Back to Home

    Terms of Service

    Last updated: 08.08.2025

    1. Acceptance of Terms

    By accessing or using the Tenderhub Software-as-a-Service application ("Application") provided by revitalyze FlexCo ("Company"), you ("Customer") agree to these Terms of Service ("Terms"). If you do not agree to these Terms, you may not use the Service. These Terms govern your use of the Application, including all content, features, and applications offered on or through the Application.

    2. Description of the Application

    The Application is an AI-powered platform developed for the construction industry to analyze and enrich tender and supplier data. The Application uses large language models (LLMs), including the Gemini API and OpenAI API, to process documents uploaded by the customer and to extract, interpret, and organize company-specific information. The purpose of the Application is to help customers streamline processes for bid evaluation and supplier data management.

    3. Customer Data

    3.1. Data Ownership and License:

    The customer retains all ownership rights to the data, documents, and other information they upload or submit to the Application ("Customer Data"). By using the Application, the customer grants the Company a limited, non-exclusive, worldwide, royalty-free license to access, process, and use the Customer Data solely for the purpose of providing and improving the Application for the customer.

    3.2. Data Protection and Security:

    The Company is committed to protecting Customer Data. The following measures are taken:

    • Storage and Location: All Customer Data is stored on servers located in a secure Azure cloud environment in Central Europe.
    • Encryption: Customer Data at rest is encrypted with AES-256. Data transmitted between the customer's device and the Application is encrypted with TLS (Transport Layer Security).
    • Data Separation: Customer Data is strictly separated from the data of other organizations and projects to prevent mutual influence.
    • Use of LLMs: The Company uses third-party LLM APIs, especially the Gemini API and OpenAI API, to process Customer Data.
    • No Model Training: Customer Data is not used to train the underlying LLM models of the Gemini API, OpenAI API, or other third-party applications.
    • Purpose of Use: The Company uses Customer Data only to improve its service for the customer.
    • No Sale of Data: The Company will not sell, rent, or trade Customer Data to third parties.

    3.3. Customer Responsibility for Data:

    The customer is solely responsible for the content, legality, and accuracy of all Customer Data. The Application is intended for the analysis of company data and is not designed for the processing or interpretation of personal data. The customer agrees not to upload any personal or sensitive personal data to the Application.

    4. Intellectual Property Rights

    The Service, including all software, technologies, and content (except for Customer Data), is the exclusive property of revitalyze and its licensors. These Terms do not grant the customer any rights to patents, copyrights, trade secrets, or trademarks related to the Service.

    5. Confidentiality

    Both parties agree to treat all non-public information received from the other party in connection with the Service as confidential. Confidential information includes, but is not limited to, prices, business plans, technical information, and Customer Data. The receiving party will protect the disclosing party's confidential information with the same care as it protects its own information.

    6. Disclaimers and Limitation of Liability

    The Application is provided "as is" and without any warranties. The Company does not guarantee that the Service will be error-free or that the results of the LLM analysis will be completely accurate or suitable for a particular purpose. The customer assumes full responsibility for the use of the Application and for verifying all information provided. In no event shall the Company be liable for indirect, incidental, special, or consequential damages arising out of or in connection with the use of the Application.

    7. Termination

    The Company may terminate or suspend the customer's access to the Application at any time and for any reason, with or without notice. Upon termination, all provisions of these Terms that by their nature should survive termination shall remain in effect.

    8. Governing Law

    These Terms are governed by and construed in accordance with the laws of Austria, without regard to conflict of law provisions.

    9. Entire Agreement

    These Terms constitute the entire agreement between you and revitalyze regarding the use of the Application and supersede all prior and contemporaneous agreements, proposals, or representations.


    Data Processing Agreement pursuant to Art. 28 GDPR

    between

    revitalyze FlexCo
    Mühltal 43
    A - 6341 Ebbs

    (hereinafter referred to as Processor)

    &

    The User

    (hereinafter referred to as Controller)

    1. SUBJECT MATTER OF THE AGREEMENT

    (1) The subject matter of this agreement is the performance of the following tasks:

    The provision of services, in particular the provision and operation of the Software-as-a-Service platform "Tenderhub" for the automated analysis of tender and contract documents.

    This agreement is to be understood as a supplement to the General Terms and Conditions for the use of the "Tenderhub" platform.

    (2) The following data categories are processed:

    • User data: Name, email address, login credentials.
    • Content data: All data contained in uploaded documents such as specifications, expert opinions, contract terms, or planning documents.
    • General tender data: Project-relevant data such as planners, project period, award criteria, budget, and scope of services.

    (3) The following categories of data subjects are subject to processing:

    • Employees, contacts, and representatives of the Controller (users of the platform).
    • Contacts, signatories, project participants, and other natural persons named in the uploaded documents (e.g., from business partners, clients, subcontractors of the Controller).

    (4) Type of processing:

    Processing includes the collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure (within the scope of contractual services), alignment or combination, as well as deletion or destruction of data.

    2. DURATION OF THE AGREEMENT

    The agreement is concluded for an indefinite period and may be terminated by either party with one (1) month's notice to the end of the month. The right to extraordinary termination for good cause remains unaffected.

    3. OBLIGATIONS OF THE PROCESSOR

    (1) The Processor undertakes to process data and processing results exclusively within the framework of the written instructions of the Controller. If the Processor receives an official order to release data of the Controller, they shall - if legally permissible - immediately inform the Controller and refer the authority to them. Likewise, processing of data for the Processor's own purposes requires a written order.

    (2) The Processor legally declares that they have taken all necessary measures to ensure the security of processing in accordance with Art. 32 GDPR (details can be found in Annex /1).

    (3) The Processor takes technical and organizational measures so that the Controller can fulfill the rights of the data subject under Chapter III of the GDPR (information, access, rectification and erasure, data portability, objection, and automated individual decision-making) within the legal deadlines at all times and provides the Controller with all necessary information. If a corresponding request is addressed to the Processor and it is evident that the applicant mistakenly considers them to be the Controller of the data processing they operate, the Processor must immediately forward the request to the Controller and inform the applicant accordingly.

    (4) The Processor supports the Controller in complying with the obligations set out in Articles 32 to 36 GDPR (data security measures, notifications of personal data breaches to the supervisory authority, notification of the data subject affected by a personal data breach, data protection impact assessment, prior consultation).

    (5) The Processor is advised that they must establish a processing directory in accordance with Art. 30 GDPR for the present commissioned processing.

    (6) The Controller is granted the right to inspect and control the data processing facilities at any time, including through third parties commissioned by them, with regard to the processing of the data provided. The Processor undertakes to provide the Controller with the information necessary to verify compliance with the obligations set out in this agreement.

    (7) Upon termination of this agreement, the Processor is obliged to hand over all processing results and documents containing data to the Controller / to destroy them on their behalf. If the Processor processes the data in a special technical format, they are obliged to release the data after termination of this agreement either in this format or, at the request of the Controller, in the format in which they received the data from the Controller or in another common format.

    (8) The Processor must immediately inform the Controller if they believe that an instruction from the Controller violates data protection provisions of the Union or the Member States.

    4. LOCATION OF DATA PROCESSING

    Data processing takes place primarily in data centers within the European Union (EU). The Controller acknowledges and agrees that for the provision of certain services, in particular for the use of language models (AI inference), data processing steps may also take place in third countries (especially the USA).

    The Processor ensures that the legal requirements of Art. 44 ff. GDPR are met for such transfers to third countries. In the case of the USA, the transfer is based on the "EU-U.S. Data Privacy Framework" (adequacy decision of the EU Commission), under which Microsoft is certified. Alternatively, or for countries without an adequacy decision, EU Standard Contractual Clauses (SCC) are concluded.

    5. SUB-PROCESSORS

    The Processor may engage sub-processors for data processing, data storage, or for the use of language models.

    They must notify the Controller. The Processor ensures that the sub-processor takes the necessary data protection measures within the meaning of Art. 28 Para. 4 GDPR. It must be ensured that the sub-processor enters into the same obligations as those incumbent on the Processor under this agreement.


    Annex ./1 – Technical and Organizational Measures

    A. CONFIDENTIALITY

    Physical Access Control: Protection against unauthorized access to data processing systems through:

    • Security of office premises (or home office workplaces) through lockable entrances and access restrictions for unauthorized third parties
    • Physical security of data centers (Frankfurt, Sweden) is ensured by the processor Microsoft.

    System Access Control: Protection against unauthorized system use through:

    • Passwords
    • Automatic locking mechanisms
    • Two-factor authentication
    • Encryption of data carriers

    Data Access Control: No unauthorized reading, copying, modifying, or removing within the system through:

    • Standard authorization profiles on a "need-to-know basis"
    • Logging of accesses
    • Periodic review of granted authorizations, especially administrative user accounts
    • Data protection-compliant disposal of no longer needed data carriers
    • Standard process for authorization assignment
    • Secure storage of storage media
    • Clear-desk/clear-screen policy (through automatic screen lock)

    B. DATA INTEGRITY

    Transfer Control: No unauthorized reading, copying, modifying, or removing during electronic transmission or transport through:

    • Encryption of data carriers
    • Encryption of files (encryption at-rest)
    • Encryption according to current state of the art (currently e.g. TLS 1.2 or higher)

    C. AVAILABILITY AND RESILIENCE

    Availability Control: Protection against accidental or intentional destruction or loss through:

    • Backup strategy (online/offline; on-site/off-site)
    • Virus protection
    • Reporting channels and emergency plans
    • Multi-level security concept with encrypted backup to an alternative data center
    • Uninterruptible power supply (UPS) according to cloud provider standards
    • Firewall
    • Security checks at infrastructure and application level
    • Standard processes for employee changes/departures

    D. PROCEDURES FOR REGULAR REVIEW, ASSESSMENT, AND EVALUATION

    Data protection management, including regular employee training

    Incident response management:

    Privacy by default:

    Order Control: No order data processing within the meaning of Art. 28 GDPR without corresponding instruction from the Controller through:

    • Clear contract design
    • Strict selection of the processor (ISO certification, ISMS)
    • Follow-up controls
    • Formalized order management
    • Pre-conviction obligation