Privacy Policy

Last updated: 9 August 2026

FindWell monitors European public tenders and helps companies prepare bids. This notice explains what personal data we process, why, on what legal basis, how long we keep it, who we share it with, and the rights you have under the EU General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”) and the Dutch implementing law (Uitvoeringswet AVG).

1. Who we are

FindWell is an automated public-procurement monitoring and bid-preparation service operated by Dani Boross, trading as FindWell, a sole proprietorship (eenmanszaak) registered in the Netherlands. For the personal data described in this notice, FindWell is the data controller (except where section 2 says we act as a processor).

  • Chamber of Commerce (KVK): 92838812 · VAT (BTW): NL617537185B01
  • Address: Van Vollenhovenstraat 3, apt 213, 3016 BE Rotterdam, Netherlands
  • Privacy enquiries: privacy@findwell.eu

We have not appointed a Data Protection Officer, as we are not required to under Article 37 GDPR; privacy enquiries reach us at the address above.

2. When we are a controller and when we are a processor

  • We are the controller for the data we decide the purposes of: your account and profile data, prospect outreach data, billing data, and our own operational and security data. This notice governs that processing.
  • We are a processor for personal data that you choose to enter into the Service about other people (for example, a contact name in a note, or a colleague you invite). For that data you are the controller and we process it on your instructions under our Data Processing Agreement (DPA), available on request at privacy@findwell.eu.

3. What data we process, why, and for how long

Where a purpose relies on our legitimate interest (Art. 6(1)(f)), you may object on grounds relating to your situation (see section 8); where it relies on consent (Art. 6(1)(a)), you may withdraw it at any time.

Provide the Service — matching tenders to your rules, generating analyses you request, sending digests/notifications, account and team management
Legal basisArt. 6(1)(b) — performance of the contract
Personal dataAccount data (name, email, company); profile data (industry, keywords, CPV codes, value ranges, schedule); application data (rules, saved tenders, tasks, invited team members, comments, notes)
RetentionWhile your account is active; deleted or anonymised within 30 days of account closure
Keep the Service secure and prevent abuse
Legal basisArt. 6(1)(f) — legitimate interest in the security and integrity of the Service
Personal dataTechnical data (IP address, request metadata, security logs)
RetentionOnly as long as necessary for security, then deleted
Improve the product
Legal basisArt. 6(1)(f) — legitimate interest
Personal dataAggregated/anonymised usage data. We do not use your keywords, company data, or bid content to train machine-learning models.
RetentionAggregated, anonymised data that does not identify you may be kept indefinitely
Billing and statutory financial records
Legal basisArt. 6(1)(c) — legal obligation (Dutch tax and accounting law)
Personal dataSubscription and invoice data. Card data is handled by Stripe directly and never reaches FindWell
Retention7 years (Dutch fiscal retention obligation, art. 52 AWR / art. 2:10 BW)
Handle your data-protection requests
Legal basisArt. 6(1)(c) — legal obligation
Personal dataYour contact details, the request, and the steps we took
RetentionAs long as needed to evidence compliance
Keep records of any personal data breach
Legal basisArt. 6(1)(c) (Art. 33(5) GDPR)
Personal dataData of affected individuals; the facts and remedial steps
RetentionAs long as needed to evidence compliance
Optional communications you opt into
Legal basisArt. 6(1)(a) — consent
Personal dataEmail address and your preferences
RetentionUntil you withdraw consent

We do not sell your personal data, and we do not share it with third parties for their own purposes. The matching engine scores tenders against your profile; it does not make automated decisions producing legal or similarly significant effects about you (Art. 22 does not apply).

4. Business outreach to prospective customers

Separately from the account data above, FindWell processes a limited amount of business contact data about decision-makers at companies that take part in public procurement, to introduce our service. This section provides the information required by Article 14 GDPR (data not obtained directly from you).

What we process
DetailName, business email address, job role, employer, and the company’s publicly recorded public-procurement activity (tenders bid on or won)
Source
DetailPublic official sources — the EU Tenders Electronic Daily (TED), TenderNed, and public contract-award notices. Not from private accounts or consumer data brokers
Purpose & legal basis
DetailTo send a small number of relevant business emails. Art. 6(1)(f) — our legitimate interest in promoting a professional service to businesses for whom it is relevant. We have completed a legitimate-interests assessment (LIA), available on request, and only contact a company when our system has found procurement activity relevant to it
Your choices
DetailEvery email has one-click unsubscribe. You may object at any time (unsubscribe, reply, or email privacy@findwell.eu); we stop immediately and add your address to a suppression list so you are not contacted again
Retention
DetailNo longer than 12 months from collection or last contact, then deleted — except a minimal suppression record kept solely to honour your opt-out
Sub-processors
DetailSmartlead (email delivery/sequencing) and MillionVerifier (email-address validation), each under a data processing agreement, with SCCs where data is processed outside the EEA

The rights in section 8 and the right to complain to the Autoriteit Persoonsgegevens apply equally to this processing.

5. Who processes data on our behalf (sub-processors)

Each sub-processor is bound by a data processing agreement and processes personal data only on our instructions. We notify active users by email at least 14 days before adding or replacing a sub-processor, so you may object.

Supabase
PurposeDatabase & storage of your account and application data
RegionEU (AWS eu-central-1, Frankfurt)
Railway
PurposeTender-processing / background infrastructure
RegionEU (europe-west4, Netherlands)
Resend
PurposeTransactional email (digests, notifications)
RegionEU (Ireland)
Vercel
PurposeWeb application hosting / edge delivery
RegionEU (Frankfurt, fra1)
Clerk
PurposeAuthentication / sign-in (name, email, session)
RegionUS
Stripe
PurposePayment processing (card data handled by Stripe; never reaches us)
RegionEU / US
OpenAI
PurposeAI analysis of tender documents and your profile (API — not used to train their models)
RegionUS

6. International data transfers

Your data is stored in the EU (Supabase/Frankfurt; Railway/europe-west4; Resend/Ireland; Vercel/Frankfurt). Some sub-processors process personal data outside the European Economic Area, currently in the United States: Clerk, OpenAI, and Stripe. For those transfers we rely on the European Commission’s Standard Contractual Clauses (Decision (EU) 2021/914), as incorporated into each provider’s data processing agreement, together with any supplementary measures required.

7. How we keep your data secure

We apply appropriate technical and organisational measures under Article 32 GDPR, including: encryption in transit (TLS 1.2+) and at rest; two-step verification at sign-in (password plus a one-time email code, via Clerk); per-organisation data isolation so one customer cannot access another’s data; least-privilege access to production data over encrypted connections; managed backups within the EU; and a breach-response process to notify affected parties without undue delay.

8. Your rights under the GDPR

You have the following rights (Articles 15–22 GDPR). To exercise any of them, email privacy@findwell.eu; we respond within one month (extendable by two months for complex requests, Art. 12(3)).

  • Access (Art. 15) — confirmation of whether we process your data, a copy, and details of the processing.
  • Rectification (Art. 16) — correct inaccurate or incomplete data.
  • Erasure / “right to be forgotten” (Art. 17) — deletion where the grounds apply.
  • Restriction (Art. 18) — limit processing in defined circumstances.
  • Data portability (Art. 20) — receive data you provided in a structured, machine-readable format where processing is based on consent or contract and carried out by automated means.
  • Object (Art. 21) — object to processing based on legitimate interest, on grounds relating to your situation; and object at any time to direct marketing, after which we stop.
  • Withdraw consent (Art. 7(3)) — where processing is based on consent, without affecting prior processing.
  • Not be subject to solely automated decisions with legal or similarly significant effect (Art. 22) — we do not make such decisions about you.

9. Cookies

We do not use advertising or tracking cookies. The application uses only essential authentication cookies (secure, HTTP-only), set by us and by our authentication provider Clerk to keep you logged in. No third-party analytics or advertising scripts are loaded.

10. Complaints and remedies

If you believe our processing infringes the GDPR you may lodge a complaint with the Dutch supervisory authority, the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl), or with the authority in your country of residence. You also have the right to an effective judicial remedy (Articles 78–79 GDPR).

11. Changes to this notice

We notify active users by email of material changes at least 14 days in advance. The current version is always available at /privacy.