Last updated: 08.08.2025
By accessing or using the Tenderhub Software-as-a-Service application ("Application") provided by revitalyze FlexCo ("Company"), you ("Customer") agree to these Terms of Service ("Terms"). If you do not agree to these Terms, you may not use the Service. These Terms govern your use of the Application, including all content, features, and applications offered on or through the Application.
The Application is an AI-powered platform developed for the construction industry to analyze and enrich tender and supplier data. The Application uses large language models (LLMs), including the Gemini API and OpenAI API, to process documents uploaded by the customer and to extract, interpret, and organize company-specific information. The purpose of the Application is to help customers streamline processes for bid evaluation and supplier data management.
The customer retains all ownership rights to the data, documents, and other information they upload or submit to the Application ("Customer Data"). By using the Application, the customer grants the Company a limited, non-exclusive, worldwide, royalty-free license to access, process, and use the Customer Data solely for the purpose of providing and improving the Application for the customer.
The Company is committed to protecting Customer Data. The following measures are taken:
The customer is solely responsible for the content, legality, and accuracy of all Customer Data. The Application is intended for the analysis of company data and is not designed for the processing or interpretation of personal data. The customer agrees not to upload any personal or sensitive personal data to the Application.
The Service, including all software, technologies, and content (except for Customer Data), is the exclusive property of revitalyze and its licensors. These Terms do not grant the customer any rights to patents, copyrights, trade secrets, or trademarks related to the Service.
Both parties agree to treat all non-public information received from the other party in connection with the Service as confidential. Confidential information includes, but is not limited to, prices, business plans, technical information, and Customer Data. The receiving party will protect the disclosing party's confidential information with the same care as it protects its own information.
The Application is provided "as is" and without any warranties. The Company does not guarantee that the Service will be error-free or that the results of the LLM analysis will be completely accurate or suitable for a particular purpose. The customer assumes full responsibility for the use of the Application and for verifying all information provided. In no event shall the Company be liable for indirect, incidental, special, or consequential damages arising out of or in connection with the use of the Application.
The Company may terminate or suspend the customer's access to the Application at any time and for any reason, with or without notice. Upon termination, all provisions of these Terms that by their nature should survive termination shall remain in effect.
These Terms are governed by and construed in accordance with the laws of Austria, without regard to conflict of law provisions.
These Terms constitute the entire agreement between you and revitalyze regarding the use of the Application and supersede all prior and contemporaneous agreements, proposals, or representations.
between
revitalyze FlexCo
Mühltal 43
A - 6341 Ebbs
(hereinafter referred to as Processor)
&
The User
(hereinafter referred to as Controller)
(1) The subject matter of this agreement is the performance of the following tasks:
The provision of services, in particular the provision and operation of the Software-as-a-Service platform "Tenderhub" for the automated analysis of tender and contract documents.
This agreement is to be understood as a supplement to the General Terms and Conditions for the use of the "Tenderhub" platform.
(2) The following data categories are processed:
(3) The following categories of data subjects are subject to processing:
(4) Type of processing:
Processing includes the collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure (within the scope of contractual services), alignment or combination, as well as deletion or destruction of data.
The agreement is concluded for an indefinite period and may be terminated by either party with one (1) month's notice to the end of the month. The right to extraordinary termination for good cause remains unaffected.
(1) The Processor undertakes to process data and processing results exclusively within the framework of the written instructions of the Controller. If the Processor receives an official order to release data of the Controller, they shall - if legally permissible - immediately inform the Controller and refer the authority to them. Likewise, processing of data for the Processor's own purposes requires a written order.
(2) The Processor legally declares that they have taken all necessary measures to ensure the security of processing in accordance with Art. 32 GDPR (details can be found in Annex /1).
(3) The Processor takes technical and organizational measures so that the Controller can fulfill the rights of the data subject under Chapter III of the GDPR (information, access, rectification and erasure, data portability, objection, and automated individual decision-making) within the legal deadlines at all times and provides the Controller with all necessary information. If a corresponding request is addressed to the Processor and it is evident that the applicant mistakenly considers them to be the Controller of the data processing they operate, the Processor must immediately forward the request to the Controller and inform the applicant accordingly.
(4) The Processor supports the Controller in complying with the obligations set out in Articles 32 to 36 GDPR (data security measures, notifications of personal data breaches to the supervisory authority, notification of the data subject affected by a personal data breach, data protection impact assessment, prior consultation).
(5) The Processor is advised that they must establish a processing directory in accordance with Art. 30 GDPR for the present commissioned processing.
(6) The Controller is granted the right to inspect and control the data processing facilities at any time, including through third parties commissioned by them, with regard to the processing of the data provided. The Processor undertakes to provide the Controller with the information necessary to verify compliance with the obligations set out in this agreement.
(7) Upon termination of this agreement, the Processor is obliged to hand over all processing results and documents containing data to the Controller / to destroy them on their behalf. If the Processor processes the data in a special technical format, they are obliged to release the data after termination of this agreement either in this format or, at the request of the Controller, in the format in which they received the data from the Controller or in another common format.
(8) The Processor must immediately inform the Controller if they believe that an instruction from the Controller violates data protection provisions of the Union or the Member States.
Data processing takes place primarily in data centers within the European Union (EU). The Controller acknowledges and agrees that for the provision of certain services, in particular for the use of language models (AI inference), data processing steps may also take place in third countries (especially the USA).
The Processor ensures that the legal requirements of Art. 44 ff. GDPR are met for such transfers to third countries. In the case of the USA, the transfer is based on the "EU-U.S. Data Privacy Framework" (adequacy decision of the EU Commission), under which Microsoft is certified. Alternatively, or for countries without an adequacy decision, EU Standard Contractual Clauses (SCC) are concluded.
The Processor may engage sub-processors for data processing, data storage, or for the use of language models.
They must notify the Controller. The Processor ensures that the sub-processor takes the necessary data protection measures within the meaning of Art. 28 Para. 4 GDPR. It must be ensured that the sub-processor enters into the same obligations as those incumbent on the Processor under this agreement.
Physical Access Control: Protection against unauthorized access to data processing systems through:
System Access Control: Protection against unauthorized system use through:
Data Access Control: No unauthorized reading, copying, modifying, or removing within the system through:
Transfer Control: No unauthorized reading, copying, modifying, or removing during electronic transmission or transport through:
Availability Control: Protection against accidental or intentional destruction or loss through:
Data protection management, including regular employee training
Incident response management:
Privacy by default:
Order Control: No order data processing within the meaning of Art. 28 GDPR without corresponding instruction from the Controller through: