Legal

Customer Data Processing Addendum

How BidHound processes personal data on behalf of its customers — the processor terms required by UK GDPR Article 28. This DPA supplements and forms part of the BidHound Terms of Service.

Last updated: 24 July 2026 · Version v0.5

00Introduction and scope

This Data Processing Addendum (“DPA”) supplements and forms part of the BidHound Terms of Service entered into between:

  • Philip Lee, a sole trader trading as BidHound of 49 Station Road, Polegate, East Sussex, BN26 6EA, United Kingdom (“BidHound”, “Processor”), contact legal@bidhound.co.uk; and
  • the customer identified in the BidHound subscription (“Customer”, “Controller”).

This DPA applies where, in providing the BidHound service, BidHound processes personal data on behalf of the Customer. This is the case principally in respect of:

  • personal data contained in documents the Customer uploads to BidHound’s Analyse feature; and
  • personal data the Customer enters into their workspace through company-profile content, pipeline notes, and similar means.

This DPA does not govern:

  • personal data BidHound processes as controller (such as account credentials, billing data, and public procurement notice data — these are governed by the BidHound Privacy Policy); or
  • personal data the Customer processes outside the BidHound service.

In the event of conflict between this DPA and the Terms of Service, this DPA prevails in respect of the processing of personal data only. This DPA is required by Article 28 of the UK General Data Protection Regulation (“UK GDPR”).

01Definitions

Terms not defined here have the meaning given in the UK GDPR. In this DPA:

  • “Customer Personal Data” means personal data processed by BidHound on behalf of the Customer under this DPA.
  • “Data Subject” means an identified or identifiable natural person whose personal data is processed.
  • “Processing” has the meaning given in UK GDPR Article 4(2).
  • “Sub-processor” means a third party engaged by BidHound to process Customer Personal Data.
  • “Restricted Transfer” means a transfer of Customer Personal Data to a country outside the UK that is not the subject of UK adequacy regulations.

02Roles and processing details

2.1 The parties acknowledge that, in respect of Customer Personal Data, the Customer is Controller and BidHound is Processor.

2.2 The details of the processing are set out in Schedule 1.

03BidHound obligations

BidHound shall:

  • 3.1 process Customer Personal Data only on the documented instructions of the Customer, including with regard to Restricted Transfers, unless required to do so by UK or other applicable law (in which case BidHound shall inform the Customer of that legal requirement before processing, unless that law prohibits it on important grounds of public interest);
  • 3.2 ensure that persons authorised to process Customer Personal Data are subject to confidentiality obligations;
  • 3.3 implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as set out in Schedule 2;
  • 3.4 engage Sub-processors only in accordance with clause 5;
  • 3.5 taking into account the nature of the processing, assist the Customer by appropriate technical and organisational measures, insofar as possible, in fulfilling the Customer’s obligation to respond to requests for exercising Data Subject rights under UK GDPR;
  • 3.6 assist the Customer in ensuring compliance with the obligations under UK GDPR Articles 32 to 36, taking into account the nature of the processing and the information available to BidHound (this includes assistance with security, breach notification, data protection impact assessments, and prior consultation with the ICO);
  • 3.7 on termination of the BidHound service, at the choice of the Customer, delete or return all Customer Personal Data, and delete existing copies, unless UK or other applicable law requires storage of the Customer Personal Data — see clause 10;
  • 3.8 make available to the Customer all information reasonably necessary to demonstrate compliance with the obligations laid down in this DPA and allow for and contribute to audits, including inspections, as set out in clause 7;
  • 3.9 immediately inform the Customer if, in BidHound’s opinion, an instruction infringes UK GDPR or other applicable data protection law.

04Security

4.1 BidHound shall implement and maintain the technical and organisational measures set out in Schedule 2.

4.2 BidHound shall keep its security measures under review and may update them from time to time provided that they continue to provide at least an equivalent level of protection.

05Sub-processors

5.1 The Customer authorises BidHound to engage the Sub-processors listed at bidhound.co.uk/legal/sub-processors (current list summarised in Schedule 3).

5.2 BidHound shall:

  • impose data protection obligations on each Sub-processor that are no less protective than those in this DPA;
  • remain liable to the Customer for the acts and omissions of each Sub-processor as if they were its own.

5.3 BidHound shall notify the Customer at least 30 days before engaging a new Sub-processor or replacing an existing one (by email to the Customer’s account email address and/or by updating the published sub-processor list). The Customer may object on reasonable data-protection grounds within that 30-day period. If the Customer objects and the parties cannot agree a resolution, the Customer may terminate the BidHound subscription with effect from the date the new Sub-processor would otherwise have been engaged.

06Data Subject rights and assistance

6.1 BidHound shall, taking into account the nature of the processing, assist the Customer (by appropriate technical and organisational measures, where possible) to respond to Data Subject requests.

6.2 If a Data Subject contacts BidHound directly with a request relating to Customer Personal Data, BidHound shall — to the extent legally permitted — forward the request to the Customer without undue delay and not respond to the request itself except on the Customer’s instructions or as required by law.

6.3 The Customer is responsible for assessing the lawful basis for processing and for responding to Data Subject requests as Controller.

07Audit

7.1 BidHound shall make available to the Customer, on reasonable written request and subject to confidentiality undertakings, information reasonably necessary to demonstrate BidHound’s compliance with this DPA. This may include responses to a security questionnaire, a copy of relevant certifications once obtained, and a written description of the technical and organisational measures.

7.2 If the information made available is not sufficient to demonstrate compliance, the Customer may request, no more than once per year, an audit of BidHound’s processing of Customer Personal Data. The parties will agree the scope, timing, and conditions of the audit. The Customer shall bear its own costs of the audit; BidHound’s reasonable costs may be charged to the Customer.

7.3 Audits shall be conducted during normal working hours, with reasonable advance notice, and in a manner that does not unreasonably interfere with BidHound’s business operations or other customers.

08Personal data breach

8.1 BidHound shall notify the Customer without undue delay — and in any event within 72 hours of becoming aware — of a Personal Data Breach affecting Customer Personal Data.

8.2 BidHound’s notification shall include, to the extent known at the time of notification:

  • a description of the nature of the breach, including the categories and approximate number of Data Subjects and records concerned;
  • the likely consequences of the breach;
  • measures taken or proposed to be taken to address the breach.

8.3 BidHound shall cooperate with the Customer in investigating and remediating the breach and in any required notification to the ICO and affected Data Subjects.

09International transfers

9.1 BidHound shall not make a Restricted Transfer of Customer Personal Data without ensuring an appropriate transfer mechanism is in place.

9.2 Where BidHound or a Sub-processor makes a Restricted Transfer, the parties agree to rely on one or more of the following mechanisms as appropriate:

  • the UK Extension to the EU-US Data Privacy Framework, where the recipient is certified;
  • the UK International Data Transfer Agreement (IDTA);
  • EU Standard Contractual Clauses with the UK Addendum.

9.3 BidHound shall conduct and document a Transfer Risk Assessment where required.

9.4 The current transfer mechanisms applicable to each non-UK Sub-processor are set out on the Sub-Processors page (summarised in Schedule 3).

10Return and deletion

10.1 On termination of the BidHound subscription and at the Customer’s choice (made within 30 days of termination), BidHound shall:

  • return Customer Personal Data to the Customer in a structured, commonly used, machine-readable format; or
  • delete Customer Personal Data.

10.2 If no choice is made within 30 days of termination, BidHound shall delete Customer Personal Data.

10.3 BidHound may retain Customer Personal Data to the extent and for as long as required by UK or other applicable law (for example, retention required by tax law) or for the establishment, exercise, or defence of legal claims. Any retained data continues to be subject to this DPA.

10.4 Sub-processors will be required to delete Customer Personal Data in line with their own contractual retention obligations to BidHound. Anthropic’s commercial API operates with a default backend retention of up to 30 days for inputs and outputs (automatically deleted after that period under Anthropic’s published Privacy Centre policy), save for content flagged for safety/abuse review. Zero Data Retention is not currently available to BidHound at its usage scale; BidHound will revisit this if it reaches the qualifying tier.

11Liability

The parties’ liability under this DPA is subject to the limitations and exclusions of liability set out in the Terms of Service. This DPA does not increase the parties’ overall liability cap.

12Term and termination

This DPA takes effect on the start date of the BidHound subscription and continues for as long as BidHound processes Customer Personal Data. Clauses that by their nature should survive termination (including 8, 10, and 11) survive termination.

13Governing law

This DPA is governed by the laws of England and Wales. Disputes arising under it are subject to the exclusive jurisdiction of the courts of England and Wales.

14Schedule 1 — Details of processing

Subject matter of the processing. Provision of AI-assisted procurement intelligence services to the Customer, including AI-assisted analysis of tender documents uploaded by the Customer.

Duration of the processing. For the duration of the Customer’s BidHound subscription, plus any wind-down or retention period set out in this DPA.

Nature and purpose of the processing. Storage, indexing, redaction, classification, AI-assisted extraction and summarisation, and presentation in the Customer’s account workspace.

Types of personal data processed. Personal data appearing in documents uploaded by the Customer, which may include: names; work email addresses; work telephone numbers; postal addresses; job titles; signatures; references to identified individuals in case studies, CVs, and similar content. Customers should not upload special category data unless they have a clear lawful basis. The Customer is responsible for the content of uploads.

Categories of Data Subjects. Buyer-side procurement personnel; supplier personnel cited in documents; named referees and case-study subjects.

15Schedule 2 — Technical and organisational measures

BidHound implements measures appropriate to the risk, including the following.

Access control. Authentication via password (bcrypt-hashed) and httpOnly session cookies (secure, sameSite=lax, expiring after a period of inactivity). Per-user account provisioning; no shared accounts. Per-customer workspace isolation enforced at the application layer.

Data segregation. Customer-uploaded documents are stored in customer-scoped storage and are not searchable by other customers. Cross-customer public-data indexes do not include personally identifying details from customer uploads.

Encryption. Transport encryption (HTTPS / TLS) for all customer-facing connections. Nightly database backups are AES-256 encrypted. Encryption of the live database file at rest is a roadmap item, disclosed on our Security page.

Redaction before external AI processing. Automated pattern-based redaction (email addresses, phone numbers, postcodes, National Insurance numbers) is applied to document and profile content in the analysis pipeline before any external AI service is called, and the customer’s company name is not included in AI analysis calls. Redaction is designed to reduce and minimise personal data in transmitted content; it is best-effort and does not guarantee complete removal of personal or confidential data from uploaded documents. The redaction policy version applied is recorded in application logs with each AI processing event.

Logging and monitoring. Application and server logs record access, uploads, external AI calls, and the redaction policy applied. Logs are retained per the retention table in the Privacy Policy.

Uploaded document handling. Uploads are restricted to the document formats required for the Analyse feature (currently PDF and DOCX). Macro-enabled Office formats and legacy macro-capable formats are not accepted by default. Uploaded files are processed for text extraction only and are not intentionally executed as code. File size limits and application-layer validation are applied before processing.

Malware-risk controls. Current controls are based on file-type restriction, non-execution of uploaded content, text-only extraction, workspace isolation, access control and monitoring. Signature-based malware scanning may be added as an additional control, but is not currently represented as a live control.

Backup and resilience. Nightly encrypted backups, retained per the retention schedule. The backup-restore procedure is tested as part of the deployment checks.

Personnel. All persons with access to Customer Personal Data are subject to confidentiality obligations.

Vendor management. Sub-processors are engaged under written data-processing agreements imposing equivalent obligations.

Certifications. Cyber Essentials certification is planned; see the roadmap on our Security page.

16Schedule 3 — Current sub-processors

The authoritative, always-current list — including transfer mechanisms, certifications, and onward sub-processors — is maintained at bidhound.co.uk/legal/sub-processors. At the date of this version it comprises: Anthropic, PBC (AI processing, United States); Hetzner Online GmbH (infrastructure hosting, Germany and Finland); AC PM, LLC / Wildbit, LLC — Postmark (email delivery, United States); Stripe Payments UK, Ltd. and group entities (payment processing, UK / United States); and Functional Software, Inc. — Sentry (error monitoring, Germany EU data residency).

17Contact

Questions about this DPA: legal@bidhound.co.uk.

See also

Our Sub-Processors page lists who else processes data and where. Our Privacy Policy covers the data BidHound processes as controller. Our Terms of Service set out the wider agreement.