Privacy Policy

Last updated: 30 June 2026

In plain terms

TendorAI holds two kinds of personal data: (1) data about regulated firms that we have taken from public registers such as the SRA, Companies House, ICAEW, FCA and Propertymark, and (2) data about people who create an account or contact us. If your firm appears on our platform and you did not give us your data directly, Section 6 explains exactly where we got it, why we hold it, and how to ask us to stop. You can object or ask for removal at any time by emailing scott.davies@tendorai.com.

1. Who we are

This Privacy Policy explains how TendorAI Ltd ("TendorAI", "we", "us", "our") collects, uses, stores and protects personal data when you use our website at tendorai.com and our services, and when we hold data about your firm that we have obtained from public sources.

TendorAI Ltd is a company registered in England and Wales under company number 16521860, with its registered office at [FILL: registered office address, Wales]. We are the data controller responsible for your personal data.

TendorAI is an AI visibility platform. We measure how often AI assistants recommend regulated professional-services firms, diagnose why a firm may be invisible to those assistants, and help firms close the underlying technical gaps.

2. The data we collect

(a) Firm data from public registers

We maintain profiles for UK regulated firms using information published in public registers. For each firm this may include:

Section 6 sets out the specific sources, legal basis and retention for this category, as required by Article 14 UK GDPR.

(b) Account data

If you register for a free or Pro account, we collect:

(c) Billing data

If you subscribe to our Pro plan (£299/month), payment is processed securely by Stripe. We do not store full card details on our own systems. We retain transaction records (such as invoices and the subscription status) as required for accounting and tax purposes.

(d) Reports and diagnostic data

When you use the platform we generate AI-visibility scores, diagnostics and content drafts relating to your firm. Where these are linked to your account, they are treated as your personal data.

(e) Website and analytics data

(f) Communications

If you email us or use our contact form, we keep a record of that correspondence and the information you provide.

3. Where we obtain your data

4. Why we use your data and our legal basis

We process personal data for the following purposes, on the bases shown:

5. Our legitimate interests

Where we rely on legitimate interests, we have weighed our interest in operating an AI visibility platform against your interests, rights and freedoms. We only process business and professional contact information that is already published in public registers or on firms' own websites, we limit the data to what is needed to run the service, and we give every firm a clear and easy route to object or be removed. You can ask for a copy of our balancing assessment by emailing us.

6. Firm data obtained from public registers (Article 14 UK GDPR)

If your firm appears on our platform and you did not provide your data to us directly, this section is your privacy notice under Article 14 UK GDPR.

To object, correct your details, or ask for your firm's profile to be removed, email scott.davies@tendorai.com. We will action valid requests without undue delay.

7. Who we share data with

We do not sell your personal data. We share it only with the service providers (processors) that help us run the platform, each under a data-processing agreement:

We may also disclose data where required by law, to enforce our terms, or to protect our rights, property or safety.

8. International transfers

Some of our providers (including Stripe, Google and certain AI service providers) process data outside the UK, including in the United States. Where personal data is transferred outside the UK, we rely on appropriate safeguards — such as the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, UK adequacy regulations, or the UK extension to the EU–US Data Privacy Framework — so that your data receives equivalent protection. You can ask us for details of the safeguards that apply.

9. Cookies

You can also control cookies through your browser settings.

10. How long we keep data

11. Your rights

Under the UK GDPR you have the right to:

To exercise any of these rights, email scott.davies@tendorai.com. We will respond within one month. You will not normally have to pay a fee.

12. Complaints

If you are unhappy with how we have handled your data, please contact us first at scott.davies@tendorai.com. We will acknowledge your complaint within 30 days and work to resolve it.

You also have the right to complain to the Information Commissioner's Office (ICO) at any time. TendorAI Ltd is registered with the ICO as a data controller under reference [FILL: ICO reference, e.g. ZA123456]. You can contact the ICO at ico.org.uk.

13. Changes to this policy

We may update this Privacy Policy from time to time. We will post any significant changes on this page and update the "last updated" date above. Your continued use of our services after changes are posted constitutes acceptance of the updated policy.

14. Contact us

TendorAI Ltd
[FILL: registered office address, Wales]
Email: scott.davies@tendorai.com