Legal

Privacy Policy

Last updated 14 September 2026

RFxFlow ("we") provides a B2B procurement platform. This policy explains how we process personal data when you use rfxflow.io. We act as a controller for account and billing data, and as a processor for tender content that organisations upload.

Data we process

  • Account data: name, email, job title, organisation, role, and authentication data (including MFA).
  • Tender data: documents, responses, scores, messages, and related files you store in the platform.
  • Usage and billing: subscription status, invoices, and security logs needed to operate the service.

Legal bases

We process account data to perform the contract (Art. 6(1)(b) GDPR) and to keep the platform secure (Art. 6(1)(f)). Organisation-uploaded tender content is processed on documented instructions from the customer under a data processing agreement.

Hosting and transfers

Application data is stored in the EU (Supabase, Frankfurt region). Email delivery uses Postmark; payments use Stripe. See the sub-processor list.

Retention

We keep account data while the organisation is active. After organisation deletion, personal data is removed from production systems except records we must keep for accounting or legal claims.

Your rights

You may request access, rectification, erasure, restriction, or portability. Signed-in users can download a copy of their account data from Settings, and organisation admins can delete the organisation. Contact privacy@rfxflow.io. You may also lodge a complaint with Datatilsynet (Denmark) or your local supervisory authority.

Cookies

We use essential cookies for authentication and session security. We do not use advertising cookies.

Back to RFxFlow