Privacy Policy

Last updated: 14 July 2026

1. Who we are

This Privacy Policy explains how TenderLedger ("we", "us", "our") processes personal data when you use our websites, applications and procurement intelligence services (the "Service"). For UK GDPR purposes, TenderLedger is the controller of personal data described below, unless otherwise stated.

Privacy and deletion contact: contact@trytenderledger.co.uk.

2. Scope and business context

The Service is designed for business customers. Where you create an account for an organisation, the organisation may control certain workplace account data. Public procurement notices, awards and related content ingested from official public sources are public-source information. Appearing as a named supplier or buyer in a public notice does not, by itself, make that notice your personal data that we must erase on demand.

3. Data we collect

We may collect:

  • Account and profile data (name, email, password hashes, organisation name, role, preferences);
  • Billing and transaction metadata processed via payment providers (we do not store full card numbers);
  • Usage and telemetry (searches, saved items, alerts, pages viewed, feature usage, IP address, device and browser data, approximate location derived from IP);
  • Communications you send us (support emails, forms);
  • Cookies and similar technologies as described below;
  • Content you upload or enter into the Service.

4. How we use data (purposes and legal bases)

We process personal data to:

  • Provide, secure, authenticate and administer the Service (contract / legitimate interests);
  • Bill and recover fees (contract / legitimate interests / legal obligation);
  • Detect abuse, fraud and security incidents (legitimate interests);
  • Improve, debug and develop the Service, including model improvement on aggregated or anonymised datasets (legitimate interests);
  • Create anonymised and aggregated statistics and commercial intelligence that we may retain and use indefinitely for any lawful commercial purpose (legitimate interests);
  • Send service notices; send product updates and marketing to business contacts where permitted (legitimate interests or consent where required);
  • Comply with law and enforce our Terms (legal obligation / legitimate interests).

We do not sell your personal data as a consumer mailing list. We do reserve the right to use anonymised and aggregated data freely and permanently, including after account closure.

5. Sharing

We may share personal data with processors who help us operate the Service (hosting, databases, email, analytics, customer support tooling, payment processors such as Stripe), with professional advisers, in connection with a merger, financing or sale of assets, and when required by law or to protect rights, safety and security. Processors are bound by contractual confidentiality and processing terms. We may also disclose information to defend legal claims.

6. International transfers

Personal data may be processed in the UK, EEA or other countries where our providers operate. Where required, we use appropriate safeguards (such as UK International Data Transfer Agreements or equivalent mechanisms) for restricted transfers.

7. Retention

We retain account data for the life of the account and thereafter as needed for billing disputes, tax, fraud prevention and legal claims — typically up to seven (7) years for transactional records, longer where required by law. Backups may persist for a limited period after deletion from live systems. Anonymised and aggregated datasets are retained indefinitely and are not subject to erasure.

8. Your UK GDPR rights

Where UK GDPR applies, you may have rights to access, rectify, erase, restrict or object to certain processing, to data portability, and to withdraw consent where processing is consent-based. You may complain to the Information Commissioner's Office (ICO) at ico.org.uk. These rights are not absolute and may be refused or limited where exemptions apply (including legal claims, freedom of expression for public information republishing contexts, and where we cannot verify identity).

9. How to request deletion

Deletion requests must be sent by email only to contact@trytenderledger.co.uk with the subject line exactly: Data deletion request.

Your email must include all of the following or it will be rejected as incomplete:

  • Full legal name of the individual making the request;
  • Account email address;
  • Organisation / company name on the account;
  • Account or organisation ID if known;
  • Clear statement of what you want deleted;
  • Proof of identity (government photo ID) and, for company accounts, written authority on company letterhead confirming you may act for the organisation;
  • Confirmation you understand that account deletion does not entitle you to any refund of fees paid.

We will verify identity and authority before acting. Incomplete, unverifiable or frivolous requests may be refused. Where UK GDPR requires a response, we aim to respond within the applicable statutory period after we have received a complete, verified request (time spent clarifying or verifying does not count as undue delay). We may extend time where requests are complex.

We may refuse or limit erasure where we need to retain data for:

  • Legal, tax, accounting or regulatory obligations;
  • Billing, chargeback and fraud prevention;
  • Establishing, exercising or defending legal claims;
  • Security logs for a proportionate period;
  • Anonymised or aggregated data that is no longer personal data;
  • Public procurement source data that is not personal data we control on your behalf;
  • Backups until they naturally rotate off.

10. Cookies and analytics

We use essential cookies to run the Service and may use analytics and marketing technologies to understand usage and improve products. You can control cookies via browser settings; disabling cookies may break login or core features.

11. Children

The Service is not directed to individuals under 18. We do not knowingly collect personal data from children.

12. Security

We implement technical and organisational measures appropriate to the risk. No method of transmission or storage is completely secure; you use the Service at your own risk regarding residual security risk.

13. Changes

We may update this Privacy Policy at any time by posting a revised version with an updated "Last updated" date. Continued use of the Service after changes take effect constitutes acceptance of the updated policy.

14. Related documents

Use of the Service is also governed by our Terms of Service and Refund Policy.