Skip to content

Privacy

What Offerium is granted, and what it keeps.

Offerium asks to reach the mailbox where your invitations to bid arrive. This page says what that permission covers, what is kept out of it, where it is held and how to end it.

Last updated: 24 September 2026

Two relationships, governed differently

Almost every dispute about a business tool starts with someone assuming the wrong one of these, so they are separated first.

  • The website and early-access enquiries. Offerium decides what is collected and why, and answers for it.
  • Your firm’s mail, bids and documents. Your firm decides which mailboxes Offerium may reach and what becomes of what it finds. Offerium handles that material on your firm’s instruction and for no purpose of its own. In European terms, which apply because the data sits in Frankfurt, your firm is the controller and Offerium is the processor, under a written data processing agreement.

If you work at a customer firm and want to know what is held about you, ask your firm first. Offerium will help it answer.

Offerium is operated by
Valinor Innovations GmbH
Registered address
Tal 44, 80331 München, Deutschland
Privacy contact
sirma@offerium.ai

The website

The public site runs no analytics, sets no advertising or tracking cookie, and loads nothing from anyone else. The typefaces are served from Offerium’s own servers, so opening a page here makes no request to Google or to any other host.

  • One cookie. It holds “de” or “en” — the language you chose with the switch in the header — and nothing else. It is not an identifier and it says nothing about you.
  • Server logs. The host records what a web server ordinarily records: address, page, time and browser, to serve the page and keep the service standing up.
  • The early-access form. Your work email, and if you offer them, your company, where your requests for quotes arrive and roughly how many a month.

What a connected workspace holds

  • Bid mail and its attachments, as received, with a hash so the record can be checked against the original.
  • The bids themselves: buyer, project, reference, deadlines, prices, what was sent and how it ended.
  • Company documents your firm puts in: insurance certificates, references, standard texts, with their expiry.
  • The people in your workspace: name, work email, whether they may approve.
  • A record of what was done, by whom, from where, and what an approver had in front of them when they said yes.

Offerium does not expire anything on a schedule. A bid from four years ago is the evidence that prices the next one, which is the whole point of the first session.

The mail permission: granted and kept are not the same thing

Neither Google nor Microsoft sells a permission that picks out the messages about bids. The narrowest either offers covers the mailbox. Offerium is therefore granted more than it keeps, and this page states what it keeps rather than implying the permission is narrower than it is.

Offerium keeps only bid mail. A message that is not about a request for a quote, an invitation to bid, a bid, a change to the documents, an award or a result is discarded and never becomes part of your workspace. Where a person connects their own mailbox, their colleagues see the bid mail on its bid and nobody sees the rest.

Offerium never moves, deletes, labels or files a message. Its own interfaces have no method for it, and the contract every connector is written against forbids it, so the promise holds even against a bug. One permission is wider than that promise: sending a package too large for one request needs a draft, and Microsoft grants drafting as read-and-write. It is narrowed by Exchange to the single address bids go out from, and it is listed below with the rest.

Google Workspace:

Signing in
openid https://www.googleapis.com/auth/userinfo.email https://www.googleapis.com/auth/userinfo.profile
Tells Offerium who you are and gives it your name and work email. No mail is touched by signing in.
Reading a mailbox you connect
https://www.googleapis.com/auth/gmail.readonly
Finds the invitations to bid and their attachments, so the deadline, the submission method, the site walk and the requirements can be taken out of the documents. The grant covers the mailbox; what is kept is the bid mail.
Sending an approved bid
https://www.googleapis.com/auth/gmail.send
Sends from your firm’s one shared address, never as a person, and never anything an approver has not seen in full.
The Bids calendar
https://www.googleapis.com/auth/calendar.app.created
A separate calendar Offerium creates. This permission reaches no calendar it did not create, so your own diary is out of its range by construction.
Saving the approved bid
https://www.googleapis.com/auth/drive.file
Writes the approved copy into the one folder an approver picked, and nowhere else. Picking the folder is what grants the access; Offerium never scans Drive.

Microsoft 365:

Signing in
openid profile email offline_access
Tells Offerium who you are and gives it your name and work email. No mail is touched by signing in. offline_access is what keeps you signed in without asking again; it carries no access to mail of its own.
Reading a shared mailbox
Mail.Read (application, Exchange RBAC)
Limited to the mailboxes your administrator names, with the tenant-wide consent removed afterwards. Without that removal the two grants combine rather than narrow, which is why the removal is part of the setup and not tidying up after it.
Reading a person’s own mailbox
Mail.Read (delegated)
Consented by the person whose mailbox it is, at their own invitation link, and by nobody else. An administrator who can consent for the firm cannot consent for a colleague’s own mail.
Sending an approved bid
Mail.Send (application)
Scoped to the shared sending mailbox alone, and granted separately from reading.
Sending a large package
Mail.ReadWrite (application)
A package too large for one request is sent as a draft, and Microsoft grants drafting as read-and-write. Scoped by Exchange to the single sending address, used only to create the draft, attach the files and send it. Most bids never need it.
The Bids calendar
Calendars.ReadWrite (application)
Scoped to the shared bids mailbox and to no other calendar in the organisation.
Saving the approved bid
Sites.Selected (application)
One library or folder, chosen by your administrator, covering what is inside it and nothing beside it.

Disconnecting a mailbox stops the reading at once. The bids already found stay, and your history does not drop.

Google user data: the Limited Use disclosure

Offerium reaches Gmail through Google’s own interfaces, under a permission that Google classes as restricted. Google requires an app in that position to state plainly that its handling of the data obeys the Limited Use rules. Offerium’s statement is Google’s own wording, and it is not reworded here:

The use of information received from Google Workspace scopes will adhere to the Google User Data Policy, including the Limited Use requirements.
Google Workspace user data and developer policy, developers.google.com

In plain terms, this is what happens to what Offerium receives from Google:

  • It is used to find, prepare, check, approve, send and record your bids — the features in front of you — and for nothing else.
  • It is never sold, and never passed to anyone for advertising, credit assessment or data brokerage.
  • It is not used to train or improve any general machine-learning model. Today Offerium sends no customer mail and no customer document to any outside model at all; if that ever changes, it changes under a contract that forbids training and retention, and this page changes with it.
  • No person at Offerium looks at your messages, except where you ask for help with a specific item and agree to it, where it is necessary to investigate abuse or keep the service secure, or where the law requires it.
  • It is passed to the hosts named below, who run the service, and to nobody else.

The same undertakings cover what Offerium receives from Microsoft 365. Microsoft states them differently; Offerium does not behave differently.

Where it is held, and who else touches it

Offerium’s servers and its database are in Frankfurt, Germany. That is true of every customer, American and German alike. It is written here rather than glossed over: if you are an American firm, your data is held in the European Union.

Render
Hosting. The web service and the database run in Render’s Frankfurt region. Render is an American company.
Resend
Delivery of sign-in link emails. It receives the address a link is sent to. Resend is an American company.
Google · Microsoft
Your own mail provider, reached through their official interfaces. Your mail is already theirs; Offerium’s copy is the bid mail it keeps.

Two of those are American companies, so this page does not say “nothing leaves the EU”. It would be false, and a promise that is false in one endpoint is worth less than an accurate sentence. Those transfers run on the standard contractual clauses in each agreement.

Isolation, encryption and the record

  • One workspace per firm, enforced in the queries rather than in the interface. There is no screen and no export that can reach another firm’s data.
  • Encrypted while it travels, and encrypted where it is stored.
  • Every action a person takes is written to a record the product cannot edit or delete. That is a database rule, not a convention: an update or a delete against it is refused.

Getting it out, and getting rid of it

  • The owner of a workspace can export everything on any day: every bid with its buyer, price, outcome and the gap to the winner where one is known, and the company documents with their expiry and hash. It is CSV, which any spreadsheet opens without asking anyone’s permission.
  • A bid removed on request is removed, and the removal is recorded.
  • Closing an account removes the workspace. The record of what was done outlives it by design: a record of a removal that is itself removed records nothing.

How long anything is kept

  • Your mailbox record and your bids stay while the workspace does. A bid desk is an archive: the value of the history is that it reaches four years back, and what is deleted can no longer be evidence for a later bid.
  • A mailbox permission stays until it is withdrawn — by you at Google or Microsoft, or in Offerium. The stored key is deleted when it is.
  • An early-access request stays until we have written to you and you are either a customer or not interested.
  • The audit log outlives the workspace on purpose. It records who approved what and when — including a deletion itself.

Your rights

Because the data is held in the European Union, European rights attach to it whoever and wherever you are: to be told what is held, to have it corrected, to have it deleted, to have its use restricted, to object to it, and to receive it in a portable form. Ask at the contact above and Offerium will answer within a month.

California. Offerium does not sell personal information and does not share it for cross-context behavioural advertising, as the CCPA and the CPRA use those words, and it runs no advertising of any kind. Requests to know, to correct and to delete go to the same address, and nobody is treated differently for making one.

No consequential decision about a person is made automatically. A bid is prepared by the machine and released by a named person; that is the governing principle of the product and not a privacy concession.

You may also complain to a data protection authority. Because the data is in Germany, that includes the authority for the state Offerium is established in.

Changes, and one thing worth saying plainly

The date at the top is the date this wording last changed. A change that alters what Offerium does with your data will be told to customers rather than left here to be found.

LegalBack to the front page