Service privacy notice for tenderers
How the BIDI service processes the personal data of tenderers' users: in which role, on what basis, who is responsible for the data in a submitted tender and how long data is kept.
Updated 22 September 2026
The Finnish version prevails in case of any discrepancy between the two language versions.
1. Roles and contact details
BIDI (the Service) is The Better One Oy's public procurement platform. Tenderers' personal data is processed in the Service in different roles, and different rules apply to each.
- For user accounts, sign-in, security and the logs created by use of the Service, The Better One Oy is the controller. This notice mainly describes that processing.
- Personal data in the company profile and in the tenderer's other own material, such as unfinished tenders and the product register, is processed as given by the tenderer's organisation, in order to provide the Service to it.
- A submitted tender is part of the procurement material of the contracting entity that received it. The contracting entity is the controller of the personal data in it, and The Better One Oy processes that data on the contracting entity's behalf.
The Better One Oy, business ID 3597598-3, Itätuulenkuja 10 A, LT 1, 02100 Espoo, Finland. Data protection matters: tietosuoja@bidi.fi. Other enquiries: myynti@bidi.fi.
2. What this notice covers
This notice covers the users of the Service on the tenderer side: representatives of tenderers who have a user account, and people whose details a tenderer brings into the Service, such as a tender's contact person.
Processing of the personal data of contracting entities' users is described separately in the service privacy notice for contracting entities. Use of the www.bidi.fi website, enquiries and marketing communication are described in the site privacy notice.
3. What personal data we process and where it comes from
User account
Name, email address, organisation and role in it, access rights in the Service, language preference, and the time and version of the terms of use accepted. The name and email address come from the sign-in service, the organisation and role from the user themselves, from the organisation's administrator or from an invitation.
Sign-in
Users sign in with a Microsoft work or school account, a Google account, or an email address and password. The sign-in service passes the Service a name, an email address and an identifier. The Service never sees or stores a password: passwords for email sign-in are managed by Microsoft Entra External ID.
Company profile
The company's basic details, which can be fetched from the open data of the Finnish Patent and Registration Office (YTJ), and the details the user adds to the profile themselves.
Use of the Service
- Technical logs: user identifier, email address at sign-in and sign-out, organisation, the requested address and a timestamp.
- Attachment access log: who uploaded, opened or deleted a file and when, the IP address and browser details.
- Clarification questions: the question, who asked it and when.
- In-app notifications and delivery records for email notifications, and a record of which tenders a tenderer has opened.
Tenders
The name, email address and phone number of the tender's contact person. Tenders also typically contain details of the tenderer's team members and reference contacts. The details are given by the user who prepares the tender.
We do not ask for special categories of personal data. Users are responsible for not bringing such data into the Service unnecessarily.
4. Purposes and legal bases
Where we are the controller, we process personal data for the following purposes on the following bases under the EU General Data Protection Regulation (2016/679).
| Purpose | Data | Legal basis |
|---|---|---|
| Providing the Service and managing access | User account, sign-in data | Contract (Art. 6(1)(b)), or legitimate interest (Art. 6(1)(f)) where the contract is with the user's employer |
| Service notifications and emails | Name, email address, language preference | Contract or legitimate interest, as above |
| Recording acceptance of the terms of use | Time and version of acceptance | Legitimate interest (Art. 6(1)(f)) |
| Security, investigating misuse and fixing faults | Technical logs, attachment access log | Legitimate interest (Art. 6(1)(f)): protecting the Service and the material processed in it |
The purpose and legal basis for personal data in a submitted tender are determined by the contracting entity as the controller.
5. AI
The functions of the Service intended for tenderers contain no AI features.
A contracting entity may use the Service's AI features to support evaluating the tenders submitted to it. Content of a tender may then be passed to the AI, and it may contain personal data. That processing is the contracting entity's, and it is described in the service privacy notice for contracting entities. AI makes no procurement decisions. The contracting entity decides on, and is responsible for, the evaluation of tenders and the procurement decision.
6. Recipients and subprocessors
We do not sell or rent personal data. Inside the Service, data is visible to those the purpose of the Service directs it to: the name, email address and phone number of a tender's contact person are visible to the contracting entity that received the tender and are printed on the PDF file produced from the tender, a clarification question is passed to the contracting entity running the tender, and an answer to a market survey to the contracting entity that runs the survey. A tender opens to the contracting entity only after the tender deadline has passed.
We use the following service providers to run the Service. A data processing agreement is in place with each.
- Microsoft Ireland Operations Ltd: the Service platform in the Azure cloud. Applications, database, file storage, message queue, logs, key storage, traffic protection, malware scanning of files, sending email (Azure Communication Services), sign-in (Microsoft Entra ID and Entra External ID) and AI (Azure OpenAI), which a contracting entity may use as described in section 5.
- Google Ireland Limited: sign-in, where a user chooses to sign in with a Google account.
When a contracting entity publishes a contract award notice in Hilma (hankintailmoitukset.fi), the notice contains the winning tenderer's name and business ID. The contracting entity decides on publication.
The Service looks up company details from the Finnish Patent and Registration Office's open interface and public procurement notices from the EU's TED service. No personal data is attached to these lookups.
We may also disclose data to an authority where the law requires it.
7. Location and transfers outside the EU and the EEA
The Service's applications, database, files and logs are located in Microsoft's Azure cloud in Sweden (Sweden Central). Data of the sign-in service and the email service is located in Europe.
Data may be transferred outside the EU and the EEA in two situations: when a contracting entity uses AI functions as described in section 5, because the Azure OpenAI deployment type is global and Microsoft may process an individual request outside the EU and the EEA, and in Microsoft's and Google's support operations under their own terms. Both companies are certified under the EU-U.S. Data Privacy Framework, and the transfers are also based on standard contractual clauses approved by the European Commission.
8. Retention
| Data | Retention |
|---|---|
| User account | As long as the account is in use. The account is deleted when the organisation or the user asks, once no procurement material that requires it to be kept is linked to it. |
| Technical logs | 30 days |
| Attachment access log | As long as the material it belongs to |
| Company profile and the tenderer's other own material | As long as the tenderer's organisation uses the Service. When the agreement ends, the material is handed over on request and deleted from the Service under the terms of use. |
| Submitted tenders | Part of the contracting entity's procurement material, and kept as the contracting entity instructs. |
| Backups | 7 days |
9. Security
We protect personal data with technical and organisational measures.
- All traffic to the Service is encrypted (TLS 1.2 or later), and data is also encrypted at rest.
- Traffic passes through a web application firewall, and the Service's backend services cannot be reached directly from the internet.
- The sign-in session is encrypted and ends after eight hours at the latest, and access rights are rechecked against the database every few minutes.
- Access rights are based on roles and organisation, and tenders open to the contracting entity only after the tender deadline.
- File upload and download links are valid for only a few minutes, and uploaded files are scanned for malware.
- Secrets and keys are kept in Azure Key Vault and are not stored in the application code.
If a personal data breach occurs, we notify the Office of the Data Protection Ombudsman within 72 hours, and you if the breach is likely to result in a high risk to your rights. We notify the contracting entity without undue delay of a breach affecting submitted tenders.
10. Cookies and browser storage
The Service uses only cookies strictly necessary for it to work: an encrypted sign-in session (up to eight hours), a check cookie during sign-in (ten minutes) and the language preference (one year). User interface settings are kept in the browser's own storage. The Service uses no analytics or marketing cookies.
11. Your rights
You have the rights the GDPR gives you over your own personal data: to know whether we process your data and to get a copy of it, to ask for inaccurate data to be corrected, for data to be erased and for processing to be restricted, to move data you have given us to another controller, and to object to processing based on legitimate interest.
Where we are the controller, you can make a request by email to tietosuoja@bidi.fi. We may ask you to clarify the request or verify your identity before we act. We reply within one month. If a request is exceptionally extensive, we may extend the deadline by up to two months and will tell you so.
A request about data in a submitted tender must be addressed to the contracting entity that received the tender, which is its controller. If such a request comes to us, we pass it on to the contracting entity and help it answer. A request about the company profile or the tenderer's other own material can be made to us at the same address.
If you consider that we process your data unlawfully, you can lodge a complaint with the Office of the Data Protection Ombudsman: PO Box 800, 00531 Helsinki, Finland, tel. +358 29 566 6700, tietosuoja@om.fi. We hope, however, that you contact us first.
12. Changes to this notice
We update this notice when the Service, the processing or the service providers we use change. The current version is always on this page, and the date of the update is shown at the top. We tell you about material changes in the Service, and the Service asks you to review the updated notice the next time you sign in.