Skip to content
Legal

Privacy Policy

BidIndex processes personal data under the EU General Data Protection Regulation (GDPR, 2016/679). This document summarises what we collect, why, how long we keep it, who we share it with, and your rights.

Last updated: September 15, 2026

Data controller

BidIndex is operated by Core Engineering Kft. (Váci út 99., 1139 Budapest, Hungary). For any data protection request: info@coreeng.eu.

The company is established in the EU, so the GDPR applies directly and no Article 27 representative is required.

What we collect

Account: email address, a bcrypt hash of your password, session token (JWT), optionally a display name and interface language; the version of the terms you accepted at sign-up and when you accepted them.

Subscription: plan state, credit balance and spending record, and the customer, subscription and transaction identifiers returned by our payment provider Paddle. We never see or store your card number.

Usage: saved search filters, your watchlist, any Slack/Teams/Discord webhook address you enter for notifications, web push subscription (endpoint, encryption keys, browser details), the profile extracted from your CV, and your company profile.

Technical: IP address and request details (server logs and rate limiting against abuse), language and session cookies.

No analytics — we use no tracking pixels, Google Analytics, or comparable tools.

Why we process (legal basis)

Performance of a contract (GDPR Art. 6(1)(b)): creating your account, running your subscription, saving searches, sending notifications, running the AI analyses and CV/company matching you request.

Legitimate interest (Art. 6(1)(f)): system security, abuse and fraud detection, keeping the service available.

Consent (Art. 6(1)(a)): web push permission is requested through your browser and can be withdrawn at any time. If your CV contains special categories of data, the basis for that data is your explicit consent under Art. 9(2)(a) (see below).

Legal obligation (Art. 6(1)(c)): retention of accounting records under Hungarian law.

CVs and special categories of data

When you upload a CV, its text is sent to our AI provider Anthropic solely to extract a profile. We do not keep the file or the raw text; what we store is the profile extracted from it (skills, roles, languages, etc.), which you can delete from your account page at any time.

Please do not include special categories of personal data (GDPR Art. 9) in your CV — such as health, racial or ethnic origin, religion or beliefs, political opinions, trade union membership, sexual orientation or biometric data. Job matching does not need them, and a photo is not needed either.

If you nevertheless upload a CV containing such data, it is processed only for the profile extraction and matching you initiate, based on your explicit consent (GDPR Art. 9(2)(a)). You can withdraw consent by deleting your profile; withdrawal does not affect the lawfulness of processing before it.

How long we keep it

Account data until you delete your account. When you delete it, the data is removed from the live system; in the database backups kept for disaster recovery it remains for at most 7 more days (daily backups) or 12 more months (monthly backups) and is deleted together with the backup at the end of that period.

Accounting records (e.g. payment and payout records received from Paddle): 8 years, as required by Hungarian accounting law. This applies even after you delete your account.

Web push subscription: until you or your browser disables it (pruned automatically on HTTP 410).

Server logs (IP address, requested address, time): kept in size-limited rotating logs; when a log is full, the oldest entries are deleted automatically. We read these logs only to investigate faults and abuse. For rate limiting, IP addresses are held briefly in memory only.

The profile extracted from your CV and your company profile: until you delete them or close your account. So that the same analysis is not charged twice, AI responses are kept in a cache that is not linked to your account.

Processors

The following service providers process data only on our behalf and on our instructions (GDPR Art. 28).

Hosting: netcup GmbH — server location: Vienna, Austria. The application, database, queue and backups run on this server, i.e. in the EU (Austria).

Email: Resend — transactional mail (verification, password reset) and the notification and deadline reminder emails you set up. Your email address and the content of the email pass through Resend.

AI: Anthropic (Claude API). When you use tender summaries, fit and knockout-criteria analysis, tender document analysis, or CV and company profile extraction and matching, the relevant text is sent to Anthropic. Under its commercial API terms, Anthropic does not use this content to train models. If you do not use these features, no text belonging to your account is sent.

Translation: Google (Google Translate). Tender, job, news and site texts are sent to Google to be translated into the language you choose. These are publicly available notice and content texts; your account data is not sent this way.

Independent controller: Paddle

Subscriptions and credit packs are sold through Paddle.com Market Ltd. (United Kingdom). Paddle is the merchant of record for these sales: it collects payment in its own name, issues the invoice, accounts for VAT and performs fraud checks. For the information you provide at checkout (name, email, country, payment details) it is therefore an independent controller, not our processor.

Card data goes directly to Paddle and never reaches our systems. Paddle passes us only what we need to run your subscription (customer and subscription identifiers, transaction status).

How Paddle processes your data is described in Paddle's own privacy policy: https://www.paddle.com/legal/privacy

Services you connect to directly or choose

Web push: if you enable browser notifications, they are delivered through the push service of your browser's vendor (Google for Chrome, Mozilla for Firefox, Apple for Safari, Microsoft for Edge). Your browser decides which service is used; notification content reaches these services end-to-end encrypted.

Webhooks: if you enter a Slack, Microsoft Teams or Discord webhook address in a filter, matching tender notifications are sent to that address. You choose the recipient; the content sent is tender information.

Public procurement sources (TED, PLACSP, BOAMP …) are one-way: we ingest from them and send them no personal data. When you open a link to a notice, that portal's own privacy terms apply.

No advertisers, data brokers, or marketing partners. We do not sell your data.

Transfers outside the EU

Our server and database are in the EU. Some of the recipients above, however, are outside the EU/EEA, and data sent to them is transferred outside the EU.

United States — Anthropic, Resend, Google (Translate): the transfer relies on the provider's certification under the EU-U.S. Data Privacy Framework (GDPR Art. 45) and/or the European Commission's Standard Contractual Clauses (GDPR Art. 46(2)(c)).

United Kingdom — Paddle: the European Commission's adequacy decision for the United Kingdom (GDPR Art. 45).

Browser push services are operated by your browser's vendor under its own terms; notification content reaches them encrypted.

You can request a copy of the safeguards a transfer relies on at info@coreeng.eu.

Email notifications

Every filter, watchlist and deadline notification email contains an unsubscribe link; clicking it is enough to stop those notification emails, no sign-in required.

Account verification, password reset and mandatory subscription notices are sent because the account needs them; they are not marketing. We do not send marketing email.

Your rights

Under GDPR Art. 15–22: access, rectification, erasure, restriction of processing, data portability, objection, and withdrawing any consent you have given at any time.

Access and portability (Art. 15, 20): use "Download my data" on your account page to download the data linked to your account as a machine-readable file.

Erasure (Art. 17): you can delete your account yourself from your account page by entering your password. Accounting records subject to a statutory retention period are kept until that period ends.

For any other request write to info@coreeng.eu; we respond within 30 days, free of charge.

Supervisory authority: the Hungarian NAIH (Nemzeti Adatvédelmi és Információszabadság Hatóság, naih.hu). You may also lodge a complaint with the data protection authority in the country where you live or work.

Cookies

Functional cookies only: language preference (NEXT_LOCALE), session token, and plan state. Sign-in does not work without the last two.

No analytics or advertising cookies — which is why there is no consent banner.

Security

All connections are TLS-encrypted. Passwords are bcrypt-hashed and never stored in plaintext.

Only the application server reaches the database; administrative access is key-based.

In case of a breach affecting personal data we notify the supervisory authority within 72 hours and inform you directly where the risk is high (GDPR Art. 33–34).

Changes

When this policy changes, its version date changes; material changes are announced by email to registered users.

Version: 2026-09-15.2