Legal

Data Processing Agreement

These data processing terms apply whenever FastTender processes personal data on behalf of a customer. For a countersigned copy, or to negotiate enterprise terms, email legal@fasttender.us.

Last updated: July 2026

Roles

For personal data your team submits or generates inside FastTender (user accounts, contacts, documents, proposals), your company is the controller (or "business" under US state privacy laws) and FastTender is the processor ("service provider"). We process that data only on your documented instructions - to provide the service - and never sell it or use it for advertising.

Scope of processing

Categories of data: account identifiers (name, work email), workspace content (company profile, pipeline, documents, proposals), and service telemetry needed to operate and secure the platform.

Purpose: providing, securing, and improving the FastTender service as described in our Terms of Service. AI features process your content solely to produce output for you; our AI providers are contractually prohibited from training models on it.

Confidentiality and personnel

Access to customer data is restricted to personnel who need it to operate or support the service, and all such personnel are bound by confidentiality obligations.

Security measures

We maintain technical and organizational measures appropriate to the risk, including: TLS encryption in transit, encryption at rest, role-based access control with workspace isolation, authentication through a dedicated identity provider, logging and monitoring, and regular backups. Details are described on our Security page (/security).

Subprocessors

We use a small number of vetted subprocessors to deliver the service. The current list, what each processes, and their locations is available on request and updated in advance of changes. We remain responsible for our subprocessors' performance.

Data subject requests

We assist you in responding to access, correction, deletion, and portability requests from your users. Requests received directly by FastTender that concern your workspace are forwarded to you without undue delay.

Breach notification

If we become aware of a security breach affecting your personal data, we will notify you without undue delay after confirming the incident, and provide the information reasonably needed for your own notification obligations.

Deletion and return

On termination of your subscription, or on request, we delete your workspace data within 30 days, except where retention is required by law (e.g. billing records held by our merchant of record). You can export your data before deletion.

Audits and reports

On written request (no more than once annually), we will provide information reasonably necessary to demonstrate compliance with these terms, including summaries of third-party assessments as they become available.