Privacy Policy
What this covers, and what it does not
This policy is about you — your account with us. We are the controller of that data.
It is not about your clients. When you enter a client's name, address or door code, you decide what is held and why, and we act on your instructions: we are your processor for that data, and the Data Processing Agreement is where those obligations are written down.
Who holds it
Anda Tech Solutions S.R.L., a company registered in Romania under trade-register number J40/10329/2022, tax identification code (CUI) 46223108, with its registered office at Strada Economu Cezărescu 52, Bloc 1, Etaj 5, Ap. 1509, Sector 6, Bucharest, Romania. You can reach us at contact@tendmatehq.com.
What we hold about you
- Your name and email address, so you can sign in and we can reach you.
- Sign-in sessions — which devices are signed in and when they were last used, so a lost phone can be signed out.
- Which business you belong to and whether you are its owner or its helper.
- A record of the versions of these documents you have agreed to, when, and from what kind of device. This is evidence that an agreement exists and we keep it for as long as the agreement matters.
- Billing identifiers from our payment provider, once billing is live. We never see or store your card details.
- Support correspondence you send us.
Why we are allowed to hold it
Because we need it to give you the service you asked for — that is a contract, under Article 6(1)(b) of the GDPR. The acceptance record is kept under Article 6(1)(c) and (f): we have to be able to show that an agreement exists.
We do not run advertising, we do not profile you, and there is no automated decision-making about you anywhere in this product.
Cookies
One cookie, called `sid`, which is what keeps you signed in. It is strictly necessary for a service you asked for, so there is no consent banner and nothing to opt out of.
There are no analytics, no advertising pixels and no tag manager anywhere on this site or in the app. A test in our codebase fails the build if one appears.
Who else sees it
Only the companies we need to run the service, each under a contract that binds them to the same standard:
- Railway Corp. — application and database hosting. Services and database are pinned to the Amsterdam (europe-west4) region, which a test asserts on every build.
- Resend (Plus Five Five, Inc.) — transactional email only: sign-in links and worker invitations. Stores data in the United States; certified under the EU-US Data Privacy Framework and covered by Standard Contractual Clauses.
- Stripe, Inc. — subscription billing. Engaged only once billing is live; it never receives your clients' data, only your own billing identifiers.
We publish this list, and we will tell you before we add to it so you have the chance to object.
Where it goes
The application and the database are hosted in the Netherlands. Sign-in emails are sent through a provider in the United States, which is certified under the EU-US Data Privacy Framework and additionally covered by Standard Contractual Clauses.
How long we keep it
- Your account: for as long as you are a customer, and thirty days after the account closes.
- Sign-in links: fifteen minutes. Worker invitations: seven days.
- Sessions: thirty days from last use.
- The acceptance record: for as long as the agreement it evidences could matter, and then six years.
- Backups: overwritten on their own rotation, so data erased from the live system can persist in a backup until that rotation completes.
What you can ask for
A copy of your data, a correction, deletion, restriction, portability, or an objection to processing. The export button in the app answers the first and the fourth immediately and without asking us.
Write to us and we will answer within a month. If you are not satisfied you can complain to the Romanian supervisory authority, ANSPDCP (dataprotection.ro), or to the authority where you live or work.