Skip to content
Licitora

Data Processing Agreement

Last updated: October 5, 2026

This Data Processing Agreement ("DPA") forms part of the Terms of Service between Alina Kovtun, Gdansk 80-416, NIP 5842834961 ("Processor", "we") and the customer that uses Licitora ("Customer"). It applies to personal data that the Customer or its users add to the Service and that we process on the Customer's behalf, in line with Article 28 GDPR. It is accepted together with the Terms; no signature is needed. A signed copy is available on request at hello@licitora.eu.

1. Scope

Subject matter and duration: providing the Service under the Terms, for as long as the Customer's workspace exists.

Nature and purpose: storing, organising, analysing and displaying workspace data; matching tenders to company profiles; sending emails to workspace members.

Categories of data subjects: the Customer's employees and other users invited to the workspace; persons whose details the Customer enters in notes or profiles.

Categories of personal data: names, business email addresses, roles in the workspace, usage and activity data, and any personal data the Customer includes in company profiles, notes or feedback. The Customer should not enter special categories of data (Art. 9 GDPR).

Account data that we need to run the contract with the Customer (such as the owner's email and billing status), data about website visitors and business contacts from public award notices are processed by us as a controller under the Privacy Policy, not under this DPA.

2. Instructions

We process personal data only on the Customer's documented instructions, which are the Terms, this DPA and the Customer's use of the Service's features, unless EU or Member State law requires otherwise; we will inform the Customer of such a requirement unless the law forbids it. We will tell the Customer if we believe an instruction infringes data protection law.

3. Confidentiality

Anyone we authorise to process the data is bound by confidentiality.

4. Security

We implement the measures in the Annex below and keep them appropriate to the risk, taking into account the state of the art and costs.

5. Subprocessors

The Customer gives general authorisation to use the subprocessors listed on the Subprocessors page. We impose on each of them data protection obligations equivalent to this DPA and remain liable for their performance. We update that page before adding or replacing a subprocessor; the Customer may object on reasonable data protection grounds within 30 days by writing to hello@licitora.eu. If we cannot address the objection, the Customer may terminate the affected subscription and receive a refund of prepaid fees for the unused period.

6. International transfers

Where a subprocessor processes data outside the EEA, the transfer relies on an adequacy decision of the European Commission (including the EU–US Data Privacy Framework) or on the Standard Contractual Clauses adopted by the Commission, with supplementary measures where needed.

7. Assistance

Taking into account the nature of the processing, we assist the Customer with data subject requests (the Service offers export and deletion in Settings → Privacy), with security, with breach notifications, and with data protection impact assessments and prior consultations, as far as they concern our processing.

8. Personal data breaches

We notify the Customer without undue delay, and in any case within 48 hours after becoming aware of a personal data breach affecting Customer data, with the information available at the time, and keep the Customer informed as we learn more.

9. Deletion and return

The Customer can export its data at any time. When the Customer deletes its workspace, or 30 days after the end of the contract, we delete the Customer's personal data from the live systems; backups are overwritten within 7 days. This does not apply to data we must keep by law.

10. Audits

We make available the information needed to demonstrate compliance with Article 28 GDPR, including this DPA, the list of subprocessors and a description of our security measures. If this is not sufficient, the Customer may conduct an audit, or have it conducted by an independent auditor bound by confidentiality, once per year with at least 30 days' notice, during business hours and without unreasonably disrupting our operations; each party bears its own costs.

11. Liability and order of precedence

Liability under this DPA follows the Terms, except where Article 82 GDPR provides otherwise. If this DPA conflicts with the Terms, this DPA prevails for data protection matters. This DPA is governed by Polish law.

Annex: technical and organisational measures

  • Hosting: database and application in the EU (Frankfurt), with providers certified for information security (e.g. ISO 27001, SOC 2).
  • Encryption: TLS for all connections; data encrypted at rest by the hosting providers.
  • Access control: workspace isolation enforced in the database with row-level security; least-privilege service keys kept only on servers; two-factor authentication on all administrative accounts; passwordless sign-in with one-time links.
  • Data minimisation: IP addresses stored only as salted hashes; no email addresses sent to the AI provider; error reports without IP addresses, cookies or request bodies.
  • Availability: daily database backups kept for 7 days; monitoring and alerts for failed jobs and errors.
  • Secure development: an automated check that no server secret reaches the browser bundle before each deployment, security headers (CSP, HSTS), automated tests including access isolation between workspaces, and filtering of outgoing website fetches to block internal network addresses.
  • Retention: deletion on request from the Service settings; automatic deletion of demo data after 30 days.