BidResolve

BidResolve · Agreement and safeguards

Data Processing Addendum

Version 2026-09-12

Download the addendum and safeguards · Pilot terms

Data Processing Addendum

Parties and roles

Adel Chetara, an individual at 35 allée de Bellevue, 94170 Le Perreux-sur-Marne, France, operates BidResolve (the Provider). The Customer is the firm or business identified in the workspace, represented by the person accepting this addendum. For personal data in documents and results, the Provider acts as a processor on the Customer’s instructions. Where the Customer is itself a processor, the Provider acts as a subprocessor; the Customer must have the controller’s authorization and pass on the applicable instructions. This addendum forms part of the pilot terms and prevails for the protection of this data. Account data, security records and optional analytics are covered separately by the privacy notice.

Subject matter, purpose and duration

Processing consists of receiving, storing, extracting and interpreting purchasing requirements and supplier offers, presenting conditions for review, calculating and checking purchasing plans, retaining revisions and producing exports. It lasts for use of the pilot and the return, deletion and backup-expiry periods below. BidResolve does not use documents for advertising, prospecting or model training. This addendum authorizes no secondary use of their content.

Data and data subjects

The scope includes business contact details, roles, names and signatures in quotations, specifications and commercial correspondence, together with their extracts, corrections and results. Data subjects include employees, representatives and contacts of the Customer and its clients and suppliers. The pilot is not intended for special-category data under Article 9, criminal-offence data under Article 10, or documents subject to secrecy obligations incompatible with the processing and transfers described. The Customer minimizes submitted data and identifies the relevant controllers in its instructions.

Documented instructions

The pilot terms, this addendum, and uploads, corrections, approvals and requests made in the workspace constitute documented instructions. Additional instructions should be sent to support@bidresolve.com with the project reference, without attaching the documents. The Provider immediately informs the Customer if an instruction appears to infringe applicable law and suspends the affected operation pending clarification. If legally required to process data otherwise, the Provider informs the Customer before that processing unless prohibited by law. The Customer remains responsible for its purposes, lawful collection and authorizations from its own clients.

Confidentiality and security

Persons authorized to access documents are bound by confidentiality and access them only to provide, secure or support the service on instructions. The Provider applies the technical and organizational measures in the Security schedule: access control, workspace isolation, encryption of public communications, storage and backup protection, logging, deletion and incident procedures. It maintains and reassesses these measures according to risk, without materially reducing protection during the contract. Content-related support uses documents already uploaded to the secure workspace; customer documents must not be attached to support emails.

Subprocessors

The Customer authorizes the providers listed in the Providers schedule for the stated operations. The Provider contractually imposes appropriate data-protection obligations on them and remains responsible to the Customer for their performance as subprocessors. Any addition or replacement affecting documents requires at least 30 days’ written notice to the account contact, stating its role, location and transfer safeguards. The Customer may object on data-protection grounds during that period. The parties seek an alternative; otherwise the affected processing is suspended or terminated with an opportunity to retrieve data. Data is not provided to the new provider before the notice period ends and the objection is addressed.

Transfers and OpenAI

Google Cloud hosts the application and its primary data in Paris. Interpretation through the OpenAI API may involve processing outside the EEA. Section 4.1 of the OpenAI DPA effective 1 January 2026 provides for EEA and Swiss data transfers under agreements containing Standard Contractual Clauses or an adequacy decision. BidResolve uses store=false and sends documents inline, without uploading them to Files. These settings do not eliminate abuse-monitoring logs, retained for up to 30 days under OpenAI’s rules and their exceptions, including legal requirements. Training on API data is disabled by default. Zero Data Retention and European regional processing are not enabled. The Provider documents transfers and safeguards and supplies relevant information on request.

Rights, assistance and oversight

The Provider assists the Customer with access, rectification, erasure, restriction and portability requests, taking account of the nature of processing. It forwards requests received directly about documents without undue delay and does not answer on the Customer’s behalf without instructions unless legally required. It provides reasonable assistance with security, impact assessments, prior consultations and personal-data-breach obligations. It makes available information necessary to demonstrate compliance with this addendum and allows audits, including inspections, by the Customer or an appointed auditor. Arrangements protect confidential information and other customers’ data, without preventing necessary oversight, particularly after an incident or at an authority’s request.

Personal-data-breach notification

After becoming aware of a breach of data processed on the Customer’s behalf, the Provider notifies the Customer without undue delay at the account address or the incident contact designated in writing. It supplies available facts, estimated categories and volumes of affected data and persons, likely consequences, measures taken or proposed, and a follow-up contact. Information is supplemented progressively without waiting for an exhaustive investigation. It preserves evidence and cooperates to limit consequences. The Customer may report an incident to support@bidresolve.com. The Provider does not replace the Customer in deciding whether to notify authorities or individuals, except under a mandate or legal obligation.

Return, deletion and end of the pilot

The Customer may export its data and request deletion during the pilot. At its end, 30 days’ notice allows retrieval before active accounts, documents, models and results are deleted. Inactive projects are deleted after 365 days. Local encrypted backups expire after 7 days; offsite backups after 30 days, with a further 7-day technical recovery window. They are isolated from ordinary use; after restoration, deletions since the backup are reapplied before service resumes. The Provider confirms active-data deletion and states residual backup periods and any legally required retention, which is limited and protected. Providers’ own logs follow the periods in their schedule. Retention merely for the Provider’s convenience is not authorized.

Scope of the commitments

This addendum is neither a compliance certification nor a guarantee that incidents cannot occur. Mandatory individual rights and the parties’ legal obligations are not limited by the pilot’s liability provisions. The accepted version and its digest are retained in the workspace history. Material changes to instructions or safeguards are documented; renewed acceptance cannot be inferred from silence or applied retrospectively.

Technical and Organizational Measures

Access and workspace separation

Project, document and result routes check workspace membership on the server. Original files are not published as static resources. Sessions and forms use Django protections, including CSRF. Administrative access uses named accounts and permissions subject to regular review. Infrastructure providers may retain technical access under their contracts; no claim is made that only one person can ever access data.

Encryption and secrets

Public connections use HTTPS. PostgreSQL has no public port and communicates over an internal Docker network. Google Cloud disks and storage use Google-provided encryption at rest with Google-managed keys. Backups are additionally encrypted with age before transfer; the operator keeps the private decryption key outside the production VM. Secrets are separate from the repository and images. This is not end-to-end encryption: the application and interpretation provider need access to content to provide the service.

Backups and restoration

The procedure pauses writes to back up PostgreSQL and documents consistently, then encrypts and transfers archives to storage separate from the VM. Digests allow copies to be checked. Target retention is 7 days locally and 30 days off-VM, plus Google Cloud’s 7-day technical recovery window. Restored copies remain isolated from email and external APIs; deletions made after the backup must be reapplied before reopening. This single-VM architecture is not high availability and provides no contractual numerical recovery-time commitment.

Logging, updates and incidents

Business actions retain actor, time and scope; original documents and results have digests. Operational logs support security and diagnosis, with restricted access and rotation. Updates use an identified release image and qualification checks. The incident procedure covers containment, evidence preservation, impact assessment, notification of affected customers and corrective-action tracking. An availability alert alone does not prove the absence of a leak or compromise.

Minimization and pilot limitations

Notifications contain a status and an authenticated link, not documents. Optional analytics do not record document content or keystrokes. Development environments must reject SMTP and its credentials; external campaigns require an explicit scope. Team sharing, SSO and application-account MFA are not available in this version. Documents subject to incompatible secrecy obligations and special-category data are excluded. The Customer may request available evidence to assess these measures before uploading data.

Providers and processing scope

Google Cloud

Role: hosting the application, PostgreSQL, documents and encrypted backups. Data: content and required technical data. Primary resource region: Paris, europe-west9. Google may use international support services and subprocessors under its Cloud Data Processing Addendum. A VM’s location does not ensure that every provider access and processing operation remains in the EEA. Agreement: https://cloud.google.com/terms/data-processing-addendum ; subprocessors: https://cloud.google.com/terms/subprocessors .

OpenAI Ireland Ltd.

Role: API interpretation of necessary document text and images. Processing outside the EEA is possible. No training on API data by default; store=false and inline documents, without Files uploads. Abuse-monitoring logs: up to 30 days, subject to documented exceptions. Neither ZDR nor European regional processing is enabled. DPA section 4.1 sets out transfer mechanisms. Agreement: https://openai.com/policies/data-processing-addendum/ ; subprocessors: https://openai.com/policies/sub-processor-list/ .

Service email and support

Spacemail (Spaceship) currently provides contact mailboxes and aliases. Support is forwarded to Gmail. These services process addresses and service messages, not project documents uploaded to the application. Customer documents must not be attached to support emails; reference them in the workspace. Agreements and information: https://www.spaceship.com/legal/data-processing-addendum/ and https://policies.google.com/privacy . Automatic email from the VM is suspended during containment. A new transactional service is not represented as active before qualification and an update to this list.

SHA-256: 3c04eff51edc748559b77ac0b8b698aadf524ff46c90ad244c2045c9ecea8c78