Privacy Policy
Last updated: 12 September 2026
This Privacy Policy explains how Meritur(“we”, “us”) collects, uses and protects personal data on our platform: a business-to-business marketplace where clients post projects and assignments, service providers submit bids that are ranked on quality, and the resulting engagements are managed. Meritur facilitates these connections; it is not a party to the contracts between clients and service providers.
Who we are (data controller)
Meritur ApS, CVR 46766288, Rebslagervej 7C, 3. tv., 2400 København NV, Denmark, is the data controller for the processing described in this policy. For any privacy question, or to exercise your rights, contact us at privacy@meritur.com.
Who this policy applies to
Merituris a business-to-business service for companies and their representatives; we do not knowingly offer it to consumers or to children. “Personal data” means information about identifiable individuals acting for a business — for example a company’s named contact — which is protected under the EU General Data Protection Regulation (GDPR) and the Danish Data Protection Act.
Data we process
- Account data: your name, work email, role (client / service provider / administrator) and authentication credentials. Sign-in is handled by our authentication provider; your password is stored in hashed form and is never visible to us.
- Company data: company name, CVR number, sector, description, self-declared size and financial ranges, and verification status. For Danish companies, parts of the profile can be prefilled from the public CVR register (activity category and ranges derived from published annual accounts); you can adjust these values.
- Project & bid content: postings, budgets, timelines, categories, uploaded attachments, bids, proposal documents, price ranges, milestone plans, counter-proposals, engagement letters and notes — which may contain personal data if you choose to include it.
- Confidential-project (NDA) contacts: for confidential projects, the name, email and phone number of each person a service provider places under the accepted non-disclosure undertaking, so the client knows who is legally bound and can reach them.
- Meetings: when a client schedules an introductory meeting on a bid, we process the meeting details (time, headline, agenda, notes) and send calendar invitations by email to the participants on both sides.
- Messages, surveys & reviews: in-platform messages (available once an engagement exists), satisfaction survey responses and any review content.
- Operational data: fee, settlement and invoice records (including 25% Danish VAT) and an audit log of key actions. Meritur never holds client funds — payment flows directly between client and service provider.
- Technical data: log data generated when you use the platform (such as timestamps and technical request information), used to operate and secure the service, and records of our AI feature usage (tokens and feature counts, not tied to profiling).
What we use it for
- to operate the marketplace: accounts, postings, bids, quality scoring, meetings, engagements, settlements and support;
- to send service emails: notifications about bids, access requests, awards, meetings and account matters;
- to keep the platform safe and honest: security, fraud and abuse prevention, preventing circumvention of the platform, and the audit log;
- to improve the service, including improving the accuracy of our AI-assisted features based on how the platform is used (see the AI section below for the strict limits that apply); and
- to comply with legal obligations such as bookkeeping and VAT.
We do not sell personal data, and we do not use your data for third-party advertising.
Legal bases
- Performance of a contract (Art. 6(1)(b) GDPR): to provide the marketplace and its features.
- Legitimate interests (Art. 6(1)(f)): security, fraud and abuse prevention, preventing circumvention, service improvement, and keeping the audit log.
- Consent (Art. 6(1)(a)): for non-essential cookies (see below). You can withdraw consent at any time.
- Legal obligation (Art. 6(1)(c)): bookkeeping, tax and VAT records.
AI features & automated decision-making
The platform uses AI to assist — never to decide alone. AI features include drafting briefs, summarising uploaded documents, suggesting form values, proposing redactions for confidential postings, and estimating bid quality scores. We minimise the personal data sent to the AI model (for example, contact details are not included in scoring inputs), and processing takes place under a data processing agreement with EU data residency for our stored data.
AI-suggested bid scores are not final automated decisions: a human reviews and confirms scoring before it ranks a bid, so there is always a human in the loop (Art. 22 GDPR). The main ranking parameters are published on the platform.
Our AI features learn from how the platform is used — for example, from expert scoring corrections — under two strict limits: your data is never used to train third-party AI models, and confidential details from one project are never exposed to another project. Learned improvements are generalised rules and statistics, screened in software against company names, personal names and project-identifying phrases before use.
When contact details are shared
The platform shares contact details deliberately and only where the process requires it:
- a client’s contact email is visible to service providers viewing its posting (for confidential projects, only after access is granted);
- a bidding service provider’s team emails are visible to the client on the ranked-bid view, so the client can reach the people behind a bid;
- on confidential projects, the client sees the name, email and phone number of each person covered by the provider’s accepted NDA;
- meeting invitations are emailed to the participants on both sides, who see each other as attendees.
Beyond this, other users’ private contact details are not displayed, and in-platform messaging opens only once an engagement exists. Contact details obtained through the platform may only be used in connection with the relevant project or engagement.
Sub-processors we share data with
We rely on the following sub-processors to run the platform. Each processes personal data only on our instructions, under a data-processing agreement, and only as needed for the purpose shown:
- Supabase — database, authentication and file storage. Purpose: storing and serving account, company, project, bid and file data. Location: EU.
- Vercel — application hosting and content delivery. Purpose: running the website and its server functions. Location: EU function region, with a global edge network for static delivery.
- Resend — transactional email delivery. Purpose: sending notification, meeting and account emails. Data shared: recipient email addresses and message content.
- Anthropic — AI model provider for the assistive features described above. Purpose: generating summaries, estimates, suggestions and redactions. Data shared: the project, bid and scoring content those features run on, with personal data minimised. Your data is not used to train third-party models.
This list may change as the platform evolves; we keep it current on this page. We may also disclose data where required by law, or to establish, exercise or defend legal claims.
Where your data is stored
We host data and run our AI processing within the EU. If a transfer outside the EU/EEA becomes necessary, we rely on an approved safeguard such as the European Commission’s Standard Contractual Clauses.
Retention & security
We keep personal data only as long as your account is active and as needed for the purposes above — then only as required by law (for example accounting records), to resolve disputes and to enforce our agreements. When no longer needed, data is deleted or anonymised. Audit logs are retained for a limited period for security and accountability and are accessible only to administrators.
We protect data with appropriate technical and organisational measures: access controls, EU-hosted infrastructure, private storage for uploaded files served through short-lived links, database-level access restrictions, and encryption in transit. No method of transmission or storage is completely secure, but we work continuously to protect your data and will inform you and the relevant authority of any breach as required by the GDPR.
Cookies
We use essential cookies and local storage only by default. These keep you signed in and remember your language and cookie choices, and do not require consent. Any non-essential cookies (for example analytics) are declined by default and are only set if you explicitly accept them. You can change your choice at any time via , and you can also manage cookies through your browser settings — though blocking essential cookies may prevent parts of the platform from working.
Your rights
Under the GDPR you can request access to, rectification of, and erasure of your personal data; restriction of processing; data portability; and you can object to processing based on legitimate interests and withdraw consent at any time (without affecting processing already carried out). You can review and update your account and company details directly on the platform, and you can close your account by contacting us. To exercise any right, write to privacy@meritur.com — we respond within the timelines the GDPR sets. You may also lodge a complaint with the Danish Data Protection Agency (Datatilsynet, datatilsynet.dk).
Business transfers
If Meritur is involved in a merger, acquisition, reorganisation or sale of assets, personal data may be transferred as part of that transaction. We will notify you before your personal data becomes subject to a different privacy policy.
Changes & contact
We may update this policy from time to time. Material changes are announced on the platform or by email, and the “Last updated” date above always reflects the current version. Questions? Contact us at privacy@meritur.com, and see our Terms of Service for the terms that govern use of the platform.