This document is pending formal legal review and may be updated before general launch.
These terms apply where COGNIVO FZ-LLC (TenderLock, the Processor) processes personal data on behalf of a customer organisation (the Controller) as part of the Service. They form part of the Terms and conditions and, for paid plans, the Subscription agreement. They are intended to meet Article 28 of the UK GDPR and EU GDPR.
1. Scope
- Subject matter and purpose: hosting and processing Customer Content so the Controller can run tenders, manage suppliers, buyers and contacts, communicate with them, evaluate submissions and keep records.
- Data subjects: the Controller's users, and people at suppliers, buyers and other third parties whose details the Controller adds or who take part in its tenders.
- Data types: names, business contact details, job titles, phone numbers, email content, call and message logs, company officer details, and any personal data included in documents and submissions.
- Special category data: the Service is not designed for it. The Controller should not upload special category or criminal offence data unless it is necessary and lawful.
- Duration: the term of the Service plus any export period, followed by deletion under section 3.
2. Our commitments
- Instructions: we process personal data only on the Controller's documented instructions, including through its use and configuration of the Service, unless the law requires otherwise. We will tell the Controller if we believe an instruction breaks data protection law.
- Confidentiality: everyone authorised to process the data is bound by confidentiality.
- Support access: our staff can access a customer account only when the customer grants time-limited support access, or where needed to keep the Service secure. Support access is logged and visible to the customer. Sealed submissions cannot be opened before their deadline.
- Security: we maintain appropriate technical and organisational measures, including encryption in transit, encrypted storage of credentials and tokens, role-based access, two-factor authentication, IP allow-lists for customers who enable them, audit logging and regular backups.
- Sub-processors: the Controller authorises the sub-processors listed below. We impose data protection terms on each one equivalent to these terms, remain responsible for them, and will give at least 30 days' notice of a new sub-processor by updating this page and emailing account owners. The Controller may object on reasonable data protection grounds.
- Assistance: we help the Controller respond to data subject requests, carry out impact assessments and meet its security and breach notification duties, taking into account the nature of the processing.
- Breaches: we notify the Controller without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting its data, with the information it reasonably needs.
- Audit: we make available the information reasonably needed to demonstrate compliance, and allow reasonable audits on at least 30 days' notice, no more than once a year unless a breach has occurred.
- Transfers: where personal data is transferred outside the UK or EEA, we use appropriate safeguards, such as the UK International Data Transfer Agreement or Addendum and the EU Standard Contractual Clauses, which are incorporated by reference where needed.
3. Return and deletion
When the Service ends, the Controller can export its data for 30 days. We then delete Customer Content from the live system within 30 days and from backups as they are overwritten, unless the law requires us to keep it.
4. Sub-processors
| Provider | Purpose | Location |
|---|---|---|
| DigitalOcean, LLC | Application hosting, database and backups | London, UK |
| Cloudflare, Inc. | DNS and network security | Global |
| Amazon Web Services (Amazon SES) | Sending and receiving email | EU / UK |
| Sendinblue SAS (Brevo) | Transactional email (being replaced by Amazon SES) | EU |
| Stripe Payments Europe Ltd | Payments and invoicing | EU / US |
| OpenAI, L.L.C. | AI features (no training on customer data) | US |
| Microsoft Corporation | Sign in with Microsoft and connected Microsoft 365 mailboxes, when a user chooses them | Global |
| Google LLC | Sign in with Google and connected Gmail mailboxes, when a user chooses them | Global |
| Creditsafe Business Solutions Ltd | Company credit checks, when ordered by the customer | UK |
| Companies House (UK government) | Public company information lookups | UK |
