Privacy Policy
Summary
- Who is responsible: ScoutTide is the controller of your personal data. Questions or requests: contact form · support@scouttide.com
- What we collect: your name and email address, how you sign in, what you do in the app, documents you upload and messages you send us. Card details go to Paddle, our merchant of record, and never reach us.
- Why: to provide the service you signed up for (contract), to keep it secure and working (legitimate interest), and to meet tax and accounting duties through Paddle (legal obligation).
- Public data: we also read publicly published tenders, contract awards and public posts. Posts by the same public username are linked only within one customer organisation; no profile is built across organisations. You can object at any time through the contact form.
- Who receives it: only the services listed in the full policy (hosting, email, AI models, payments and similar), each for a stated purpose. We never sell personal data or use it for advertising.
- Where: on servers in Germany. Some services are outside the EEA; transfers are protected by Standard Contractual Clauses or an adequacy decision.
- How long: your account until you delete it; an organisation whose plan has ended and where nobody has signed in for 30 days is deleted after a further 180 days; public posts after 30 days; backups within 30 days.
- Your rights: access, correct, delete or download your data, restrict or object to its use, and complain to a data protection authority. Most of it you can do yourself under Account.
- Cookies: only the ones the service needs to work. No advertising, no analytics, no tracking. Cookie policy
Who is responsible for your data
The controller is ScoutTide. Reach us about anything in this policy through the contact form (choose Privacy or a data request) or at support@scouttide.com.
What we collect, and why
| Data | Why | Legal basis |
|---|---|---|
| Name and email address | To identify you, attribute claims to a person, and send the account email you asked for (verification, password reset, invitations, the morning digest). | Contract (Art. 6(1)(b)) |
| Sign-in identifier from your provider, or a password hash | To let you sign back in. Passwords are stored only as a bcrypt hash, never in readable form. | Contract |
| What you do in the app: claims, stages, notes, dismissals, saved searches, products, activity log | The product itself, and the audit trail your colleagues rely on. | Contract; legitimate interest in a reliable audit trail (Art. 6(1)(f)) |
| Documents you upload | To store them and show them to your organisation. | Contract |
| Subscription status and plan | To know which features your organisation has paid for. Card details never reach us; Paddle holds them. | Contract |
| Messages you send us (contact and feedback forms, email) | To answer you. Your name, address and message are emailed to our support mailbox. | Legitimate interest in answering; contract where it concerns your account |
| Session and language cookies | To keep you signed in and show the language you chose. See the cookie policy. | Strictly necessary |
| Server logs (time, address requested, IP address, errors) | To keep the service running, stop abuse and investigate faults. | Legitimate interest in a secure, working service |
| Billing records: the organisation's name, the buyer's name, email address and country, and the invoices | To meet tax and accounting obligations. Paddle, our merchant of record, keeps these records as tax law requires. | Legal obligation (Art. 6(1)(c)) |
You do not have to give us anything beyond a name and an email address, but without them we cannot create an account.
Data we did not get from you: public tenders, awards and posts
ScoutTide reads publicly published material so it can show it to the organisations it is relevant to. The basis for all of it is our and our customers' legitimate interest in finding public business opportunities (Art. 6(1)(f)).
- Tender notices from official procurement portals. These can name a contact person at the buying authority, as published by that authority. Kept until the tender closes, unless a customer is working on it.
- Contract awards from public award notices published by procurement authorities (for example the EU's TED, national procurement portals and open contracting datasets; the Sources page in the application lists them). They name the buyer and the winning supplier, and a supplier can be a sole trader or a freelancer trading under their own name. Purpose: to show customers who won similar work and when a contract may come up for renewal. Kept as a record of public contracts for as long as that history is useful for renewals; there is no fixed deletion date.
- Public forum and social posts (for example Reddit, Hacker News, Stack Exchange, Upwork or LinkedIn search results). We keep the post's text, link, public username and date, exactly as published. Kept until the post is 30 days old, unless a customer is working on it.
Linking posts by the same author. Within one organisation, posts are linked by the author's public username, so that organisation's team can see that someone has asked before ("seen before", and how many of their posts it has). That link belongs to that one organisation: no profile is built across organisations, and nothing about anyone is sold or shared. A language model labels what a post is asking for (for example "looking for a supplier"); it classifies the post, not the person, and draws no conclusions about who the author is. The link is deleted once none of the author's posts is kept any more.
We keep only what the public page shows. If you are named in any of this, or wrote one of those posts, and want it removed from ScoutTide, tell us through the contact form (choose Privacy or a data request): you can object at any time, and we will delete it and stop showing it unless we have compelling legitimate grounds that override your interests, which for this material we do not expect.
Who else receives it
Only these, and only what each row says. The list is generated from the services this deployment is actually configured to use; the same list, with each recipient's role, is on the sub-processors page.
| Service | What it receives | Provider | Based in |
|---|---|---|---|
| Hosting | Everything the application stores, on the server it runs on. | netcup GmbH (Germany) | Germany |
| Google (Sign in with Google) | Your name, email address and Google account identifier, when you choose to sign in with Google. | Google Ireland Ltd / Google LLC | Ireland / United States |
| Email delivery (smtpout.secureserver.net) | Your email address and the contents of every email ScoutTide sends: account emails (verification, password reset, invitations), billing and trial emails, the morning digest, messages sent through the contact and feedback forms, reminders to add a product, and service notices to organisation managers. | GoDaddy (GoDaddy.com, LLC, "Secureserver" mail) (United States) | United States |
| AI model service (Gonka24) | The text of the tender or post being worked on, plus your organisation profile and product descriptions, for matching, profile building, generating search feeds, reading tender documents and translation. No account credentials are ever sent. | Operator of api.gonka24.com | Location not confirmed |
| AI model service (Ollama) | The text of the tender or post being worked on, plus your organisation profile and product descriptions, for matching, profile building, generating search feeds, reading tender documents and translation. No account credentials are ever sent. | Ollama, Inc. (United States) | United States |
| AI model service (Bitdeer AI) | The text of the tender or post being worked on, plus your organisation profile and product descriptions, for matching, profile building, generating search feeds, reading tender documents and translation. No account credentials are ever sent. | Bitdeer Technologies (Singapore) | Singapore |
| Text similarity (embeddings) | A short excerpt of each tender or post and of your product descriptions, to find likely matches. No personal data about you is sent. | Bitdeer Technologies (Singapore) | Singapore |
| Payments (Paddle) | Your organisation's name, the buyer's name, email address, country and payment details, to take payment, charge tax and issue invoices. Paddle is the merchant of record and handles this as a controller in its own right. | Paddle.com Market Ltd (United Kingdom) | United Kingdom |
| Web search (Serper) | The search terms of feeds you create, for example an Upwork or LinkedIn query. No personal data is sent. | Serper | Location not confirmed |
| Web search (SerpApi) | The search terms of feeds you create, for example an Upwork or LinkedIn query. No personal data is sent. | SerpApi (United States) | United States |
| Web search (Tavily) | The search terms of feeds you create, for example an Upwork or LinkedIn query. No personal data is sent. | AlphaAI Technologies Inc. (Tavily) (United States) | United States |
| Web search (Exa) | The search terms of feeds you create, for example an Upwork or LinkedIn query. No personal data is sent. | Exa (United States) | United States |
| Web search (DataForSEO) | The search terms of feeds you create, for example an Upwork or LinkedIn query. No personal data is sent. | DataForSEO OÜ (Estonia) | Estonia |
We do not sell personal data, and we do not use it for advertising or to train any model of our own. We may disclose data where the law requires it.
Transfers outside the EEA and UK
Application data is stored on servers in Germany. Some of the services above are based elsewhere, as the Based in column shows: in particular, the AI model services receive the text of tenders and posts together with your organisation profile and product descriptions, and may be in the United States or Singapore. Where data leaves the EEA or the UK, it goes only to a recipient in a country with an adequacy decision (including US companies certified under the EU–US Data Privacy Framework) or under the European Commission's Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), with the UK International Data Transfer Addendum for UK data, and with supplementary measures such as encryption in transit. Ask us for a copy of the safeguards that apply.
How long we keep it
- Your account and its activity: until you delete the account, or ask us to. When the only member of an Individual organisation deletes their account, the organisation is deleted with it after the same 14 days' grace as a manager's request.
- An organisation whose plan has ended: an organisation whose plan has ended and where nobody has signed in for 30 days is deleted after a further 180 days; the deletion is scheduled with 14 days' grace, during which any manager who signs in can stop it. A sign-in or a new plan starts the count again. An organisation a manager deleted: held for 14 days so it can be restored, then deleted.
- Backups: nightly database and document snapshots are kept for 14 days; database snapshots taken before each deployment are kept for up to 30 days. Deleted data has left every backup within 30 days.
- Sign-in tokens (verification, password reset): 7 days and 2 hours respectively, then they stop working.
- Invitations: an invitation expires after 30 days; revoked, expired and accepted invitations are deleted 30 days later.
- Documents: until the person who added them or a manager deletes them.
- Messages to support: as long as needed to deal with what you asked.
- Application and server logs: kept for up to 14 days, then overwritten; they are not archived.
- Invoices and payment records are kept by Paddle for as long as tax law requires.
- Payment notifications from Paddle (the messages Paddle sends us when a subscription starts, changes, ends or is refunded, which include the buyer's name, email address and billing address): those about your organisation's subscription are kept as its billing history until the organisation is deleted; any that matched no organisation or needed no action are deleted after 90 days.
- Public posts: until 30 days old. Tenders: until they close. Either stays longer only while a customer is working on it.
Your rights
Under the GDPR and the UK GDPR you can ask to access, correct, delete or take a copy of your data, to restrict how we use it, and to object to anything we do on the basis of legitimate interest. Most of it you can do yourself, in the app:
- See and take your data: Account → Download my data gives you everything we hold about you as a JSON file.
- Correct it: Account settings for your name, email and password.
- Delete it: Account → Delete account removes your personal data. Work that belongs to your organisation (a claim's history, an uploaded document) stays with the organisation, no longer attributed to you.
- Stop the digest: from any digest email or from Account settings.
For anything else, use the contact form. We answer within one month, and it costs nothing. You can also complain to a data protection supervisory authority, in particular the one where you live or work; in the UK that is the Information Commissioner's Office.
Automated decisions
A language model scores how relevant each tender or post is to your organisation's products, and can set low-scoring ones aside. It judges documents and posts, not people, nothing it does has a legal or similarly significant effect on anyone, and you can put back anything it set aside. See how we use AI.
Security
Everything travels over HTTPS (TLS). Passwords are hashed, sessions expire after a period of inactivity, every organisation's data is kept apart from every other's, and access to the servers is limited to the people who run the service.
Invitations
When a manager invites a colleague, we store that email address to admit them when they sign in. If you received an invitation you did not want, ignore it: it expires in 30 days and is deleted 30 days after that. Or tell us and we will delete it straight away.
Children
ScoutTide is a business tool and is not directed at anyone under 16 (or the higher age your country sets for consent to data processing). We do not knowingly collect personal data from children. If we learn that we have, we delete it promptly; tell us through the contact form if you believe we hold such data.
Changes
We post any change here with a new date, and email the managers of every organisation at least 30 days before a material change takes effect.