Back to legal

Privacy Policy

Last updated 18 September 2026

This policy explains what personal data Vunna processes, why, on what legal basis, who else touches it and what you can ask us to do about it. It is written to be read, not to be survived.

1. Who is responsible

The controller for the processing described here, within the meaning of Article 4(7) GDPR, is:

Laddro Digital UG (haftungsbeschränkt)

Belziger Str. 69-71

10823 Berlin

Germany

Email: hello@getvunna.com

We are not required to appoint a data protection officer, and have not appointed one. Write to the address above for anything in this policy.

2. Where this policy applies

To getvunna.com, the application at app.getvunna.com, our API, and the emails we send you. It does not cover the procurement portals we link to, which have their own policies.

3. What we collect, and why

3.1 Account

Your email address, a hash of your password, and the time you last signed in. We need these to give you an account at all. Legal basis: Article 6(1)(b) GDPR, performance of the contract.

3.2 Your company profile

The profile you build is about a company rather than a person, but it can contain personal data if you put it there: the company name and website, a description of what you do, your capabilities, CPV classifications, the countries you work in, a contract value range, keywords, exclusions, and the address you want the daily digest sent to. Legal basis: Article 6(1)(b) GDPR.

If you ask us to draft a profile from your website, we fetch that website and read it. Whatever is publicly on those pages, including any staff names, is processed in the course of producing the draft.

3.3 How you use the feed

Which notices were matched to you, which you saved or dismissed, and any feedback you give on a match. We use feedback to improve matching. Legal basis: Article 6(1)(b) GDPR for the feed itself, and Article 6(1)(f) GDPR, our legitimate interest in a service that matches better, for the improvement.

3.4 Payments

If you subscribe, we hold your plan, its status, and the Stripe customer and subscription identifiers. Your company billing address, VAT identification number and payment details are held by Stripe, not by us; we never receive your full card number. Invoices are rendered by Stripe from that data. Legal basis: Article 6(1)(b) GDPR, and Article 6(1)(c) GDPR for the invoice and tax records we are required to keep.

3.5 Email we send

We send transactional email about your account and, if you configure one, a daily digest to the address you chose. Our email provider records delivery events such as delivered, bounced and complained, so that we can tell whether a digest arrived. Legal basis: Article 6(1)(b) GDPR.

3.6 Email you send us

What you write to us, and your address, so we can reply and keep a record of the matter. Legal basis: Article 6(1)(b) and Article 6(1)(f) GDPR.

3.7 Technical logs

Our hosting providers record the usual server-side information for each request, including IP address, timestamp, the path requested and the user agent. We use it to run the service, to find faults and to detect abuse. Legal basis: Article 6(1)(f) GDPR.

4. Personal data of other people

Tender notices are published by contracting authorities and often name a contact person at the buying organisation, with a work email address or phone number. That data reaches us as part of the public notice, it is processed so that we can show you the notice as published, and our legal basis is Article 6(1)(f) GDPR, the legitimate interest of you and of the publisher in the notice reaching potential bidders.

Those contacts are published so that suppliers can ask about a procedure. Using them for unrelated marketing is both a breach of these Terms and, in most cases, unlawful.

If you enter someone else’s personal data into a profile, you are responsible for having a lawful basis to do so.

5. AI processing

Matching is done with help from AI models operated by third parties. Two things are sent to them:

  • Your profile text and the text of a tender notice, to a large language model, to judge relevance and write the explanation you see.
  • Profile and notice text, to an embeddings model, to produce the numeric representations used to shortlist candidates.

Your account email address, your password, your payment data and your billing address are never sent to a model provider. Both providers process this data as our processors, under their API terms, and neither uses it to train their models.

No automated decision has legal effect on you. A relevance score decides the order of a list you read; it does not decide anything about you within the meaning of Article 22 GDPR.

6. Processors we use

These providers process personal data on our behalf, each under a data processing agreement. Where data leaves the European Economic Area we rely on the European Commission’s Standard Contractual Clauses and, where the provider is certified, the EU-U.S. Data Privacy Framework.

ProviderWhat they do for usWhere they process
SupabaseThe PostgreSQL database holding accounts, profiles and matchesEuropean Union (Ireland)
Google Cloud PlatformHosting for our API and matching engine on Cloud Run, and secret storageeurope-west4, the Netherlands, with some control plane processing in the United States
VercelHosting and edge runtime for the website and the applicationEuropean Union by default, United States fallback
Stripe Payments Europe LtdCard processing, subscriptions, invoicing and tax determinationIreland, with affiliate processing in the United States
AnthropicThe language model that drafts a profile from a website and judges whether a notice matchesUnited States
OpenAIThe embeddings model used to shortlist noticesUnited States
ResendDelivery of the daily digest and transactional emailEuropean Union and United States
CloudflareDNS, edge routing and inbound mail routing for our domainsGlobal edge network
Google WorkspaceOur own mailbox, which receives what you write to usEuropean Union and United States

We do not sell your data, we do not share it with advertisers, and we do not use your profile for advertising.

7. Transfers outside the EEA

Our database, our API and our matching engine run in the European Union. The model providers in Section 6 process in the United States, and some other providers process globally. For each transfer we rely on one or more of: the Standard Contractual Clauses, Decision (EU) 2021/914; certification under the EU-U.S. Data Privacy Framework where the provider is certified; and supplementary measures including encryption in transit, encryption at rest and access control.

Write to hello@getvunna.com if you want the details of the safeguards applied to a particular transfer.

8. Security

  • TLS in transit, enforced on every Vunna domain.
  • Encryption at rest for the database.
  • Passwords stored as bcrypt hashes and never in readable form.
  • Session tokens held in HTTP-only cookies with the Secure and SameSite attributes in production, never in browser storage a script can read.
  • Secrets held in Google Cloud Secret Manager, never in source code.
  • An incident response procedure, including notification to the supervisory authority within 72 hours under Article 33 GDPR and to affected users under Article 34 GDPR where the risk requires it.

No system is perfectly secure. If you find a security problem, please write to hello@getvunna.com before disclosing it publicly.

9. Cookies

We keep this deliberately small. Vunna sets two cookies of its own:

CookiePurposeLifetime
accessTokenYour signed-in session15 minutes
refreshTokenKeeps you signed in without asking for your password again30 days

Both are strictly necessary and exempt from consent under Section 25(2) number 2 TDDDG, because the service cannot work without them. On the billing page only, Stripe sets its own cookies for fraud prevention, which are equally necessary to take a payment safely.

We use no analytics, no advertising cookies, no retargeting pixels and no session recording, and we store nothing else on your device. Because we set nothing that requires consent, there is no cookie banner.

10. How long we keep things

CategoryRetention
Account, company profile, saved and dismissed noticesUntil your account is deleted
Match feedbackUntil your account is deleted
Refresh tokensExpire after 30 days, and are removed when you sign out
Payment, invoice and tax recordsUp to 10 years, as required by Section 147 AO and Section 257 HGB
Email correspondence with usUp to 3 years after the matter is closed
Email delivery events90 days
Server and security logsUp to 90 days

11. Your rights

If you are in the EEA, the United Kingdom or another jurisdiction with comparable rights, you have the right to:

  • Access, Article 15. Ask for a copy of the data we hold about you.
  • Rectification, Article 16. Ask us to correct anything wrong.
  • Erasure, Article 17. Ask us to delete your account and its data.
  • Restriction, Article 18. Ask us to pause processing while something is checked.
  • Portability, Article 20. Ask for the data you gave us in a structured, machine-readable format.
  • Objection, Article 21. Object to processing based on legitimate interest.
  • Complain to a supervisory authority, in particular the Berliner Beauftragte für Datenschutz und Informationsfreiheit (Berlin Commissioner for Data Protection and Freedom of Information), or the authority where you live or work.

There is no self-service delete button yet. Until there is, erasure and every other request above is handled by hand: write to hello@getvunna.com and we will act on it. We may need to confirm your identity first. We reply within one month, as Article 12(3) GDPR requires, and will tell you if a complex request needs longer.

When we delete an account we delete its profile, matches and feedback. We keep the small amount that tax law requires us to keep, such as the link between an invoice and your company name and country.

12. Children

Vunna is a business tool and is not directed at children. We do not knowingly collect data from anyone under 18.

13. Changes to this policy

We may update this policy, and will change the date at the top when we do. For a change that materially affects how we process your personal data we give at least 30 days’ notice by email or in the application before it takes effect.

14. Contact

Laddro Digital UG (haftungsbeschränkt)

Belziger Str. 69-71

10823 Berlin

Germany

Email: hello@getvunna.com