1. Controller
DFS AI Global d.o.o., OIB: 08392520258, Petrova ulica 133, 10000 Zagreb, Croatia. Contact: dfsaiglobal@gmail.com.
2. Roles
For customer-controlled content uploaded to the Service, including tender documents, reference files, CVs, business records, and datastore files, DFS AI Global d.o.o. generally acts as a data processor on behalf of the customer.
For account administration, authentication, billing, security logging, fraud prevention, customer support, and internal product usage analytics, DFS AI Global d.o.o. acts as a data controller.
3. Categories of Data
We may process:
- user account data, such as name, email, and login credentials
- company and tender profile information
- access logs, authentication records, and security events
- uploaded datastore files, tender documents, references, CVs, attachments, extracted text, and related metadata
- agent conversations, answers, generated checklists, and outputs
- reminders, saved procurements, notification settings, and email events
- billing, subscription, invoice, and payment-status records
- first-party product usage records, such as login success, page views, feature use, tender opening, document upload, reminder creation, and agent session creation
The Service is intended for business use. Customers are responsible for ensuring that uploaded files and profile data are lawful, accurate, and appropriate for processing in the Service.
4. Purpose and Legal Basis
- Account creation, authentication, tenant administration, and support: performance of contract and legitimate interest.
- Tender profile setup, relevance matching, tender monitoring, saved procurements, reminders, and email notifications: performance of contract.
- Datastore uploads, document extraction, search, reference and CV matching, agent workflows, and AI-assisted tender analysis: performance of contract and processing on customer instructions.
- Billing, subscription management, invoices, accounting, and tax records: performance of contract and legal obligation.
- Security monitoring, abuse prevention, audit trails, service integrity, and incident response: legitimate interest and legal obligation where applicable.
- First-party product usage analytics: legitimate interest in understanding service adoption, reliability, feature usage, support needs, and operational health. These records are stored server-side and are not designed to include raw IP addresses, user agents, email addresses, browser fingerprints, or third-party tracking identifiers.
- Marketing communications, if any: consent or legitimate interest where permitted by applicable law, with an unsubscribe option.
5. Uploaded Files, Datastore, and AI Processing
Uploaded customer files are used only to provide features inside the customer tenant, including extraction, indexing, search, tender analysis, reference matching, CV matching, checklist generation, reminders, and agent workflows.
We do not sell uploaded files, use them for advertising, or use them to train AI models. Customer content may be processed by contracted infrastructure and AI subprocessors only as necessary to provide, secure, monitor, and support the Service.
Google Workspace API data use. The use and transfer of raw or derived user data received from Google Workspace APIs, including Google Calendar, will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Google Calendar data is used only to provide the calendar reminder functionality requested by the user. It is not sold, used for advertising, or used to create, train, or improve generalized AI or ML models.
AI-assisted outputs may be incomplete or inaccurate and are intended to support human review. Customers remain responsible for reviewing outputs before making tender, legal, financial, or operational decisions.
6. AI Assistant Connectors (TOP Connect)
TOP Connect lets a user connect the Service to a third-party AI assistant, currently Claude (Anthropic) and ChatGPT (OpenAI), so that the assistant can answer questions using TOP data. This section describes that connector specifically. Connecting is optional, is initiated by the user, and requires a subscription plan that includes TOP Connect.
What is collected
When a user connects, we process the identity of the connecting account (the user and the tenant it belongs to), the parameters the assistant sends with each request (for example a company identifier such as an OIB, a date range, or a CPV code), and the procurement data returned in response. The connector is read-only: no connector function creates, modifies, deletes, submits, or transfers anything.
The connector does not receive conversation content, user files, chat history, assistant memory, or conversation summaries. It receives only the request parameters described above.
How it is used and stored
Requests are answered by reading the Service's own database, and the connector does not store conversations. Access records are written for security, audit, abuse prevention, and rate limiting, and use pseudonymous user and tenant identifiers rather than names or email addresses. Access tokens and personal data are not written to these records.
One exception, for completeness. Two of the connector's twelve functions may make a single outbound request to the Croatian public procurement portal (eojn.hr) while answering: one to retrieve a procurement record the Service does not yet hold, and one to refresh a contract's details when the stored copy has aged. Those requests carry only the public procurement or contract identifier. They never carry the user's identity, account data, tool arguments beyond that identifier, or any conversation content, and eojn.hr is the only external host the connector may contact. The request is bounded — HTTPS only, a five-second timeout, no retries and a capped response size — and if it fails, the locally stored record is returned instead. No other third party receives anything.
Third-party sharing
Using the connector necessarily sends the requested procurement data to the assistant provider that requested it — Anthropic or OpenAI — which processes it as a controller under its own terms and privacy policy. No other third party receives data through the connector. We do not sell connector data, use it for advertising, or use it to train AI models.
Retention
Connector access and audit records follow the security log retention described in section 9, generally up to 12 months. Authorisation grants and their tokens persist until the user or a tenant administrator revokes the connection, the user's seat or access permission is removed, or the subscription lapses. Revocation invalidates the associated tokens immediately, and the assistant loses access without any further step.
Access boundaries
Each user connects with their own account and sees only what that account is entitled to see. Tenant separation is derived from the authenticated connection and cannot be influenced by a request parameter, so one customer's matched tenders are not reachable from another customer's connection. The analytics functions read the published Croatian public procurement record, which is public data.
Contact
Privacy questions about the connector: dfsaiglobal@gmail.com. Operational support: support@tender-op.com. Setup and disconnection instructions are in the TOP Connect documentation.
7. Recipients and Subprocessors
Personal data may be processed by contracted service providers only for the purposes described in this Policy. These may include cloud hosting and storage providers, AI infrastructure providers, email delivery providers, payment and billing providers, invoicing/accounting providers, security/logging providers, and professional advisers where necessary.
We do not share customer content with third parties for their own advertising or model-training purposes.
8. International Transfers
The Service is operated primarily using European cloud infrastructure where available. Some subprocessors may process data from, or provide support from, countries outside the European Economic Area. Where international transfers occur, we rely on appropriate safeguards such as European Commission Standard Contractual Clauses or equivalent lawful transfer mechanisms.
9. Retention
- Account and tenant data: for the duration of the contract and as needed for legitimate business records.
- Billing, invoices, and accounting records: according to applicable tax and accounting retention obligations.
- Uploaded files and extracted datastore content: for the duration of the customer account, unless deleted earlier by the customer or retained temporarily in backups.
- Deleted or hidden records, including soft-deleted agent sessions: hidden from normal application views and retained only as needed for recovery, audit, security, support, legal obligations, and temporary backups.
- Security logs and audit records: generally up to 12 months, unless a longer period is required for incident investigation or legal reasons.
- First-party product usage analytics: generally up to 365 days.
- Support communications: as long as needed to handle the request and maintain business records.
10. Security
We implement technical and organisational measures including:
- encryption in transit
- encryption at rest
- role-based access control
- audit logging
- restricted administrator access
- tenant separation controls
- backup and availability controls
11. Data Subject Rights
Users may request:
- access
- rectification
- erasure
- restriction
- portability
- objection
- withdrawal of consent where processing is based on consent
Requests: dfsaiglobal@gmail.com
12. Data Breaches
Customers will be notified without undue delay after detection of a breach affecting their data, in line with applicable data protection obligations.
13. Contact and Complaints
Privacy requests can be sent to dfsaiglobal@gmail.com.
Supervisory authority: Croatian Personal Data Protection Agency (AZOP).