Legal
Privacy Notice
How BlackReach Limited collects, uses, shares and protects personal information in BlackReach Intelligence.
Last updated: 8 August 2026
1. Who we are and when this notice applies
BlackReach Limited (company 17240929), registered at 71–75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ, is the controller for website enquiries, account administration, billing, security, public procurement intelligence and our own service operations. Contact our privacy lead at privacy@blackreach.co.
A customer normally controls personal information that its users add to a private workspace. For that content, BlackReach acts as processor under our Data Processing Addendum. The customer remains responsible for its instructions and its own privacy information.
2. What we process, why and on what basis
| Activity | Personal information | Purpose | Lawful basis |
|---|---|---|---|
| Accounts and access | Name, business email, authentication identifier, membership and role | Provide and secure the service | Contract; legitimate interests in security and account administration |
| Customer workspaces | Company profiles, pursuits, notes, uploaded documents, evidence, tasks and reports | Deliver customer-requested procurement workflows | Processor activity under the customer’s instructions; contract for BlackReach’s own service administration |
| Procurement intelligence | Official notices, contacts published in notices, buyers, suppliers, awards, Companies House officers and PSC evidence | Provide sourced market intelligence, identity resolution, provenance and historic analysis | Legitimate interests in providing accurate business-to-business procurement intelligence |
| AI-assisted features | Relevant company evidence, procurement text, prompts and generated output | Structure evidence, assist research and drafting, and create embeddings | Contract or processor instructions; legitimate interests for service quality and safety |
| Billing | Billing contact, plan, invoices and subscription identifiers | Administer subscriptions and meet accounting obligations | Contract; legal obligation |
| Notifications | Business email, selected alert types and delivery metadata | Send invitations, requested alerts, security and service messages | Contract; legitimate interests; user choice for optional alerts |
| Anonymous usage statistics | Daily workspace-level counts of broad product areas used; a rotating pseudonymous input retained for no more than 48 hours | Produce aggregate service statistics and improve BlackReach without keeping individual journeys | Legitimate interests and the PECR statistical-purpose exception; simple objection in Settings |
| Shared-work audit | Account, action type, affected record and timestamp for selected workspace changes | Protect customer records, attribute changes and support collaboration | Contract; legitimate interests in service integrity, support and security |
| Security and operations | IP address, user agent, audit events, timestamps and limited technical logs | Prevent misuse, investigate incidents and maintain resilience | Legitimate interests; legal obligation where applicable |
Where we rely on legitimate interests, we assess the purpose, necessity and effect on individuals. Those interests do not override your rights, including your right to object.
3. Sources of personal information
- You, your employer and workspace administrators.
- Clerk for authenticated account identity and Stripe for billing status.
- Official procurement publications including Find a Tender, Contracts Finder, Public Contracts Scotland, Sell2Wales and eTendersNI.
- Companies House and other official public registers.
- Customer-authorised websites, documents and secure tender-portal activity.
Publicly available information remains personal information where it identifies a person. BlackReach limits its use to professional procurement and corporate-register context, preserves its source and provides correction, objection and erasure routes. We do not build consumer profiles or sell personal information for advertising.
Where UK GDPR requires us to inform a person whose information we obtained indirectly, we do so within the applicable period or at first contact/disclosure. If individual notice would be impossible or involve disproportionate effort for a large official public dataset, we document that assessment, keep this notice prominent, minimise personal fields, preserve source and date, and maintain an effective rights route. We do not treat public availability as a blanket exemption.
4. AI-assisted processing and profiling
BlackReach uses automated parsing, matching, embeddings, scoring and summarisation. Opportunity scores concern fit between a customer company and a procurement, not a person’s eligibility for employment, credit or public services. Outputs support human commercial decisions and do not produce legal or similarly significant effects about individuals.
We minimise content sent to AI providers, use business/API arrangements, and require users to review generated material. Provider details are published in our Subprocessor Register.
5. Who receives personal information
Authorised members of your workspace can access its shared content according to their role. A limited number of authorised BlackReach personnel may access information when required for support, security or legal obligations. Service providers process information only for defined operational purposes under contractual controls.
We may disclose information where required by law, to protect rights or security, or as part of a corporate transaction with appropriate confidentiality safeguards. We do not sell workspace content or personal information to advertisers.
6. International transfers
Providers may process information in the UK, EEA or other countries. For a restricted transfer, we use an applicable adequacy regulation or contractual safeguard such as the UK International Data Transfer Agreement or UK Addendum, together with the required transfer assessment and supplementary measures. Current locations and mechanisms are listed on the Subprocessor Register.
7. Retention
- Account and active workspace records: for the customer relationship, then normally deleted or returned within 30 days of a verified termination instruction, subject to legal exceptions.
- BlackReach-managed encrypted database backups: rolling seven-day window. A hosting-provider infrastructure backup, if present, is put beyond ordinary use and expires within the provider DPA’s maximum 14-day period.
- Secure portal ended-session records: 30 days; encrypted browser profiles are deleted when the connection or workspace is removed.
- Pursuit documents: the workspace-selected period, normally one year, then file content and extracted text are purged.
- Short-lived pseudonymous inputs used to calculate daily participant totals: no more than 48 hours.
- Anonymous workspace usage totals: up to two years; low-participant results are suppressed in reports.
- Necessary shared-work audit records: normally one year, unless a security, legal or dispute hold applies.
- Read or archived notifications and invitation records: 12 months; old unread notifications: no more than 24 months.
- Privacy request, preference and incident accountability records: six years unless a legal hold applies.
- Official procurement and corporate-register evidence: while necessary for sourced historical intelligence, subject to periodic necessity, accuracy and objection review.
Legal, tax, fraud-prevention or dispute records may be kept longer where necessary and access remains restricted.
8. Your rights
Depending on the circumstances, you may request access, correction, erasure, restriction or portability, or object to processing. You can object to anonymous usage statistics at any time under Settings → Privacy and data; the choice takes effect for new statistics immediately. Authenticated users can also download an account portability bundle and lodge a formal privacy request there.
You may also email privacy@blackreach.co. We normally respond within one calendar month after receiving the request or any information reasonably required to verify identity. Rights are not absolute; if an exemption applies, we will explain the decision and available complaint route.
9. Complaints, children and changes
You can complain to the UK Information Commissioner’s Office at ico.org.uk. We would appreciate the opportunity to address your concern first.
BlackReach is a business service and is not intended for children. We update this notice when processing materially changes and will bring significant changes to account users’ attention.