Data Handling Schedule
How we handle your tender data.
This page is maintained by Honey-B2024 Ltd (trading as Bidsmith ASF, company no. 15744305, ICO registration ZC178845 Tier 1) to give you a plain, non-marketing record of how customer data is received, stored, processed, retained and deleted. It complements — it does not replace — the Privacy Policy and any executed Data Processing Agreement.
1. What data we receive
Tender packs. ITT, TOR, SQ, specifications, drawings, pricing schedules and appendices you upload.
Company documents. Case studies, method statements, policies, certifications, accreditations, insurances and CVs you add to your workspace knowledge base.
Account data. Name, work email, organisation name, workspace membership, role, and billing contact.
Product telemetry. Sign-in events, feature usage counters, error diagnostics. No third-party ad tracking.
2. Where it is stored and for how long
Customer tender data is hosted in the UK / EEA. Transfers outside adequacy regions require Standard Contractual Clauses (SCCs) plus the UK International Data Transfer Addendum (IDTA).
Retention. Customer content is retained for the duration of the subscription. After termination, live data is retained for 30 days to allow re-activation, then deleted from primary storage. Encrypted backups are rotated out within a further 60 days.
Statutory retention. Invoice and tax records are retained for 6 years as required by HMRC.
3. Third-party processors
The register below lists the sub-processors we use, what each receives, where it is stored, and the fallback vendor we would move to if a processor became unavailable.
| Vendor | Purpose | Data | Region | Retention | Fallback |
|---|---|---|---|---|---|
| Cloudflare, Inc. | Application hosting, edge routing, CDN and DDoS protection. | Request metadata, IP address, in-transit application traffic | Global edge network; request logs retained in short-lived edge storage. | Edge logs typically under 7 days. No customer documents stored at rest. | Vercel / AWS CloudFront |
| Supabase Inc. (managed Postgres & object storage) | Structured storage of accounts, bids, drafts and uploaded tender documents; authentication. | Account data, workspace membership, tender uploads, generated drafts, knowledge-base documents | EU (EEA) region. | Duration of subscription + 30 days; encrypted backups rotated out within a further 60 days. | Self-managed Postgres on an AWS eu-west-2 (London) instance |
| OpenAI, L.L.C. | Primary language-model inference for drafting and analysing bid responses. | Tender extracts, prompt content, draft text | United States. Transfers under SCCs + UK IDTA. | API data not used for model training; provider-side retention up to 30 days for abuse monitoring. | Anthropic |
| Anthropic PBC | Secondary language-model inference (failover and document restyling). | Tender extracts, prompt content, draft text | United States. Transfers under SCCs + UK IDTA. | API data not used for model training; limited provider-side retention for abuse monitoring. | OpenAI |
| Cohere Inc. | Text embeddings for semantic retrieval over your knowledge base. | Document text chunks submitted for embedding | United States / Canada. Transfers under SCCs + UK IDTA. | Embedding requests are not retained for training; vectors are stored by us in the EEA database. | OpenAI embeddings |
| Stripe Payments Europe, Ltd. | Subscription billing, checkout and invoicing. | Billing contact, email address, card data held by Stripe (we never see card numbers), invoice history | EEA with US transfers under SCCs; Stripe is PCI DSS Level 1. | Statutory 6 years for invoice and tax records. | GoCardless / direct bank invoicing |
| Lovable (managed platform email) | Account, security and workflow notification emails. | Email address, name, message content | EEA / US, depending on the delivery provider. Transfers under SCCs + UK IDTA. | Delivery logs retained up to 30 days. | Postmark (EU) / direct SMTP |
| Intercom R&D Unlimited Company | In-app support messenger on the public marketing site. | Name, email address, support conversation content, page-visit metadata | EEA (Dublin) hosting region. | Conversation history retained while your account is active. | Email support at Info@bidsmith.co.uk |
This register is reviewed on material changes and at least annually. Where a processor operates outside the UK / EEA, transfers are covered by Standard Contractual Clauses plus the UK International Data Transfer Addendum.
4. Who can access it, and under what circumstances
You and your workspace members. Row-level authorisation confines each customer's data to their own organisation.
Named Bidsmith operators. A small number of named engineers may access customer data solely to (a) fulfil a support ticket you raise, (b) investigate a security incident, or (c) restore service after an outage. Access is logged.
Legal disclosure. Only on receipt of a valid, enforceable order from a competent UK authority, and only to the minimum extent required.
5. How to request deletion (DSAR)
UK GDPR gives you the right to access, rectify, erase, restrict, port or object to the processing of your personal data.
Send DSAR and deletion requests to Info@bidsmith.co.uk. We respond within one month.
You can also complain to the UK Information Commissioner's Office at ico.org.uk.
6. What we do NOT do
We do not train public foundation models on your tender data.
We do not sell customer data to third parties.
We do not run ad-tracking, cross-site profiling or third-party marketing pixels on the authenticated product.
We do not access your workspace content for marketing case-studies without your explicit written consent.
Last reviewed: 2026-08-24. This schedule is maintained by Honey-B2024 Ltd. Material changes will be notified to workspace owners by email.
