Data Processing Addendum
Effective Date: June 20, 2026
1. Parties
This Data Processing Addendum ("DPA") is entered into between:
- "Customer" (you and the organization you represent), acting as the data controller with respect to bid documents, RFP documents, proposal content, and any personal data contained therein that you upload to the Service; and
- "Provider" (UnfetteredMind LLC), acting as the data processor.
This DPA supplements and forms part of the Terms of Service for BidResponse AI (the "Service").
2. Scope and Purpose of Processing
Provider will process Customer's data (including any personal data contained in uploaded documents) solely to provide the Service as described in the Terms of Service.
Purpose: To enable Customer to build a knowledge base from past proposals, upload RFPs, receive AI-generated draft answers grounded in Customer's knowledge base, and export completed proposals.
Subject Matter: Processing of Customer's uploaded documents (proposals, RFPs, and related materials) and metadata.
Duration: For the duration of the subscription and as necessary to provide the Service, plus any retention period required by law.
Types of Personal Data: Customer determines what personal data, if any, is included in uploaded documents. This may include names, contact information, organizational details, or other information contained in proposals and RFPs.
3. Processor Obligations
Provider agrees to:
a. Process Only on Instructions
Process Customer data only on documented instructions from Customer (via use of the Service as described in the Terms of Service), unless required to do so by applicable law.
b. Confidentiality
Ensure that persons authorized to process Customer data are subject to confidentiality obligations.
c. Security Measures
Implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
- Encryption of data in transit using HTTPS/TLS.
- Per-tenant data isolation using Postgres Row-Level Security (RLS) to prevent unauthorized access across organizations.
- Secure authentication and access controls.
- Regular security monitoring and error tracking.
d. Assist with Data Subject Requests
Assist Customer, to the extent reasonably possible, in responding to requests from data subjects exercising their rights (access, correction, deletion, etc.) under applicable data protection laws.
e. Notify of Breaches
Notify Customer without undue delay upon becoming aware of any personal data breach affecting Customer data.
4. Subprocessors
Customer consents to Provider's use of the following subprocessors to assist in providing the Service:
- Supabase: Database, file storage, and authentication (US region).
- Anthropic: AI processing for generating draft answers and extracting questions.
- OpenAI: Embeddings generation for knowledge base retrieval.
- Stripe: Payment processing.
- Vercel: Web hosting and serverless compute.
- Resend: Transactional email.
- Sentry: Error monitoring.
Provider will ensure that each subprocessor is subject to data protection obligations no less protective than those in this DPA. If Provider engages a new subprocessor or changes an existing one, Provider will notify Customer with reasonable advance notice. Customer may object to a new subprocessor on reasonable data protection grounds; if the parties cannot resolve the objection, Customer may terminate the subscription.
5. No Training on Customer Data
Provider does NOT use Customer data to train any AI model.
Customer documents are processed by third-party AI services (Anthropic, OpenAI) solely to generate responses for Customer's use. Customer data is not incorporated into AI training datasets.
6. Data Return and Deletion
Upon termination of the subscription or upon Customer's request, Provider will:
- Return Customer data in a commonly used, machine-readable format (if requested); and/or
- Delete all Customer data in Provider's possession or control, typically within 30 days, except where retention is required by law.
Customer may request data export or deletion at any time by contacting legal@bidresponseai.app.
7. Audit and Cooperation
Provider will make available to Customer information reasonably necessary to demonstrate compliance with the obligations in this DPA. Provider will reasonably cooperate with audits or inspections conducted by Customer or an independent auditor appointed by Customer, upon reasonable advance notice and subject to confidentiality obligations.
8. Governing Law
This DPA shall be governed by and construed in accordance with the laws of the State of Texas, United States, consistent with the Terms of Service.
9. Contact
For questions regarding this DPA or data processing practices, please contact legal@bidresponseai.app.