Service privacy notice
How personal data is processed inside the BIDI service: in which role, on what basis, who it is shared with and how long it is kept.
Updated 21 September 2026
The Finnish version prevails in case of any discrepancy between the two language versions.
1. Roles and contact details
BIDI (the Service) is The Better One Oy's public procurement platform. Personal data in the Service is processed in two different roles, and different rules apply to each.
- For user accounts, sign-in, security and the logs created by use of the Service, The Better One Oy is the controller. This notice mainly describes that processing.
- For personal data contained in procurement material, tenders and other material a customer organisation brings into the Service, the customer organisation is the controller and The Better One Oy acts as a processor on its behalf. That processing is agreed with the customer in a data processing agreement.
The Better One Oy, business ID 3597598-3, Itätuulenkuja 10 A, LT 1, 02100 Espoo, Finland. Data protection matters: tietosuoja@bidi.fi. Other enquiries: myynti@bidi.fi.
2. What this notice covers
This notice covers the users of the Service: representatives of contracting authorities and tenderers who have a user account, and people a user invites into the Service without an account, such as experts asked to review, specify or answer a questionnaire.
Use of the www.bidi.fi website, enquiries and marketing communication are described separately in the site privacy notice.
3. What personal data we process and where it comes from
User account
Name, email address, organisation and role in it, access rights in the Service, language preference, and the time and version of the terms of use accepted. The name and email address come from the sign-in service, the organisation and role from the organisation's administrator or from an invitation.
Sign-in
Users sign in with a Microsoft work or school account, a Google account, or an email address and password. The sign-in service passes the Service a name, an email address and an identifier. The Service never sees or stores a password: passwords for email sign-in are managed by Microsoft Entra External ID.
Use of the Service
- Technical logs: user identifier, email address at sign-in and sign-out, organisation, the requested address and a timestamp.
- Attachment access log: who uploaded, opened or deleted a file and when, the IP address and browser details.
- Electronic contract signature: the signer's name, title, email address, signature, time and IP address.
- Use of AI functions: the function, the time and the amount of computation used. The log also keeps an excerpt of at most 240 characters of the input and the response.
- In-app notifications and delivery records for email notifications, and a record of which tenders a tenderer has opened.
Invited people without an account
Name, email address and organisation as given by the person inviting them, the answers and comments the person gives, and a one-time verification code with which the person confirms their email address before opening the material.
Procurement material
Procurement documents and tenders typically contain names and contact details of contact persons, details of a tenderer's team members and reference contacts, and the name of the person making the procurement decision. We process this data on behalf of the customer organisation as described in section 1.
We do not ask for special categories of personal data. Users are responsible for not bringing such data into the Service unnecessarily.
4. Purposes and legal bases
Where we are the controller, we process personal data for the following purposes on the following bases under the EU General Data Protection Regulation (2016/679).
| Purpose | Data | Legal basis |
|---|---|---|
| Providing the Service and managing access | User account, sign-in data | Contract (Art. 6(1)(b)), or legitimate interest (Art. 6(1)(f)) where the contract is with the user's employer |
| Service notifications and emails | Name, email address, language preference | Contract or legitimate interest, as above |
| Recording acceptance of the terms of use | Time and version of acceptance | Legitimate interest (Art. 6(1)(f)) |
| Security, investigating misuse and fixing faults | Technical logs, attachment access log | Legitimate interest (Art. 6(1)(f)): protecting the Service and the material processed in it |
| Limiting and monitoring use of AI functions | Usage amounts, log excerpts | Legitimate interest (Art. 6(1)(f)): cost control and preventing misuse |
| Verifying an invited person | Name, email address, verification code | Legitimate interest (Art. 6(1)(f)): material opens only for the person it was meant for |
The purpose and legal basis for personal data in procurement material are determined by the customer organisation as the controller.
5. Use of AI
The Service uses AI to support drafting and evaluating procurement material. The language model is OpenAI's GPT-4o, used through Microsoft's Azure OpenAI Service in the Service provider's own Azure environment. The AI receives only the material the function chosen by the user needs, and that material may contain personal data.
- Microsoft does not use the Service's inputs or responses to train language models, and they are not shared with OpenAI.
- The Azure OpenAI resource is located in the EU, in the West Europe region. Its deployment type is global, however, so Microsoft may route an individual request for processing in one of its data centres outside the EU and the EEA. Section 7 covers this transfer.
- Microsoft may retain inputs and responses for abuse monitoring for up to 30 days under its own terms.
AI suggests and explains; a person decides. AI makes no procurement decisions and no other decisions with legal effects on you.
6. Recipients and subprocessors
We do not sell or rent personal data. Inside the Service, data is visible to those the purpose of the Service directs it to: a tender's contact person is visible to the contracting authority that received the tender, for example, and an invited expert's name is visible to the person who invited them.
We use the following service providers to run the Service. A data processing agreement is in place with each.
- Microsoft Ireland Operations Ltd: the Service platform in the Azure cloud. Applications, database, file storage, message queue, logs, key storage, traffic protection, malware scanning of files, sending email (Azure Communication Services), sign-in (Microsoft Entra ID and Entra External ID) and AI (Azure OpenAI).
- Google Ireland Limited: sign-in, where a user chooses to sign in with a Google account.
When a contracting authority publishes a procurement notice, the Service sends it to Hilma (hankintailmoitukset.fi). The notice contains the contact details the contracting authority gives and, in a contract award notice, the winning tenderer's name and business ID. The contracting authority decides on publication.
The Service looks up company details from the Finnish Patent and Registration Office's open interface and public procurement notices from the EU's TED service. No personal data is attached to these lookups.
We may also disclose data to an authority where the law requires it.
7. Location and transfers outside the EU and the EEA
The Service's applications, database, files and logs are located in Microsoft's Azure cloud in Sweden (Sweden Central). Data of the sign-in service and the email service is located in Europe.
Data may be transferred outside the EU and the EEA in two situations: when AI requests are processed as described in section 5, and in Microsoft's and Google's support operations under their own terms. Both companies are certified under the EU-U.S. Data Privacy Framework, and the transfers are also based on standard contractual clauses approved by the European Commission.
8. Retention
| Data | Retention |
|---|---|
| User account | As long as the account is in use. The account is deleted when the organisation or the user asks, once no procurement material that requires it to be kept is linked to it. |
| Technical logs and AI log excerpts | 30 days |
| Attachment access log and contract signature data | As long as the procurement material they belong to |
| Procurement material | As instructed by the customer organisation. When the contract ends, the material is handed over to the customer and deleted from the Service under the terms of use. |
| Backups | 7 days |
9. Security
We protect personal data with technical and organisational measures.
- All traffic to the Service is encrypted (TLS 1.2 or later), and data is also encrypted at rest.
- Traffic passes through a web application firewall, and the Service's backend services cannot be reached directly from the internet.
- The sign-in session is encrypted and ends after eight hours at the latest, and access rights are rechecked against the database every few minutes.
- Access rights are based on roles and organisation, and tenders open to the contracting authority only after the tender deadline.
- File upload and download links are valid for only a few minutes, and uploaded files are scanned for malware.
- Secrets and keys are kept in Azure Key Vault and are not stored in the application code.
If a personal data breach occurs, we notify the Office of the Data Protection Ombudsman within 72 hours, and you if the breach is likely to result in a high risk to your rights. We notify a customer organisation without undue delay of a breach affecting its material.
10. Cookies and browser storage
The Service uses only cookies strictly necessary for it to work: an encrypted sign-in session (up to eight hours), a check cookie during sign-in (ten minutes) and the language preference (one year). An invited person's verified access and user interface settings are kept in the browser's own storage. The Service uses no analytics or marketing cookies.
11. Your rights
You have the rights the GDPR gives you over your own personal data: to know whether we process your data and to get a copy of it, to ask for inaccurate data to be corrected, for data to be erased and for processing to be restricted, to move data you have given us to another controller, and to object to processing based on legitimate interest.
Where we are the controller, you can make a request by email to tietosuoja@bidi.fi. We may ask you to clarify the request or verify your identity before we act. We reply within one month. If a request is exceptionally extensive, we may extend the deadline by up to two months and will tell you so.
A request about data in procurement material must be addressed to the customer organisation that is its controller. If such a request comes to us, we pass it on to the customer and help the customer answer it.
If you consider that we process your data unlawfully, you can lodge a complaint with the Office of the Data Protection Ombudsman: PO Box 800, 00531 Helsinki, Finland, tel. +358 29 566 6700, tietosuoja@om.fi. We hope, however, that you contact us first.
12. Changes to this notice
We update this notice when the Service, the processing or the service providers we use change. The current version is always on this page, and the date of the update is shown at the top. We tell you about material changes in the Service, and the Service asks you to review the updated notice the next time you sign in.