Tendrova
GDPR notice

Privacy notice

This notice explains who processes data, what we use, why, for how long, and the rights available to you.

Last updated: 2026-08-02

Controller

ReRoot d.o.o., Ribarska 4, Osijek, Hrvatska, OIB 53340601457, VAT ID HR53340601457, is the controller. Privacy and rights requests: info@tendrova.com. No DPO has been appointed; a responsible ReRoot contact handles requests.

Data categories

We process data you provide, service-generated data, provider data, and relevant public data.

  • Account/authentication, email, identifiers and security events.
  • Workspace, members, roles, profile, offerings, locations, CPV codes, keywords and settings.
  • Matches, saved/dismissed opportunities, searches, notifications and bounded operational telemetry.
  • Subscription, address, tax identifier, Stripe IDs, invoices and refunds; ReRoot does not receive full card numbers.
  • Support, complaints, unsubscribes, language and email preferences.
  • Device/security data, cookies, local storage and consent evidence.
  • Public TED contact details contained in procurement notices.

Purposes and legal bases

Contract: accounts, workspaces, matching, requested notifications, support and subscriptions. Legal obligation: tax, accounting, authority requests and consumer complaints.

Legitimate interests: security, abuse prevention, reliability, bounded aggregate telemetry, and reuse of relevant public procurement information, subject to necessity and balancing assessments.

Consent: Google Analytics, Google Ads, Meta Pixel, remarketing and optional marketing. Consent can be withdrawn without losing the core service.

Required and optional data

Email, authentication and essential billing fields are contract requirements. Profile data is needed for useful matching. Marketing consent and most extra profile fields are optional.

Recipients, processors, and transfers

Recipients include Firebase/Google Cloud, Vercel, Stripe, Resend, OpenAI, consented Google Analytics/Ads and Meta, advisers, and authorities as necessary.

We use processing agreements and, for transfers outside the EEA, adequacy decisions or Standard Contractual Clauses with transfer assessments and supplementary measures. Request relevant safeguards by email.

AI and automation

Selected company descriptions, offerings, keywords, and CPV codes may be sent to OpenAI for analysis or embeddings. Credentials, card data, and unnecessary identifiers are excluded.

Tendrova makes no solely automated decision producing legal or similarly significant effects. Users decide whether to examine or participate in procurement.

Public TED data — GDPR Article 14

Names, business roles, organizations, business emails, phones, and addresses may come from public TED notices and official documents. We display and connect this data under legitimate interests in transparent access to procurement.

Data is available to subscribers and necessary processors while the official notice remains relevant. Where individual notice would involve disproportionate effort, this public notice is used with minimisation, correction, and justified display-suppression measures.

Retention

Account data lasts for the contract. After confirmed deletion, operational content is removed within 30 days and backups expire within 90 days unless a legal hold applies. Security logs are planned for up to 12 months.

Consent evidence lasts for consent plus three years, complaints at least one year, and accounting evidence at least 11 years where required. Providers may have separate legal retention duties.

Your rights

You may request access, copy, correction, erasure, restriction, portability, or object to legitimate interests and direct marketing. Withdraw consent in Cookie Settings or by email.

Contact info@tendrova.com. We may proportionately verify identity and normally respond within one month. Mandatory accounting/evidence records remain protected until expiry. You may complain to the Croatian Personal Data Protection Agency (AZOP).

Security and incidents

We use access controls, workspace boundaries, encryption in transit, least privilege, security logging, and vendor management. No system is completely secure. We assess incidents and notify AZOP and affected people when GDPR requires it.

info@tendrova.com