Legal

Privacy Policy

This policy explains what Coira Cost processes, why it does so, who receives it, and the choices you have.

Effective date: 18 August 2026

01

Controller and contact

Service operator / data controller
Coira Cost
info@coir.ie

The operator above is the controller for personal data processed through Coira, except where a named provider acts as an independent controller for its own service. Privacy questions and rights requests can be sent to info@coir.ie.

02

Information we process

  • Account data: email address, name, company, login provider, account identifiers and plan status.
  • Bid Review data: project description, client, location, bid, cost, margin, scope and exclusions submitted to generate a pack. In the current version these inputs are processed transiently and are not intentionally saved to your account or written to the application database.
  • Search activity: search terms and selected filters used to operate, secure and improve search. Current search logs are not intentionally linked to an account identifier.
  • Report requests: contact, company, role, project description, location, sector and budget information you submit.
  • Community submissions: optional contact and role details plus the project-cost information you contribute.
  • Payments: Stripe customer, subscription and transaction identifiers, billing status and limited billing details. We do not receive your full card number.
  • Support and commercial records: correspondence, requests, follow-ups and relevant CRM records.
  • Technical data: security, authentication, session and request data generated when you use the service.
03

Why we use it and our legal bases

  • Contract: to create and administer accounts, provide requested tools and reports, process subscriptions and support users.
  • Legitimate interests: to secure, troubleshoot, measure and improve the service; understand product use; prevent abuse; and manage business relationships, balanced against your rights.
  • Legal obligation: to keep required financial records, respond to lawful requests and comply with applicable law.
  • Consent: where required for optional marketing or non-essential cookies. You may withdraw consent at any time.

We do not use Coira’s submit/hold output to make a legal or similarly significant decision about you. It is a tool for your own human commercial decision.

Account email, authentication and any payment fields identified as required are needed to create or supply the relevant account or subscription. Required fields on report and submission forms are needed to process that request. If you do not provide them, we may be unable to provide the requested service. Fields marked optional may be left blank.

04

AI assisted features

Three features send information you supply to an AI model. Each of them says so on screen, at the point you meet the output — that labelling is how this service meets the transparency duty in Article 50 of the EU AI Act (Regulation (EU) 2024/1689), which has applied since 2 August 2026.

  • Coira guide (chat assistant): Free-text answers and links to tools inside the product. Processed by Anthropic.
  • AI-assisted tender extraction (bid workspace): Scope summary, dates, return requirements, risks, clarification questions, packages and a recommended next action — written by the model, in its own words, from tender text the user supplied. Processed by Anthropic.
  • Budget Builder indicative range: The headline low/mid/high euro range and its basis note, when the model path runs. The elemental package split is NOT model output — it is a published percentage template applied to whichever range was produced. Processed by Anthropic.

What is sent is the text you supply — your question to the assistant, your tender pack text, or your project brief — together with the context needed to answer it. Do not paste personal data, confidential tender material or trade secrets into these features unless you are authorised to do so and it is necessary.

Two further pipelines use Google’s Gemini models on published public procurement notices only — to read a floor area or a classification out of notice text. No account data and nothing you submit is sent to them. Where a figure shown to you is derived from one of those extractions, it is labelled on the page as AI-extracted.

Everything else in Coira is deterministic and involves no AI model: the cost benchmarks and medians, Bid Check, the Estimator, the elemental package split, the rule-based tender extractor, and all sector and trade classification. We label what is genuinely AI and nothing more.

We do not use any AI feature to make a legal or similarly significant decision about you, and none of them decides anything automatically. The output is an input to your own commercial judgement.

05

Sub-processors

These are every third party that processes information on our behalf, what each one is used for, and what it receives. We do not sell personal data. We may also disclose information to professional advisers or authorities where required by law, needed to protect rights or security, or as part of a genuine business sale or restructuring subject to appropriate safeguards.

SupabaseProcessor
Used for: Application database, account authentication, session management and file storage.
Receives: All account data: email address, name, company, role, plan status, and every user-created record listed in lib/personal-data.js (saved reports, bid models, watchlists, documents, projects, tags, Tender Check runs).
Location: UNVERIFIED — the hosting region of this specific project has not been confirmed from the Supabase dashboard. Supabase offers EU regions; whether this project uses one is an open question, not an assumption.
VercelProcessor
Used for: Application hosting, edge delivery, serverless function execution and request logging.
Receives: Request metadata generated by using the service: IP address, user agent, request paths and timestamps. Any personal data inside a request body transits Vercel while the request is being served.
Location: UNVERIFIED — US-headquartered provider with configurable function regions; the regions in use have not been confirmed.
StripeProcessor for subscription administration; independent controller for payment data under its own terms
Used for: Subscription checkout, payment processing, invoicing and billing status webhooks.
Receives: Billing identity, email address, customer and subscription identifiers, transaction records. Full card numbers are handled by Stripe and are never received by Coira.
Location: UNVERIFIED — Stripe operates through both EU and US entities; which one contracts here has not been confirmed.
Current status: Not yet processing live personal data — card payments are switched off in code until a live Stripe key is configured.
AnthropicProcessor
Used for: The three AI features named in the AI section of this policy: the Coira guide chat assistant, AI-assisted tender extraction, and the Budget Builder indicative range.
Receives: Whatever the user puts into those features. That is the material risk here: tender pack text pasted into the bid workspace can contain named individuals, contact details and commercially confidential pricing, and the chat assistant receives free text. Coira does not control what is pasted in.
Location: UNVERIFIED — US-headquartered provider; the serving region for these API calls has not been confirmed.
GoogleProcessor for notice enrichment; identity provider for Google sign-in
Used for: Two unrelated things. (1) Google sign-in, if the user chooses it. (2) The Gemini batch pipelines that read PUBLIC procurement notice text to extract floor areas and classifications — these do not process customer content.
Receives: Sign-in: the account identifiers Google returns on authentication. Gemini pipelines: published public procurement notice text only — no account data and no user-submitted content is sent to them.
Location: UNVERIFIED — US-headquartered provider; the serving region has not been confirmed.
Current status: Gemini pipelines have never run against production — no API key is configured and no enriched row exists.
06

International transfers — work in progress

Several of the providers above are headquartered outside the European Economic Area, so some processing may take place outside the EEA. We are being straight with you about where this stands: the specific transfer mechanism for each provider has not yet been confirmed and recorded, and we would rather say so than claim a safeguard we have not verified.

Each provider named above publishes standard data-processing terms and standard transfer clauses. Confirming which of those apply to our accounts, and recording them, is an open task being worked through before paid subscriptions are accepted. If your organisation needs the position for a specific provider before then, email info@coir.ie and you will get an accurate answer rather than a boilerplate one.

07

Retention

Our current retention targets are:

  • Bid Review inputs: not intentionally persisted by the current application after the response is generated.
  • Search logs: up to 12 months, then deleted or aggregated where practicable.
  • Report requests, support records and identifiable community submissions: generally up to 24 months after the last meaningful contact or review.
  • Approved benchmark data may remain after identifiers are removed and it is no longer personal data.
  • Account records: while the account is active and for a reasonable period after closure, normally no more than 24 months unless a dispute, security need or legal duty requires longer.
  • Invoices, subscription and tax records: normally six years or any longer period required by law.

Provider backups and security logs follow the provider’s documented schedules. We may retain specific records longer where reasonably required for legal claims, fraud prevention, security or regulatory compliance.

08

Aggregated and de-identified data

We may derive aggregated or de-identified statistics from account, search, report and community data — for example benchmark ranges, cost indices or usage trends. Once information no longer identifies you or a specific project, we may use it for product development, research, and our own reporting or marketing. We do not try to re-identify de-identified data except where necessary for security or legal compliance.

09

Community data and confidentiality

Community cost submissions are reviewed before publication. We aim not to publish the submitter’s name, email or direct contact details. Project fields may still identify a project or organisation, so do not submit information you lack authority to disclose. “Anonymous” publication cannot guarantee that a project is impossible to recognise from its facts.

10

Cookies and local storage

Coira currently uses storage that is necessary for authentication, session continuity, security and user-requested functionality. We do not currently use optional advertising cookies. If non-essential analytics or marketing technology is added, we will update this policy and request consent where required before it is activated.

11

Security

We use reasonable technical and organisational measures designed to protect information, including access controls and managed infrastructure. No internet service can guarantee absolute security. Please tell us promptly if you believe information or an account has been compromised.

12

Your rights

Depending on the circumstances, GDPR gives you the right to:

  • access your personal data;
  • correct it;
  • erase it;
  • restrict how we use it;
  • receive a copy of it;
  • object to certain processing; and
  • withdraw consent at any time.

You may also complain to Ireland’s Data Protection Commission.

To exercise a right, email info@coir.ie. We may need to verify your identity and may retain limited information needed to record and comply with the request.

13

Children and policy changes

Coira is a business tool and is not directed to children. You must be at least 18 to create an account or purchase a subscription.

We may update this policy when the service, providers or legal requirements change. We will change the effective date and provide additional notice where a material change requires it.