Data Processing Addendum
Data Processing Agreement · Version 1.0
Last updated 31 July 2026
On this page
This Data Processing Addendum takes effect only when it is incorporated into an Order Form or other written agreement between the parties.
1. Parties and Application
1.1 This Data Processing Addendum, or DPA, forms part of the agreement between Compliance0 Pty Ltd (ACN 687 131 479), trading as Tendor, and the customer identified in the applicable Order Form for the Tendor services described in that Order Form. Tendor and the customer are each a Party and together the Parties.
1.2 This DPA applies to Customer Personal Data that Tendor processes on the Customer's behalf to provide the Services. It does not expand the Services or authorise either Party to process information for an unrelated purpose.
1.3 If this DPA conflicts with another part of the Agreement concerning Customer Personal Data, this DPA prevails. A customer specific Order Form may impose a stricter obligation only where it expressly identifies the provision it varies and is agreed in writing by both Parties.
1.4 The descriptions of controller and processor in this DPA record the contractual allocation of responsibility. Australian privacy law does not use those labels in the same way as every overseas privacy regime, and the labels do not change either Party's obligations under applicable law.
2. Definitions
2.1 In this DPA:
- Agreement means the applicable Order Form, the Tendor Terms and Conditions, this DPA and any other document expressly incorporated into the Order Form.
- Applicable Privacy Law means privacy and data protection law applicable to a Party's processing, including the Privacy Act 1988 (Cth), the Australian Privacy Principles and the Notifiable Data Breaches scheme.
- Customer Data means information, files, records, prompts, instructions, connected system content and other material submitted to, stored in or generated through the Services for the Customer.
- Customer Personal Data means Personal Information contained in Customer Data that Tendor processes on the Customer's behalf, as further described in Schedule 1.
- Order Form means an ordering document, proposal, statement of work or other written agreement that identifies the Customer and the Services.
- Personal Information has the meaning given in the Privacy Act 1988 (Cth) and includes an equivalent concept under another Applicable Privacy Law.
- Process and Processing include collecting, recording, organising, storing, retrieving, using, analysing, disclosing, transmitting, combining, restricting, deleting and destroying Personal Information.
- Security Incident means a confirmed breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of or access to Customer Personal Data processed by Tendor or a Subprocessor. An unsuccessful attempt that does not compromise Customer Personal Data is not a Security Incident.
- Sensitive Information has the meaning given in the Privacy Act 1988 (Cth) and includes an equivalent specially protected category under another Applicable Privacy Law.
- Services means the Tendor services identified in the applicable Order Form.
- Subprocessor means a third party engaged by Tendor to process Customer Personal Data on Tendor's behalf in delivering the Services.
3. Privacy Roles and Data Categories
3.1 The Parties recognise three data categories.
3.2 Customer Personal Data includes Personal Information in Customer provided documents, tender packs, evidence libraries, project records, prompts, instructions, drafts, correspondence and connected system content. Tendor acts as the Customer's processor or service provider for this information and processes it on documented instructions.
3.3 Tendor Account and Operations Data includes user account details, authentication and access records, billing information, service telemetry, security logs, fraud or misuse signals and support records. Tendor determines the purposes and means of this processing for account administration, security, billing, service monitoring, legal compliance and operation of the Services. Tendor is independently responsible for this processing under its Privacy Policy and Applicable Privacy Law.
3.4 Public Source Data includes tender, grant, procurement, award, budget, council and other material that Tendor independently collects from public sources for its platform. Tendor is independently responsible for its handling of Personal Information in this material. Public Source Data is not Customer Personal Data merely because the Customer can access it through the Services.
3.5 Each Party must comply with Applicable Privacy Law that applies to its processing. The Customer is responsible for the lawfulness, accuracy and transparency of Customer Personal Data and for giving Tendor lawful instructions.
4. Customer Instructions and Permitted Processing
4.1 Tendor will process Customer Personal Data only:
- to provide, secure, maintain and support the Services and agreed onboarding or professional services;
- in accordance with the Agreement, the Customer's configuration choices and other documented instructions agreed by the Parties; or
- as required by law, in which case Tendor will inform the Customer before processing unless the law prohibits notice.
4.2 If Tendor reasonably considers that an instruction infringes Applicable Privacy Law, Tendor will notify the Customer and may suspend the affected processing while the Parties resolve the issue.
4.3 Tendor will not sell Customer Personal Data or use it for advertising.
4.4 Tendor will not use identifiable Customer Data, prompts, files or outputs to train, fine tune, evaluate or improve a model or service made available to other customers or the public.
4.5 Tendor may use aggregated, anonymised or de-identified information to operate, measure and improve the Services only where it is not reasonably capable of identifying the Customer or an individual, the use is permitted by the Agreement and Tendor does not attempt to re-identify it.
4.6 The Customer must not submit Sensitive Information unless the Order Form or a signed addendum expressly identifies the category, purpose and safeguards. Tendor may reject, isolate or securely delete Sensitive Information submitted outside the agreed scope after giving reasonable notice where practicable.
5. Confidentiality, Customer Isolation and Competitive Conflicts
5.1 Customer Personal Data is the Customer's Confidential Information. Tendor will limit access to personnel and Subprocessors who need it for an authorised service, support, security or legal purpose.
5.2 Authorised personnel must use individual accounts, follow approved access and secure handling procedures and be bound by confidentiality obligations that continue after their access ends.
5.3 Tendor will not disclose Customer Personal Data to another customer. Tendor will not use one customer's confidential data, pricing, tender strategy, bid content, source documents, private invitations or generated outputs to support another customer.
5.4 Tendor applies organisation and resource scoped access controls intended to keep each customer's workspace, documents, credentials, search records and task context separate from those of every other customer.
5.5 Where personnel support customers operating in the same market, Tendor will maintain the same need to know restrictions, customer scoped workspaces and confidentiality controls. A commercial relationship with another business, including a competitor, does not authorise access to or use of the Customer's data.
5.6 The fact that Tendor may provide the same platform, public source material or general methodology to businesses in the same industry does not constitute a cross-customer disclosure. Industry, geography, buyer or tender exclusivity exists only where it is expressly defined in a separate signed Order Form, including its scope, term, exceptions and price.
5.7 If Tendor becomes aware of an actual access conflict involving Customer Personal Data, Tendor will restrict the affected access, preserve relevant records, investigate and escalate the matter under its security and privacy procedures.
6. Security Program
6.1 Tendor will maintain reasonable and appropriate administrative, technical and organisational measures designed to protect Customer Personal Data from misuse, interference, loss, accidental or unlawful destruction, alteration, unauthorised access and unauthorised disclosure.
6.2 The baseline measures are described in Schedule 2. Tendor may update individual measures as technologies and threats change, provided it does not materially reduce the overall protection of Customer Personal Data during the service term or breach a stricter customer specific commitment.
6.3 Security responsibilities are assigned to authorised owners. Tendor will review material security risks, significant changes, relevant incidents and material vendor changes, and will track corrective actions to completion or documented risk acceptance.
6.4 The Customer is responsible for managing its users and connected accounts, protecting credentials, configuring sharing and permissions appropriately and reviewing AI assisted outputs before reliance, external use or submission. These responsibilities do not reduce Tendor's obligations under this DPA.
7. Security Incident Management and Notification
7.1 Tendor will maintain procedures for incident identification, triage, containment, investigation, evidence preservation, remediation, recovery and follow-up review.
7.2 Tendor will notify the Customer without undue delay and no later than 72 hours after becoming aware of a Security Incident affecting Customer Personal Data.
7.3 Tendor will also notify the Customer promptly if it has reasonable grounds to suspect a material Security Incident affecting Customer Personal Data and customer action may reasonably be required before Tendor can complete its investigation.
7.4 A notice will, to the extent known at the time, describe the nature of the incident, the affected data and systems, likely consequences, containment and remediation measures and a contact for coordination. Tendor may provide information in phases as the investigation develops.
7.5 Tendor will take reasonable steps to contain and mitigate the incident and provide reasonable assistance for the Customer's assessment and notification obligations. Each Party remains responsible for its own obligations under the Notifiable Data Breaches scheme and other Applicable Privacy Law.
7.6 Tendor will not notify a regulator or an affected individual on the Customer's behalf unless instructed in writing or required by law. Where legally permitted and practicable, the Parties will coordinate before making a notice about the same incident.
8. Subprocessors
8.1 The Customer gives general authorisation for Tendor to engage the Subprocessors listed in Schedule 3.
8.2 Tendor will:
- conduct proportionate due diligence before appointing a Subprocessor;
- limit the Subprocessor's access to what is reasonably required for its function;
- bind the Subprocessor to written confidentiality, security, processing, incident and deletion obligations appropriate to its function and the data;
- remain responsible to the Customer for Tendor's obligations under this DPA where a Subprocessor's act or omission causes Tendor to breach them; and
- maintain a current register identifying each provider, processing function, relevant data categories and principal processing locations.
8.3 Tendor will give at least 30 days' prior notice before a new or replacement Subprocessor begins processing Customer Personal Data, except where an urgent replacement is reasonably required to protect security, availability or legal compliance. In that case, Tendor will notify the Customer as soon as reasonably practicable.
8.4 During the notice period, the Customer may object on reasonable data protection grounds. The Parties will work in good faith to address the objection. If they cannot reasonably resolve it, Tendor may cease using the Subprocessor, offer a commercially reasonable alternative or allow the Customer to terminate the materially affected Service with a pro-rata refund of prepaid fees for the unused period.
8.5 An objection cannot be based only on the fact that a supplier also serves another customer or competitor.
9. Overseas Processing and Data Locations
9.1 Customer Personal Data may be processed in Australia and in the other locations identified in Schedule 3. A listed location describes the principal service or storage location. Provider support, security, routing and resilience functions may involve additional locations under the provider's applicable terms.
9.2 Core Tendor application compute and primary Google Cloud storage are operated in Google Cloud's Sydney region, Australia. Tendor's primary Supabase project data is hosted in the Sydney region, Australia. These commitments do not mean that every enabled service, network edge, support function, AI request, email or transient service is confined to Australia.
9.3 Before disclosing Personal Information to an overseas recipient where Australian Privacy Principle 8 applies, Tendor will take reasonable steps in the circumstances to ensure the recipient handles the information consistently with the Australian Privacy Principles. Those steps may include contractual obligations, provider due diligence, security controls, limits on purpose and access, incident terms, deletion terms and review of downstream processing.
9.4 Contractual authorisation of processing locations is not intended to operate as an individual's informed consent to an exception under Australian Privacy Principle 8. Each Party remains responsible for any notice, lawful basis, authorisation or consent that Applicable Privacy Law requires from it.
9.5 A customer specific residency or location restriction applies only where it is expressly stated in an Order Form or signed addendum and Tendor has confirmed that every affected component can meet it.
10. AI Assisted Processing
10.1 Tendor may send task relevant prompts, source excerpts and generated content to the approved AI providers in Schedule 3 to deliver an enabled feature.
10.2 Tendor will minimise the material sent to an AI provider to what is reasonably required for the task, use provider business or API terms where available and configure available data controls appropriate to the service.
10.3 Customer Data is not used by Tendor to train shared or public AI models. Tendor will not enable provider model training or data sharing for Customer Personal Data.
10.4 AI outputs are drafts and may be incomplete or inaccurate. The Customer remains responsible for technical, commercial, legal, pricing and submission decisions and for human review before external use.
11. Customer Authorised Integrations
11.1 The Customer may choose to connect services such as Microsoft 365, SharePoint, Google Drive, an email inbox or a tender portal. Tendor will access only the systems, accounts, scopes and material authorised by the Customer and required for the enabled workflow.
11.2 Connected account credentials and tokens will be protected separately from task content, limited to required scopes where supported and revoked or deleted when the connection is removed or no longer required.
11.3 A provider selected and independently contracted by the Customer is normally a customer authorised integration rather than a Tendor Subprocessor. If Tendor selects or controls a provider to process Customer Personal Data on Tendor's behalf, Tendor will treat that provider as a Subprocessor under clause 8.
11.4 Tendor will not take an external write, send, publish or submission action through an integration unless the workflow and Customer authorisation permit it.
12. Individual Rights and Regulatory Assistance
12.1 Taking account of the nature of the processing and information available to it, Tendor will provide reasonable assistance for the Customer to respond to valid requests to access, correct, delete or restrict Customer Personal Data and to substantiated privacy complaints or regulatory enquiries relating to Tendor's processing under this DPA.
12.2 If Tendor receives a request directly from an individual about Customer Personal Data, Tendor will verify the request as appropriate, forward it to the Customer without undue delay and not respond substantively except on the Customer's documented instruction or as required by law.
12.3 Assistance is included where reasonably required because of Tendor's breach of this DPA. Material assistance beyond the ordinary operation of the Services may be charged at an agreed professional services rate where the Agreement permits it.
13. Return, Deletion and Retention
13.1 During the service term, the Customer may request an export of Customer Data in accordance with the Agreement.
13.2 On valid instruction or expiry or termination of the affected Service, Tendor will, at the Customer's election, return or delete active Customer Personal Data within 90 days unless the Agreement states a shorter period.
13.3 Deletion will address active records, files, integration credentials, search indexes, cached copies and other derived records associated with the Customer that are within Tendor's possession or control. Tendor will take reasonable steps to cause its Subprocessors to delete or return the affected Customer Personal Data under their applicable terms.
13.4 Where an individual item cannot reasonably be deleted from a routine backup, it will remain protected, will not be restored except for legitimate recovery purposes and will be overwritten through the ordinary backup lifecycle. Where immediate destruction is not technically possible, Tendor will put the information beyond ordinary use until destruction becomes possible.
13.5 Tendor may retain Customer Personal Data where required by law. It will isolate that data and limit further processing to the applicable legal purpose.
13.6 On reasonable written request, Tendor will provide confirmation that the applicable return or deletion process has been completed, subject to lawful retention and routine backup limitations.
14. Audit and Assurance
14.1 On reasonable written request, no more than once in any 12-month period unless a regulator requires otherwise or a material Security Incident affects the Customer, Tendor will provide information reasonably necessary to demonstrate compliance with this DPA.
14.2 Tendor may satisfy the request through a security narrative, architecture and data flow description, completed questionnaire, Subprocessor information, control evidence or an available independent report.
14.3 If that information is reasonably insufficient, the Customer may request a targeted audit by an independent auditor that is not a Tendor competitor. The audit must occur on reasonable notice during business hours, be subject to confidentiality, avoid another customer's data and Tendor source code or active vulnerability details and not unreasonably disrupt operations. Penetration or other active testing requires separate prior written approval and an agreed scope.
14.4 Each Party bears its own audit costs unless the audit identifies a material breach of this DPA by Tendor, in which case Tendor will bear the reasonable, documented external audit costs attributable to confirming that breach.
15. Government and Legal Requests
15.1 If Tendor receives a binding request for Customer Personal Data, it will, where legally permitted, notify the Customer before disclosure, reasonably assist the Customer to seek protection and disclose only the information legally required.
16. Continuity and Recovery
16.1 Tendor will maintain backup, recovery, monitoring and operational procedures proportionate to the Services and the risks to Customer Personal Data.
16.2 Recovery access will be limited to authorised personnel. Recovery copies remain subject to the confidentiality, access and use restrictions in this DPA.
16.3 Customer specific recovery objectives, service levels or availability commitments apply only where stated in the Order Form.
17. Liability, Duration and General Terms
17.1 Liability arising from this DPA is subject to the limitations and exclusions in the Agreement or applicable Order Form. This DPA and the rest of the Agreement do not create duplicate aggregate caps.
17.2 This DPA begins on the effective date of the Agreement and continues while Tendor processes Customer Personal Data. Provisions that by their nature should survive, including confidentiality, deletion, liability and governing law, survive expiry or termination.
17.3 The governing law and dispute process are those stated in the Agreement.
Schedule 1. Description of Processing
| Item | Description |
|---|---|
| Subject matter | Provision, security, maintenance and support of the Tendor Services and agreed onboarding or professional services. |
| Duration | The applicable service term plus the return, deletion and lawful retention periods in clause 13. |
| Nature of processing | Collection, hosting, storage, organisation, retrieval, analysis, extraction, generation, review, export, authorised integration actions, security monitoring, support, deletion and other operations required for the Services. |
| Purpose | Tender and grant opportunity discovery and qualification; evidence and document management; analysis of tender packs; AI assisted preparation and review of draft responses and supporting material; authorised collaboration, integration and submission workflows; service support, security and recovery. |
| Data subjects | Customer users and personnel; the Customer's clients, prospects, suppliers, subcontractors and professional contacts; tender and grant contact persons; staff and referees described in project or capability evidence; and other individuals whose Personal Information the Customer lawfully includes in Customer Data. |
| Personal Information | Names and business contact details; job titles and professional profiles; account and access information; project roles, qualifications, licences, employment or contractor information; correspondence; Personal Information contained in tender packs, evidence documents, prompts, drafts and connected system content; and other categories expressly agreed in the Order Form. |
| Sensitive Information | Not intended for routine processing. Processing requires an express written scope identifying the category, purpose and safeguards. |
| Frequency | Continuous or on demand during the service term, depending on Customer use and enabled workflows. |
Schedule 2. Technical and Organisational Measures
| Control area | Baseline measures |
|---|---|
| Governance and risk | Assigned security and privacy responsibilities; risk based control review; material vendor review; incident and corrective action tracking; controlled exceptions. |
| Identity and access | Individual authentication; organisation and resource scoped authorisation; role and purpose based personnel access; multifactor authentication support; access removal when responsibilities change. |
| Customer isolation | Customer scoped workspaces, records, files, credentials, search context and task execution; checks against organisation and resource permissions; no cross-customer use of confidential data. |
| Encryption and secrets | HTTPS and TLS for production web and API traffic; provider managed encryption at rest; protected secrets and connected account credentials; no credentials in routine logs or customer content. |
| File and document security | Private storage; permission checked access; short lived scoped download links where used; controlled export and deletion paths. |
| AI and automation | Approved provider routing; task relevant context only; no shared or public model training from Customer Data; constrained worker environments; human review and external action controls. |
| Integrations | Customer approved accounts and scopes; protected OAuth credentials; revocation and deletion controls; authorised external actions only. |
| Secure development | Source control; peer review; automated build and test checks; dependency and vulnerability checks; focused review of changes affecting access, customer isolation, integrations or document handling. |
| Environment separation | Separation of production and development environments; exceptional production data use for support or recovery requires limited access, approval and removal of temporary copies. |
| Logging and monitoring | Operational and security monitoring; restricted log access; logging designed to minimise Customer content and exclude credentials and temporary file access links. |
| Incident response | Triage, containment, investigation, evidence preservation, remediation, recovery, notification and post-incident corrective action. |
| Retention and deletion | Active data return or deletion; coverage of files, structured records, credentials, indexes, caches and derived records; protected backup expiry; lawful retention isolation. |
| Continuity and recovery | Managed infrastructure, monitoring, backup and recovery procedures; restricted recovery access; protected recovery copies. |
| Personnel | Confidentiality duties; individual accounts; need to know access; secure handling procedures; access review and removal. |
| Subprocessor management | Due diligence; written protection obligations; minimum necessary access; location and function register; change notice and objection process. |
Schedule 3. Current Subprocessors and Processing Locations
The locations below identify the principal service or storage location based on the configured service and provider terms. Support, security, routing, resilience and downstream provider functions may involve additional locations. Tendor will maintain this register and notify changes under clause 8.
| Provider | Function and Customer Personal Data | Principal processing location |
|---|---|---|
| Google Cloud | Core application compute, object storage, deployment, secrets, key management, logging, monitoring and selected document or agent workloads. Data depends on the enabled component. | Core production compute and primary storage: Sydney, Australia. A limited internal agent storage component may use the United States multi-region where enabled. Google support and resilience functions may operate globally. |
| Supabase | Authentication, managed PostgreSQL, storage, realtime and edge functions. Processes account data, structured Customer Data, access metadata and content used by enabled functions. | Primary project data: Sydney, Australia. Edge function execution, logs, support and resilience may involve other supported locations. |
| Cloudflare | DNS, content delivery, web application firewall, traffic protection and edge delivery. Processes network identifiers, request metadata and data in transit according to enabled services. | Global edge network. Data localisation features apply only where separately configured and agreed. |
| Resend | Transactional and service email delivery. Processes recipient details, delivery metadata and message content required to send the communication. | United States, with downstream providers as listed by Resend. |
| OpenAI | AI analysis, extraction, generation and image functions where enabled. Processes task relevant prompts, source excerpts and outputs. | United States. API data is not used for model training by default unless expressly opted in. |
| Google Gemini and Google Cloud Vertex AI, where enabled | AI analysis, extraction, grounding and generation. Processes task relevant prompts, source excerpts and outputs. | United States. |
Schedule 4. Customer Authorised Integrations
The following categories may be enabled at the Customer's direction. They are not Tendor Subprocessors where the Customer selects and independently contracts with the provider. The Customer controls the source account, permissions and material made available.
| Integration category | Typical purpose | Control position |
|---|---|---|
| Microsoft 365 and SharePoint | Import or retrieve approved evidence, tender material and business documents. | Customer authorises the account and scopes and may revoke access. |
| Google Drive and Google Workspace | Import or retrieve approved evidence, tender material and business documents. | Customer authorises the account and scopes and may revoke access. |
| Customer email inbox | Receive private invitations, tender packs and workflow messages selected by the Customer. | Customer authorises the mailbox and permissions. External send actions require an enabled workflow and Customer authority. |
| Tender and procurement portals | Retrieve opportunities, post authorised questions or support an authorised submission workflow where technically available. | Customer controls its portal account. Final submission responsibility remains with the Customer unless expressly agreed otherwise. |
| Other customer selected systems | Support a customer specific workflow agreed in writing. | Provider status, data scope, location and control position are assessed before enablement. |
Contact
Compliance0 Pty Ltd trading as Tendor
ACN: 687 131 479 | ABN: 32 687 131 479
Privacy enquiries: privacy@tendor.ai
Security enquiries: security@tendor.ai
Version 1.0 · Last Updated: 31 July 2026