Privacy policy

Last updated: October 2026

  1. 01

    Data controller

    The controller for your data is the operator of prokirixeis.gr. Contact: ioan.kapageridis@gmail.com.

  2. 02

    What we hold

    Your email, name, hashed password, the alerts you have created with the delivery hours and days you chose, and the history of emails we sent you. If you add recipients to an alert, we hold their email address, whether and when they confirmed or declined, their delivery schedule, and the history of emails we sent them. If you invite colleagues to your team, we keep their email address, when we sent them an invitation, whether and when they accepted, and the account they joined with. If another account invites you, it sees your name and the day you joined. Team members see and work on the bids of the account that invited them, and see its name and the other members’ names. A person named as responsible for a bid appears on it by name, and in the bid webhooks the team’s account has set up; the reference is deleted with that person’s account. A person assigned a task on a bid appears on it by name, never in the webhooks; the assignment is deleted with that person’s account. Comments on a bid show the team the name of whoever wrote them and of those they mention, never in the webhooks; your comments and the mentions of you are deleted with your account. Everyone on the team receives a morning email with what happened on its bids the day before: the names of those who commented, task titles and stages, never a comment’s text; a mention of you reaches only you. You stop it in Settings or from the link in the email. The team record is deleted with the account of the team’s owner or of the member. If you add tenders to your bids, we hold for each one the bid's stage and when it changed, and what you write yourself: the owner, the bid amount, a deadline of your own and the guarantee letters you record (kind, amount, issuer and dates). When you insert one of your library texts into a bid, we hold a copy of its title and text as they were at that moment, and which of its files you chose; the files stay in the library. If you declare a tax number (ΑΦΜ) in your settings, we hold the number and, from ΑΑΔΕ's answer, only the name its tax registry holds for it and when we checked it. If you declare ΜΗΤΕ classes in your settings, we hold the register, the category and the class you declared, and use them only for the «Only what fits my ΜΗΤΕ classes» filter in your search and alerts. If you declare activity codes (ΚΑΔ) or fetch them from ΓΕΜΗ, we hold the codes, where they came from and when. We use them only for the warning on a tender's page, and they are deleted with your account. If you subscribe, Stripe holds the payment details — we never see a card number. We keep two things Stripe gives us about your subscription: the card's fingerprint, a non-reversible Stripe identifier that is the same for the same card and from which no card number can be recovered, and the tax id you may have given at Stripe's checkout. We do not keep, and never see, a card number, an expiry date or a CVV. If you ask for business verification, we hold the ΑΦΜ you claimed, which kind of evidence you gave, the claim's status and when it was filed and decided. If the evidence is a paid invoice, we hold that invoice's Stripe id. If it is a ΓΕΜΗ certificate or a έναρξη εργασιών document, we hold the document itself. If you have a subscription on michanikosGPT, which has the same operator, then on every change to it — whatever its plan — michanikosGPT sends us your email, whether the subscription gives Pro, until when, and when it read that state. We do not keep the email: we keep only an irreversible fingerprint of it (SHA-256), whether the subscription gives Pro, until when, and when michanikosGPT read it, so that if you have or open an account here with the same verified email you get Pro at no charge. This applies whether or not you have an account here. If you connect a Slack or Teams channel to an alert, we hold the service, the name you gave it, when you confirmed you may post there, and the webhook URL only in encrypted form. We show the URL to nobody, you included, and never write it to a log. If you add a webhook to an alert, we hold the name you gave it, when you confirmed you may send there, and its address and signing secret only in encrypted form. We show you the secret once, when it is created, and never write either to a log. If you add a webhook for your bids, we hold the name you gave it, when you confirmed you may send there, and its address and signing secret only in encrypted form. We also hold every change to a bid as we sent it — the tender, the stage, the owner, the amount and the deadline — and whether it arrived. If you connect your Pipedrive, we keep the address of your account there, your company's and your user's number in Pipedrive, when you gave your consent, the stage mapping you chose, which deal each of your bids became, and the access Pipedrive gave us only encrypted. If you connect your HubSpot, we keep the number of your account there, when you gave your consent, the stage mapping you chose, which deal each of your bids became, and the access HubSpot gave us only encrypted. If you connect your Zoho CRM, we keep the data centre and the number of your organisation there, when you gave your consent, the stage mapping you chose, which deal each of your bids became, and the access Zoho gave us only encrypted. If you turn on push notifications in a browser, we hold the address its push service gave it and the two keys we encrypt what we send it with. They are deleted as soon as you turn push off in that browser, or as soon as the service answers that the address no longer exists. If you use the content library, we hold the texts you write there, their tags, the name of the responsible person you give, the review dates and the files you attach, such as CVs or certificates. Your account can see and download those files. If you have a team, its members who hold a seat can search your library’s texts and see their titles and tags, to insert them into one of your bids; every member of the team can read the texts inserted into your bids and download the files that came with them. If you record that you filed a request for access to an award's documents, we hold the day you filed it and the day the answer is due. We do not keep the request file. If you ask for a first draft of a technical offer, we keep the text the model wrote, the tender it was written for and the titles of your texts and works it drew on. Only your account sees and downloads the draft, and it is deleted with the account. If you fill in the ESPD profile, we hold your company's details and the answers you gave (exclusion grounds, certificates, turnover, reference contracts) until you delete them or the account is deleted. The notice's ESPD file you upload is read only to build the pre-filled file, and we do not keep it. If you fill in a compliance matrix, we hold the answers and references you write in it. Only your account can see and download them, and they are deleted with it. The matrix itself — the requirements from the tender documents — contains nothing about you. If you follow a tender, we hold which tender, when you started, whether you pressed follow or it started from a bid of yours or an alert's link, and, if you stopped, when, and which emails about its amendments we sent you and when. If you create API keys, we hold the name you gave each, its first characters, when it was created, when it was last used and when it was revoked. We do not keep the key itself: we keep only an irreversible fingerprint of it (SHA-256), so that we recognise it when you send it. We hold the same for browser-extension keys. With the key, the extension sends us only the ΑΔΑΜ or ΑΔΑ of the ΚΗΜΔΗΣ, ΕΣΗΔΗΣ or Διαύγεια page you have open, and we do not keep it. If you press «Add to my bids» in the extension, the tender goes into your bids, as when you press it here.

  3. 03

    Why we process it

    To provide the service (performance of a contract), to send the alerts you asked for, and to meet tax obligations where they arise. We send alerts to recipients you add only with their own consent: they give it through the link in the confirmation email, and we record when. They withdraw it with one click from any alert email. We are the controller for those addresses. We keep the card fingerprint and the Stripe checkout tax id for one reason: the free trial is offered once per business, and without them there is no way to establish that two accounts belong to the same business. When that happens the trial is not started, the subscription is cancelled with nothing charged, and the pair of accounts is shown to an administrator. No account is ever blocked automatically, and a person can undo the flag. The same holds when the earlier account has since been deleted, through the code section 6 describes; there is then no pair to show. You can always subscribe at the normal price. We keep the tax number and its registry name to show you the contracts awarded to that number, and so that each number belongs to one account only. They are deleted together with your account. We process a business-verification claim and its evidence so that a person can establish that the ΑΦΜ is yours — above all when the same number has been declared by two accounts. You and the administrator who decides are the only readers of the document, and every administrator read of another account's document is logged.

  4. 04

    Cookies and analytics

    We use strictly necessary cookies to keep you signed in. Usage analytics are collected ONLY with your explicit consent — nothing is sent before you answer.

  5. 05

    Who else is involved

    Hetzner Online GmbH (database and scraper, Falkenstein, Germany), Vercel (hosting, Frankfurt), Resend (email), Stripe (payments), PostHog (analytics, consent only). When you declare a tax number or ask for a new check, we ask ΑΑΔΕ's «Βασικά στοιχεία μητρώου» (basic registry details) service whether the number is valid and active and what name it is registered under. We send it only the number. When you ask us to fetch your activity codes from ΓΕΜΗ, we ask ΓΕΜΗ's open-data service which active codes the business with that tax number holds. We send it only the tax number. When you ask for a first draft of a technical offer, we send Google's Gemini API the tender's details, excerpts of its documents where we hold them, the titles and contracting authorities of your similar works, and the title and text of the library entries you pick that time. We do not send your email, the responsible person you name on an entry, or its files. Google processes these texts to write the draft, and that processing may take place outside the European Union. When you ask a question about a tender's documents, we send Google's Gemini API the question you wrote and excerpts of its documents. We do not send your email address or other account details. Google processes them to write the answer, and that processing may take place outside the European Union. We keep the question and the answer in your account, so you can find them again, and they are deleted with it. When you ask for profession and CPV code suggestions for an alert, we send Google's Gemini API the description of your business that you wrote and our list of professions. We do not send your email or any other detail of your account, and we do not store the description. Google processes it to make the suggestions, and that processing may take place outside the European Union. Data is hosted in the European Union. A business-verification document is stored in Vercel Blob, in a private store: it has no public address and does not leave the server without a check on who is asking. If you connect a Slack or Microsoft Teams channel, we send that service — which you chose — the alert's tenders and the name showing who connected the channel. What happens to them there is governed by that service's terms for your workspace. If you add a webhook, we send the address you gave the alert's tenders, its name and its id. If you add a webhook for your bids, we send the address you gave every change to a bid: the tender, the stage, the owner, the amount and the deadline. If the address is Zapier's or Make's, processing there is governed by that service's terms for your account. If you connect your Pipedrive, we send to your own account there every change of a bid: the tender's title, the stage, the amount and the deadline. We read from it only the pipelines, the stages, the deal fields and your company's and your user's number, and we search deals by our own field. Processing there is governed by Pipedrive's terms for your account. If you connect your HubSpot, we send to your own account there every change of a bid: the tender's title, the stage, the amount and the deadline. We read from it only the pipelines, their stages and the definition of the property we add to deals. Processing there is governed by HubSpot's terms for your account. If you connect your Zoho CRM, we send to your own account there, in the data centre where Zoho keeps it, every change of a bid: the tender's title, the stage, the amount and the deadline. We read from it only the number of your organisation, the definitions of the deal fields, the deal layouts and the pipelines with their stages. Processing there is governed by Zoho's terms for your account. If you turn on push notifications, each notification passes through your browser's push service (Google Firebase Cloud Messaging, Mozilla, Apple or Microsoft), encrypted so that only your browser can read it. It carries only how many new tenders were found and a link to your alert — not your name, your email or the alert's name.

  6. 06

    How long we keep it

    For as long as you have an account. After deletion, personal data is permanently erased. Financial records are retained for as long as tax law requires, without your personal details. The history of alert emails we sent, to you and to your recipients, is kept for the life of the account and deleted with it. Records of checks that found nothing and sent no email are deleted after 30 days. Changes to bids that we sent to a webhook are deleted after 30 days. An invitation link can be accepted for 14 days after it was last sent. For an address you invited that has not accepted, we keep the address you entered, the alert you invited it to and the schedule you chose for it, the invitation's status, and how many invitations were sent to it and when. We keep them so that your account cannot invite that address more than three times, and so that a decline is always recorded, through any invitation, however long after it was sent. They stay on your account however old they are, and are deleted with the account. A recipient you removed, and an address that declined or stopped the alerts, also stay on the account that added them — a declined address so that account cannot invite it again — and are deleted with the account. The card fingerprint, the Stripe checkout tax id and any duplicate-account flag stay for the life of the account and are deleted with it. When the account is deleted we keep, for 24 months from the deletion, one thing for each of the first two: a code computed from it with a secret key, from which the fingerprint or the tax id cannot be read back without that key. We keep it with no email, name or account, and for one reason: so that a new account paying with the same card, or giving the same tax id, is not offered the free trial again. If the same card or tax id is on an account deleted later, the 24 months start again from that deletion. Then the code is deleted. A record of each billing notification Stripe sent us — the notification's own id, its kind, and whether we managed to act on it — is kept for as long as the service runs, because it is how we find a message that never reached you. When we cannot act on one, we keep the type of the error and not its text; since 18 September 2026 the record carries no name, address or account number of yours. The id resolves to your customer record at Stripe. A business-verification document is deleted as soon as the claim is decided or withdrawn, and in any case when the account is deleted. The claim's record — the ΑΦΜ, the kind of evidence, the status — stays on the account for as long as the account exists. What michanikosGPT sends us about a subscription is kept while the subscription gives Pro and for 3 days after it ends. Once it gives no Pro, it is deleted within 2 days of the last update; once it has ended, within 2 days of the last update or of the end of those 3 days, whichever is later. This holds whether or not you have an account here.

  7. 07

    Your rights

    You have the right of access, rectification, erasure, portability and objection. Email us and we respond within one month. If you receive alerts as a recipient without an account of your own, the link in every alert email stops that alert, or every alert from the account that added you, with one click. Declining an invitation stops that one invitation. You can also write to us, and we will stop sending to your address on request.

  8. 08

    Account deletion

    Deletion is permanent, not hiding: the account and its personal data are genuinely removed from the database. The account's alert recipients go with it, declined addresses included, together with the history of emails we sent them. Financial records that must be retained for tax reasons are anonymised — the record stays, your details go. Business-verification claims go with the account too, together with the documents you uploaded for them. One thing outlives the deletion, for 24 months: a code computed with a secret key from the card fingerprint and the Stripe checkout tax id, with no email, name or account, kept only so that the free trial is not offered again to the same card or tax id (section 6). With the account, and with an alert when you delete it, its channels and their webhook URLs are deleted. With the account, your bids' webhooks and the changes we sent them are deleted. When you remove a webhook, the changes waiting to be sent go with it. With the account, and when you disconnect Pipedrive, the connection, the access and the links between bids and deals are deleted. If you remove the app from inside Pipedrive, we delete the access as soon as Pipedrive tells us; the connection and the links stay until you disconnect it or connect it again. The deals in Pipedrive are yours and stay there. With the account, and when you disconnect HubSpot, the connection, the access and the links between bids and deals are deleted. The deals in HubSpot are yours and stay there. With the account, and when you disconnect Zoho CRM, the connection, the access and the links between bids and deals are deleted. The deals in Zoho CRM are yours and stay there. Your library texts go with the account too, together with their files. A text you delete yourself loses its files at once. Your API keys go with the account too, revoked ones included.

  9. 09

    Tender data

    The details of tenders, contracts and public bodies' acts (authorities, their VAT numbers, amounts) are public data of the source each record names — ΚΗΜΔΗΣ, TED, Diavgeia or Cyprus's data.gov.cy, for example — and are not your personal data. For awardees that are legal persons — we recognise them by their tax number — we hold, from ΓΕΜΗ's open data, the registered name, the ΓΕΜΗ number, the legal form, the status, the date of incorporation, the registered seat and the activity codes (ΚΑΔ). For natural persons, such as sole traders, we do not ask ΓΕΜΗ and hold nothing from it, and from no legal person do we hold any person's name, such as a director's or a partner's.

  10. 10

    Third-party data inside the registry records

    The ΚΗΜΔΗΣ records we mirror can contain the contact details of the public employee who filed the entry — in practice a work email address. The TED notices we mirror usually carry the name and email address of the buyer's contact person. We retain them as part of a faithful copy of an official public register, on the lawful basis of legitimate interest. They are published on no page, used for no communication and used for no marketing; they are stripped before a record leaves the server. They are kept for as long as the corresponding registry record. From data.gov.cy we mirror the list of public contracts awarded in Cyprus, as the Treasury of the Republic of Cyprus publishes it under CC BY 4.0. The list names an awardee by name only, with no tax number, so we cannot tell a sole trader from a company. The name therefore appears only in the record of the award itself, as published; it appears in no ranking, profile or report of awardees. The same list has a column naming other economic operators of the same procedure as well; we keep it inside our copy of the record, show it on no page, and strip it before a record leaves the server. We retain these as part of a copy of an official public posting, on the lawful basis of legitimate interest, for as long as we keep the record. Awardees who are natural persons — such as sole traders, whom we tell by their tax number (ΑΦΜ) — are published in ΚΗΜΔΗΣ with their name and tax number. On the page of a single record we show them as the buyer published them, for the transparency that ν. 4412/2016 provides for. On every other view that gathers records or describes an awardee — rankings of awardees, buyer and framework-agreement pages, awardee profiles, reports, questions, the API and the browser extension — we show neither their name nor their tax number: we count them as «natural person». We build no profile of a natural person, and a search by their tax number does not gather their records. Awards by buyers outside Greece for work in Greece — such as the European Investment Bank or an EU body — come from TED, which does not reliably tell a natural person from a company. So of their awardees we keep only the name, the country and the region of their seat; we do not store the field with their identifier, not even inside the copy of the notice we keep. We show the name on the page of the single record, in the record's entry in the API and in the alert about it — email, channel message or webhook; these awardees enter no ranking, sum or profile. Where the notice itself marks the awardee as a natural person, we keep only the words «natural person» in place of the name, in the copy of the notice too. Awards of other countries reach us from TED, and the same rule holds for them with a different test: TED does not reliably say whether an awardee is a natural person, and the identifier it publishes can be a person's own national number. So we treat as a company only an awardee whose published name states a company's legal form (such as ЕООД, d.o.o., LTD or SRL) and not a sole trader's; only for that awardee do we keep the identifier, and only that awardee enters rankings and reports. Of every other awardee we keep the name, the country and the region of their seat; we do not store their identifier, not even inside the copy of the notice we keep. We show their name on the page of the single record, in the record's entry in the API and in the alert about it — email, channel message or webhook — and in no ranking, profile or search by identifier. Where the notice itself marks the awardee as a natural person, we keep only the words «natural person» in place of the name. The test also hides companies that a notice names without their legal form; we prefer that to naming a person. From Διαύγεια we mirror the details — not the document — of public bodies' acts about their purchases: direct awards, award decisions, spending commitments, expenditure approvals and payments. For every counterparty such an act names — an awardee or a payee, natural persons included — we keep the name and tax number (ΑΦΜ) as the body posted them, together with the amount. Where the body has declared that the act contains personal data we keep neither the name nor the tax number; if it declares so later, we erase them as soon as we read the act's new version. We retain them as part of a copy of an official public posting, on the lawful basis of legitimate interest, for as long as we retain the copy of the act; when the body corrects the act, we follow its newer version. In the list of small direct awards (μικροπρομήθειες), in its alert email and in the browser extension, a legal person is shown with its details as posted. A natural person — whom we tell by their Greek tax number, and we treat anyone posted without a tax number as one — is shown with neither their name nor their tax number: we count them as «natural person». In the list of small direct awards, a counterparty the act declares with another country's tax number is shown as posted, because that number does not tell whether it is a natural person. For an act the body has declared to contain personal data we say only that the awardee is not published. Under «Payments» on the page of a single record we show the amount, the date and the payee's tax number only when it is the tax number of an awardee of that same contract, as the contract's own record publishes it; no name from Διαύγεια appears there. From the same payments we compute how fast a buyer pays, naming no one. To assign a payment to a category we use the payee's tax number only when it is a legal person's. A revoked act appears neither among the small direct awards nor among the payments, and the browser extension shows it as revoked, without its awardees. We show an act's subject as the body wrote it, and the search over small direct awards reads only that: no view gathers acts by the name or the tax number of a natural person, and we build no profile of one. For access, rectification, erasure or objection, as in section 7: ioan.kapageridis@gmail.com.

For data protection matters: ioan.kapageridis@gmail.com. You have the right to complain to the Hellenic Data Protection Authority (dpa.gr).