Legal

Processing terms

These terms govern personal data that a customer firm uploads to Coira — above all the tender returns an adjudication reads. The firm is the controller of that material and Coira is its processor. They are written to meet Article 28(3) of the GDPR.

00

Status of this document

This is a draft prepared for legal review and it has not yet been reviewed by a solicitor. Every commitment in it was written from the software as built rather than from a template, and where the product does not do something it says so instead of promising it. It is published so that a customer, and their advisers, can see exactly what is and is not being undertaken. It is not legal advice.

Effective from 8 September 2026. It forms part of the Terms of Service and applies wherever a firm uploads personal data belonging to third parties.

01

Who is who

  • You, the customer firm, are the controller. You obtained the tender returns, you decide what to upload and why, and you hold whatever relationship exists with the tenderers and their staff.
  • Coira is the processor, operated by:

Coira Cost fionan971@gmail.com

Contact for anything in this document: fionan971@gmail.com

02

Subject matter, duration, nature and purpose (Art 28(3))

  • Subject matter: reading, comparing and reporting on tender returns and related documents you upload.
  • Duration: for as long as you keep the adjudication, and until you delete it or ask us to.
  • Nature and purpose: extracting priced items, qualifications and exclusions from documents; comparing them across tenderers; presenting findings for a person at your firm to decide; and producing the report you issue.
  • Categories of personal data: the names, job titles, direct telephone numbers, email addresses and sometimes signatures of the people who prepared or transmitted a bid, as they appear on covering letters and transmittal sheets; the names and rates of your own staff where you load a rate card; and the account details of your users.
  • Categories of data subject: your own staff; and staff of the contractors and suppliers who priced the package. The second group have no relationship with Coira and did not choose to deal with us, which is why the instruction to act on their data has to come from you.
  • No special category data is sought, and the product has no purpose for any.
03

We process only on your documented instructions (Art 28(3)(a))

We process the material only to provide the service to you. We do not use it for any purpose of our own. Specifically:

  • we do not use your documents or their contents to train or fine-tune any model;
  • we do not pool your data with another customer's, and the vocabulary the tool learns from your review queue is never merged into a shared model or another firm's;
  • we do not sell, license or disclose it, other than to the sub-processors listed below and where the law requires;
  • if we ever believed an instruction from you infringed data protection law, we would tell you rather than act on it.
04

Confidentiality (Art 28(3)(b))

Everyone with access to the material is bound to confidentiality. The material is commercially confidential as well as personal: it is contractors' pricing, given to you in confidence, and its value to a competitor is obvious. Access by our own personnel is limited to what is necessary to operate and support the service.

05

Security (Art 28(3)(c), Art 32)

The measures actually implemented, rather than a generic list:

  • Tenant isolation is enforced in the database, not only in application code: every adjudication table carries the owning firm and row-level security restricts reads and writes to members of that firm.
  • Uploaded files are not publicly reachable. No client role can read an object in the document store directly; access is brokered by the server after it has checked who is asking.
  • Decisions are attributed. Every accept or reject records who made it and when, in an append-only trail. If the content behind a decision later changes, the decision is cleared and returned for a fresh one rather than carried over onto material the person never saw.
  • Data is stored in the EEA. The application database is hosted in eu-north-1 (Stockholm).
  • Deletion removes the files, not only the records — see section 08.

Access is logged. Every document records the person who uploaded it, every accept or reject records who decided it, and every time a document is opened a row is written naming who was granted access and when. That log cannot be edited or deleted by anyone, including us — the database refuses it. So a firm can answer “who at my firm opened this tender return?”.

Two limits on that, stated rather than glossed. The log records that access was GRANTED, not that the file was fetched: we cannot see whether a browser followed the link it was given, and we will not record something we did not witness. And documents uploaded before 8 September 2026 carry no uploader, because nothing recorded it at the time and we will not invent one.

06

Sub-processors (Art 28(3)(d), Art 28(2))

We use the sub-processors below. We will tell you before adding or replacing one, and you may object. Each is listed with what it actually receives.

  • Supabase — Application database, account authentication, session management and file storage.
  • Vercel — Application hosting, edge delivery, serverless function execution and request logging.
  • Stripe — Subscription checkout, payment processing, invoicing and billing status webhooks.
  • Resend — Transactional email. Today that is the owner notification sent when somebody submits an access request, and the sender used by lib/notify.js.
  • Anthropic — Seven registered surfaces (lib/ai-disclosure.js). LIVE AND CUSTOMER-FACING: the Coira guide chat assistant; AI-assisted tender extraction in the bid workspace; the Budget Builder indicative range. ADJUDICATION, all three reading tender-return content and all three currently OFF: the schedule-extractor cell read (F2, which has no model provider registered at runtime, so it never calls out); the aligner/skeptic pair (F3, switched off by default in both the API route and the command line on 8 Sep 2026, and not reachable from a request); the qualifications reader (F4, covering letters). INTERNAL, not customer data: the Coira OS agents (morning brief, second brain, chief of staff), which run on the operator's own account.
  • Google — Two unrelated things. (1) Google sign-in, if the user chooses it. (2) The Gemini batch pipelines that read PUBLIC procurement notice text to extract floor areas and classifications — these do not process customer content.

Where an entry records something as unverified, that is a statement about our own paperwork, not a claim that the position is fine. The current list and its open items are on the privacy notice.

07

Helping you answer data subjects, and regulators (Art 28(3)(e), (f))

If someone whose details are inside a document you uploaded contacts us directly, we will not act on their request ourselves. We will refer them to you and tell you.You hold the relationship and the context; we have no way to verify who they are or what they are entitled to, and acting alone would risk disclosing your material to a stranger.

On your instruction we will help you locate, export, correct or delete material within the service, and will assist with security incidents, notifications and impact assessments so far as the information is ours to give.

08

Deletion and return (Art 28(3)(g))

You can delete an adjudication. Deleting one removes the uploaded files from storage as well as the database records, and it does so in that order, so that a failure leaves everything in place and retryable rather than leaving files nobody can find. If anything cannot be reached, the result says so rather than reporting success.

What is deliberately kept, and why:

  • Invoices and billing records, for the statutory accounting period (Irish Revenue: six years).
  • Your firm's learned vocabulary, which is taught across every job rather than the one being deleted, and which holds no third-party personal data.

Stated plainly: closing a firm's whole account is not yet self-service. Erasure at that level is carried out by us on your written request.

09

Audit (Art 28(3)(h))

We will make available the information needed to show that these obligations are met, and will co-operate with an audit or inspection you or your auditor carries out, on reasonable notice and subject to protecting other customers' confidentiality.

10

International transfers

Application data is stored in the EEA. Some sub-processors are established outside it; the privacy notice records, per processor, what has been confirmed and what has not. Where a transfer outside the EEA occurs and requires a Chapter V mechanism, we will not make it until one is in place.