Privacy Policy
Last updated: May 1, 2026
Asistan ("we", "us", or "our") operates the Asistan mobile application and related services (collectively, the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.
1. Information We Collect
1.1 Account Information
- Email address and password (or Apple Sign-In credentials)
- Company or organization name (optional)
1.2 Keyword Profiles & Preferences
- Keywords and search criteria you configure for tender matching
- Notification preferences (frequency, quiet hours, minimum match score)
1.3 Device & Usage Data
- Device model and iOS version
- Apple Push Notification service (APNs) token
- App usage statistics and crash logs (via Apple frameworks)
1.4 Tender Data
- We do not create the tender listings. We collect publicly available procurement notices from government and institutional websites.
- Bookmarks and dismissals you make within the app
2. How We Use Your Information
- To provide the Service: Matching tenders against your keyword profiles and sending notifications.
- To improve the Service: Analyzing usage patterns to enhance matching accuracy and relevance.
- To communicate with you: Sending account-related emails (verification, password reset).
- For security: Detecting fraud, abuse, and unauthorized access.
3. How We Store & Protect Your Data
- All data is stored on encrypted servers within the European Union.
- We use industry-standard TLS encryption for data in transit.
- Passwords are hashed using bcrypt. We never store passwords in plain text.
- Access to production databases is restricted and logged.
4. Third-Party Services
- Apple Sign-In: If you choose to sign in with Apple, we receive your Apple ID and name/email as authorized by you.
- Apple Push Notification service (APNs): We send push notifications through Apple's infrastructure. Apple may process device tokens pursuant to their privacy policy.
- Moonshot AI (Kimi): We use Moonshot's API for semantic search and tender evaluation. Your keyword profiles and tender text may be transmitted to Moonshot for embedding generation and relevance scoring. Moonshot does not retain this data for model training. You can withdraw AI processing consent at any time in Settings → Privacy & Legal → AI Data Consent. Without consent, you can still browse and bookmark tenders, but AI matching and personalized recommendations will be disabled.
- PostgreSQL / pgvector: Our database provider (self-hosted) stores all application data.
5. Your Rights (GDPR)
If you are located in the European Union, you have the following rights:
- Access: Request a copy of all data we hold about you.
- Correction: Update inaccurate or incomplete data.
- Deletion: Request deletion of your account and associated data.
- Portability: Export your data in a machine-readable format.
- Restriction: Limit how we process your data.
- Objection to AI Processing: Withdraw consent for AI-powered matching at any time via the app settings. This stops the transmission of your keyword profiles to Moonshot AI.
You can exercise most rights directly in the app via Settings → Export My Data or Settings → Delete Account. For other requests, email us at privacy@datameshconsulting.co.uk.
6. Data Retention
- Account data is retained until you delete your account.
- Device tokens are retained until you sign out or disable notifications.
- Anonymous usage metrics may be retained indefinitely for analytics.
7. Children's Privacy
The Service is not intended for use by anyone under the age of 16. We do not knowingly collect personal information from children under 16. If you believe we have collected such data, please contact us immediately.
8. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes via email or in-app notification. The "Last updated" date at the top of this page reflects the most recent revision.
Contact Us
If you have any questions about this Privacy Policy, please contact us at: