BirdlyBirdlyAll terms & policies
Draft — pending legal review

This document is not yet in force. It is published for review only and does not apply to customers. Birdly is not open for business in the UK yet.

Still to be completed before publication: [DATE]

Data Processing Agreement

Last updated: [DATE]

This Data Processing Agreement ("DPA") forms part of the agreement between Birdly and a business Customer where Birdly processes Customer Personal Data as a processor on behalf of the Customer.

It applies only to processing for which the Customer determines the purposes and essential means and instructs Birdly to process personal information on its behalf.

It does not change Birdly's role as independent controller for Birdly's own account administration, billing, security, legal compliance, product analytics or Private Job matching purposes where Birdly determines the relevant purposes/means.

1. Parties

Controller

The business Customer using Birdly, to the extent the Customer is controller of Customer Personal Data.

Processor

Birdly.dk
CVR no. 35764283
c/o Jonas Bonde Nielsen
Fjordvej 4
4300 Holbæk
Denmark

2. Relationship with main agreement

This DPA forms part of Birdly's Terms & Conditions and the Customer's Subscription/agreement.

If there is a conflict between this DPA and main Terms on Birdly's processor obligations, this DPA takes priority for that matter.

It remains in force for as long as Birdly processes Customer Personal Data on the Customer's behalf.

3. Applicable Data Protection Law

Depending on processing, applicable law may include:

"Data Protection Law" means the law applicable to the relevant processing.

4. Processing details and instructions

Subject matter, nature, purpose, duration, data types and data-subject categories are in Appendix A.

Customer use of Birdly within documented features/settings constitutes documented instructions for the processing described in Appendix A.

Additional documented instructions must be consistent with the agreement, lawful, technically reasonable and within Service scope unless separately agreed.

5. Controller responsibilities

The Customer is responsible for deciding lawful purposes, ensuring a lawful basis, giving privacy information, ensuring instructions are lawful, minimising uploaded data and responding to data-subject requests as controller.

The Customer must not instruct Birdly to process unlawful data, unlawfully obtained data, or special-category/criminal data unless genuinely necessary, lawful, and supported/agreed by Birdly.

6. Birdly acts on documented instructions

Birdly processes Customer Personal Data only on documented instructions or where law requires otherwise.

If law requires processing outside instructions, Birdly will notify the Customer before processing unless prohibited.

Birdly will tell the Customer if it reasonably believes an instruction breaches Data Protection Law and may pause affected processing while clarified.

7. Confidentiality

Birdly ensures authorised people have access only where necessary, are subject to appropriate confidentiality duties and receive appropriate data-protection/security instructions. Access is removed when no longer required.

8. Security

Birdly implements appropriate technical/organisational measures considering state of art, cost, nature/scope/context/purpose and risks.

Measures include, as appropriate:

See Appendix B and Security & Operations.

9. Sub-processors

General authorisation

The Customer gives Birdly general written authorisation to appoint sub-processors needed to provide the Service.

Birdly maintains a current list.

Notice

Birdly gives reasonable advance notice before adding/replacing a material sub-processor processing Customer Personal Data. Intended standard: at least 30 days where reasonably practicable.

Objection

The Customer may object during the notice period on reasonable, documented data-protection grounds. The parties will try to resolve the issue in good faith.

If Birdly cannot reasonably provide the affected feature without the sub-processor, the Customer may terminate the affected Service before the new sub-processor begins processing, without an additional early-termination fee.

Birdly imposes legally required equivalent processor obligations on sub-processors and remains responsible to the Customer for the sub-processor's performance of flowed-down obligations.

10. International transfers

Birdly will not make a restricted transfer except under Data Protection Law.

Where UK GDPR applies, Birdly may rely on UK adequacy, UK Extension to an applicable data privacy framework, UK IDTA, UK Addendum to EU SCCs, another approved safeguard or lawful exception.

Where EU GDPR applies, Birdly may rely on EU adequacy, applicable frameworks, EU SCCs or another lawful Chapter V mechanism.

Where required, Birdly will perform the relevant transfer risk assessment/data protection test and supplementary measures.

11. Data-subject rights

Taking into account the nature of processing, Birdly will provide reasonable technical/organisational assistance to help the Customer respond to access, rectification, erasure, restriction, portability, objection and other applicable requests.

If Birdly receives a request directly concerning Customer Personal Data processed solely for the Customer, Birdly may redirect the individual to the Customer and will not independently respond unless legally required or instructed.

12. Compliance assistance

Taking into account processing and available information, Birdly reasonably assists with security, breach assessment/notifications, DPIAs and supervisory-authority consultation where related to Birdly processing.

Material bespoke work beyond normal Service may be subject to a reasonable agreed fee, without preventing mandatory compliance.

13. Personal-data breaches

Birdly will notify the Customer without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data processed as processor.

Where feasible, Birdly aims to provide an initial notification within 36 hours. This is an operational target; not every detail must be known within that time.

Birdly will provide reasonably available information about nature, affected people/records, likely consequences and measures taken/proposed, potentially in phases.

Notification does not itself admit fault/liability.

14. Deletion and return

At end of processing, Birdly will, at the Customer's choice and subject to practical Service operation, delete or return/export Customer Personal Data unless law requires storage.

The normal Birdly service-retention period may include a 90-day grace period after Subscription termination. Where Birdly acts as processor and the Customer instructs earlier deletion that is legally/technically possible, Birdly will comply within a reasonable period.

Backups may retain data until overwritten under ordinary backup cycles; during that period data remains protected and not returned to normal active use except where restoration is required.

15. Information, audits and inspections

Birdly makes available information reasonably necessary to demonstrate compliance with Article 28 and this DPA.

Routine audit requests may be satisfied through security documentation, data-flow/sub-processor information, questionnaires and assurance reports where available.

If insufficient, Customer may request an audit. Unless there is a breach, credible evidence of material non-compliance or regulator requirement:

Birdly cooperates with competent supervisory authorities where legally required.

16. Records

Birdly keeps processor activity records where required and provides information reasonably required to demonstrate processor compliance.

17. Liability

The liability provisions/cap in the main Terms apply to this DPA to the maximum extent permitted by law. Nothing limits liability to the extent Data Protection Law or other mandatory law does not permit it.

18. Termination

This DPA ends when the main agreement has ended and Birdly has ceased processing Customer Personal Data on the Customer's behalf, except obligations that must continue for retained data.

19. Governing law

Unless a mandatory data-transfer mechanism requires otherwise, this DPA is governed by Danish law. To the extent permitted by applicable law, the District Court of Holbæk has jurisdiction under the B2B Terms.

20. Contact

Data protection: support@birdly.dk

Birdly.dk
CVR no. 35764283
Fjordvej 4
4300 Holbæk
Denmark


APPENDIX A — DETAILS OF PROCESSING

Subject matter

Birdly processes Customer Personal Data to provide features where the Customer supplies personal information and Birdly processes it on the Customer's behalf.

Typical examples:

Duration

For the relevant Subscription/feature plus applicable deletion/grace period, unless earlier deletion is instructed or longer storage legally required.

Typical Birdly draft/upload retention: up to 90 days where the feature specifies it.

Nature

Collection, receipt, storage, organisation, structuring, extraction, retrieval, consultation, use, summarisation, draft generation, transmission, restriction, deletion and backup.

Purpose

To provide agreed Birdly features, including tender/bid assistance and secure storage/display of Customer-provided material.

Data-subject categories

May include Customer employees, directors/owners, subcontractors, reference contacts, professional contacts, consultants, proposed tender personnel, buyer contacts contained in Customer documents and other individuals lawfully included in tender material.

Data types

May include name, job title, employer, professional contact details, work history, CV information, qualifications/certifications, professional references, signatures, tender-role information and uploaded business-document information.

Special-category/criminal data

Not intended as part of the standard Service. Customer must not upload it unless genuinely necessary, lawful and supported by the Birdly feature/security arrangement.


APPENDIX B — SECURITY MEASURES

Birdly measures include, as appropriate:

Access

Authentication/secrets

Transmission

Storage

Files

Availability/recovery

Suppliers

Incident response

Development

Birdly may update measures as technology/risk changes, provided the overall protection level is not materially reduced without justification.


APPENDIX C — SUB-PROCESSORS

Current approved sub-processors are listed at:

https://getbirdly.co.uk/sub-processors

The Customer grants general authorisation subject to section 9 of this DPA.

The production list must be verified before UK launch.