Data Processing Addendum (DPA)
This DPA forms part of the Terms of Service between you ("Controller") and Tender Guide ("Processor") for Personal Data processed via the Bid.Guide platform. It satisfies Article 28 GDPR, Article 9 Saudi PDPL, Article 26 UAE PDPL, and equivalent GCC frameworks.
1. Definitions
Terms used here have the meanings in the GDPR / Saudi PDPL / UAE PDPL. "Personal Data" means any information relating to an identified or identifiable natural person.
2. Subject matter, duration, nature, purpose
- Subject matter: Personal Data processed by Bid.Guide on behalf of the Controller in connection with tender discovery, qualification, drafting, submission, evaluation, award, and notification.
- Duration: the term of the Controller's account plus the retention schedule in our Privacy Notice.
- Nature & purpose: collection, storage, transmission, structuring, retrieval, AI-assisted analysis and content generation, notification dispatch, audit logging.
3. Categories of data & data subjects
- Data subjects: employees and authorised representatives of bidder firms; staff of tender-issuing entities; platform end-users.
- Categories: contact details (name, business email, phone), professional details (role, employer, certifications), firm-related identifiers (registration numbers, classifications, local-content scores), document content uploaded for tender purposes, account & session metadata.
- Special categories: not collected.
4. Processor obligations
The Processor shall:
- Process Personal Data only on documented instructions from the Controller (the Terms + this DPA + use of the platform).
- Ensure personnel are bound by confidentiality.
- Implement the security measures in Annex II.
- Assist the Controller in responding to data-subject rights requests.
- Assist with DPIAs and consultations with supervisory authorities.
- Notify breaches per §8.
- Delete or return Personal Data at the end of the engagement per §11.
- Make available all information necessary to demonstrate compliance.
5. Sub-processors
The Controller authorises the engagement of sub-processors listed in the current Sub-processor Register. We give 30 days' prior notice of any addition or replacement; you may object on reasonable grounds. We bind every sub-processor to obligations no less protective than this DPA.
6. International transfers
Personal Data is primarily processed in UAE-North and KSA-Riyadh. Any cross-border transfer of Personal Data subject to GDPR is made under the EU SCCs (2021/914) modules as appropriate, attached as Annex I. Transfers of GCC government-procurement data are made only where lawful in the relevant jurisdiction and subject to a documented Transfer Impact Assessment.
7. Security measures
See Annex II. We maintain ISO 27001 certification; SOC 2 Type II is in progress.
8. Breach notification
We notify the Controller without undue delay and in any event within 24 hours of becoming aware of a Personal Data breach affecting their data, providing: nature, categories, approximate number of records, likely consequences, measures taken or proposed. We assist with onward notification to data subjects and supervisory authorities.
9. Assistance with data-subject rights
We assist the Controller with access, rectification, erasure, restriction, portability, and objection requests via in-app self-service tools and, where needed, dedicated DPO support, normally within 7 days of request.
10. Audits
We make available our current SOC 2 / ISO 27001 reports and audited TOMs on request. Controllers may, on 30 days' notice and at their cost, audit our compliance with this DPA at a frequency not exceeding once per year, scoped to documents and personnel reasonably necessary, subject to confidentiality.
11. Return & deletion
On termination, we return Personal Data on request (export to JSON / CSV / standard formats) and delete remaining copies within 30 days, except where retention is required by law (e.g. KSA 10-year procurement records). Deletion is verified via secure crypto-shredding for any encrypted volumes.
12. Liability
Liability under this DPA is subject to the limitations in the Terms.
Annex I — SCCs / GCC transfer mechanisms
EU SCC modules: 2 (controller → processor) where you transfer EU resident data to us; 3 (processor → sub-processor) for our sub-processor chain. UAE PDPL Article 22 adequacy: we rely on adequacy where the destination jurisdiction has been listed by the UAE Data Office, otherwise on the Standard Contractual Clauses framework issued under UAE PDPL. KSA PDPL Articles 29–32: KSA-resident data is processed in-region; any exception is escalated to the Controller for explicit pre-approval and documented in this Annex.
Annex II — Technical & organisational measures
- Confidentiality: RBAC with least privilege; SSO/SAML; mandatory MFA for admin roles; quarterly access review.
- Integrity: code review on every change; immutable audit logs in WORM storage; SHA-256 hashes for every file; tamper-evident timestamps on sealed bids.
- Availability: 99.9% uptime target; backups every 6h with 30-day retention; tested DR runbook with 4h RPO / 8h RTO.
- Encryption: TLS 1.3+ in transit; AES-256 at rest; secrets in HSM-backed KMS.
- Pseudonymisation: authentication tokens hashed (SHA-256 + per-env pepper); analytics keys salted.
- Network: VPC isolation per tenant tier; WAF in front of all public endpoints; rate-limiting on auth + invite endpoints.
- Personnel: background checks; annual security training; signed confidentiality undertakings.
- Physical: data centres are ISO 27001 / SOC 2 with biometric access.
- Testing: annual third-party penetration test; continuous SAST + DAST; bug bounty.
- Incident response: 24/7 on-call; documented runbook; 24h breach notification to Controllers.