Privacy Policy
This policy explains what Coira Cost processes, why it does so, who receives it, and the choices you have.
Effective date: 18 August 2026
Controller and contact
The operator above is the controller for personal data processed through Coira, except where a named provider acts as an independent controller for its own service. Privacy questions and rights requests can be sent to info@coir.ie.
Information we process
- Account data: email address, name, company, login provider, account identifiers and plan status.
- Bid Review data: project description, client, location, bid, cost, margin, scope and exclusions submitted to generate a pack. In the current version these inputs are processed transiently and are not intentionally saved to your account or written to the application database.
- Search activity: search terms and selected filters used to operate, secure and improve search. Current search logs are not intentionally linked to an account identifier.
- Report requests: contact, company, role, project description, location, sector and budget information you submit.
- Community submissions: optional contact and role details plus the project-cost information you contribute.
- Payments: Stripe customer, subscription and transaction identifiers, billing status and limited billing details. We do not receive your full card number.
- Support and commercial records: correspondence, requests, follow-ups and relevant CRM records.
- Technical data: security, authentication, session and request data generated when you use the service.
Why we use it and our legal bases
- Contract: to create and administer accounts, provide requested tools and reports, process subscriptions and support users.
- Legitimate interests: to secure, troubleshoot, measure and improve the service; understand product use; prevent abuse; and manage business relationships, balanced against your rights.
- Legal obligation: to keep required financial records, respond to lawful requests and comply with applicable law.
- Consent: where required for optional marketing or non-essential cookies. You may withdraw consent at any time.
We do not use Coira’s submit/hold output to make a legal or similarly significant decision about you. It is a tool for your own human commercial decision.
Account email, authentication and any payment fields identified as required are needed to create or supply the relevant account or subscription. Required fields on report and submission forms are needed to process that request. If you do not provide them, we may be unable to provide the requested service. Fields marked optional may be left blank.
AI assisted features
Three features send information you supply to an AI model. Each of them says so on screen, at the point you meet the output — that labelling is how this service meets the transparency duty in Article 50 of the EU AI Act (Regulation (EU) 2024/1689), which has applied since 2 August 2026.
- Coira guide (chat assistant): Free-text answers and links to tools inside the product. Processed by Anthropic.
- AI-assisted tender extraction (bid workspace): Scope summary, dates, return requirements, risks, clarification questions, packages and a recommended next action — written by the model, in its own words, from tender text the user supplied. Processed by Anthropic.
- Budget Builder indicative range: The headline low/mid/high euro range and its basis note, when the model path runs. The elemental package split is NOT model output — it is a published percentage template applied to whichever range was produced. Processed by Anthropic.
What is sent is the text you supply — your question to the assistant, your tender pack text, or your project brief — together with the context needed to answer it. Do not paste personal data, confidential tender material or trade secrets into these features unless you are authorised to do so and it is necessary.
Two further pipelines use Google’s Gemini models on published public procurement notices only — to read a floor area or a classification out of notice text. No account data and nothing you submit is sent to them. Where a figure shown to you is derived from one of those extractions, it is labelled on the page as AI-extracted.
Everything else in Coira is deterministic and involves no AI model: the cost benchmarks and medians, Bid Check, the Estimator, the elemental package split, the rule-based tender extractor, and all sector and trade classification. We label what is genuinely AI and nothing more.
We do not use any AI feature to make a legal or similarly significant decision about you, and none of them decides anything automatically. The output is an input to your own commercial judgement.
Sub-processors
These are every third party that processes information on our behalf, what each one is used for, and what it receives. We do not sell personal data. We may also disclose information to professional advisers or authorities where required by law, needed to protect rights or security, or as part of a genuine business sale or restructuring subject to appropriate safeguards.
International transfers — work in progress
Several of the providers above are headquartered outside the European Economic Area, so some processing may take place outside the EEA. We are being straight with you about where this stands: the specific transfer mechanism for each provider has not yet been confirmed and recorded, and we would rather say so than claim a safeguard we have not verified.
Each provider named above publishes standard data-processing terms and standard transfer clauses. Confirming which of those apply to our accounts, and recording them, is an open task being worked through before paid subscriptions are accepted. If your organisation needs the position for a specific provider before then, email info@coir.ie and you will get an accurate answer rather than a boilerplate one.
Retention
Our current retention targets are:
- Bid Review inputs: not intentionally persisted by the current application after the response is generated.
- Search logs: up to 12 months, then deleted or aggregated where practicable.
- Report requests, support records and identifiable community submissions: generally up to 24 months after the last meaningful contact or review.
- Approved benchmark data may remain after identifiers are removed and it is no longer personal data.
- Account records: while the account is active and for a reasonable period after closure, normally no more than 24 months unless a dispute, security need or legal duty requires longer.
- Invoices, subscription and tax records: normally six years or any longer period required by law.
Provider backups and security logs follow the provider’s documented schedules. We may retain specific records longer where reasonably required for legal claims, fraud prevention, security or regulatory compliance.
Aggregated and de-identified data
We may derive aggregated or de-identified statistics from account, search, report and community data — for example benchmark ranges, cost indices or usage trends. Once information no longer identifies you or a specific project, we may use it for product development, research, and our own reporting or marketing. We do not try to re-identify de-identified data except where necessary for security or legal compliance.
Community data and confidentiality
Community cost submissions are reviewed before publication. We aim not to publish the submitter’s name, email or direct contact details. Project fields may still identify a project or organisation, so do not submit information you lack authority to disclose. “Anonymous” publication cannot guarantee that a project is impossible to recognise from its facts.
Cookies and local storage
Coira currently uses storage that is necessary for authentication, session continuity, security and user-requested functionality. We do not currently use optional advertising cookies. If non-essential analytics or marketing technology is added, we will update this policy and request consent where required before it is activated.
Security
We use reasonable technical and organisational measures designed to protect information, including access controls and managed infrastructure. No internet service can guarantee absolute security. Please tell us promptly if you believe information or an account has been compromised.
Your rights
Depending on the circumstances, GDPR gives you the right to:
- access your personal data;
- correct it;
- erase it;
- restrict how we use it;
- receive a copy of it;
- object to certain processing; and
- withdraw consent at any time.
You may also complain to Ireland’s Data Protection Commission.
To exercise a right, email info@coir.ie. We may need to verify your identity and may retain limited information needed to record and comply with the request.
Children and policy changes
Coira is a business tool and is not directed to children. You must be at least 18 to create an account or purchase a subscription.
We may update this policy when the service, providers or legal requirements change. We will change the effective date and provide additional notice where a material change requires it.