Legal

Privacy Policy

This policy explains what Coira Cost processes, why it does so, who receives it, and the choices you have.

Effective date: 18 August 2026

01

Controller and contact

Service operator / data controller
Coira Cost
fionan971@gmail.com

The operator above is the controller for personal data processed through Coira, except in two cases. Where a named provider acts as an independent controller for its own service, it is the controller for that processing. And where a customer firm supplies data about its own staff — the rate card described in section 02 — that firm is the controller and Coira acts only as its processor, on that firm's instruction. Privacy questions and rights requests can be sent to fionan971@gmail.com.

02

Information we process

  • Account data: email address, name, company, login provider, account identifiers and plan status.
  • Bid Review data: project description, client, location, bid, cost, margin, scope and exclusions submitted to generate a pack. In the current version these inputs are processed transiently and are not intentionally saved to your account or written to the application database.
  • Search activity: search terms and selected filters used to operate, secure and improve search. Current search logs are not intentionally linked to an account identifier.
  • Report requests: contact, company, role, project description, location, sector and budget information you submit.
  • Community submissions: optional contact and role details plus the project-cost information you contribute.
  • Payments: Stripe customer, subscription and transaction identifiers, billing status and limited billing details. We do not receive your full card number.
  • Support and commercial records: correspondence, requests, follow-ups and relevant CRM records.
  • Technical data: security, authentication, session and request data generated when you use the service.
  • Rate-limit records: a keyed hash of your connection address and the endpoint used, kept for up to 48 hours, for the public tender reader and the model-backed features. The address itself is not stored. Forty-eight rather than twenty-four because the row expires after a day and is removed by a sweep that runs once a day: one created just after the sweep waits for the following one.
  • Contact details published in tender notices: public procurement notices routinely name a contact person and their work email at the contracting authority, and those fields are carried into the archive with the notice. This is the largest category of personal data held, it is collected from published sources rather than from the individuals themselves, and those individuals have no relationship with Coira. It is processed on the basis of legitimate interests, to make public tender information findable; it is never used to market anything, and a contact who asks for their details to be removed from the archive is removed.

    Enter the address as it appears on the notice. The tender notices themselves stay — they are public procurement records — but the named contact details are removed, and they are not added back when those notices are next refreshed.

  • Tender returns uploaded for adjudication: when a consultancy runs an adjudication it uploads the priced documents it received from the contractors who bid. Those documents are the contractors' confidential commercial pricing, and they routinely carry personal data about people who are not Coira users and never chose to deal with us — the name, job title, direct line, email address and sometimes the signature of whoever prepared or transmitted the bid, on a covering letter or transmittal sheet.
  • Who is responsible for it: the consultancy is the controller of that material. It obtained the documents, it decides what to upload, and it holds whatever relationship exists with the tenderers. Coira is a processor and acts on the consultancy's instruction only. If you are a contractor and your details are inside a document a consultancy uploaded, your request goes to that consultancy first; we act on what they tell us. We hold no relationship with you and cannot verify your request ourselves, which is why it has to reach us through them.
  • The terms that govern it: the processing terms at /terms/processing set out what Coira may and may not do with material a firm uploads, written to meet Article 28 of the GDPR.
  • What we do with it: we read the documents to extract prices, qualifications and exclusions, compare them, and present the result to the firm that uploaded them. We do not use them to train models, we do not pool them across customers, and the vocabulary the tool learns from one firm's corrections is never merged into another's. An adjudication is visible to members of the uploading firm and to nobody else. It can be deleted, and deleting it removes the stored files as well as the records.
  • Staff names and charge-out rates held for a customer firm: the fee tool holds a firm's own rate card, which names individual employees against an hourly charge-out rate. Coira does not decide what is in it and does not use it for any purpose of its own: the firm is the controller of that data and Coira processes it on the firm's instruction only.
  • Where those names and rates actually go: two different rates are held per person and they are not treated alike. The firm's internal cost rate is never selected into any client-facing output. The charge-out rate is different: it is the price being tendered, and a fee submission names the people it applies to, so the tendered rates sheet in the workbook the tool produces does carry each named person, their title and their hourly charge-out rate. That sheet is meant to be read by the contracting authority. The per-person resource plan — who is doing how many hours — is not in that file and is produced only when the firm asks for its own internal copy. A firm loading a rate card should expect the charge-out rates and the names attached to them to appear in what it submits, and should not load anything into it that it would not put in a tender.
  • Erasure of the rate card: it is erased on the firm's written request. Closing a firm's account is not yet something the firm can do for itself, so that erasure is a step we carry out rather than something the product does on its own.
03

Why we use it and our legal bases

  • Contract: to create and administer accounts, provide requested tools and reports, process subscriptions and support users.
  • Legitimate interests: to secure, troubleshoot, measure and improve the service; understand product use; prevent abuse; and manage business relationships, balanced against your rights.
  • Legal obligation: to keep required financial records, respond to lawful requests and comply with applicable law.
  • Consent: where required for optional marketing or non-essential cookies. You may withdraw consent at any time.

We do not use Coira’s submit/hold output to make a legal or similarly significant decision about you. It is a tool for your own human commercial decision.

Account email, authentication and any payment fields identified as required are needed to create or supply the relevant account or subscription. Required fields on report and submission forms are needed to process that request. If you do not provide them, we may be unable to provide the requested service. Fields marked optional may be left blank.

04

AI assisted features

Three features send information you supply to an AI model. Each of them says so on screen, at the point you meet the output — that labelling is how this service meets the transparency duty in Article 50 of the EU AI Act (Regulation (EU) 2024/1689), which has applied since 2 August 2026.

  • Coira guide (chat assistant): Free-text answers and links to tools inside the product. Processed by Anthropic.
  • AI-assisted tender extraction (bid workspace): Scope summary, dates, return requirements, risks, clarification questions, packages and a recommended next action — written by the model, in its own words, from tender text the user supplied. Processed by Anthropic.
  • Budget Builder indicative range: The headline low/mid/high euro range and its basis note, when the model path runs. The elemental package split is NOT model output — it is a published percentage template applied to whichever range was produced. Processed by Anthropic.

What is sent is the text you supply — your question to the assistant, your tender pack text, or your project brief — together with the context needed to answer it. Do not paste personal data, confidential tender material or trade secrets into these features unless you are authorised to do so and it is necessary.

Two further pipelines use Google’s Gemini models on published public procurement notices only — to read a floor area or a classification out of notice text. No account data and nothing you submit is sent to them. Where a figure shown to you is derived from one of those extractions, it is labelled on the page as AI-extracted.

Everything else in Coira is deterministic and involves no AI model: the cost benchmarks and medians, Bid Check, the Estimator, the elemental package split, the rule-based tender extractor, and all sector and trade classification. We label what is genuinely AI and nothing more.

We do not use any AI feature to make a legal or similarly significant decision about you, and none of them decides anything automatically. The output is an input to your own commercial judgement.

05

Sub-processors

These are every third party that processes information on our behalf, what each one is used for, and what it receives. We do not sell personal data. We may also disclose information to professional advisers or authorities where required by law, needed to protect rights or security, or as part of a genuine business sale or restructuring subject to appropriate safeguards.

Supabase — Processor
Used for: Application database, account authentication, session management and file storage.
Receives: All account data: email address, name, company, role, plan status, and every user-created record listed in lib/personal-data.js (saved reports, bid models, watchlists, documents, projects, tags, Tender Check runs).
Location: eu-north-1 (Stockholm, EU). Read from the Supabase management API for this project on 8 September 2026.
Vercel — Processor
Used for: Application hosting, edge delivery, serverless function execution and request logging.
Receives: Request metadata generated by using the service: IP address, user agent, request paths and timestamps. Any personal data inside a request body transits Vercel while the request is being served.
Location: UNVERIFIED — US-headquartered provider with configurable function regions; the regions in use have not been confirmed.
Stripe — Processor for subscription administration; independent controller for payment data under its own terms
Used for: Subscription checkout, payment processing, invoicing and billing status webhooks.
Receives: Billing identity, email address, customer and subscription identifiers, transaction records. Full card numbers are handled by Stripe and are never received by Coira.
Location: UNVERIFIED — Stripe operates through both EU and US entities; which one contracts here has not been confirmed.
Current status: Not yet processing live personal data — card payments are switched off in code until a live Stripe key is configured.
Resend — Processor
Used for: Transactional email. Today that is the owner notification sent when somebody submits an access request, and the sender used by lib/notify.js.
Receives: The prospect's email address, and their name and company where they gave them, inside the body of an owner notification. No customer tender content passes through it.
Location: UNVERIFIED — US-headquartered provider; the sending region has not been confirmed.
Current status: Sending from Resend's default onboarding sender unless COIR_NOTIFY_FROM names a verified domain, so today it can reach only the account owner.
Anthropic — Processor
Used for: Seven registered surfaces (lib/ai-disclosure.js). LIVE AND CUSTOMER-FACING: the Coira guide chat assistant; AI-assisted tender extraction in the bid workspace; the Budget Builder indicative range. ADJUDICATION, all three reading tender-return content and all three currently OFF: the schedule-extractor cell read (F2, which has no model provider registered at runtime, so it never calls out); the aligner/skeptic pair (F3, switched off by default in both the API route and the command line on 8 Sep 2026, and not reachable from a request); the qualifications reader (F4, covering letters). INTERNAL, not customer data: the Coira OS agents (morning brief, second brain, chief of staff), which run on the operator's own account.
Receives: Whatever the user puts into those features. That is the material risk here: tender pack text pasted into the bid workspace can contain named individuals, contact details and commercially confidential pricing, and the chat assistant receives free text. Coira does not control what is pasted in.
Location: UNVERIFIED — US-headquartered provider; the serving region for these API calls has not been confirmed.
Google — Processor for notice enrichment; identity provider for Google sign-in
Used for: Two unrelated things. (1) Google sign-in, if the user chooses it. (2) The Gemini batch pipelines that read PUBLIC procurement notice text to extract floor areas and classifications — these do not process customer content.
Receives: Sign-in: the account identifiers Google returns on authentication. Gemini pipelines: published public procurement notice text only — no account data and no user-submitted content is sent to them.
Location: UNVERIFIED — US-headquartered provider; the serving region has not been confirmed.
Current status: Gemini pipelines have never run against production — no API key is configured and no enriched row exists.
06

International transfers — work in progress

Several of the providers above are headquartered outside the European Economic Area, so some processing may take place outside the EEA. We are being straight with you about where this stands: the specific transfer mechanism for each provider has not yet been confirmed and recorded, and we would rather say so than claim a safeguard we have not verified.

Each provider named above publishes standard data-processing terms and standard transfer clauses. Confirming which of those apply to our accounts, and recording them, is an open task being worked through before paid subscriptions are accepted. If your organisation needs the position for a specific provider before then, email fionan971@gmail.com and you will get an accurate answer rather than a boilerplate one.

07

Retention

Our current retention targets are:

  • Uploaded tender returns and the readings taken from them: kept until the firm deletes the adjudication they belong to. There is no automatic deletion schedule for them yet. Deleting an adjudication removes its stored files and its rows together — the files first, so nothing is left behind in storage that no row points at — and a firm can do that itself at any time, for any adjudication, without asking us. Three things deliberately survive that deletion: the firm’s own learned vocabulary (which it taught across all of its jobs, and which holds no third party’s data), shared reference material such as published Technical Guidance Document clauses, and invoices, which are kept for the statutory accounting period below.
  • Bid Review inputs: not intentionally persisted by the current application after the response is generated.
  • Search logs: up to 12 months, then deleted or aggregated where practicable.
  • Report requests, support records and identifiable community submissions: generally up to 24 months after the last meaningful contact or review.
  • Approved benchmark data may remain after identifiers are removed and it is no longer personal data.
  • Account records: while the account is active and for a reasonable period after closure, normally no more than 24 months unless a dispute, security need or legal duty requires longer.
  • Invoices, subscription and tax records: normally six years or any longer period required by law.

Provider backups and security logs follow the provider’s documented schedules. We may retain specific records longer where reasonably required for legal claims, fraud prevention, security or regulatory compliance.

08

Aggregated and de-identified data

We may derive aggregated or de-identified statistics from account, search, report and community data — for example benchmark ranges, cost indices or usage trends. Once information no longer identifies you or a specific project, we may use it for product development, research, and our own reporting or marketing. We do not try to re-identify de-identified data except where necessary for security or legal compliance.

09

Community data and confidentiality

Community cost submissions are reviewed before publication. We aim not to publish the submitter’s name, email or direct contact details. Project fields may still identify a project or organisation, so do not submit information you lack authority to disclose. “Anonymous” publication cannot guarantee that a project is impossible to recognise from its facts.

10

Cookies and local storage

Coira currently uses storage that is necessary for authentication, session continuity, security and user-requested functionality. We do not currently use optional advertising cookies. If non-essential analytics or marketing technology is added, we will update this policy and request consent where required before it is activated.

11

Security

We use reasonable technical and organisational measures designed to protect information, including access controls and managed infrastructure. No internet service can guarantee absolute security. Please tell us promptly if you believe information or an account has been compromised.

12

Your rights

Depending on the circumstances, GDPR gives you the right to:

  • access your personal data;
  • correct it;
  • erase it;
  • restrict how we use it;
  • receive a copy of it;
  • object to certain processing; and
  • withdraw consent at any time.

You may also complain to Ireland’s Data Protection Commission.

To exercise a right, email fionan971@gmail.com. We may need to verify your identity and may retain limited information needed to record and comply with the request.

13

Children and policy changes

Coira is a business tool and is not directed to children. You must be at least 18 to create an account or purchase a subscription.

We may update this policy when the service, providers or legal requirements change. We will change the effective date and provide additional notice where a material change requires it.