Tender documents are confidential. This page describes how we handle them, for everyone who has to review that before giving approval.
All customer data, meaning accounts, company profiles, uploaded documents and analysis results, is stored with our provider Supabase in the Frankfurt am Main data center. The application is delivered through a content delivery network that serves program code only and stores no customer data.
For the analysis we transmit text content of your documents to AI providers, solely to deliver the service. Your data is never used to train AI models, neither by us nor by our providers. This is guaranteed in the data processing agreement.
We never process payment data ourselves. You enter card details directly with our payment provider. We neither see nor store them.
The most important measures at a glance. We provide the full overview of technical and organizational measures for your review.
Every transfer between browser, server and providers is encrypted.
All data is stored AES-256 encrypted at rest in the data center.
Passwords are stored exclusively as cryptographic hashes. We could not read them even if we wanted to.
Every company is its own tenant. In every interface, access is derived from the verified login token, never from an identifier sent by the browser.
All API keys live exclusively on the server, never in the browser and never in the source code.
You delete documents and analyses yourself at any time, immediately and permanently. Account deletion is completed within 30 days and confirmed in writing.
We are a young company and we are open about what is missing: we are currently not ISO 27001 certified. Certification is planned but has not yet taken place. There is also no option to run validait in your own data center at the moment. If one of these is decisive for your approval, talk to us and we will tell you honestly whether and when we can deliver it.
Only the two founding partners have access to production data, and only for operations and support. There is no automated analysis of your documents for any other purpose. We ask you not to upload special categories of personal data within the meaning of Article 9 GDPR to the platform.
If you upload personal data of third parties to the platform, for example names of contact persons in tender documents, you are the controller and we are the processor. The data processing agreement (German)Accessibility under Article 28 GDPR is publicly available and becomes part of the contract upon conclusion. There you will also find the complete list of our sub-processors with their locations and transfer safeguards.
If you discover a security vulnerability, please write to s.loeffler@validait.de. We will confirm receipt promptly, keep you informed about the fix and credit you as the finder if you wish. Please do not publish details until the vulnerability is closed.
We will put together the data processing agreement, the privacy policy and an overview of the technical and organizational measures for your internal approval. Just get in touch.
Request documents