Tenderax

Data Processing Agreement

Last updated 16 July 2026  ·  Operated by Klokk Nettablering
policy_version: 2026-07-16.1

This Data Processing Agreement ("DPA") forms part of the agreement between the customer ("Controller") and Klokk Nettablering, operator of Tenderax ("Processor"), and applies to the extent Processor processes personal data on Controller's behalf in the course of providing the Tenderax service. It is intended to satisfy Article 28 of the GDPR. By accepting the Terms of Service and continuing to use Tenderax, Controller and Processor agree to this DPA.

1. Subject matter, duration, nature and purpose

Processor processes personal data uploaded by Controller (e.g. within company profile data, uploaded tender or company documents, and contact information entered into the platform) for the duration of the subscription, for the purpose of providing tender-relevance scoring, document analysis, and related Tenderax features. The nature of processing is automated storage, retrieval, and AI-assisted analysis of the data Controller submits.

2. Types of personal data and data subjects

Personal data may include names, work contact details, and role information belonging to Controller's employees, contacts, or business partners as included in uploaded documents or company profile fields. Data subjects are typically employees of Controller and, where uploaded documents reference them, individuals named in tender or company documentation.

3. Processor obligations

Processor shall:

4. Confidentiality

Processor ensures that any person authorised to process personal data under this DPA has committed to confidentiality or is under an appropriate statutory obligation of confidentiality.

5. Security measures

Processor implements the technical and organisational security measures described in Annex II, including encryption in transit and at rest, access controls, and regular review of sub-processor safeguards.

6. Sub-processing

Controller provides general authorisation for Processor to engage the sub-processors listed below. Processor will inform Controller of any intended addition or replacement of sub-processors, giving Controller the opportunity to object on reasonable data-protection grounds within 14 days of notice.

Sub-processorPurposeLocation
Amazon Web Services (AWS SES)Transactional email deliveryEU (eu-north-1, Stockholm)
StripePayment processing and billingUnited States
Anthropic (Claude API)AI relevance scoring and document analysisUnited States
ip-api.comIP-based country detection for currency displayUnited States
Hetzner Online GmbHApplication hostingGermany (EU)

Processor remains fully liable to Controller for the performance of each sub-processor's obligations.

7. Assistance with data-subject rights

Taking into account the nature of processing, Processor shall assist Controller, insofar as possible, by appropriate technical and organisational measures, in fulfilling Controller's obligation to respond to requests from data subjects exercising their rights under Chapter III of the GDPR.

8. Personal data breach notification

Processor shall notify Controller without undue delay, and in any event within 48 hours of becoming aware, after confirming a personal data breach affecting Controller's data, providing information reasonably necessary for Controller to meet its own notification obligations under Articles 33 and 34 GDPR.

9. Deletion or return on termination

On termination of the underlying subscription, Processor shall, at Controller's choice, delete or return all personal data processed on Controller's behalf, and delete existing copies, within 30 days, unless EU or Norwegian law requires continued storage of specific data.

10. Audit rights

Processor shall make available to Controller all information reasonably necessary to demonstrate compliance with this DPA and shall allow for and contribute to audits, including inspections, conducted by Controller or an auditor mandated by Controller, subject to reasonable advance notice, confidentiality, and no more than once per 12-month period absent cause.

11. International transfers

Where personal data is transferred to a sub-processor outside the EU/EEA, such transfer is governed by the European Commission's Standard Contractual Clauses (SCCs), incorporated by reference into the relevant sub-processor agreement, supplemented by additional safeguards where required.

12. Precedence

In the event of a conflict between this DPA and the Terms of Service with respect to the processing of personal data, this DPA prevails.

Annex I — Parties and processing details

FieldDetail
ControllerThe Tenderax customer named on the applicable subscription account
ProcessorKlokk Nettablering, Norway
Subject matterProvision of the Tenderax tender-intelligence platform
DurationTerm of the subscription plus 30 days for deletion
Categories of data subjectsController's employees, contacts, and individuals named in uploaded documents
Categories of personal dataName, work email, role, and any personal data contained in uploaded tender or company documents
Special category dataNot intentionally processed; Controller shall not upload special category data
Processing operationsStorage, retrieval, AI-assisted scoring and analysis, display within the platform

Annex II — Technical and organisational security measures

For questions about this DPA, contact [email protected].

← Back to Tenderax