Terms of use for contracting entities
The terms on which contracting entities and those working on their behalf use the BIDI service: what the service is for, what the parties can expect of each other, the role of AI and how customer material is handled.
Updated 22 September 2026
The Finnish version prevails in case of any discrepancy between the two language versions.
1. Service and its purpose
BIDI (the Service) is a tendering platform for public procurement produced by The Better One Oy (the Provider). The Service supports preparing a procurement, drafting the procurement documents, comparing tenders and the contract stage in one workspace.
The Service is intended for contracting entities and those working on their behalf, and for tenderers submitting tenders in procurements. These terms apply to contracting entities and those working on their behalf. The Service is a tool for preparing and running a procurement. It is not an official notification channel and it does not replace publishing a contract notice in the channel the law prescribes.
The scope of the Service, the number of users, the fees and the contract period are agreed separately in an order agreement.
The Customer may invite people into the Service without an account, such as experts asked to review, specify or answer a questionnaire. The invitation is given on the Customer's behalf, and the answers and comments an invited person gives are the Customer's material.
Tenderers submitting tenders in procurements use the Service under the terms of use for tenderers.
2. Parties and formation of the agreement
The parties to the agreement are the Provider and the organisation using the Service (the Customer). A person using the Service on the Customer's behalf is referred to below as the User.
The agreement between the Provider and the Customer is formed by the order agreement, of which these terms are part. Where no order agreement has been made, the agreement is formed when a User accepts these terms on the Customer's behalf. Where the order agreement and these terms conflict, the order agreement prevails.
A User accepts these terms on first signing in to the Service. When the terms change, the Service asks for acceptance again as described in section 10. The Service records when acceptance was given and which version of the terms was accepted.
These terms apply unless otherwise agreed in writing between the Provider and the Customer.
3. Registration and authentication
Using the Service requires an account. Accounts are created at the Customer's request or by an administrator the Customer has named. The User must give correct and current information and keep it up to date.
Users sign in with a Microsoft work or school account (Microsoft Entra ID), a Google account, or an email address and password. Passwords for email sign-in are managed by Microsoft Entra External ID, and the Service never sees or stores a password. Email sign-in asks for the password at every sign-in.
The Service does not itself require multi-factor authentication. When signing in with a Microsoft or Google account, authentication follows the policies of the User's own organisation, and the Customer is responsible for those policies being adequate. The Provider recommends using multi-factor authentication.
A sign-in session ends after eight hours at the latest. Access rights are checked against the database every five minutes, so a removed or changed right takes effect within five minutes at the latest.
The User undertakes not to present themselves as another person or as a representative of an organisation other than the one they represent. The Provider may remove an account where this has happened.
A right of use is personal. Passing credentials to a third party is prohibited, and the User is responsible for what is done with their credentials.
The User is not, however, responsible for use where the credentials reach a third party for a reason beyond the User's control, such as a breach of the Provider's systems. This requires that the User does not prevent the Provider from closing the account.
If there is reason to believe credentials have reached a third party, the User must immediately change the password of the account they sign in with, at the sign-in service that account uses, and report it to myynti@bidi.fi. Users must sign out of any shared device.
4. Rights and obligations of the parties
The Customer receives the right, set out in these terms and the order agreement, to use the Service in its own procurement work. The right of use may not be transferred or sublicensed.
The Provider may issue instructions on using the Service, and the User is obliged to follow them.
The Provider develops the Service and may add, change and remove features. Changes that materially reduce functionality are announced to the Customer in advance. Statements in demonstration material do not bind the Provider.
The Customer is responsible for the material it brings into the Service and for having the right to process that material there. The Provider does not monitor or verify the accuracy or lawfulness of material the Customer enters.
The Customer is responsible for ensuring that its activity in the Service does not breach the law, infringe the rights of a third party or offend good practice, and does not disrupt the Service or its other users. Where the Provider has reasonable grounds to suspect a breach of this section, it may block access and restrict use of the material immediately.
The Service database is backed up automatically and can be restored to any point in time within the last seven days. Backups are kept for seven days and are not stored in a second geographic region. Attachments are stored as three copies within the same data centre, and no separate backup is taken of them. If material is lost or corrupted in the Provider's systems, the Provider restores it without undue delay.
5. Use of AI and the nature of the output
The Service uses AI to support drafting and assessing procurement material. The AI proposes and justifies, the procurement professional decides.
What the Service produces, whether a suggestion, a draft or an assessment, is support for the work. It is not legal advice and not a procurement decision, and it cannot be relied on as grounds for the lawfulness of a procurement. Responsibility for a procurement decision, for its reasoning and for its lawfulness always rests with the contracting entity.
Content produced by the Service has to be reviewed before it is used. AI can produce content that is wrong or incomplete, and it can produce different suggestions from the same material on different occasions.
The Provider does not warrant that content produced by the Service is free of errors, current, or compliant with procurement legislation.
The Service's language model is OpenAI's GPT-4o, and CPV code suggestions also use the text-embedding-3-large model. Both are used through Microsoft's Azure OpenAI Service in the Provider's own Azure environment. The Service uses no other AI services.
The Azure OpenAI resource is located in the EU, in the West Europe region. Its deployment type is global, however, so Microsoft may process an individual request outside the EU and the EEA. The Provider's contracting party is Microsoft Ireland Operations Ltd, whose parent company is Microsoft Corporation of the United States. Microsoft may retain inputs and responses for abuse monitoring for up to 30 days. Processing of personal data in AI functions is described in the service privacy notice.
For every AI call the Service records the User, the organisation, the function, the model, the time, the amount of computation used and a hash computed from the input. These records are kept for as long as the user account exists. Technical logs also keep an excerpt of at most 240 characters of the input and the response, and those logs are kept for 30 days.
An AI suggestion becomes part of the procurement material only when the User accepts it into the document. From then on it is the Customer's material like the rest of the document.
6. Customer material
Material the Customer brings into the Service, and the procurement documents produced in it, remain the Customer's. The Provider processes that material in order to provide the Service and on the Customer's behalf.
Processing of personal data contained in the material is agreed separately in a data processing agreement, under which the Customer is the controller and the Provider the processor. Where that agreement and these terms conflict on the processing of personal data, the data processing agreement prevails.
On termination the Customer is entitled to receive its material in a usable format. The material is then deleted from the Service.
Customer material is not used to train AI models. The Provider does not train models on Customer material, and Microsoft does not use inputs or responses of the Azure OpenAI Service to train models or share them with OpenAI.
The Customer may request its material within 30 days after the agreement ends. The material is handed over in a machine-readable format: documents as PDF files, structured data as JSON or CSV, and attachments as the original files. One hand-over is free of charge.
The material is deleted from the Service within 90 days after the agreement ends. It disappears from backups as they expire, within seven days of deletion.
7. Information security
The Provider protects the data processed in the Service with appropriate technical and organisational measures against unlawful and accidental loss, alteration and unauthorised access. Complete security cannot be guaranteed.
The Customer is responsible for the security of its own devices, network connections and access management, and for removing a User's access when that person no longer works on the Customer's behalf.
The following safeguards are in place in the Service:
- All traffic to the Service is encrypted (TLS 1.2 or later), and data is also encrypted at rest.
- Traffic passes through a web application firewall (Azure Front Door), and the Service's backend services cannot be reached directly from the internet.
- The sign-in session is encrypted. Access rights are based on roles and organisation, and tenders open to the contracting entity only after the tender deadline has passed.
- File upload and download links are valid for only a few minutes. Uploaded files are scanned for malware, and a finding is shown as a warning mark on the file. The file is not removed, so the User has to assess a marked file before opening it.
- Secrets and keys are kept in Azure Key Vault, and the parts of the Service access them through managed identities.
- File handling is logged: who uploaded, opened or deleted a file, when, and from which IP address.
Microsoft Azure, the platform the Service runs on, is certified under ISO/IEC 27001 among other standards. The Provider itself holds no security certification. The protection of personal data is described in more detail in the service privacy notice.
The Provider notifies the Customer of a security incident affecting the Customer's material without undue delay and at the latest within 72 hours of detecting it.
8. Service availability
As a rule the Service is available around the clock, every day of the year. The Provider does not, however, guarantee uninterrupted operation unless an availability level has been separately agreed.
The Service is updated and developed as needed, and maintenance and development work may cause interruptions. Foreseeable interruptions are announced in the Service in advance.
The Provider promises no numeric availability level unless one has been agreed in the order agreement. Where an availability level is agreed, the order agreement also sets how it is measured and what follows from falling short of it. Planned maintenance is carried out outside office hours where possible.
9. Intellectual property rights
All intellectual property rights in the Service, its implementation and the material the Provider produces belong to the Provider. The Customer receives the limited right of use set out in these terms for the duration of the contract period.
Rights in the procurement documents and comparisons produced in the Service belong to the Customer. The Customer may use them freely in its own procurement work and in meeting its obligations under the Act on the Openness of Government Activities.
The Customer may not copy, modify or resell the Service or any part of it, or use the Service to develop a competing product.
10. Validity and termination
These terms remain in force for as long as the Customer uses the Service. The contract period and notice are agreed in the order agreement. Termination does not release a party from obligations that arose before it.
The Provider may block a User's access to the Service immediately where there are reasonable grounds. Reasonable grounds may include the following, and the list is not exhaustive:
- The User breaches these terms or applicable law.
- The User disrupts the Service, its other users or a third party.
- The User's credentials have reached a third party.
Blocking an individual User does not terminate the Customer's agreement and does not release it from payment obligations.
The Provider may amend these terms. An amendment is announced in the Service and the User is asked to accept the amended terms at their next sign-in. If the Customer does not accept the amendment, it may terminate the order agreement to end before the amendment takes effect.
Where no contract period has been agreed in the order agreement, the agreement is valid until further notice, and either party may terminate it with three months' notice.
An amendment to these terms is announced at least 30 days before it takes effect. An amendment required by law or by security may take effect sooner.
11. Limitation of liability
The Provider is liable for the Service conforming to these terms and the order agreement. The Provider is not liable for indirect damage such as lost profit, interruption of operations or a claim made by a third party.
The Provider is not liable for a procurement decision, its reasoning or its lawfulness, or for choices made in a procurement procedure. Responsibility for these rests with the contracting entity as set out in section 5.
This limitation does not apply to damage caused intentionally or through gross negligence, and it does not limit liability that cannot be limited under mandatory Finnish law.
The Provider's total liability for damages is limited to the fees the Customer has paid for the Service during the 12 months preceding the damage. Where the Customer pays no fees for the Service, the Provider's liability is limited to the extent mandatory law allows.
12. Force majeure
A party is released from its obligations and from the obligation to pay damages where a failure to perform is due to an impediment beyond its control that it could not reasonably have taken into account or avoided.
Force majeure includes, for example, war, a natural disaster, an act of an authority, an interruption of general telecommunications or electricity supply, and widespread industrial action.
A party must notify the other of a force majeure event without undue delay and state how long it is expected to last.
13. Applicable law and dispute resolution
These terms are governed by Finnish law, excluding its conflict of law provisions.
The parties will seek to resolve any disagreement by negotiation in the first instance.
A disagreement that cannot be resolved by negotiation is settled by the Helsinki District Court as the court of first instance, unless otherwise agreed in the order agreement. With a public sector Customer it may be agreed in the order agreement that disputes are settled by the district court of the Customer's domicile.
14. Contact details
The Better One Oy, business ID 3597598-3, Itätuulenkuja 10 A, LT 1, 02100 Espoo, Finland. Enquiries: myynti@bidi.fi.
Matters concerning the processing of personal data: tietosuoja@bidi.fi.