Legal
Privacy Policy
This policy explains how BlackReach expects to process personal data in the website and product. It is specific to the current BlackReach architecture and should be reviewed before live customer use.
Last updated: 31 May 2026
1. Controller details
BlackReach is the controller for personal data processed through the website, onboarding and customer account administration, except where we process workspace content on behalf of a customer under a data processing arrangement. Replace this section with the registered legal entity, address, company number and data protection contact before production.
Contact: privacy@blackreach.co
2. What personal data we process
We may process account details, name, email address, authentication identifiers, workspace membership, role, billing email, organisation details, team invitations, company profile inputs, qualification preferences, notes, watchlists, report metadata, support messages and technical logs.
We may also process information extracted from public procurement sources, including buyer names, supplier names, award information, notices, contact-like public records where present, and source metadata.
3. Why we process personal data
- To create accounts, authenticate users and operate secure workspaces.
- To provide procurement intelligence, qualification scoring, watchlists, reports and relationship mapping.
- To send transactional emails such as invitations, product notifications and billing-related messages.
- To process subscriptions, invoices and receipts through Stripe.
- To secure, debug, maintain and improve the service.
- To comply with legal, accounting, tax and security obligations.
4. Lawful bases
Depending on the processing activity, we expect to rely on contract performance, legitimate interests, legal obligation and, where required, consent. For example, we process account and workspace data to provide the service, billing data to administer subscriptions, logs for security and reliability, and non-essential cookies only with consent where required.
5. Public procurement data and AI-assisted processing
BlackReach processes customer-provided workspace information and may process public procurement information from public-sector portals, notices, awards, source documents and related public records.
BlackReach may use automated parsing, enrichment, entity matching, scoring and summarisation to produce procurement intelligence. These outputs support customer judgement and should not be treated as solely automated decisions with legal effect about individuals.
6. Processors and sharing
BlackReach currently expects to use Clerk for authentication, Stripe for billing and payment processing, and Resend for transactional product email. Hosting, database and monitoring providers should be listed before production deployment.
We may share data with service providers that help us operate BlackReach, including authentication, hosting, database, payment, email, monitoring and support providers. We do not sell customer workspace data to advertisers.
7. International transfers
Some providers may process data outside the UK. Where required, BlackReach should use appropriate safeguards such as adequacy regulations, standard contractual clauses, UK IDTA/addendum mechanisms or equivalent transfer arrangements. Final provider locations should be confirmed before production.
8. Retention
We keep account and workspace data while the account is active. Billing records may be retained for tax and accounting reasons. Security logs are retained for a limited period appropriate to security and operational needs. Public procurement intelligence may be retained as part of historical market records unless deletion is legally required.
9. Your rights
Depending on the circumstances, individuals may have rights to access, correct, delete, restrict, object to processing, request portability and complain to the UK Information Commissioner’s Office. Requests can be sent to privacy@blackreach.co.