Main Data Processing Addendum

This Addendum (“MDPA”) governs the processing of personal data that the Client, as Data Controller, carries out through the Tender Brain S.r.l. software and platform, with registered office in Gorgonzola, via Milano 37/C (20064 – MI) – Tax code and VAT number: 13931000965 (hereinafter, “Tender Brain” or the “Processor”).

Whereas

  • the Client has purchased TenderBrain licenses from the Processor, a software product developed by Tender Brain S.r.l. providing access to generative Artificial Intelligence (AI) (the “Contract”);
  • use of TenderBrain involves the storage, on Tender Brain’s servers and possibly those of Third Parties, of personal data collected and processed by the Client as Data Controller;
  • the Processor therefore must carry out, on behalf of the Client, personal data processing operations for the execution of the Contract;
  • the Processor has the expertise and technical knowledge regarding the purposes and methods of processing and the security measures to be adopted, and the Client, as Data Controller, intends to appoint Tender Brain S.r.l. as Data Processor under the Contract, which accepts the appointment.

Subject matter

By signing this MDPA, the Client appoints TenderBrain as processor of the personal data processed by the Client through the software covered by the Contract and consequently stored on the Processor’s servers and other IT infrastructure.

This MDPA, if signed by the Parties, constitutes an annex and integral part of the General Terms of Use of Software Products accepted by the Client upon acquiring the TenderBrain license.

This appointment is made in accordance with Art. 28 of EU Regulation 2016/679 (the “Regulation”), it being understood that the Processor provides sufficient guarantees to implement appropriate technical and organizational measures so that processing meets the requirements of the Regulation, ensuring protection of data subjects’ rights.

Processing operations covered by the appointment

In carrying out its activities related to the execution of the Contract, and in particular the activities necessary for support services for the TenderBrain application, the cloud infrastructure hosting it, and integration with cloud and generative AI services, the Processor will process, and is authorized by the Controller to process, all Personal Data of the Controller or other data subjects acquired and processed through the Tender Brain application.

Controller’s representations and warranties

The Controller represents and warrants, releasing the Processor from any verification in this regard:

  • that all Personal Data processed through TenderBrain has been lawfully acquired by the Controller based on a legitimate legal basis under the Regulation;
  • that it has provided data subjects with adequate notice regarding data processing;
  • that it has adequately informed data subjects of TenderBrain’s appointment as Data Processor;
  • that it has updated its record of processing activities;
  • that it has appointed a Data Protection Officer (DPO), where required;
  • that it does not process, except in rare cases, Special Categories of Data, Judicial Data or Personal Data relating to minors;
  • that it has formalized appointments with its Authorized Persons and provided adequate training;
  • that it undertakes to ensure that data uploaded does not exceed the purposes of each activity performed on TenderBrain, ensuring accuracy, updating, relevance and completeness;
  • that it has fulfilled every other obligation required under the Regulation.

Nature and purpose of data processing

The provision of Personal Data is necessary for the execution of the Contract and the use of TenderBrain. The Processor will process exclusively the Personal Data provided by the Controller or uploaded by Authorized Persons and necessary for execution of the Contract.

Type of data processed and categories of data subjects

The Processor may process only Personal Data necessary for correct execution of the contract: registry data of license subscribers, content uploaded by users into TenderBrain, and cloud services maintained by Tender Brain. Only in rare cases may processing involve Special Categories of data, judicial data, and data relating to minors, subject to prior notice to the Processor.

Processor’s obligations

The Processor undertakes to process Personal Data only on documented instructions from the Controller, to respect confidentiality, integrity and quality of data, to comply with the principles set by applicable law, and in particular to:

  • adequately train its employees and collaborators;
  • ensure that persons are expressly authorized to process data;
  • adopt the measures required under Art. 32 GDPR;
  • keep a record of processing activities under Art. 30 GDPR;
  • make available to the Controller the information necessary to demonstrate compliance with obligations under Art. 28 GDPR;
  • allow review and inspection activities;
  • process data exclusively within the European Union, except for transfers compliant with Chapter V of the GDPR.

Controller’s instructions

Uploading Personal Data to TenderBrain constitutes a request for processing for the execution of the Contract in accordance with TenderBrain’s technical specifications, which the Controller declares to know and accept.

Security measures

The Processor guarantees that it has adopted the measures set out in Art. 32 of the Regulation to minimize the risk of destruction, loss, unauthorized access or unauthorized processing of data (see detail in “Technical and organizational measures” below).

System administrators

The Processor has appointed a System Administrator in accordance with the Italian Data Protection Authority’s Order of 27 November 2008 and subsequent amendments, undertaking to designate dedicated professional roles, maintain an updated list, verify their activity annually, and maintain compliant log files.

Authorized persons

The Processor identifies its “Authorized Persons” — employees or collaborators involved in processing — providing them with detailed written instructions.

Sub-processors

The Controller authorizes the Processor to appoint Sub-processors for the execution of the Contract. Tender Brain will notify the Client of any changes to the list of sub-processors at least 15 days before they take effect.

Data subject requests

In case of requests related to the exercise of data subject rights (Articles 15-21 GDPR), the Processor must notify the Controller within one day, verify the identity of the requester, and provide the necessary documentation within three days.

Notification of breaches, loss or damage

The Processor must immediately report to the Controller any requests for access to Personal Data by third parties/authorities, or cases of Personal Data breach (loss, damage, destruction, modification, unauthorized disclosure, unlawful access).

Audits and inspections

The Processor allows the Controller to verify compliance with this appointment, making available all necessary information and contributing to review and inspection activities.

Term

This appointment is effective from the date of signature by the Processor until termination of the relationship between the parties.


Annex B — Third-Party Products and Services (Sub-processors)

Cloud infrastructure: TenderBrain resides in a Google Cloud Platform account owned by Tender Brain. The contracting party on behalf of Google is Google Cloud Italy S.r.l., with servers located within the European Economic Area (infrastructure in St. Ghislain, Belgium; backups within the European Union).

Third-party AI services: OpenAI OpCo, LLC and Google Cloud Italy S.r.l., purchased through Open Gate S.p.A.

Email notification service: MailGun (Sinch), for account management notifications (e.g. password reset). Info: mailgun.com/legal/privacy-policy and mailgun.com/legal/dpa

The updated list of sub-processors will be made available on this page.

Annex C — Technical and organizational measures to ensure data security

Introduction

Tender Brain developed TenderBrain to provide secure and pluralistic access to artificial intelligence (access to different generative AI engines in a single tool). Tender Brain maintains an information security program designed to safeguard its systems, data and customer data.

Description of how TenderBrain works

TenderBrain is a software tool that provides access to various generative artificial intelligence models, through accounts provided by Tender Brain S.r.l.

Main features: access to generative artificial intelligence; selection of different models (Google Gemini, OpenAI ChatGPT); document upload and querying via RAG procedures.

Service providers: Open Gate S.p.A., Google Cloud Platform (Google infrastructure and AI models), OpenAI (AI models), MailGun (email notifications).

Use of AI models: users perform chat interactions and request document indexing.

Security measures

TenderBrain supports 3 authentication methods:

  • Username (email) and password – passwords stored using an up-to-date hashing algorithm (bcrypt)
  • Login with Google – authentication delegated to the Google provider
  • API-Key – for service accounts interacting with the tool’s APIs

Tender Brain adopts industry best practices to protect cloud infrastructure:

  • Separate production and non-production environments
  • Regular checks to identify security vulnerabilities
  • Access logs available for security and availability inquiries
  • WAF – Google Cloud Platform’s Cloud Armor active against DDoS attacks and other web attacks

Access control: employee access follows the principle of least privilege; client data is used only in accordance with the DPA and the contract.

Protection of data in transit and at rest: encryption of data at rest in production datastores; encryption of data in transit; audit logs of infrastructure management operations; disk encryption on all company devices. Client data can be deleted on request by emailing support@opengate.biz .

Continuity and resilience: system restoration in case of interruption; monitoring and reporting of failures; anti-malware and intrusion detection/prevention solutions.

Data segregation: logical/physical segregation of client data; access restriction based on personnel roles and responsibilities; segregation of information system functions; separation of test and production environments.

Staff training: security and privacy training for employees, with supplementary training where necessary.

Incident management: security incident response plan; system logs for security and general observability; timely notification to the Client in case of a personal data breach, in accordance with the DPA.