Data Processing Agreement
This Data Processing Agreement ("DPA") forms part of the agreement between the customer ("Controller") and Klokk Nettablering, operator of Tenderax ("Processor"), and applies to the extent Processor processes personal data on Controller's behalf in the course of providing the Tenderax service. It is intended to satisfy Article 28 of the GDPR. By accepting the Terms of Service and continuing to use Tenderax, Controller and Processor agree to this DPA.
1. Subject matter, duration, nature and purpose
Processor processes personal data uploaded by Controller (e.g. within company profile data, uploaded tender or company documents, and contact information entered into the platform) for the duration of the subscription, for the purpose of providing tender-relevance scoring, document analysis, and related Tenderax features. The nature of processing is automated storage, retrieval, and AI-assisted analysis of the data Controller submits.
2. Types of personal data and data subjects
Personal data may include names, work contact details, and role information belonging to Controller's employees, contacts, or business partners as included in uploaded documents or company profile fields. Data subjects are typically employees of Controller and, where uploaded documents reference them, individuals named in tender or company documentation.
3. Processor obligations
Processor shall:
- Process personal data only on documented instructions from Controller, including with regard to international transfers, unless required otherwise by EU or Norwegian law;
- Ensure persons authorised to process the data are bound by confidentiality;
- Implement appropriate technical and organisational measures per Annex II;
- Assist Controller in responding to data-subject requests and in meeting obligations under Articles 32–36 GDPR;
- Make available to Controller information necessary to demonstrate compliance with this DPA.
4. Confidentiality
Processor ensures that any person authorised to process personal data under this DPA has committed to confidentiality or is under an appropriate statutory obligation of confidentiality.
5. Security measures
Processor implements the technical and organisational security measures described in Annex II, including encryption in transit and at rest, access controls, and regular review of sub-processor safeguards.
6. Sub-processing
Controller provides general authorisation for Processor to engage the sub-processors listed below. Processor will inform Controller of any intended addition or replacement of sub-processors, giving Controller the opportunity to object on reasonable data-protection grounds within 14 days of notice.
| Sub-processor | Purpose | Location |
|---|---|---|
| Amazon Web Services (AWS SES) | Transactional email delivery | EU (eu-north-1, Stockholm) |
| Stripe | Payment processing and billing | United States |
| Anthropic (Claude API) | AI relevance scoring and document analysis | United States |
| ip-api.com | IP-based country detection for currency display | United States |
| Hetzner Online GmbH | Application hosting | Germany (EU) |
Processor remains fully liable to Controller for the performance of each sub-processor's obligations.
7. Assistance with data-subject rights
Taking into account the nature of processing, Processor shall assist Controller, insofar as possible, by appropriate technical and organisational measures, in fulfilling Controller's obligation to respond to requests from data subjects exercising their rights under Chapter III of the GDPR.
8. Personal data breach notification
Processor shall notify Controller without undue delay, and in any event within 48 hours of becoming aware, after confirming a personal data breach affecting Controller's data, providing information reasonably necessary for Controller to meet its own notification obligations under Articles 33 and 34 GDPR.
9. Deletion or return on termination
On termination of the underlying subscription, Processor shall, at Controller's choice, delete or return all personal data processed on Controller's behalf, and delete existing copies, within 30 days, unless EU or Norwegian law requires continued storage of specific data.
10. Audit rights
Processor shall make available to Controller all information reasonably necessary to demonstrate compliance with this DPA and shall allow for and contribute to audits, including inspections, conducted by Controller or an auditor mandated by Controller, subject to reasonable advance notice, confidentiality, and no more than once per 12-month period absent cause.
11. International transfers
Where personal data is transferred to a sub-processor outside the EU/EEA, such transfer is governed by the European Commission's Standard Contractual Clauses (SCCs), incorporated by reference into the relevant sub-processor agreement, supplemented by additional safeguards where required.
12. Precedence
In the event of a conflict between this DPA and the Terms of Service with respect to the processing of personal data, this DPA prevails.
Annex I — Parties and processing details
| Field | Detail |
|---|---|
| Controller | The Tenderax customer named on the applicable subscription account |
| Processor | Klokk Nettablering, Norway |
| Subject matter | Provision of the Tenderax tender-intelligence platform |
| Duration | Term of the subscription plus 30 days for deletion |
| Categories of data subjects | Controller's employees, contacts, and individuals named in uploaded documents |
| Categories of personal data | Name, work email, role, and any personal data contained in uploaded tender or company documents |
| Special category data | Not intentionally processed; Controller shall not upload special category data |
| Processing operations | Storage, retrieval, AI-assisted scoring and analysis, display within the platform |
Annex II — Technical and organisational security measures
- Encryption of personal data in transit (TLS 1.2+) and at rest;
- Role-based access controls limiting internal access to personal data on a need-to-know basis;
- Authenticated, logged access to production systems;
- Regular review of sub-processor security and data-processing agreements;
- Isolated storage of uploaded documents with per-account access boundaries;
- Redis caching of transient data (e.g. IP-derived country) limited to a 1-hour expiry;
- Documented incident-response process for personal data breaches;
- Regular backups with restricted access to backup infrastructure.
For questions about this DPA, contact [email protected].
← Back to Tenderax