
How mytender.io protects customer data: UK-only processing, our processor role, sub-processors, AI handling, security and retention under UK GDPR.
Last updated: 5 October 2026
This overview is written for customer security, procurement and data protection reviewers. For how we handle personal data as a controller (website, enquiries, business contacts and recruitment), see our Privacy Policy.
When a customer uses mytender.io, the customer is the Data Controller and mytender.io acts solely as its Data Processor. Customers upload their own material – tenders, case studies, policies, past bids and staff CVs – and the platform generates bid content from it for them. The customer decides why and how that data is processed (which documents, which bids, who has access) and determines the lawful basis.
We process customer data only on the customer's documented instructions, under a Data Processing Agreement meeting Article 28 UK GDPR, and only to deliver the service. Customer data is never used to train AI models. The customer owns the generated content, and data is exported or deleted on exit.
Our Data Protection Officer is Nicolas Dickreuter (nicolas@mytender.io). Privacy requests and complaints are handled at privacy@mytender.io, monitored by the DPO. Board-level responsibility for data protection sits with the CEO, Samuel Aaron.
All customer data is hosted and processed in the United Kingdom. AI inference runs in-region on Amazon Bedrock in AWS London; requests do not leave the London region. Supporting models (classification, search, embeddings) also run in AWS London, so all AI processing of customer data takes place in the UK.
| Purpose | Provider | Location |
|---|---|---|
| Hosting and encrypted backups | Amazon Web Services (AWS) | UK – AWS London (eu-west-2) |
| Database storage | MongoDB Atlas (on AWS) | UK – AWS London (eu-west-2) |
| AI inference | Amazon Bedrock (AWS) | UK – AWS London (eu-west-2) |
No international transfers take place under our customer contracts. Any future transfer would happen only with prior notice to the customer and a valid UK GDPR Chapter V mechanism (UK IDTA). mytender.io support and engineering access to customer data is not routed outside the UK or EEA; where a customer requires it, access is limited to designated UK-based staff and requires the customer's approval.
| Sub-processor | Role | Location |
|---|---|---|
| Amazon Web Services (AWS) | Hosting, encrypted backups, AI inference via Amazon Bedrock | UK – AWS London (eu-west-2) |
| MongoDB Atlas | Database storage | UK – AWS London (eu-west-2) |
Anthropic and OpenAI are model providers, not sub-processors. Their models are accessed only through Amazon Bedrock in AWS London, and no data is sent directly to either.
Customers get at least 30 days' prior written notice of any new or replacement sub-processor (name, location, nature of processing) and may object. If an objection cannot be resolved, the customer may terminate the affected part of the service. A sub-processor register (name, location, role, data processed) is available to enterprise customers on request and updated within 30 days of any change.
Sub-processors are bound by Article 28 Data Processing Agreements, retain data only on our documented instructions, and are reviewed annually against their independent third-party audit reports and published security documentation.
| Event | Commitment |
|---|---|
| Suspected incident affecting customer data, or significant AI failure | Initial notification within 4 hours of detection |
| Confirmed personal data breach affecting customer data | Within 24 hours of internal confirmation |
| Confirmed non-personal security incident affecting customer data | Within 24 hours of internal confirmation |
| Full incident report | Within 72 hours of confirmation |
Where we are controller, the DPO assesses ICO notification under Article 33 UK GDPR within the statutory 72 hours. Where we are processor, we support the customer's notifications at no charge. A formal breach register is maintained by the DPO.
In the table below, T is the date of contract termination.
| Data | Retention |
|---|---|
| Account data and bid/tender content | Duration of the contract; after termination kept securely until T+30 days solely for export |
| Active production data, including sub-processor copies | Deleted by T+37 days at the latest |
| Encrypted backups (30-day rolling cycle) | Overwritten by T+67 days at the latest |
| Deletion requests outside termination | Completed within 7 calendar days |
| Session logs | 30 days |
| Security and audit metadata (including IP addresses; no bid content) | 12 months |
| Legal and financial records | Statutory period (e.g. billing records 6 years under UK tax legislation, anonymised where possible) |
The following are available to customers on request: Information Security Policy; Data Protection Policy; Data Retention and Disposal Policy; Incident Response Policy; Business Continuity Policy; Backup Policy; Supplier Information Security Policy; Information Transfer Policy; Records of Processing Activities; sub-processor register; DPIA support; and certificates.
Data Protection Officer: Nicolas Dickreuter – nicolas@mytender.io
Privacy requests and complaints: privacy@mytender.io
For how we handle personal data as a controller, see our Privacy Policy.
If you have any questions about our data protection practices or would like to exercise your rights, please contact our Data Protection Officer at privacy@mytender.io.