Privacy Policy
Last updated: 2026
Imprint: vergabefix is a German company. This Privacy Policy is governed by German law, specifically the General Data Protection Regulation (GDPR/DSGVO) and the German Federal Data Protection Act (BDSG). This English translation is provided for your convenience. In case of any discrepancy, the German version shall prevail.
Understanding German Data Protection Terms
DSGVO (Datenschutz-Grundverordnung): The German term for GDPR - General Data Protection Regulation, the EU's comprehensive data protection law.
BDSG (Bundesdatenschutzgesetz): German Federal Data Protection Act, the national implementation of GDPR in Germany.
Auftragsverarbeitung: Data Processing Agreement (DPA) - a contract required when third parties process personal data on behalf of a company.
UG (haftungsbeschränkt) i.G. (Entrepreneurial Company with Limited Liability, in formation): A recognized German corporate structure designed for innovative startups, offering full limited liability protection while we complete our formal registration.
1. Data Controller
The data controller within the meaning of the General Data Protection Regulation (GDPR) is:
vergabefix UG i.G.
Bohmter Straße 75
49074 Osnabrück
Germany
Represented by: Managing Director: Michael Keno Neese
Email: info@vergabefix.de
2. Legal Basis for Data Processing
This Privacy Policy informs you about the nature, scope, and purpose of the processing of personal data within our online offering and related websites, functions, and content (collectively referred to as "Platform" or "Online Offering").
We process personal data only in compliance with applicable data protection regulations, in particular the GDPR and BDSG. Processing only occurs when one of the following legal bases applies:
- Art. 6(1)(a) GDPR (Consent): The data subject has given consent to the processing.
- Art. 6(1)(b) GDPR (Contract Performance): Processing is necessary for the performance of a contract or for pre-contractual measures.
- Art. 6(1)(c) GDPR (Legal Obligation): Processing is necessary for compliance with a legal obligation.
- Art. 6(1)(f) GDPR (Legitimate Interests): Processing is necessary for the purposes of legitimate interests, unless overridden by the data subject's interests.
Types of Data Processed
- Inventory Data: Names, addresses, company information
- Contact Data: Email addresses, phone numbers
- Contract Data: Contract subject, duration, payment information
- Usage Data: Pages visited, access times, interactions
- Content Data: Form entries, company profile data
- Communication Data: Email correspondence, support inquiries
Categories of Data Subjects
Platform users, business customers, prospects, communication partners, and visitors to the online offering.
3. Your Rights
You have the following rights regarding your personal data:
- Right of Access (Art. 15 GDPR): You may request information about your personal data processed by us.
- Right to Rectification (Art. 16 GDPR): You may request correction of inaccurate or completion of incomplete data.
- Right to Erasure (Art. 17 GDPR): You may request deletion of your data, unless statutory retention obligations apply.
- Right to Restriction (Art. 18 GDPR): You may request restriction of the processing of your data.
- Right to Data Portability (Art. 20 GDPR): You may request to receive your data in a structured, commonly used format.
- Right to Object (Art. 21 GDPR): You may object to processing based on legitimate interests.
- Right to Withdraw Consent (Art. 7(3) GDPR): You may withdraw consent at any time with effect for the future.
- Right to Lodge a Complaint (Art. 77 GDPR): You have the right to lodge a complaint with a supervisory authority.
To exercise your rights, please contact: info@vergabefix.de
Competent Supervisory Authority:
Die Landesbeauftragte für den Datenschutz Niedersachsen
(Lower Saxony Data Protection Commissioner)
Prinzenstraße 5, 30159 Hannover, Germany
Website: www.lfd.niedersachsen.de
4. Security Measures
In accordance with Art. 32 GDPR, we implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, implementation costs, and the nature, scope, context, and purposes of processing.
Our measures include:
- Encrypted data transmission using TLS/SSL (HTTPS)
- Encrypted storage of sensitive data
- Access control and authentication mechanisms
- Regular security updates and monitoring
- Physical security of server infrastructure
- Regular data backups
5. Hosting and Infrastructure
Our platform is hosted on Amazon Web Services (AWS) servers in the Frankfurt region (eu-central-1).
Provider: Amazon Web Services EMEA SARL
38 Avenue John F. Kennedy, L-1855 Luxembourg
Privacy Policy: aws.amazon.com/privacy/
AWS is certified according to ISO 27001, SOC 2, and other standards. A Data Processing Agreement (DPA) is in place with AWS. Data processing occurs exclusively within the EU.
Legal Basis: Art. 6(1)(f) GDPR (legitimate interest in secure and efficient provision of our online offering).
6. Access Data and Log Files
Information is automatically collected and stored in server log files with each access to our servers:
- Browser type and version
- Operating system used
- Referrer URL (previously visited page)
- IP address of the accessing device
- Date and time of access
- Files accessed and data volume transferred
- Access status message
This data is stored for a maximum of 90 days and then automatically deleted. Data required for evidence purposes is exempt from deletion until the respective incident is finally resolved.
Legal Basis: Art. 6(1)(f) GDPR (legitimate interest in security and stability of the offering and investigation of misuse).
8. Registration and User Account
Registration is required to use our platform. During registration, we collect the following data:
Required Information:
- Email address
- Name (first and last name)
- Password (stored encrypted)
Optional Information (for optimal platform use):
- Company data (company name, address, legal form)
- Contact information (phone, website)
- Financial data (revenue, insurance)
- References and certifications
- CPV codes and areas of expertise
The optional information is used for platform personalization and automatic eligibility matching for tenders.
During registration and subsequent logins, we store the IP address and time of the action. This serves to protect against misuse.
Legal Basis: Art. 6(1)(b) GDPR (contract performance) and Art. 6(1)(f) GDPR (legitimate interest in protection against misuse).
9. Use of the vergabefix Platform
In connection with the use of our platform, we process:
- Search Queries: Your search terms and filter settings to display relevant tenders.
- Alert Settings: Your saved search profiles for automatic notifications.
- Profile Information: The company data you enter for eligibility matching.
- Usage Statistics: Information about your interactions with the platform.
Tender data originates from public sources (TED, Bund.de) and is aggregated and processed by us.
Legal Basis: Art. 6(1)(b) GDPR (contract performance).
10. AI-Powered Features
Our platform uses AI services from OpenAI for certain features:
- Semantic search
- Automatic tender summaries (Executive Summary)
Provider: OpenAI, L.L.C.
3180 18th Street, San Francisco, CA 94110, USA
Privacy Policy: openai.com/privacy
Important Privacy Note:
Only non-sensitive data is transmitted to OpenAI:
- Search terms
- Publicly available tender texts
NOT transmitted to OpenAI:
- Sensitive company data (financial data, revenue)
- Insurance information
- Bank details
- Personal data from your profile
Transmission occurs via an encrypted connection. OpenAI processes the data in accordance with their privacy policy and the Data Processing Agreement concluded with us.
Legal Basis: Art. 6(1)(b) GDPR (contract performance) and Art. 6(1)(f) GDPR (legitimate interest in providing AI-powered features).
11. Payment Processing
We use external payment service providers for payment processing:
Klarna
Provider: Klarna Bank AB
Sveavägen 46, 111 34 Stockholm, Sweden
Privacy Policy: klarna.com/international/privacy-policy/
PayPal
Provider: PayPal (Europe) S.à r.l. et Cie, S.C.A.
22-24 Boulevard Royal, L-2449 Luxembourg
Privacy Policy: paypal.com/webapps/mpp/ua/privacy-full
Payment data (e.g., bank details, credit card numbers) is transmitted directly to the payment service provider during payment. We do not store complete payment data.
Legal Basis: Art. 6(1)(b) GDPR (contract performance).
12. Contact
When you contact us (by email, contact form, or ticket system), your information is stored for processing your inquiry and for possible follow-up questions.
Data processed:
- Name
- Email address
- Message content
- Time of inquiry
The data is deleted as soon as it is no longer required for the purpose for which it was collected and no statutory retention obligations apply.
Legal Basis: Art. 6(1)(b) GDPR (pre-contractual measures or contract performance) or Art. 6(1)(f) GDPR (legitimate interest in answering inquiries).
14. Web Analytics with Google Analytics
We use Google Analytics, a web analytics service provided by Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.
Purpose: Analysis of website usage to improve our offering.
IP Anonymization: We use Google Analytics with IP anonymization enabled. This means that your IP address is truncated by Google within EU member states or other EEA countries. Only in exceptional cases is the full IP address transferred to a Google server in the USA and truncated there.
Data Processed:
- Truncated IP address
- Pages visited and time spent
- Technical information (browser, operating system, screen resolution)
- Source of visit (referrer)
Retention Period: Data is stored for 14 months and then automatically deleted.
Opt-Out: You can prevent Google Analytics collection:
- By declining in the cookie banner
- By installing the browser add-on: tools.google.com/dlpage/gaoptout
More information: policies.google.com/privacy
Legal Basis: Art. 6(1)(a) GDPR (consent via cookie banner).
15. Google Fonts
We use Google Fonts to display external fonts. Google Fonts is a service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
When you visit our website, a connection to Google servers is established to load the fonts. Your IP address is transmitted to Google in the process.
More information: developers.google.com/fonts/faq
Privacy Policy: policies.google.com/privacy
Legal Basis: Art. 6(1)(f) GDPR (legitimate interest in an appealing presentation of our online offering).
16. Appointment Scheduling with Calendly
We use the scheduling service Calendly for booking onboarding meetings:
Provider: Calendly, LLC
271 17th St NW, Ste 1000, Atlanta, GA 30363, USA
Privacy Policy: calendly.com/privacy
The following data is collected when booking an appointment:
- Name
- Email address
- Selected appointment
- Optional: Additional information you provide
Calendly is certified under the EU-U.S. Data Privacy Framework.
Legal Basis: Art. 6(1)(b) GDPR (pre-contractual measures).
17. Disclosure of Data
Data is only disclosed to third parties in accordance with legal requirements:
- Data Processors: We use external service providers as data processors (e.g., for hosting, payment processing, newsletter delivery). Data Processing Agreements are in place with these providers.
- Legal Obligation: If we are legally obligated to do so or on the basis of a court order.
- Protection of Our Rights: If necessary for the assertion, exercise, or defense of legal claims.
Third-Country Transfers: If data is transferred to third countries (outside the EU/EEA), this only occurs if an adequate level of data protection is ensured (e.g., through EU Commission adequacy decisions, Standard Contractual Clauses, or certification under the EU-U.S. Data Privacy Framework).
We do not sell data to third parties.
18. Data Deletion
Data stored by us is deleted as soon as it is no longer required for its intended purpose and deletion is not precluded by statutory retention obligations.
After Contract Termination:
- Your data will be retained for 30 days to allow you to export your data.
- After the 30-day period, the data will be irrevocably deleted.
- You can request a data export by email at any time.
Statutory Retention Obligations (German Law):
- 6 years pursuant to § 257(1) HGB (commercial letters, accounting records)
- 10 years pursuant to § 147(1) AO (books, records, tax-relevant documents)
If data must be retained due to legal obligations, its processing will be restricted (blocked).
19. Changes to this Privacy Policy
We reserve the right to update this Privacy Policy to adapt it to changed legal situations or changes to the service and data processing.
The current version is always available on our website. For significant changes, we will notify you by email or through the platform.
We recommend that you regularly review this Privacy Policy.
Contact for Privacy Questions
For questions about data protection, please contact:
vergabefix UG i.G.
Bohmter Straße 75
49074 Osnabrück
Germany
Represented by: Managing Director: Michael Keno Neese
Email: info@vergabefix.de