Data Processing Agreement
Last updated: [DATE]
This Data Processing Agreement ("DPA") forms part of the agreement between Birdly and a business Customer where Birdly processes Customer Personal Data as a processor on behalf of the Customer.
It applies only to processing for which the Customer determines the purposes and essential means and instructs Birdly to process personal information on its behalf.
It does not change Birdly's role as independent controller for Birdly's own account administration, billing, security, legal compliance, product analytics or Private Job matching purposes where Birdly determines the relevant purposes/means.
1. Parties
Controller
The business Customer using Birdly, to the extent the Customer is controller of Customer Personal Data.
Processor
Birdly.dk
CVR no. 35764283
c/o Jonas Bonde Nielsen
Fjordvej 4
4300 Holbæk
Denmark
2. Relationship with main agreement
This DPA forms part of Birdly's Terms & Conditions and the Customer's Subscription/agreement.
If there is a conflict between this DPA and main Terms on Birdly's processor obligations, this DPA takes priority for that matter.
It remains in force for as long as Birdly processes Customer Personal Data on the Customer's behalf.
3. Applicable Data Protection Law
Depending on processing, applicable law may include:
- EU GDPR;
- UK GDPR;
- UK Data Protection Act 2018, as amended; and
- other applicable national data protection law.
"Data Protection Law" means the law applicable to the relevant processing.
4. Processing details and instructions
Subject matter, nature, purpose, duration, data types and data-subject categories are in Appendix A.
Customer use of Birdly within documented features/settings constitutes documented instructions for the processing described in Appendix A.
Additional documented instructions must be consistent with the agreement, lawful, technically reasonable and within Service scope unless separately agreed.
5. Controller responsibilities
The Customer is responsible for deciding lawful purposes, ensuring a lawful basis, giving privacy information, ensuring instructions are lawful, minimising uploaded data and responding to data-subject requests as controller.
The Customer must not instruct Birdly to process unlawful data, unlawfully obtained data, or special-category/criminal data unless genuinely necessary, lawful, and supported/agreed by Birdly.
6. Birdly acts on documented instructions
Birdly processes Customer Personal Data only on documented instructions or where law requires otherwise.
If law requires processing outside instructions, Birdly will notify the Customer before processing unless prohibited.
Birdly will tell the Customer if it reasonably believes an instruction breaches Data Protection Law and may pause affected processing while clarified.
7. Confidentiality
Birdly ensures authorised people have access only where necessary, are subject to appropriate confidentiality duties and receive appropriate data-protection/security instructions. Access is removed when no longer required.
8. Security
Birdly implements appropriate technical/organisational measures considering state of art, cost, nature/scope/context/purpose and risks.
Measures include, as appropriate:
- TLS/HTTPS in transit;
- access controls;
- restricted admin permissions;
- credential/secrets management;
- backups/recovery;
- logging/monitoring;
- controlled production access;
- supplier due diligence; and
- incident response.
See Appendix B and Security & Operations.
9. Sub-processors
General authorisation
The Customer gives Birdly general written authorisation to appoint sub-processors needed to provide the Service.
Birdly maintains a current list.
Notice
Birdly gives reasonable advance notice before adding/replacing a material sub-processor processing Customer Personal Data. Intended standard: at least 30 days where reasonably practicable.
Objection
The Customer may object during the notice period on reasonable, documented data-protection grounds. The parties will try to resolve the issue in good faith.
If Birdly cannot reasonably provide the affected feature without the sub-processor, the Customer may terminate the affected Service before the new sub-processor begins processing, without an additional early-termination fee.
Birdly imposes legally required equivalent processor obligations on sub-processors and remains responsible to the Customer for the sub-processor's performance of flowed-down obligations.
10. International transfers
Birdly will not make a restricted transfer except under Data Protection Law.
Where UK GDPR applies, Birdly may rely on UK adequacy, UK Extension to an applicable data privacy framework, UK IDTA, UK Addendum to EU SCCs, another approved safeguard or lawful exception.
Where EU GDPR applies, Birdly may rely on EU adequacy, applicable frameworks, EU SCCs or another lawful Chapter V mechanism.
Where required, Birdly will perform the relevant transfer risk assessment/data protection test and supplementary measures.
11. Data-subject rights
Taking into account the nature of processing, Birdly will provide reasonable technical/organisational assistance to help the Customer respond to access, rectification, erasure, restriction, portability, objection and other applicable requests.
If Birdly receives a request directly concerning Customer Personal Data processed solely for the Customer, Birdly may redirect the individual to the Customer and will not independently respond unless legally required or instructed.
12. Compliance assistance
Taking into account processing and available information, Birdly reasonably assists with security, breach assessment/notifications, DPIAs and supervisory-authority consultation where related to Birdly processing.
Material bespoke work beyond normal Service may be subject to a reasonable agreed fee, without preventing mandatory compliance.
13. Personal-data breaches
Birdly will notify the Customer without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data processed as processor.
Where feasible, Birdly aims to provide an initial notification within 36 hours. This is an operational target; not every detail must be known within that time.
Birdly will provide reasonably available information about nature, affected people/records, likely consequences and measures taken/proposed, potentially in phases.
Notification does not itself admit fault/liability.
14. Deletion and return
At end of processing, Birdly will, at the Customer's choice and subject to practical Service operation, delete or return/export Customer Personal Data unless law requires storage.
The normal Birdly service-retention period may include a 90-day grace period after Subscription termination. Where Birdly acts as processor and the Customer instructs earlier deletion that is legally/technically possible, Birdly will comply within a reasonable period.
Backups may retain data until overwritten under ordinary backup cycles; during that period data remains protected and not returned to normal active use except where restoration is required.
15. Information, audits and inspections
Birdly makes available information reasonably necessary to demonstrate compliance with Article 28 and this DPA.
Routine audit requests may be satisfied through security documentation, data-flow/sub-processor information, questionnaires and assurance reports where available.
If insufficient, Customer may request an audit. Unless there is a breach, credible evidence of material non-compliance or regulator requirement:
- no more than one audit per 12 months;
- reasonable written notice;
- normal business hours;
- confidentiality;
- no access to other Customers' data; and
- Customer bears its own audit costs.
Birdly cooperates with competent supervisory authorities where legally required.
16. Records
Birdly keeps processor activity records where required and provides information reasonably required to demonstrate processor compliance.
17. Liability
The liability provisions/cap in the main Terms apply to this DPA to the maximum extent permitted by law. Nothing limits liability to the extent Data Protection Law or other mandatory law does not permit it.
18. Termination
This DPA ends when the main agreement has ended and Birdly has ceased processing Customer Personal Data on the Customer's behalf, except obligations that must continue for retained data.
19. Governing law
Unless a mandatory data-transfer mechanism requires otherwise, this DPA is governed by Danish law. To the extent permitted by applicable law, the District Court of Holbæk has jurisdiction under the B2B Terms.
20. Contact
Data protection: support@birdly.dk
Birdly.dk
CVR no. 35764283
Fjordvej 4
4300 Holbæk
Denmark
APPENDIX A — DETAILS OF PROCESSING
Subject matter
Birdly processes Customer Personal Data to provide features where the Customer supplies personal information and Birdly processes it on the Customer's behalf.
Typical examples:
- storing tender-response material;
- generating/pre-filling bid templates;
- extracting/structuring Customer documents;
- making drafts available through authorised links;
- storing Customer-controlled professional references/CVs; and
- related support/hosting.
Duration
For the relevant Subscription/feature plus applicable deletion/grace period, unless earlier deletion is instructed or longer storage legally required.
Typical Birdly draft/upload retention: up to 90 days where the feature specifies it.
Nature
Collection, receipt, storage, organisation, structuring, extraction, retrieval, consultation, use, summarisation, draft generation, transmission, restriction, deletion and backup.
Purpose
To provide agreed Birdly features, including tender/bid assistance and secure storage/display of Customer-provided material.
Data-subject categories
May include Customer employees, directors/owners, subcontractors, reference contacts, professional contacts, consultants, proposed tender personnel, buyer contacts contained in Customer documents and other individuals lawfully included in tender material.
Data types
May include name, job title, employer, professional contact details, work history, CV information, qualifications/certifications, professional references, signatures, tender-role information and uploaded business-document information.
Special-category/criminal data
Not intended as part of the standard Service. Customer must not upload it unless genuinely necessary, lawful and supported by the Birdly feature/security arrangement.
APPENDIX B — SECURITY MEASURES
Birdly measures include, as appropriate:
Access
- need-to-know access;
- controlled admin access;
- removal when no longer required.
Authentication/secrets
- credentials kept outside public code;
- secure environment/secrets handling appropriate to infrastructure.
Transmission
- TLS/HTTPS in transit.
Storage
- managed cloud infrastructure;
- primary database region currently Paris, France;
- access controls.
Files
- private storage where possible;
- time-limited/signed access where implemented;
- deletion based on feature retention.
Availability/recovery
- backup/recovery mechanisms;
- incident recovery processes.
Suppliers
- contracts/DPAs with relevant processors/sub-processors;
- transfer safeguards where required.
Incident response
- assessment;
- containment;
- remediation;
- controller notification as required.
Development
- secrets separated from public source;
- testing/review before production changes;
- vulnerability/dependency management appropriate to Service scale.
Birdly may update measures as technology/risk changes, provided the overall protection level is not materially reduced without justification.
APPENDIX C — SUB-PROCESSORS
Current approved sub-processors are listed at:
https://getbirdly.co.uk/sub-processors
The Customer grants general authorisation subject to section 9 of this DPA.
The production list must be verified before UK launch.