# Data Processing Agreement

**Version 1.0** · Effective 2026-09-25

This Data Processing Agreement (**"DPA"**) forms part of the [Terms of Service](/terms) (the **"Agreement"**)
between:

- **ACCER INFORMATION TECHNOLOGY LIMITED**, trading as **Tender Preflight**, a private company limited by shares incorporated in Ireland,
  registered number 804260, with its registered office at 6 Fern Road, Sandyford, Dublin, D18 FP98, Ireland (**"Provider"**);
  and
- the organisation that accepted the Agreement (**"Customer"**). It applies whenever the Provider processes personal data on the Customer's behalf in
providing Tender Preflight (the **"Service"**). It is intended to satisfy Article 28(3) GDPR. Where the Customer is itself
a processor, it is also intended to satisfy Article 28(4) GDPR.

## 1. Definitions

1.1 **"GDPR"** means Regulation (EU) 2016/679.

1.2 **"Data Protection Law"** means the GDPR, the Data Protection Acts 1988 to 2018 and any other applicable data
protection law of the European Union or its Member States.

1.3 Terms such as **controller**, **processor**, **personal data**, **processing**, **data subject**, **personal data
breach** and **supervisory authority** have the meanings given in the GDPR.

1.4 **"Customer Personal Data"** means personal data contained in Customer Content (as defined in the Terms) that the
Provider processes on the Customer's behalf.

1.5 **"Sub-processor"** means a processor engaged by the Provider to process Customer Personal Data.

## 2. Roles of the parties

2.1 **Customer as controller.** Where the Customer decides why and how Customer Personal Data is processed, the
Customer is the controller and the Provider is its processor. This is the usual case for a supplier preparing its own
tender, for example when it uploads its staff CVs, references and signed forms.

2.2 **Customer as processor.** Where the Customer processes Customer Personal Data on behalf of another controller,
the Customer is a processor and the Provider is its **Sub-processor**. This is the usual case for a tender
consultancy or bid-writing agency working for a client (the **"Client"**). In that case the Customer confirms, and
remains responsible for ensuring, that:

- the Client has authorised the Customer to process the data and to engage sub-processors, including the Provider,
  either specifically or under a general authorisation of which the Customer has informed the Client as Article 28(2)
  GDPR requires;
- the Customer's instructions to the Provider are consistent with the Client's instructions; and
- before instructing the Provider, the Customer passes on any additional data protection requirements of the Client
  that apply to the Provider's processing.

2.3 **Mixed roles.** The Customer may act in different roles for different tenders. The parties' roles follow from the
facts and from Data Protection Law, not from the organisation type selected at registration. This DPA applies in each
case.

2.4 **Provider as controller.** The Provider processes the account details of Authorised Users, acceptance records and
security logs as a **controller**. That processing is described in the [Privacy Notice](/privacy), not in this DPA.

## 3. Details of the processing

The subject matter, duration, nature and purpose of the processing, and the types of personal data and categories of
data subjects, are set out in **Annex 1**.

## 4. Instructions

4.1 The Provider processes Customer Personal Data only on the Customer's documented instructions, including with
regard to transfers to third countries, unless Union or Member State law requires otherwise. If the law requires
otherwise, the Provider will inform the Customer before processing, unless the law prohibits this on important
grounds of public interest.

4.2 The Customer's documented instructions consist of:

- the Agreement;
- the Customer's use and configuration of the Service, such as uploading, checking, exporting and deleting; and
- any further written instructions agreed between the parties.

4.3 The Provider will inform the Customer immediately if, in its opinion, an instruction infringes Data Protection
Law.

4.4 The Provider will not:

- sell Customer Personal Data or use it for advertising;
- combine it with data from other customers;
- use it to train, fine-tune or improve AI models; or
- use it for any purpose of its own, except for the aggregated, non-identifying statistics described in section 5.5
  of the Terms.

## 5. AI processing

5.1 Parts of the Service analyse Customer Content automatically, including by optical character recognition (OCR) and
a large language model. The language model runs on infrastructure operated by or for the
Provider in Ireland (European Union). Customer Personal Data is not sent to any external AI service.
5.2 Only text passages extracted from documents are submitted to the language model, never the files themselves.
Model responses are cached per tender and deleted with that tender. Prompts are not written
to application logs.
5.3 Using model weights published by a third party does not involve disclosing any data to that third party.

5.4 The Service does not make decisions that produce legal effects concerning data subjects, or similarly
significant effects. It produces findings for review by the Customer.

5.5 The Provider will not route Customer Personal Data to an external AI service unless:

- that service has been added to the Sub-processor List under section 8; or
- the Customer has expressly enabled it.

## 6. Confidentiality

The Provider ensures that everyone it authorises to process Customer Personal Data is under an appropriate statutory
or contractual obligation of confidentiality, and accesses the data only as necessary to provide, secure or support
the Service.

## 7. Security

7.1 The Provider implements the technical and organisational measures described in **Annex 2**, taking into account
the state of the art, the costs of implementation, the nature, scope, context and purposes of the processing, and the
risks to data subjects (Article 32 GDPR).

7.2 The Provider may update these measures, provided that the overall level of protection is not reduced.

## 8. Sub-processors

8.1 **General authorisation.** The Customer gives the Provider general written authorisation to engage
Sub-processors. The current Sub-processors are listed in the [Sub-processor List](/subprocessors). Where the Customer
is a processor (section 2.2), it confirms that its Client's authorisation covers this.

8.2 **Changes.** The Provider will give at least **30 days' notice** before adding or
replacing a Sub-processor. Notice is given by updating the Sub-processor List, by an in-Service notice and by e-mail
to account holders.

8.3 **Objections.** The Customer may object on reasonable data protection grounds within
**15 days** of the notice, by writing to support@accerit.ie. The parties will
discuss the objection in good faith. If they cannot resolve it, the Customer may terminate the affected part of the
Service without penalty before the change takes effect.

8.4 **Flow-down.** The Provider imposes on each Sub-processor, by written contract, data protection obligations that
are in substance the same as those in this DPA. In particular, each Sub-processor must give sufficient guarantees of
appropriate technical and organisational measures. The Provider remains fully liable to the Customer for its
Sub-processors' performance (Article 28(4) GDPR).

8.5 **Emergency replacement.** If a Sub-processor must be replaced urgently for security or continuity reasons, the
Provider may replace it with a new one that offers at least equivalent protection. The Provider will then notify the
Customer as soon as possible, and the Customer's right to object applies.

## 9. International transfers

9.1 Customer Personal Data is stored on the Provider's own servers in **Ireland (European Union)**.

9.2 The Service is delivered through a content delivery network / reverse proxy (currently Cloudflare — see the
[Sub-processor List](/subprocessors)) that sits in front of the Provider's server. Traffic to and from the Service,
including Customer Personal Data, passes through that Sub-processor's network in transit; it does not keep a
separate copy of stored files or database records. Where that Sub-processor is located outside the European
Economic Area, this is a transfer of Customer Personal Data for the purposes of Chapter V GDPR.

9.3 The Provider will not transfer Customer Personal Data outside the European Economic Area, or allow it to be
accessed from such a country, unless all of the following apply:

- the Customer has been given notice under section 8 (this includes the transfer described in 9.2, disclosed in the
  Sub-processor List from the outset);
- the transfer complies with Chapter V GDPR, for example under an adequacy decision or the European Commission's
  Standard Contractual Clauses (Module 2 or 3); and
- any required supplementary measures are in place.

9.4 On request, the Provider will provide information on the transfer mechanism used for each Sub-processor listed.

## 10. Assistance

10.1 **Data subject requests.** Taking into account the nature of the processing, the Service lets the Customer find,
export and delete Customer Personal Data. If the Provider receives a request from a data subject about Customer
Personal Data, it will forward the request to the Customer without undue delay and will not respond itself, except
on the Customer's instruction or where the law requires it.

10.2 **Other obligations.** The Provider will reasonably assist the Customer with its obligations under Articles 32 to
36 GDPR, taking into account the nature of the processing and the information available to it. These obligations
cover security, breach notification, data protection impact assessments and prior consultation. The Provider may
charge a reasonable fee for assistance that goes substantially beyond what the Service provides, unless the
assistance is needed because of the Provider's own breach.

## 11. Personal data breaches

11.1 The Provider will notify the Customer **without undue delay, and in any event within 48
hours**, after becoming aware of a personal data breach affecting Customer Personal Data. This is intended to allow
the Customer, and where applicable its Client, to meet the 72-hour deadline in Article 33 GDPR.

11.2 The notification will describe, as far as the information is available:

- the nature of the breach, including the categories and approximate number of data subjects and records concerned;
- the likely consequences;
- the measures taken or proposed; and
- a contact point.

Information that is not yet available will follow in phases, without undue further delay.

11.3 The Provider will take reasonable steps to contain the breach and to mitigate its effects. It will keep a record
of the breach.

11.4 A notification under this section is not an admission of fault or liability. Where the Customer is a processor,
the Customer is responsible for informing its Client.

## 12. Deletion and return

12.1 **During the term.** The Customer can delete individual documents, whole tenders or its account at any time.
Deletion removes, from active systems, the files and all data derived from them: extracted text, requirements,
evidence, findings and cached model responses. What remains is only an audit entry without content that records that
a deletion took place. Tenders that have not been checked for **90 days** are deleted automatically.

12.2 **On termination.** Before deleting its account, the Customer can export its reports (PDF, Excel, CSV) and
download its original files. Any Customer Personal Data still held when the Agreement ends is deleted within 30 days,
unless Union or Member State law requires the Provider to keep it.

12.3 **Backups.** Deleted data can remain in encrypted backups for up to **35 days**, until
those backups expire. It is not restored or otherwise processed in that time, except to restore the Service after an
incident. If a restore takes place, deletions are re-applied.

12.4 On request, the Provider will confirm deletion in writing.

## 13. Demonstrating compliance and audits

13.1 On request, the Provider will make available the information necessary to demonstrate compliance with Article
28 GDPR and this DPA. This includes:

- a description of its technical and organisational measures;
- its records of processing; and
- answers to reasonable security questionnaires.

13.2 If this information is not sufficient, the Customer, or an independent auditor it appoints who is bound by
confidentiality, may carry out an audit, including an inspection (Article 28(3)(h) GDPR). Audits must:

- be announced at least 30 days in advance, except after a personal data breach or at the request of a supervisory
  authority;
- take place no more than once in any 12 months, with the same exceptions;
- take place during business hours and avoid unreasonable disruption; and
- not give access to other customers' data or to the Provider's confidential information that is unrelated to the
  Service.

13.3 The Customer bears its own costs of an audit. The Provider bears its own costs, unless the audit reveals a
material breach of this DPA by the Provider, in which case the Provider bears the costs of both.

13.4 Where the Customer is a processor, it may use this section on behalf of its Client, and may share this DPA and
the Sub-processor List with its Client.

## 14. Requests from authorities

If a public authority requests Customer Personal Data, the Provider will:

- redirect the authority to the Customer where possible;
- notify the Customer before disclosing any data, unless the law prohibits this;
- challenge requests that it considers unlawful or disproportionate; and
- disclose only the minimum required.

## 15. Special categories of data

15.1 The Service does not need special categories of personal data (Article 9 GDPR) or data about criminal convictions
(Article 10 GDPR). The Customer should remove such data before upload unless the tender requires it — for example,
some public procurement documents (such as an ESPD) require the Customer's own self-declaration about grounds for
exclusion, which may fall within Article 10. Where such a document is present, the Service's checks are limited to
whether it was submitted, is signed and is dated correctly for the tender; the Service does not read, analyse or
extract the substance of what is declared. If the Customer uploads such data, the Customer is responsible for having
a lawful basis and, for Article 10 data, authorisation under Union or Irish law (including section 55, Data
Protection Act 2018).

15.2 The Service is not intended for data about children.

## 16. Liability, precedence and duration

16.1 Liability under this DPA is subject to the limitations in the Terms, except where the GDPR or other law does not
allow limitation. Nothing in this DPA limits the rights of data subjects.

16.2 If this DPA conflicts with the Terms on the processing of personal data, this DPA prevails.

16.3 This DPA remains in force for as long as the Provider processes Customer Personal Data on the Customer's behalf.
Sections 6, 11, 12 and 13 survive for as long as necessary to complete deletion and to meet legal obligations.

16.4 This DPA is governed by the laws of Ireland, and the courts of Ireland have exclusive jurisdiction, subject to
mandatory Data Protection Law.

## 17. Article 28(3) GDPR cross-reference

| Article 28(3) GDPR requirement | Where it is addressed |
|---|---|
| Subject matter, duration, nature, purpose, data types, data subjects | Annex 1 |
| (a) Processing only on documented instructions, including transfers | Sections 4 and 9 |
| (b) Confidentiality of authorised persons | Section 6 |
| (c) Security of processing (Art. 32) | Section 7, Annex 2 |
| (d) Conditions for engaging sub-processors | Section 8, Sub-processor List |
| (e) Assistance with data subject rights | Section 10.1 |
| (f) Assistance with Articles 32–36 | Sections 10.2 and 11 |
| (g) Deletion or return at the end of the services | Section 12 |
| (h) Information and audits; notice of unlawful instructions | Sections 4.3 and 13 |

## Annex 1 — Details of the processing

**Subject matter.** Checking tender submissions against tender documents, for the Customer.

**Duration.** The term of the Agreement. After that, until deletion under section 12.

**Nature of the processing.** The processing consists of:

- storage of uploaded files;
- unpacking of archives;
- conversion of documents to text, including OCR of scanned pages;
- classification of documents;
- extraction of requirements;
- automated comparison, including language-model analysis of text excerpts;
- search;
- generation of findings, summaries and reports;
- export; and
- deletion.

**Purpose.** To provide the Service to the Customer, and to secure and support it.

**Categories of data subjects.** Depending on the documents uploaded:

- the Customer's (or its Client's) staff, directors and proposed key personnel;
- subcontractors and consortium partners;
- referees and client contacts named in references;
- signatories of forms and declarations;
- insurance and certification contacts; and
- officials of the contracting authority named in tender documents.

**Types of personal data.** Depending on the documents uploaded:

- names;
- business contact details;
- job titles and roles;
- signatures;
- CV content (employment history, qualifications, professional memberships, experience);
- references and project descriptions;
- declarations; and
- document metadata such as author names.

**Special categories.** Not required (see section 15).

**Frequency.** Continuous, whenever the Customer uses the Service.

**Retention.** Until the Customer deletes the data, or automatically after 90 days without a
preflight check. Backups are kept for up to 35 days (section 12).

**Location.** Ireland (European Union).

## Annex 2 — Technical and organisational measures

The measures are described in the [Security Measures](/security) published with this version of the DPA. They form
part of this Annex. Each published version of the Security Measures is archived with its SHA-256 fingerprint.
