This document is pending formal legal review and may be updated before general launch.
These terms apply where TenderLock processes personal data on behalf of a customer organisation (the Controller) as part of the Service, and form part of the Subscription agreement and the Terms and conditions.
1. Scope
- Subject matter: hosting and processing of Customer Content, including tenders, bids, clarifications and evaluation records.
- Data subjects: the Controller's users, and contacts at suppliers and other third parties.
- Data types: names, business contact details and any personal data included in documents.
- Duration: for the term of the Service and any agreed export period.
2. Our commitments
- Instructions: we process personal data only on the Controller's documented instructions.
- Confidentiality: our staff are bound by confidentiality. Support access to sealed or confidential content is restricted, time-limited and logged.
- Security: we maintain appropriate technical and organisational measures, including encryption in transit, access controls, two-factor authentication and malware scanning.
- Sub-processors: we use the sub-processors listed below and will give notice of changes.
- Assistance: we help the Controller respond to data subject requests and meet its security and breach notification duties.
- Breaches: we notify the Controller without undue delay after becoming aware of a personal data breach.
- Deletion: at the end of the Service we delete or return personal data, subject to legal retention duties.
- Audit: we make available information reasonably needed to demonstrate compliance.
3. Sub-processors
| Provider | Purpose |
|---|---|
| DigitalOcean and Amazon Web Services | Hosting and storage |
| Brevo | Transactional email |
| Stripe | Payments and invoicing |
| OpenAI | AI features |
