Privacy Policy
How we collect, use, and protect your personal data.
Last updated: 17 February 2026
Who we are
BidScout is operated by NETTLEPIE Korlátolt Felelősségű Társaság (Nettlepie Kft.), a company registered in Hungary.
- Registered address: 7621 Pécs, Apáca utca 19., Hungary
- Company registration: 01-09-404721
- Tax number: 32056945-2-02
- EU VAT: HU32056945
- Contact: hello@bidscout.eu
When we say “BidScout”, “we”, or “us” in this policy, we mean Nettlepie Kft.
What we collect
We collect the following categories of personal data:
- Account data — email address and hashed password when you create an account.
- Company profile — company name, country, city, company size, website, industry, description, skills, certifications, and procurement preferences you provide during onboarding.
- Usage data — saved tenders, feedback on matches (interested / not relevant), and AI-generated match scores.
- Notification preferences — your email alert settings.
Why we collect it
We use your data for the following purposes:
- AI tender matching — we generate embeddings from your company profile to match you with relevant public procurement opportunities.
- Email alerts — we send daily digest emails with your top tender matches based on your notification preferences.
- Account management — authentication, password resets, and email verification.
- Product improvement — we use aggregated, anonymised usage data to improve our matching algorithms and user experience.
Third-party processors
We share your data with the following service providers who process it on our behalf:
- Vercel (San Francisco, USA) — hosting and serverless infrastructure.
- Neon (San Francisco, USA) — PostgreSQL database with pgvector.
- OpenRouter (San Francisco, USA) — AI embeddings and tender summaries.
- Postmark by ActiveCampaign (USA) — transactional email delivery.
All US-based processors are selected for their compliance with data protection standards. We do not sell your data to third parties.
Cookies
BidScout uses a single session cookie (NextAuth JWT) to keep you signed in. This cookie is strictly necessary for the service to function and does not require consent.
We do not use tracking cookies, analytics cookies, or any third-party advertising cookies.
Data security
We protect your data with the following measures:
- Passwords are hashed using bcrypt before storage — we never store plaintext passwords.
- Email verification and password reset tokens use HMAC-SHA256 signatures.
- All connections use HTTPS encryption in transit.
- Database is encrypted at rest (Neon).
Data retention
- Account data is kept for as long as your account is active. You can request deletion at any time.
- Usage data (saved tenders, feedback) is deleted when your account is deleted.
Your rights under GDPR
As a data subject in the EU, you have the right to:
- Access — request a copy of your personal data.
- Rectification — correct inaccurate data.
- Erasure — request deletion of your data.
- Portability — receive your data in a machine-readable format.
- Restriction — limit how we process your data.
- Objection — object to processing based on legitimate interests.
- Lodge a complaint — file a complaint with the Hungarian National Authority for Data Protection and Freedom of Information (NAIH) at naih.hu.
To exercise any of these rights, contact us at hello@bidscout.eu.
Changes to this policy
We may update this privacy policy from time to time. For material changes, we will notify registered users by email. The “last updated” date at the top reflects the most recent revision.
Contact
Questions about this privacy policy? Email us at hello@bidscout.eu.