after closureIntegral part of the tender and contract record; retained and deleted with it
Contractor data (names, emails, firm names, IPs in the audit log)Lifetime of account + 6 months after closureIntegral part of the tender record; retained and deleted with it
Audit log (tender_return_events)Same as the associated tender content (see above)Integral part of the tender record; retained and deleted with it
Transactional email and support correspondence6 yearsLimitation period for contract claims under the Limitation Act 1980; dispute resolution
Newsletter / compliance-pack subscription (email, chosen list, consent record)Until you unsubscribe; then a minimal suppression record (your email and the fact you unsubscribed)We email only while you are subscribed; the suppression record ensures we honour your unsubscribe
Billing and tax records (invoice metadata, Stripe customer identifier)7 years from the end of the tax year to which they relateUK tax-law minimum (6 years); held for a 1-year safety margin
Benchmarking Commons anonymised recordsIndefiniteNo personal data is retained; once anonymised, there is nothing to delete (see section 6)
Server-side technical logs and security logs90 days in the hot tier; archived for up to 12 monthsSecurity monitoring and investigation

15.3 All retention periods are indicative. We may retain personal data longer where we reasonably consider it necessary to defend or bring legal claims, or where required by law.

15.4 Closing an account and deleting an account are different. The periods above describe what we keep while your account is open, and for a short window after you close it — closure retains your account and tender content for 6 months to allow reactivation (see the Terms). If instead you delete your account (see section 16.6), we erase your identifiable, active-use data on confirmation, keeping only the limited categories the carve-outs in section 16.6 require (for example billing and tax records). Deletion is the erasure right described in section 16; closure is not.


16. Your rights under UK GDPR

16.1 Subject to the conditions set out in UK GDPR, you have the following rights in respect of personal data we hold about you as controller:

16.2 Benchmarking Commons — specific rules. Toggling off the Benchmarking Commons (your right to object under Article 21) stops future contributions. Past anonymised contributions stay in the aggregate because, by design, we do not retain a link between those records and you — there is nothing identifiable to erase. This is explained at the point of opt-in and is a material part of participation.

16.3 Data subject requests from your clients and contractors. If your client or a contractor named in a tender makes a rights request relating to data in your account, that request is your responsibility as the controller. Schedule 1 (Data Processing Terms) of the Terms of Service describes how we will assist you in responding.

16.4 How to make a request. Email hello@tendermark.ai. We will respond within one month of receiving your request, or tell you within that period if we need longer because your request is complex.

16.5 No fee is charged for a rights request in the ordinary course. We may charge a reasonable fee or decline to act where a request is manifestly unfounded or excessive, as allowed by UK GDPR.

16.6 Account closure and account deletion. These are two different actions, and it matters which you choose:

When you delete your account, we keep only what the law or these documents require:

(a) billing and tax records — your payment-processor customer record and invoices are retained for the statutory tax-retention period (see section 15); we detach your saved payment details but do not delete the invoice and tax history;

(b) anonymised Benchmarking Commons records — if you opted in, past anonymised contributions stay in the aggregate, because by design they hold no link back to you and there is nothing identifiable to erase (see sections 6 and 16.2);

(c) audit entries under a live matter — audit entries needed for a live dispute, investigation or legal obligation are retained until that matter is resolved (see section 8.5); and

(d) backups — residual copies in our backups are not accessed after deletion and age out on our normal backup cycle (see Schedule 1, clause 13.3).

You can start account deletion from your account settings on the web, and reach it from within the mobile application, which opens the account-deletion page on the web (see section 13A.7).


17. Children

The Services are not directed at, and are not available to, anyone under the age of 18. We do not knowingly collect personal data from children.


18. Changes to this Policy

18.1 We may change this Privacy Policy from time to time — for example, to reflect changes in the Services, in applicable law, or in our sub-processor list.

18.2 If we make a material change that affects your rights, we will notify you by email to the address on your account and by an in-product notice, at least 30 days before the change takes effect.

18.3 Non-material changes take effect on posting of the revised Policy, with the effective date at the top of the document updated accordingly.

18.4 We keep an archive of superseded versions of this Policy. Contact hello@tendermark.ai if you need a copy.


19. Complaints

19.1 If you have a concern about how we handle your personal data, please email hello@tendermark.ai first. We will do our best to resolve it.

19.2 You also have the right to complain to the UK regulator, the Information Commissioner's Office (ICO):

Information Commissioner's Office Wycliffe House, Water Lane Wilmslow, Cheshire SK9 5AF United Kingdom

Helpline: 0303 123 1113 Website: https://ico.org.uk


Tendermark Ltd, 66 Paul Street, London EC2A 4NA · Company number 17161246

Download PDF