Legal
Data Processing Agreement
Last updated 14 September 2026
This Data Processing Agreement ("DPA") applies when RFxFlow processes personal data on behalf of a customer organisation using the platform. It supplements the Terms of Service and is intended to meet Art. 28 GDPR.
Roles
The customer is the controller for tender documents, vendor contacts, responses, and evaluation records they store. RFxFlow is the processor. Account billing identity may be processed by RFxFlow as an independent controller as described in the Privacy Policy.
Instructions
We process customer personal data only to provide the platform: storage, access control, AI analysis requested by the customer, email notifications, and backups. We will not use customer tender content to train general-purpose models.
Security
- EU hosting for application data (Frankfurt).
- Encryption in transit; access limited by organisation membership and RLS policies.
- Optional organisation-enforced MFA.
- Confidentiality obligations for personnel with production access.
Sub-processors
Current sub-processors are listed at /subprocessors. We will notify customers of material changes.
Assistance and deletion
We assist with data subject requests via the product (export from Settings) and support at privacy@rfxflow.io. On organisation deletion, we delete or anonymise customer data in production systems within 30 days, except data retained for legal obligations.
This DPA is a starting operational document. Enterprise customers may request a signed version at hello@rfxflow.io.