Last updated: 9 August 2026
FindWell monitors European public tenders and helps companies prepare bids. This notice explains what personal data we process, why, on what legal basis, how long we keep it, who we share it with, and the rights you have under the EU General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”) and the Dutch implementing law (Uitvoeringswet AVG).
FindWell is an automated public-procurement monitoring and bid-preparation service operated by Dani Boross, trading as FindWell, a sole proprietorship (eenmanszaak) registered in the Netherlands. For the personal data described in this notice, FindWell is the data controller (except where section 2 says we act as a processor).
We have not appointed a Data Protection Officer, as we are not required to under Article 37 GDPR; privacy enquiries reach us at the address above.
Where a purpose relies on our legitimate interest (Art. 6(1)(f)), you may object on grounds relating to your situation (see section 8); where it relies on consent (Art. 6(1)(a)), you may withdraw it at any time.
We do not sell your personal data, and we do not share it with third parties for their own purposes. The matching engine scores tenders against your profile; it does not make automated decisions producing legal or similarly significant effects about you (Art. 22 does not apply).
Separately from the account data above, FindWell processes a limited amount of business contact data about decision-makers at companies that take part in public procurement, to introduce our service. This section provides the information required by Article 14 GDPR (data not obtained directly from you).
The rights in section 8 and the right to complain to the Autoriteit Persoonsgegevens apply equally to this processing.
Each sub-processor is bound by a data processing agreement and processes personal data only on our instructions. We notify active users by email at least 14 days before adding or replacing a sub-processor, so you may object.
Your data is stored in the EU (Supabase/Frankfurt; Railway/europe-west4; Resend/Ireland; Vercel/Frankfurt). Some sub-processors process personal data outside the European Economic Area, currently in the United States: Clerk, OpenAI, and Stripe. For those transfers we rely on the European Commission’s Standard Contractual Clauses (Decision (EU) 2021/914), as incorporated into each provider’s data processing agreement, together with any supplementary measures required.
We apply appropriate technical and organisational measures under Article 32 GDPR, including: encryption in transit (TLS 1.2+) and at rest; two-step verification at sign-in (password plus a one-time email code, via Clerk); per-organisation data isolation so one customer cannot access another’s data; least-privilege access to production data over encrypted connections; managed backups within the EU; and a breach-response process to notify affected parties without undue delay.
You have the following rights (Articles 15–22 GDPR). To exercise any of them, email privacy@findwell.eu; we respond within one month (extendable by two months for complex requests, Art. 12(3)).
We do not use advertising or tracking cookies. The application uses only essential authentication cookies (secure, HTTP-only), set by us and by our authentication provider Clerk to keep you logged in. No third-party analytics or advertising scripts are loaded.
If you believe our processing infringes the GDPR you may lodge a complaint with the Dutch supervisory authority, the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl), or with the authority in your country of residence. You also have the right to an effective judicial remedy (Articles 78–79 GDPR).
We notify active users by email of material changes at least 14 days in advance. The current version is always available at /privacy.