Legal
Data Processing Addendum
The data-processing terms that apply when BlackReach Limited processes customer workspace personal information on a customer’s behalf.
Last updated: 8 August 2026
1. Parties, scope and precedence
This Data Processing Addendum (“DPA”) forms part of the agreement between BlackReach Limited, company 17240929, of 71–75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ (“BlackReach”) and the customer using BlackReach Intelligence (“Customer”). It applies where BlackReach processes personal information for Customer as processor.
Customer is controller and BlackReach is processor for private workspace content. BlackReach remains controller for its account administration, billing, security, legal compliance and independently sourced public procurement intelligence, as explained in the Privacy Notice. If this DPA conflicts with the main agreement on processor obligations, this DPA prevails.
2. Processing details
- Subject and purpose: operating customer accounts, company profiles, evidence, opportunity qualification, pursuits, tender documents, reports, notifications, secure portal workflows and support.
- Duration: the customer agreement plus the return/deletion period in section 11.
- Nature: collection, storage, organisation, retrieval, analysis, AI-assisted transformation, transmission at Customer’s direction, restriction, backup and deletion.
- People: Customer users, personnel, business contacts, bid contributors and people appearing in Customer-provided procurement material.
- Information: names, business contact details, roles, authentication identifiers, company and bid information, notes, tasks, evidence, portal audit metadata, documents and generated output.
- Sensitive information: the service is not designed for special-category or criminal-offence information. Customer must not submit it unless the parties first document the need, condition, safeguards and instructions.
3. Customer instructions and responsibilities
BlackReach will process Customer personal information only on documented instructions in the agreement, product configuration, support requests or other written directions, including instructions about transfers, unless UK law requires otherwise. If legally permitted, BlackReach will tell Customer before processing required by law.
Customer is responsible for the lawfulness, fairness and accuracy of its instructions; its notices and lawful bases; user permissions; and avoiding unnecessary personal or sensitive information. BlackReach will immediately inform Customer if an instruction appears to infringe applicable data-protection law.
4. Confidentiality and security
BlackReach limits access to authorised people who need it and are bound by confidentiality. BlackReach maintains risk-appropriate technical and organisational measures including workspace authorisation, encryption in transit, encrypted off-site backups, secret isolation, malware scanning, audit trails, network segmentation, vulnerability management, recovery controls and secure deletion. Current measures are described in the security schedule available to customers on request.
5. Subprocessors
Customer gives general written authorisation for the providers in the Subprocessor Register. BlackReach will place equivalent data-protection obligations on subprocessors, remains responsible for their processor obligations, and will give reasonable advance notice of a material new provider. Customer may make a reasonable written objection on data-protection grounds; the parties will work in good faith on a mitigation or alternative.
6. International transfers
BlackReach will not make a restricted transfer of Customer personal information without a lawful transfer route. Where adequacy regulations do not apply, BlackReach will use an approved mechanism such as the UK International Data Transfer Agreement or UK Addendum, perform the required transfer assessment, and apply supplementary measures where appropriate.
7. Individual rights
Taking account of the processing, BlackReach will provide reasonable technical and organisational assistance for access, correction, erasure, restriction, objection and portability requests. If BlackReach receives a request concerning Customer-controlled information, it will notify Customer and will not respond substantively except on Customer’s instruction or where law requires.
8. Incidents and breach notification
BlackReach will notify Customer without undue delay after becoming aware of a personal-data breach affecting Customer personal information. The notice will include available information about its nature, affected information and people, likely consequences, containment and mitigation, and a contact point. BlackReach will provide updates as the investigation develops and will not notify a regulator or affected person on Customer’s behalf without instruction unless legally required.
9. Compliance assistance
Taking account of the nature of processing and information available, BlackReach will reasonably assist Customer with security obligations, breach assessment and notification, DPIAs and regulator consultation. BlackReach maintains processing, retention, security and incident records required of a processor.
10. Information, audits and inspections
BlackReach will make information reasonably necessary to demonstrate Article 28 compliance available to Customer. Normally this is satisfied through current security documentation, independent reports where available and written responses. If those are insufficient following a material concern, Customer may conduct one proportionate audit per year on reasonable notice, subject to confidentiality, security and non-disruption controls. Customer bears its audit costs unless the audit identifies a material BlackReach breach.
11. Return and deletion
On verified written instruction or termination, BlackReach will return an available export and delete Customer workspace personal information within 30 days, at Customer’s choice, unless UK law requires retention. Data in BlackReach’s managed rolling encrypted backup set is put beyond ordinary use and expires within seven days. A hosting-provider infrastructure backup, if present, expires within the provider DPA’s maximum 14-day period. BlackReach may retain restricted billing, security, privacy-request and legal-claims records for their documented periods. Independently controlled public procurement intelligence is not Customer workspace content.
12. Contact and changes
Contact privacy@blackreach.co for instructions, rights assistance, security information or a signed copy. Changes that materially reduce Customer protection will not apply during a current subscription without notice and a lawful basis.