Terms of use for tenderers
The terms on which tenderers use the BIDI service: how the agreement is formed, what to keep in mind when submitting a tender, what the parties can expect of each other and how tenderer material is handled.
Updated 22 September 2026
The Finnish version prevails in case of any discrepancy between the two language versions.
1. Service and its purpose
BIDI (the Service) is a tendering platform for public procurement produced by The Better One Oy (the Provider). These terms govern use of the Service as a tenderer.
In the Service a tenderer can maintain its company profile, browse public tenders, ask the contracting entity clarification questions, prepare and submit tenders, and answer market surveys. A tenderer supplying healthcare products can also maintain a product register in the Service.
The Service is a tool for taking part in procurements. It is not an official notification channel and it does not replace publishing a contract notice in the channel the law prescribes. The procedure, deadlines and requirements of an individual procurement are set by the contracting entity in its call for tenders, and these terms do not change them.
Contracting entities and those working on their behalf use the Service under the terms of use for contracting entities.
2. Parties and formation of the agreement
The parties to the agreement are the Provider and the tenderer's organisation on whose behalf the Service is used (the Customer). A person using the Service on the Customer's behalf is referred to below as the User.
The agreement is formed when a User accepts these terms on the Customer's behalf.
A User accepts these terms on first signing in to the Service. When the terms change, the Service asks for acceptance again as described in section 11. The Service records for each User when acceptance was given and which version of the terms was accepted.
A User who works in the Service on both the tenderer side and the contracting entity side accepts the terms of each side separately.
These terms apply unless otherwise agreed in writing between the Provider and the Customer.
3. Registration and authentication
Using the Service requires an account. A User can create the tenderer's organisation in the Service or join an organisation that already exists there. The basic details of a company profile can be fetched from the open data of the Finnish Patent and Registration Office (YTJ). The User must give correct and current information and keep it up to date.
Users sign in with a Microsoft work or school account (Microsoft Entra ID), a Google account, or an email address and password. Passwords for email sign-in are managed by Microsoft Entra External ID, and the Service never sees or stores a password. Email sign-in asks for the password at every sign-in.
The Service does not itself require multi-factor authentication. When signing in with a Microsoft or Google account, authentication follows the policies of the User's own organisation, and the Customer is responsible for those policies being adequate. The Provider recommends using multi-factor authentication.
A sign-in session ends after eight hours at the latest. Access rights are checked against the database every five minutes, so a removed or changed right takes effect within five minutes at the latest.
The User undertakes not to present themselves as another person or as a representative of an organisation other than the one they represent. The Provider may remove an account where this has happened.
A right of use is personal. Passing credentials to a third party is prohibited, and the User is responsible for what is done with their credentials.
The User is not, however, responsible for use where the credentials reach a third party for a reason beyond the User's control, such as a breach of the Provider's systems. This requires that the User does not prevent the Provider from closing the account.
If there is reason to believe credentials have reached a third party, the User must immediately change the password of the account they sign in with, at the sign-in service that account uses, and report it to myynti@bidi.fi. Users must sign out of any shared device.
4. Rights and obligations of the parties
The Customer receives the right, set out in these terms, to use the Service in taking part in public procurements. The right of use may not be transferred or sublicensed.
The Provider may issue instructions on using the Service, and the User is obliged to follow them.
The Provider develops the Service and may add, change and remove features. Changes that materially reduce functionality are announced in advance. Statements in demonstration material do not bind the Provider.
The Customer is responsible for the material it brings into the Service, such as its company profile, tenders and product register, and for having the right to process that material there. The Provider does not monitor or verify the accuracy or lawfulness of material the Customer enters.
The Customer is responsible for ensuring that its activity in the Service does not breach the law, infringe the rights of a third party or offend good practice, and does not disrupt the Service or its other users. Where the Provider has reasonable grounds to suspect a breach of this section, it may block access and restrict use of the material immediately.
The Service database is backed up automatically and can be restored to any point in time within the last seven days. Backups are kept for seven days and are not stored in a second geographic region. Attachments are stored as three copies within the same data centre, and no separate backup is taken of them. If material is lost or corrupted in the Provider's systems, the Provider restores it without undue delay.
5. Tenders and the procurement procedure
The contracting entity sets the procedure, the deadlines and the requirements for tenders in its call for tenders. The Provider is not a party to the procurement procedure and cannot change the deadlines or requirements the contracting entity has set.
The Customer is responsible for the correctness of its tender and for submitting it within the deadline. A tender can be withdrawn before the tender deadline.
A submitted tender opens to the contracting entity only after the tender deadline has passed. The name, email address and phone number of the tender's contact person are visible to the contracting entity and are printed on the PDF file produced from the tender.
A submitted tender is part of the contracting entity's procurement material. The contracting entity is responsible for how it is handled, for its public access and for its retention under the legislation that applies to it.
A clarification question is passed to the contracting entity running the tender, which decides on the answer and on publishing it. An answer to a market survey is passed to the contracting entity that runs the survey.
When a contracting entity publishes a contract award notice in Hilma (hankintailmoitukset.fi), the notice contains the winning tenderer's name and business ID. The contracting entity decides on publication.
6. AI
The functions of the Service intended for tenderers contain no AI features.
A contracting entity may use the Service's AI features to support evaluating the tenders submitted to it. AI makes no procurement decisions. The contracting entity decides on, and is responsible for, the evaluation of tenders and the procurement decision.
The Provider does not train AI models on Customer material, and Microsoft does not use inputs or responses of the Azure OpenAI Service the Service uses to train models or share them with OpenAI.
7. Tenderer material
Material the Customer brings into the Service, such as its company profile, product register and unfinished tenders, remains the Customer's. The Provider processes that material in order to provide the Service to the Customer.
A submitted tender is part of the contracting entity's procurement material as described in section 5, and it is not deleted from the contracting entity's material at the Customer's request.
The Customer may request its own material within 30 days after the agreement ends. The material is handed over in a machine-readable format: documents as PDF files, structured data as JSON or CSV, and attachments as the original files. One hand-over is free of charge.
The Customer's own material is deleted from the Service within 90 days after the agreement ends. It disappears from backups as they expire, within seven days of deletion.
The processing of personal data is described in the service privacy notice for tenderers.
8. Information security
The Provider protects the data processed in the Service with appropriate technical and organisational measures against unlawful and accidental loss, alteration and unauthorised access. Complete security cannot be guaranteed.
The Customer is responsible for the security of its own devices, network connections and access management, and for removing a User's access when that person no longer works on the Customer's behalf.
The following safeguards are in place in the Service:
- All traffic to the Service is encrypted (TLS 1.2 or later), and data is also encrypted at rest.
- Traffic passes through a web application firewall (Azure Front Door), and the Service's backend services cannot be reached directly from the internet.
- The sign-in session is encrypted. Access rights are based on roles and organisation, and tenders open to the contracting entity only after the tender deadline has passed.
- File upload and download links are valid for only a few minutes. Uploaded files are scanned for malware, and a finding is shown as a warning mark on the file. The file is not removed, so the User has to assess a marked file before opening it.
- Secrets and keys are kept in Azure Key Vault, and the parts of the Service access them through managed identities.
- File handling is logged: who uploaded, opened or deleted a file, when, and from which IP address.
Microsoft Azure, the platform the Service runs on, is certified under ISO/IEC 27001 among other standards. The Provider itself holds no security certification.
The Provider notifies the Customer of a security incident affecting the Customer's material without undue delay and at the latest within 72 hours of detecting it.
9. Service availability
As a rule the Service is available around the clock, every day of the year. The Provider does not, however, guarantee uninterrupted operation and promises no numeric availability level.
The Service is updated and developed as needed, and maintenance and development work may cause interruptions. Foreseeable interruptions are announced in the Service in advance. Planned maintenance is carried out outside office hours where possible.
10. Intellectual property rights
All intellectual property rights in the Service, its implementation and the material the Provider produces belong to the Provider. The Customer receives the limited right of use set out in these terms for as long as the agreement is in force.
Rights in the material the Customer brings into the Service remain with the Customer. By submitting a tender the Customer makes it available to the contracting entity for use in that procurement as described in section 5.
The Customer may not copy, modify or resell the Service or any part of it, or use the Service to develop a competing product.
11. Validity and termination
These terms remain in force for as long as the Customer uses the Service. The agreement is valid until further notice, and either party may terminate it with three months' notice. Termination does not release a party from obligations that arose before it.
The Provider may block a User's access to the Service immediately where there are reasonable grounds. Reasonable grounds may include the following, and the list is not exhaustive:
- The User breaches these terms or applicable law.
- The User disrupts the Service, its other users or a third party.
- The User's credentials have reached a third party.
Blocking an individual User does not terminate the Customer's agreement.
The Provider may amend these terms. An amendment is announced in the Service and the User is asked to accept the amended terms at their next sign-in. If the Customer does not accept the amendment, it may terminate the agreement to end before the amendment takes effect.
An amendment to these terms is announced at least 30 days before it takes effect. An amendment required by law or by security may take effect sooner.
12. Limitation of liability
The Provider is liable for the Service conforming to these terms. The Provider is not liable for indirect damage such as lost profit, interruption of operations or a claim made by a third party.
The Provider is not liable for a contracting entity's procurement decision, its reasoning or its lawfulness, or for choices made in a procurement procedure. Responsibility for these rests with the contracting entity as set out in sections 5 and 6.
This limitation does not apply to damage caused intentionally or through gross negligence, and it does not limit liability that cannot be limited under mandatory Finnish law.
Where the Customer pays no fees for the Service, the Provider's liability is limited to the extent mandatory law allows.
13. Force majeure
A party is released from its obligations and from the obligation to pay damages where a failure to perform is due to an impediment beyond its control that it could not reasonably have taken into account or avoided.
Force majeure includes, for example, war, a natural disaster, an act of an authority, an interruption of general telecommunications or electricity supply, and widespread industrial action.
A party must notify the other of a force majeure event without undue delay and state how long it is expected to last.
14. Applicable law and dispute resolution
These terms are governed by Finnish law, excluding its conflict of law provisions.
The parties will seek to resolve any disagreement by negotiation in the first instance.
A disagreement that cannot be resolved by negotiation is settled by the Helsinki District Court as the court of first instance.
15. Contact details
The Better One Oy, business ID 3597598-3, Itätuulenkuja 10 A, LT 1, 02100 Espoo, Finland. Enquiries: myynti@bidi.fi.
Matters concerning the processing of personal data: tietosuoja@bidi.fi.