Data Processing Addendum
This addendum ("DPA") forms part of the Terms of Service between ScoutTide ("we", the processor) and the organisation that uses ScoutTide ("you", the controller), whenever we process personal data on your behalf. It applies automatically; nothing needs to be signed. If it conflicts with the terms on the processing of personal data, this DPA prevails. Terms such as personal data, processing and personal data breach have the meaning given in the GDPR (Regulation (EU) 2016/679) and, where it applies, the UK GDPR.
1. Subject matter and duration
The subject matter is the provision of the ScoutTide service described in the terms. Processing lasts for as long as we provide the service to you, and afterwards only for the deletion periods in section 10.
2. Nature and purpose
Hosting, storing, displaying, searching, matching and transmitting data so your organisation can find, triage and work on tenders and posts: accounts and sign-in, the shared queue, claims and pipeline, notes and documents, AI matching and translation, email notifications and the morning digest, support, security and backups.
3. Types of personal data
- Identity and contact data of your users: name, email address, sign-in identifier, role, language.
- Usage data: claims, stages, notes, dismissals, saved searches, products, the activity log, and technical logs (IP address, time, address requested).
- Whatever personal data your users put into notes, product descriptions and uploaded documents.
The service is not designed for special categories of personal data (GDPR Art. 9) or data about criminal convictions; please do not upload them.
4. Categories of data subjects
Your users (employees, contractors and others you invite), people you invite, and people named in content your users add, such as contacts in your notes or documents.
5. Your instructions
We process personal data only on your documented instructions, which are the terms, this DPA and your use and configuration of the service, unless the law requires otherwise, in which case we will tell you before processing unless the law forbids it. We will tell you if we believe an instruction infringes data protection law. You are responsible for having a lawful basis for the personal data you put into ScoutTide.
6. Our obligations
- Confidentiality: everyone we authorise to process personal data is bound by confidentiality.
- Security: we apply the measures in section 9 (GDPR Art. 32) and keep them under review.
- Assistance: taking into account the nature of the processing, we help you answer data subjects' requests (most can be handled in-app: data download, correction, account deletion) and with your obligations under GDPR Articles 32 to 36.
- Records: we keep a record of processing activities as GDPR Art. 30(2) requires.
7. Sub-processors
You give general authorisation for us to use sub-processors. The current ones are listed on the sub-processors page, which is part of this DPA. We impose data protection obligations on each that are no less protective than this DPA, and remain responsible for them. We email your organisation's managers at least 30 days before adding or replacing a sub-processor. You may object on reasonable data protection grounds within that period; if we cannot address the objection, you may end the affected service and receive a refund of prepaid fees for the period after the change.
At the date of this page they are: netcup GmbH (Germany); GoDaddy (GoDaddy.com, LLC, "Secureserver" mail) (United States); Operator of api.gonka24.com; Ollama, Inc. (United States); Bitdeer Technologies (Singapore); Serper; SerpApi (United States); AlphaAI Technologies Inc. (Tavily) (United States); Exa (United States); DataForSEO OÜ (Estonia).
8. International transfers
Your data is stored on servers in Germany. Where a sub-processor processes it outside the EEA or the UK, the transfer relies on an adequacy decision (such as the EU–US Data Privacy Framework for certified US companies) or on the European Commission's Standard Contractual Clauses (Decision (EU) 2021/914, module 3, processor-to-processor), with the UK International Data Transfer Addendum for UK data, together with supplementary measures such as encryption in transit.
9. Security measures
- In transit: all traffic to the service uses HTTPS (TLS); calls to sub-processors use TLS.
- At rest: data is held on a server in Germany. We do not currently apply disk- or database-level encryption at rest; access is restricted as described below. Passwords are stored only as bcrypt hashes.
- Access control: every organisation's data is kept apart from every other's in the application; server access is limited to the people who run the service, by SSH key only (no passwords), behind a firewall that admits only SSH and the web, with repeated failed logins blocked automatically.
- Sessions: signed-in sessions expire after inactivity; forms are protected against cross-site request forgery.
- Backups: nightly database and document snapshots kept for 14 days, and database snapshots taken before each deployment kept for up to 30 days, with a documented restore procedure.
- Updates and monitoring: security updates are applied automatically to the server's operating system, and service health is monitored with alerts to the operator.
10. Deletion and return at the end
When the service ends you can export your data (lists as Excel, CSV or PDF, documents by download, each user's own data from Account settings) for as long as the organisation exists. An organisation deleted by a manager is held for 14 days so it can be restored, then deleted; an organisation whose plan has ended and where nobody has signed in for 30 days is deleted after a further 180 days, with 14 days' grace in which a manager who signs in can stop it. Deleted data leaves our backups within 30 days. We keep personal data longer only where the law requires it.
11. Personal data breaches
We notify your organisation's managers without undue delay, and in any case within 72 hours, after becoming aware of a personal data breach affecting your data, with the information we have (what happened, the data and people likely affected, the likely consequences and the measures taken or proposed), and we update you as we learn more.
12. Audits
We make available the information needed to demonstrate compliance with GDPR Art. 28, in the first place by answering your written questions and by this DPA. Where that is not enough, or a supervisory authority requires it, we allow an audit by you or an auditor you appoint who is bound by confidentiality, on at least 30 days' notice, during business hours, no more than once a year unless a breach has occurred, and at your cost.
13. Liability and order of precedence
The limitations of liability in the terms apply to this DPA, except where the GDPR does not allow them. This DPA ends automatically when we no longer process personal data for you.
Questions about this DPA: support@scouttide.com.