Privacy Policy

Last updated: 2026

Imprint: vergabefix is a German company. This Privacy Policy is governed by German law, specifically the General Data Protection Regulation (GDPR/DSGVO) and the German Federal Data Protection Act (BDSG). This English translation is provided for your convenience. In case of any discrepancy, the German version shall prevail.

Understanding German Data Protection Terms

DSGVO (Datenschutz-Grundverordnung): The German term for GDPR - General Data Protection Regulation, the EU's comprehensive data protection law.

BDSG (Bundesdatenschutzgesetz): German Federal Data Protection Act, the national implementation of GDPR in Germany.

Auftragsverarbeitung: Data Processing Agreement (DPA) - a contract required when third parties process personal data on behalf of a company.

UG (haftungsbeschränkt) i.G. (Entrepreneurial Company with Limited Liability, in formation): A recognized German corporate structure designed for innovative startups, offering full limited liability protection while we complete our formal registration.

1. Data Controller

The data controller within the meaning of the General Data Protection Regulation (GDPR) is:

vergabefix UG i.G.

Bohmter Straße 75

49074 Osnabrück

Germany

Represented by: Managing Director: Michael Keno Neese

Email: info@vergabefix.de

3. Your Rights

You have the following rights regarding your personal data:

  • Right of Access (Art. 15 GDPR): You may request information about your personal data processed by us.
  • Right to Rectification (Art. 16 GDPR): You may request correction of inaccurate or completion of incomplete data.
  • Right to Erasure (Art. 17 GDPR): You may request deletion of your data, unless statutory retention obligations apply.
  • Right to Restriction (Art. 18 GDPR): You may request restriction of the processing of your data.
  • Right to Data Portability (Art. 20 GDPR): You may request to receive your data in a structured, commonly used format.
  • Right to Object (Art. 21 GDPR): You may object to processing based on legitimate interests.
  • Right to Withdraw Consent (Art. 7(3) GDPR): You may withdraw consent at any time with effect for the future.
  • Right to Lodge a Complaint (Art. 77 GDPR): You have the right to lodge a complaint with a supervisory authority.

To exercise your rights, please contact: info@vergabefix.de

Competent Supervisory Authority:

Die Landesbeauftragte für den Datenschutz Niedersachsen

(Lower Saxony Data Protection Commissioner)

Prinzenstraße 5, 30159 Hannover, Germany

Website: www.lfd.niedersachsen.de

4. Security Measures

In accordance with Art. 32 GDPR, we implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, implementation costs, and the nature, scope, context, and purposes of processing.

Our measures include:

  • Encrypted data transmission using TLS/SSL (HTTPS)
  • Encrypted storage of sensitive data
  • Access control and authentication mechanisms
  • Regular security updates and monitoring
  • Physical security of server infrastructure
  • Regular data backups

5. Hosting and Infrastructure

Our platform is hosted on Amazon Web Services (AWS) servers in the Frankfurt region (eu-central-1).

Provider: Amazon Web Services EMEA SARL

38 Avenue John F. Kennedy, L-1855 Luxembourg

Privacy Policy: aws.amazon.com/privacy/

AWS is certified according to ISO 27001, SOC 2, and other standards. A Data Processing Agreement (DPA) is in place with AWS. Data processing occurs exclusively within the EU.

Legal Basis: Art. 6(1)(f) GDPR (legitimate interest in secure and efficient provision of our online offering).

6. Access Data and Log Files

Information is automatically collected and stored in server log files with each access to our servers:

  • Browser type and version
  • Operating system used
  • Referrer URL (previously visited page)
  • IP address of the accessing device
  • Date and time of access
  • Files accessed and data volume transferred
  • Access status message

This data is stored for a maximum of 90 days and then automatically deleted. Data required for evidence purposes is exempt from deletion until the respective incident is finally resolved.

Legal Basis: Art. 6(1)(f) GDPR (legitimate interest in security and stability of the offering and investigation of misuse).

7. Cookies

Our website uses cookies. Cookies are small text files stored on your device that store certain settings and data for exchange with our system via your browser.

Types of Cookies

Technically Necessary Cookies (Session Cookies):

These cookies are essential for the operation of the website. They enable basic functions such as page navigation, login status, and access to protected areas. These cookies are set without your consent.

Analytics Cookies:

These cookies help us understand how visitors interact with our website by anonymously collecting and reporting information. These cookies are only set with your consent.

Cookie Settings

On your first visit to our website, you will be asked for your consent to non-necessary cookies via a cookie banner. You can change your settings at any time via the "Cookie Settings" link in the footer.

You can also manage or delete cookies in your browser settings. Excluding cookies may result in functional limitations.

Legal Basis: Art. 6(1)(a) GDPR (consent) for non-necessary cookies; Art. 6(1)(f) GDPR (legitimate interest) for technically necessary cookies.

8. Registration and User Account

Registration is required to use our platform. During registration, we collect the following data:

Required Information:

  • Email address
  • Name (first and last name)
  • Password (stored encrypted)

Optional Information (for optimal platform use):

  • Company data (company name, address, legal form)
  • Contact information (phone, website)
  • Financial data (revenue, insurance)
  • References and certifications
  • CPV codes and areas of expertise

The optional information is used for platform personalization and automatic eligibility matching for tenders.

During registration and subsequent logins, we store the IP address and time of the action. This serves to protect against misuse.

Legal Basis: Art. 6(1)(b) GDPR (contract performance) and Art. 6(1)(f) GDPR (legitimate interest in protection against misuse).

9. Use of the vergabefix Platform

In connection with the use of our platform, we process:

  • Search Queries: Your search terms and filter settings to display relevant tenders.
  • Alert Settings: Your saved search profiles for automatic notifications.
  • Profile Information: The company data you enter for eligibility matching.
  • Usage Statistics: Information about your interactions with the platform.

Tender data originates from public sources (TED, Bund.de) and is aggregated and processed by us.

Legal Basis: Art. 6(1)(b) GDPR (contract performance).

10. AI-Powered Features

Our platform uses AI services from OpenAI for certain features:

  • Semantic search
  • Automatic tender summaries (Executive Summary)

Provider: OpenAI, L.L.C.

3180 18th Street, San Francisco, CA 94110, USA

Privacy Policy: openai.com/privacy

Important Privacy Note:

Only non-sensitive data is transmitted to OpenAI:

  • Search terms
  • Publicly available tender texts

NOT transmitted to OpenAI:

  • Sensitive company data (financial data, revenue)
  • Insurance information
  • Bank details
  • Personal data from your profile

Transmission occurs via an encrypted connection. OpenAI processes the data in accordance with their privacy policy and the Data Processing Agreement concluded with us.

Legal Basis: Art. 6(1)(b) GDPR (contract performance) and Art. 6(1)(f) GDPR (legitimate interest in providing AI-powered features).

11. Payment Processing

We use external payment service providers for payment processing:

Klarna

Provider: Klarna Bank AB

Sveavägen 46, 111 34 Stockholm, Sweden

Privacy Policy: klarna.com/international/privacy-policy/

PayPal

Provider: PayPal (Europe) S.à r.l. et Cie, S.C.A.

22-24 Boulevard Royal, L-2449 Luxembourg

Privacy Policy: paypal.com/webapps/mpp/ua/privacy-full

Payment data (e.g., bank details, credit card numbers) is transmitted directly to the payment service provider during payment. We do not store complete payment data.

Legal Basis: Art. 6(1)(b) GDPR (contract performance).

12. Contact

When you contact us (by email, contact form, or ticket system), your information is stored for processing your inquiry and for possible follow-up questions.

Data processed:

  • Name
  • Email address
  • Message content
  • Time of inquiry

The data is deleted as soon as it is no longer required for the purpose for which it was collected and no statutory retention obligations apply.

Legal Basis: Art. 6(1)(b) GDPR (pre-contractual measures or contract performance) or Art. 6(1)(f) GDPR (legitimate interest in answering inquiries).

13. Newsletter

With your consent, you can subscribe to our newsletter, which keeps you informed about current news and offers.

Double Opt-In: Registration uses the double opt-in procedure. After registration, you will receive an email to confirm your registration. This confirmation is necessary to prevent anyone from registering with someone else's email address.

For newsletter delivery, we use:

Provider: rapidmail GmbH

Wentzingerstraße 21, 79106 Freiburg, Germany

Privacy Policy: rapidmail.de/datenschutz

Data Collected: Email address, optionally: name, registration time, IP address, confirmation time.

Statistical Analysis: Newsletters may contain a "web beacon" that is retrieved from our server when the newsletter is opened. This collects technical information such as browser information and IP address, as well as the time of retrieval. This information is used to technically improve our newsletter.

Unsubscribe: You can unsubscribe from the newsletter at any time. An unsubscribe link can be found at the end of each newsletter. After unsubscribing, your data will be deleted unless statutory retention obligations apply.

Legal Basis: Art. 6(1)(a) GDPR (consent).

14. Web Analytics with Google Analytics

We use Google Analytics, a web analytics service provided by Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.

Purpose: Analysis of website usage to improve our offering.

IP Anonymization: We use Google Analytics with IP anonymization enabled. This means that your IP address is truncated by Google within EU member states or other EEA countries. Only in exceptional cases is the full IP address transferred to a Google server in the USA and truncated there.

Data Processed:

  • Truncated IP address
  • Pages visited and time spent
  • Technical information (browser, operating system, screen resolution)
  • Source of visit (referrer)

Retention Period: Data is stored for 14 months and then automatically deleted.

Opt-Out: You can prevent Google Analytics collection:

More information: policies.google.com/privacy

Legal Basis: Art. 6(1)(a) GDPR (consent via cookie banner).

15. Google Fonts

We use Google Fonts to display external fonts. Google Fonts is a service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

When you visit our website, a connection to Google servers is established to load the fonts. Your IP address is transmitted to Google in the process.

More information: developers.google.com/fonts/faq

Privacy Policy: policies.google.com/privacy

Legal Basis: Art. 6(1)(f) GDPR (legitimate interest in an appealing presentation of our online offering).

16. Appointment Scheduling with Calendly

We use the scheduling service Calendly for booking onboarding meetings:

Provider: Calendly, LLC

271 17th St NW, Ste 1000, Atlanta, GA 30363, USA

Privacy Policy: calendly.com/privacy

The following data is collected when booking an appointment:

  • Name
  • Email address
  • Selected appointment
  • Optional: Additional information you provide

Calendly is certified under the EU-U.S. Data Privacy Framework.

Legal Basis: Art. 6(1)(b) GDPR (pre-contractual measures).

17. Disclosure of Data

Data is only disclosed to third parties in accordance with legal requirements:

  • Data Processors: We use external service providers as data processors (e.g., for hosting, payment processing, newsletter delivery). Data Processing Agreements are in place with these providers.
  • Legal Obligation: If we are legally obligated to do so or on the basis of a court order.
  • Protection of Our Rights: If necessary for the assertion, exercise, or defense of legal claims.

Third-Country Transfers: If data is transferred to third countries (outside the EU/EEA), this only occurs if an adequate level of data protection is ensured (e.g., through EU Commission adequacy decisions, Standard Contractual Clauses, or certification under the EU-U.S. Data Privacy Framework).

We do not sell data to third parties.

18. Data Deletion

Data stored by us is deleted as soon as it is no longer required for its intended purpose and deletion is not precluded by statutory retention obligations.

After Contract Termination:

  • Your data will be retained for 30 days to allow you to export your data.
  • After the 30-day period, the data will be irrevocably deleted.
  • You can request a data export by email at any time.

Statutory Retention Obligations (German Law):

  • 6 years pursuant to § 257(1) HGB (commercial letters, accounting records)
  • 10 years pursuant to § 147(1) AO (books, records, tax-relevant documents)

If data must be retained due to legal obligations, its processing will be restricted (blocked).

19. Changes to this Privacy Policy

We reserve the right to update this Privacy Policy to adapt it to changed legal situations or changes to the service and data processing.

The current version is always available on our website. For significant changes, we will notify you by email or through the platform.

We recommend that you regularly review this Privacy Policy.

Contact for Privacy Questions

For questions about data protection, please contact:

vergabefix UG i.G.

Bohmter Straße 75

49074 Osnabrück

Germany

Represented by: Managing Director: Michael Keno Neese

Email: info@vergabefix.de