Vjaġġa lill-kontenut

Ftehim dwar l-Ipproċessar tad-Data (DPA)

Il-versjoni Ġermaniża hi l-awtoritativa.

This page provides the Data Processing Agreement (DPA) pursuant to Art. 28 GDPR as a template for the customer's review. It is not concluded by merely visiting this page; it automatically becomes part of any paid or free usage agreement entered into via tendova.eu, to the extent the customer has personal data processed through the platform.

§ 1 Parties and scope

The controller within the meaning of Art. 4 No. 7 GDPR is the respective customer (“Controller”). The processor within the meaning of Art. 4 No. 8 GDPR is:

AAA BW GmbH
Robert-Koch-Weg 3, 72555 Metzingen, Deutschland
Register court: Amtsgericht Stuttgart, register number: HRB 806390
Email: [email protected]

This DPA specifies the parties' data-protection obligations in connection with the use of the Tendova platform and supplements the General Terms and Conditions (“AGB”). In the event of any conflict between this DPA and the AGB, this DPA takes precedence on data-protection matters.

§ 2 Subject matter, duration, and nature of processing

The subject matter of the processing is the provision of a tender-intelligence service (search, matching, alerts, AI-assisted summaries, and document analysis) based on the Tendova platform. The duration of processing corresponds to the term of the usage agreement (subscription) between the parties, plus the retention periods set out in § 10. The nature and purpose of processing follow from the plan booked and the features the controller actively uses, in particular uploading tender documents for AI-assisted analysis.

§ 3 Categories of data and data subjects

The following categories of data are processed under this DPA:

  • Account and profile data (name, business email address, company affiliation)
  • Tender documents uploaded by the controller's users and their contents
  • Usage and log data (search queries, interactions, IP address, timestamps)

Data subjects are the employees and other users the controller has authorized to use the platform, as well as, where applicable, natural persons whose data is contained in uploaded tender documents.

§ 4 Processing on instructions

The processor processes personal data solely on the controller's documented instructions, unless required to do otherwise by European Union or member state law. The controller's configuration and use of the platform (e.g. uploading documents, activating AI features) constitutes an instruction within the meaning of this clause.

§ 5 Confidentiality

The processor ensures that all persons authorized to process personal data have committed themselves to confidentiality or are subject to an appropriate statutory obligation of confidentiality.

§ 6 Technical and organizational measures

The processor implements appropriate technical and organizational measures within the meaning of Art. 32 GDPR, in particular:

  • Encrypted data transmission (TLS) for all client-server connections
  • Primary infrastructure operated on dedicated servers within the European Union (§ 8)
  • Role-based access control, limited to what is necessary
  • Regular data backups
  • Logging of security-relevant events to detect anomalies

§ 7 Sub-processors

The controller grants the processor a general authorization to engage the sub-processors listed below. The processor will notify the controller of any intended changes (addition or replacement of sub-processors) in advance by email or via the platform; the controller may object to such changes within 14 days on reasonable data-protection grounds.

Sub-processorPurposeLocationTransfer mechanism
Hetzner Online GmbHHosting and server infrastructureGermany (EU)No third-country transfer
Cloudflare, Inc.CDN, DNS, and web application firewallEU / USAEU-US Data Privacy Framework (DPF) and Standard Contractual Clauses (SCC)
OpenRouter, Inc.AI model routing — forwards requests for processing to the AI providers listed belowUSAStandard Contractual Clauses (SCC) pursuant to Art. 46 GDPR
Anthropic PBC (via OpenRouter)AI inference — summaries and document analysisUSAStandard Contractual Clauses (SCC) pursuant to Art. 46 GDPR
OpenAI LLC (via OpenRouter)AI inference — text embeddings for semantic searchUSAStandard Contractual Clauses (SCC) pursuant to Art. 46 GDPR
Mistral AI (via OpenRouter)AI inference — automated translationFrance (EU)No third-country transfer
Migadu MailTransactional email delivery (e.g. alerts, account confirmations)SwitzerlandEU Commission adequacy decision (Art. 45 GDPR)
Stripe Payments Europe, Ltd.Payment processing and invoicingIreland (EU)No third-country transfer

Stripe Payments Europe, Ltd. becomes operative as a sub-processor only upon activation of paid subscriptions on tendova.eu.

§ 8 Third-country transfers, AI processing, and data residency

Primary data storage and processing take place on dedicated Hetzner Online GmbH servers in Germany. Where the controller actively uses AI-assisted features (e.g. summaries, document Q&A), the relevant tender text or excerpts from uploaded documents are transmitted for processing to the AI providers listed in § 7. AI features are always opt-in and triggered per action by active user interaction; anyone wishing to avoid this transmission simply does not use the relevant AI features. Under the terms and data processing agreements of the AI providers used, customer data submitted through the platform is not used to train AI models.

§ 9 Assistance with data subject rights

The processor assists the controller, to the extent reasonable, with appropriate technical and organizational measures in fulfilling requests from data subjects (Art. 15 to 22 GDPR). Self-service data access and export are available to the controller at any time via Account Settings → Privacy.

§ 10 Deletion and return upon termination

The controller can export or fully delete organization data at any time via Account Settings → Privacy. Upon termination of the usage agreement, the processor deletes all personal data processed on the controller's behalf, unless statutory retention obligations (e.g. commercial and tax retention periods for billing data) require otherwise.

§ 11 Audit and inspection rights

On request, the processor provides the controller with the information necessary to demonstrate compliance with the obligations set out in Art. 28 GDPR and permits audits, including inspections, conducted by the controller or an auditor mandated by the controller, to the extent economically reasonable and subject to reasonable advance notice.

§ 12 Data breach notification

The processor notifies the controller without undue delay upon becoming aware of a personal data breach within the meaning of Art. 4 No. 12 GDPR affecting data processed under this DPA, and assists the controller in fulfilling any notification obligations toward supervisory authorities and data subjects.

§ 13 Liability and final provisions

The parties' liability in connection with this DPA is governed by the liability provisions of the AGB and the mandatory requirements of the GDPR. Should individual provisions of this DPA be or become invalid, the validity of the remaining provisions shall remain unaffected.