Data Handling Schedule

How we handle your tender data.

This page is maintained by Honey-B2024 Ltd (trading as Bidsmith ASF, company no. 15744305, ICO registration ZC178845 Tier 1) to give you a plain, non-marketing record of how customer data is received, stored, processed, retained and deleted. It complements — it does not replace — the Privacy Policy and any executed Data Processing Agreement.

1. What data we receive

Tender packs. ITT, TOR, SQ, specifications, drawings, pricing schedules and appendices you upload.

Company documents. Case studies, method statements, policies, certifications, accreditations, insurances and CVs you add to your workspace knowledge base.

Account data. Name, work email, organisation name, workspace membership, role, and billing contact.

Product telemetry. Sign-in events, feature usage counters, error diagnostics. No third-party ad tracking.

2. Where it is stored and for how long

Customer tender data is hosted in the UK / EEA. Transfers outside adequacy regions require Standard Contractual Clauses (SCCs) plus the UK International Data Transfer Addendum (IDTA).

Retention. Customer content is retained for the duration of the subscription. After termination, live data is retained for 30 days to allow re-activation, then deleted from primary storage. Encrypted backups are rotated out within a further 60 days.

Statutory retention. Invoice and tax records are retained for 6 years as required by HMRC.

3. Third-party processors

The register below lists the sub-processors we use, what each receives, where it is stored, and the fallback vendor we would move to if a processor became unavailable.

VendorPurposeDataRegionRetentionFallback
Cloudflare, Inc.Application hosting, edge routing, CDN and DDoS protection.Request metadata, IP address, in-transit application trafficGlobal edge network; request logs retained in short-lived edge storage.Edge logs typically under 7 days. No customer documents stored at rest.Vercel / AWS CloudFront
Supabase Inc. (managed Postgres & object storage)Structured storage of accounts, bids, drafts and uploaded tender documents; authentication.Account data, workspace membership, tender uploads, generated drafts, knowledge-base documentsEU (EEA) region.Duration of subscription + 30 days; encrypted backups rotated out within a further 60 days.Self-managed Postgres on an AWS eu-west-2 (London) instance
OpenAI, L.L.C.Primary language-model inference for drafting and analysing bid responses.Tender extracts, prompt content, draft textUnited States. Transfers under SCCs + UK IDTA.API data not used for model training; provider-side retention up to 30 days for abuse monitoring.Anthropic
Anthropic PBCSecondary language-model inference (failover and document restyling).Tender extracts, prompt content, draft textUnited States. Transfers under SCCs + UK IDTA.API data not used for model training; limited provider-side retention for abuse monitoring.OpenAI
Cohere Inc.Text embeddings for semantic retrieval over your knowledge base.Document text chunks submitted for embeddingUnited States / Canada. Transfers under SCCs + UK IDTA.Embedding requests are not retained for training; vectors are stored by us in the EEA database.OpenAI embeddings
Stripe Payments Europe, Ltd.Subscription billing, checkout and invoicing.Billing contact, email address, card data held by Stripe (we never see card numbers), invoice historyEEA with US transfers under SCCs; Stripe is PCI DSS Level 1.Statutory 6 years for invoice and tax records.GoCardless / direct bank invoicing
Lovable (managed platform email)Account, security and workflow notification emails.Email address, name, message contentEEA / US, depending on the delivery provider. Transfers under SCCs + UK IDTA.Delivery logs retained up to 30 days.Postmark (EU) / direct SMTP
Intercom R&D Unlimited CompanyIn-app support messenger on the public marketing site.Name, email address, support conversation content, page-visit metadataEEA (Dublin) hosting region.Conversation history retained while your account is active.Email support at Info@bidsmith.co.uk

This register is reviewed on material changes and at least annually. Where a processor operates outside the UK / EEA, transfers are covered by Standard Contractual Clauses plus the UK International Data Transfer Addendum.

4. Who can access it, and under what circumstances

You and your workspace members. Row-level authorisation confines each customer's data to their own organisation.

Named Bidsmith operators. A small number of named engineers may access customer data solely to (a) fulfil a support ticket you raise, (b) investigate a security incident, or (c) restore service after an outage. Access is logged.

Legal disclosure. Only on receipt of a valid, enforceable order from a competent UK authority, and only to the minimum extent required.

5. How to request deletion (DSAR)

UK GDPR gives you the right to access, rectify, erase, restrict, port or object to the processing of your personal data.

Send DSAR and deletion requests to Info@bidsmith.co.uk. We respond within one month.

You can also complain to the UK Information Commissioner's Office at ico.org.uk.

6. What we do NOT do

We do not train public foundation models on your tender data.

We do not sell customer data to third parties.

We do not run ad-tracking, cross-site profiling or third-party marketing pixels on the authenticated product.

We do not access your workspace content for marketing case-studies without your explicit written consent.

Last reviewed: 2026-08-24. This schedule is maintained by Honey-B2024 Ltd. Material changes will be notified to workspace owners by email.