1. Responsibility and scope
D180 LLC operates the D180 platform and defines the rules for collecting, using and retaining the data processed within the service. The technical capabilities provided by our hosting, database, authentication, email and payment platforms fall under shared responsibility: D180 configures and operates the application, while its providers run the underlying technical services.
2. Data collected and purposes
D180 mainly processes the following categories of data:
- identity and account: first name, last name, email, company, country, preferences and profile information;
- platform usage: searches, alerts, saved tenders, quote requests and interactions;
- billing and payment: subscription status, payment references and accounting information;
- support and security: messages sent to the team, technical logs and events required for diagnostics.
This data is used to provide the service, manage accounts, send expected notifications, handle quote requests, manage billing, improve the platform and protect users.
3. Retention and deletion
- Active account : Kept as long as the account remains open.
- Inactive or closed account : Data not subject to legal obligation is deleted or archived on request.
- Billing : Accounting records kept for up to 10 years.
- Technical logs : Security and diagnostic logs kept for up to 12 months.
- Cookies : Non-essential cookies kept for a maximum of 13 months.
To request access, rectification, export or deletion of your data, email contact@d180.info.
4. Subprocessors and integrations
The providers used by D180 are limited to what the platform requires to operate:
- Lovable Cloud — Application hosting, backend, authentication, database and emails.
- Cloudflare — Distribution, performance and network protection.
- Stripe (via Jalkilixecom LLP) — Payment processing and subscription management.
- Google — OAuth sign-in when the user chooses Google.
- Firecrawl — Collection and verification of public tender sources.
- Lovable AI — Translation and content enrichment assistance.
Data is not sold to third parties for commercial purposes.
5. Security and access
D180 enforces role-based access controls, restricts admin areas to authorised users, protects sensitive routes on the server side and logs the events required to monitor operations. All exchanges with the platform use TLS encryption. Passwords are handled by the authentication service and are not stored in plain text by D180.
Admin pages exposing sensitive information, such as email logs or error details, are restricted to signed-in administrators.
6. Emails, deletion and unsubscribe
Confirmation, account recovery, notification and follow-up emails are sent from the D180 notification domain. Send events are tracked to detect failures, blocks and permanently failed messages. Unsubscribes and address removals are honoured to avoid unwanted sends.
7. Incident handling
In the event of a security incident, D180 assesses the scope, isolates the root cause, fixes the issue, documents the actions taken and informs affected people when regulations require it. Incidents with a significant impact on personal data are handled as a priority and may lead to notification of the competent authorities.
8. Security contact and vulnerabilities
Contact : contact@d180.info
To report a vulnerability, suspected abuse or any security-related question, contact the address above with a clear description, reproduction steps and any element useful for diagnosis. D180 acknowledges receipt and prioritises reports based on potential impact.
