TeamMatch

Privacy Policy

Last updated: 14 September 2026

This Privacy Policy explains how Tesla Solution d.o.o., Pavlovec Zabočki 19A, Pavlovec Zabočki, Republic of Croatia, OIB 77355791759 ("Tesla Solution", "we") processes personal data in connection with the TeamMatch platform.

TeamMatch is a B2B platform. Most data we process relates to businesses and to the individuals acting for them. The English version of this policy prevails in the event of a discrepancy between language versions.

1. Controller and processor

Tesla Solution is the controller for personal data processed for its own purposes: user accounts, company profiles, marketplace listings and matching, communication, subscriptions and billing, security and fraud prevention, and platform improvement.

For data that a business customer enters into TeamMatch Office, the customer determines the purposes and means of processing. In that case the customer is the controller and Tesla Solution acts as a processor on the customer's behalf under the Data Processing Agreement.

2. Categories of data we process

  • Account data: email address, authentication data, language preference, role.
  • Company data: company name, address, country, VAT number and verification result, contact person, phone number.
  • Marketplace data: requests, team listings, trades, availability, locations, match results, messages exchanged on the platform.
  • Subscription and billing data: subscription status, tier, billing period, payment status, invoice identifiers, tax details.
  • Technical and security data: IP address, device and browser data, log data, error reports.
  • TeamMatch Office data (customer-controlled): workers, identity documents, passports, A1 certificates, work permits, driving licences, certificates and qualifications, document expiry dates, languages, timesheets, project assignments, compensation and hourly-rate information, project billing data, vehicles and vignettes, accommodation information.
  • Inbound email data: emails sent to TeamMatch addresses, processed as private drafts for administrative review.

3. Purposes and legal bases

  • Providing the platform and the contract with your company — Article 6(1)(b) GDPR.
  • Billing, accounting and tax obligations — Articles 6(1)(b) and 6(1)(c) GDPR.
  • Platform security, abuse and fraud prevention, and improvement of the service — Article 6(1)(f) GDPR.
  • Verification of VAT numbers against the European Commission VIES service — Articles 6(1)(c) and 6(1)(f) GDPR.
  • Processing of TeamMatch Office data — on the instructions of the customer, which determines the legal basis for its own processing.

4. Matching and AI-assisted processing

Matching between requests and available teams is based on structured criteria such as trade, location, size and availability. Matching produces suggestions; it does not by itself produce legal effects or similarly significantly affect individuals, and no automated decision-making in the sense of Article 22 GDPR takes place.

Where you use AI-assisted functions, the relevant text or document content is sent to the Lovable AI Gateway and processed by a Google Gemini model to extract or structure information. AI output may be inaccurate and must be verified by the user.

5. Worker data and documents

Worker data and uploaded documents in TeamMatch Office are stored in private storage, separated per customer, and are not published on the marketplace or shared with other users.

Customer-uploaded documents are not routinely accessible to TeamMatch personnel. Access is restricted to specifically authorised personnel, under the principle of least privilege, and only where reasonably necessary for support requested by the customer, resolving a technical problem, investigating a security incident, preventing fraud or abuse, fulfilling documented customer instructions, or complying with a binding legal obligation. We do not claim that access is technically impossible.

6. Disclosure of company contact details

Company identity and contact details are not shown to other users until a business relationship becomes active on the platform. From that moment the other company can see the contact details necessary for the cooperation.

7. Service providers

We only state providers that are actually used in the production configuration. Hosting locations, certifications and transfer mechanisms of these providers are to be confirmed with each provider before production launch.

  • Lovable Cloud (managed Supabase infrastructure) — hosting, database, authentication, private file storage.
  • Stripe — payment processing, subscriptions, invoicing and tax calculation.
  • Lovable AI Gateway (Google Gemini models) — AI-assisted parsing and document extraction.
  • Mailgun — inbound email processing.
  • European Commission VIES — VAT number verification.

8. International transfers

Where a provider processes data outside the European Economic Area, the transfer is based on a valid mechanism under Chapter V GDPR, such as an adequacy decision or Standard Contractual Clauses. We do not make any claim about specific data-centre locations that we have not verified.

9. Retention

We retain account, company and marketplace data for as long as the account exists and afterwards only as long as necessary for legal obligations and the defence of legal claims. Billing records are retained for the period required by accounting and tax law. TeamMatch Office data is retained according to the customer's instructions. We do not state fixed retention periods that are not defined in our actual configuration.

10. Security

Access to data is controlled by authentication and by database-level access rules that restrict each company to its own data. Uploaded documents are stored in a private storage bucket that is not publicly accessible. We apply the technical and organisational measures offered by our infrastructure provider. We do not claim certifications or specific encryption standards that we have not verified.

11. Your rights

Requests relating to data we control can be sent to requests@teammatch.eu. If your request concerns data held in a customer's TeamMatch Office, please address the customer, which is the controller for that data.

  • access, rectification, erasure, restriction, data portability and objection under the GDPR;
  • withdrawal of consent where processing is based on consent, without affecting prior processing;
  • the right to lodge a complaint with a supervisory authority, in particular the Croatian Personal Data Protection Agency (AZOP) or the authority of your habitual residence.

12. Cookies and local storage

TeamMatch uses only strictly necessary cookies and local storage, for example to keep you signed in and to remember your language choice. See the Cookie Policy for details.

13. Contact

Tesla Solution d.o.o., Pavlovec Zabočki 19A, Pavlovec Zabočki, Republic of Croatia, OIB 77355791759. Email: requests@teammatch.eu. Website: https://teammatch.eu.