1. Definitions
Terms used in this DPA have the meanings given in the UK GDPR. Customermeans the organisation that has agreed to the Terms of Service and acts as controller of the personal data processed under this DPA. Processor means Rhics Ltd.
2. Roles and scope
The Customer is the controller and the Processor is the processor in respect of Customer Personal Data processed to provide the Service. Where the Customer is itself a processor, it appoints the Processor as sub-processor and warrants that it has the necessary authority from the underlying controller.
3. Subject matter and duration
The subject matter of processing is the provision of the Contract Tenders platform. The duration is the term of the Customer's Subscription, plus any additional period reasonably required to delete or return the personal data.
4. Nature and purpose
The Processor will process personal data as required to host the Workspace, ingest and retrieve documents, generate AI outputs, provide support, secure the Service, and comply with legal obligations.
5. Categories of data subjects and data
- Data subjects: the Customer's users, employees, associates, references, contacts, and any individuals identified in Customer Content.
- Personal data: identification and contact details, professional background, employment information, CV data, tender-related correspondence, and any other data the Customer chooses to upload.
- The Customer must not upload special category data or criminal-offence data unless it has a lawful basis and appropriate safeguards.
6. Instructions
The Processor will process personal data only on documented instructions from the Customer, including as set out in the Terms of Service, this DPA, and any lawful configuration selected by the Customer in the Service. The Processor will inform the Customer if, in its opinion, an instruction infringes data protection law.
7. Confidentiality
The Processor ensures that personnel authorised to process personal data are bound by confidentiality and receive appropriate training.
8. Security
The Processor implements the technical and organisational measures described in the Security page of the website, including tenant isolation with row-level security, encryption in transit (TLS 1.2+) and at rest (AES-256), MFA on privileged actions, least-privilege access, patching and vulnerability management, backups, monitoring, and incident response. The Processor may update these measures provided the level of protection is not diminished.
9. Sub-processors
The Customer authorises the Processor to appoint sub-processors listed on our Sub-processors page. The Processor will notify the Customer at least 30 days before adding or replacing a sub-processor, giving the Customer the opportunity to object on reasonable data protection grounds. Where the Customer objects, the parties will work in good faith to resolve the objection; failing that, the Customer may terminate the affected part of the Service.
10. International transfers
Where personal data is transferred outside the United Kingdom, the Processor will use the UK International Data Transfer Agreement, or the EU Standard Contractual Clauses with the UK Addendum, together with appropriate technical measures, unless an adequacy decision applies.
11. Data subject rights
Taking into account the nature of processing, the Processor will assist the Customer, by appropriate technical and organisational measures and insofar as reasonably possible, to respond to requests to exercise data subject rights under the UK GDPR.
12. Assistance to controller
The Processor will provide reasonable assistance to the Customer with data protection impact assessments, prior consultation with the ICO, and other obligations under Articles 32 to 36 UK GDPR, taking into account the nature of processing and the information available.
13. Personal data breaches
The Processor will notify the Customer without undue delay and in any event within 72 hours of becoming aware of a personal data breach affecting Customer Personal Data, and will provide reasonably available information required for the Customer to comply with its own notification obligations.
14. Deletion or return
At the end of the Subscription the Processor will, at the Customer's choice, delete or return all Customer Personal Data, and delete existing copies unless retention is required by law. Default deletion occurs within 30 days of termination unless the Customer requests earlier deletion or export.
15. Audit rights
The Processor makes available to the Customer information necessary to demonstrate compliance with Article 28 UK GDPR, and will allow for and contribute to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer, on reasonable prior written notice and no more than once per year unless required by a regulator or following a personal data breach. Audits shall be conducted at the Customer's cost, during business hours, and subject to reasonable confidentiality and security requirements.
16. Governing law
This DPA is governed by the laws of England and Wales and the courts of England and Wales have exclusive jurisdiction. In the event of any conflict between this DPA and the Terms of Service in relation to the processing of personal data, this DPA prevails.
Questions about this document? Please write to laura@contracttenders.com. Contract Tenders is a service of Rhics Ltd, 150 City Road, London EC1V 2NX, United Kingdom.
