Back to BlackReach

Legal

Privacy Notice

How BlackReach Limited collects, uses, shares and protects personal information in BlackReach Intelligence.

Last updated: 8 August 2026

1. Who we are and when this notice applies

BlackReach Limited (company 17240929), registered at 71–75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ, is the controller for website enquiries, account administration, billing, security, public procurement intelligence and our own service operations. Contact our privacy lead at privacy@blackreach.co.

A customer normally controls personal information that its users add to a private workspace. For that content, BlackReach acts as processor under our Data Processing Addendum. The customer remains responsible for its instructions and its own privacy information.

2. What we process, why and on what basis

ActivityPersonal informationPurposeLawful basis
Accounts and accessName, business email, authentication identifier, membership and roleProvide and secure the serviceContract; legitimate interests in security and account administration
Customer workspacesCompany profiles, pursuits, notes, uploaded documents, evidence, tasks and reportsDeliver customer-requested procurement workflowsProcessor activity under the customer’s instructions; contract for BlackReach’s own service administration
Procurement intelligenceOfficial notices, contacts published in notices, buyers, suppliers, awards, Companies House officers and PSC evidenceProvide sourced market intelligence, identity resolution, provenance and historic analysisLegitimate interests in providing accurate business-to-business procurement intelligence
AI-assisted featuresRelevant company evidence, procurement text, prompts and generated outputStructure evidence, assist research and drafting, and create embeddingsContract or processor instructions; legitimate interests for service quality and safety
BillingBilling contact, plan, invoices and subscription identifiersAdminister subscriptions and meet accounting obligationsContract; legal obligation
NotificationsBusiness email, selected alert types and delivery metadataSend invitations, requested alerts, security and service messagesContract; legitimate interests; user choice for optional alerts
Anonymous usage statisticsDaily workspace-level counts of broad product areas used; a rotating pseudonymous input retained for no more than 48 hoursProduce aggregate service statistics and improve BlackReach without keeping individual journeysLegitimate interests and the PECR statistical-purpose exception; simple objection in Settings
Shared-work auditAccount, action type, affected record and timestamp for selected workspace changesProtect customer records, attribute changes and support collaborationContract; legitimate interests in service integrity, support and security
Security and operationsIP address, user agent, audit events, timestamps and limited technical logsPrevent misuse, investigate incidents and maintain resilienceLegitimate interests; legal obligation where applicable

Where we rely on legitimate interests, we assess the purpose, necessity and effect on individuals. Those interests do not override your rights, including your right to object.

3. Sources of personal information

  • You, your employer and workspace administrators.
  • Clerk for authenticated account identity and Stripe for billing status.
  • Official procurement publications including Find a Tender, Contracts Finder, Public Contracts Scotland, Sell2Wales and eTendersNI.
  • Companies House and other official public registers.
  • Customer-authorised websites, documents and secure tender-portal activity.

Publicly available information remains personal information where it identifies a person. BlackReach limits its use to professional procurement and corporate-register context, preserves its source and provides correction, objection and erasure routes. We do not build consumer profiles or sell personal information for advertising.

Where UK GDPR requires us to inform a person whose information we obtained indirectly, we do so within the applicable period or at first contact/disclosure. If individual notice would be impossible or involve disproportionate effort for a large official public dataset, we document that assessment, keep this notice prominent, minimise personal fields, preserve source and date, and maintain an effective rights route. We do not treat public availability as a blanket exemption.

4. AI-assisted processing and profiling

BlackReach uses automated parsing, matching, embeddings, scoring and summarisation. Opportunity scores concern fit between a customer company and a procurement, not a person’s eligibility for employment, credit or public services. Outputs support human commercial decisions and do not produce legal or similarly significant effects about individuals.

We minimise content sent to AI providers, use business/API arrangements, and require users to review generated material. Provider details are published in our Subprocessor Register.

5. Who receives personal information

Authorised members of your workspace can access its shared content according to their role. A limited number of authorised BlackReach personnel may access information when required for support, security or legal obligations. Service providers process information only for defined operational purposes under contractual controls.

We may disclose information where required by law, to protect rights or security, or as part of a corporate transaction with appropriate confidentiality safeguards. We do not sell workspace content or personal information to advertisers.

6. International transfers

Providers may process information in the UK, EEA or other countries. For a restricted transfer, we use an applicable adequacy regulation or contractual safeguard such as the UK International Data Transfer Agreement or UK Addendum, together with the required transfer assessment and supplementary measures. Current locations and mechanisms are listed on the Subprocessor Register.

7. Retention

  • Account and active workspace records: for the customer relationship, then normally deleted or returned within 30 days of a verified termination instruction, subject to legal exceptions.
  • BlackReach-managed encrypted database backups: rolling seven-day window. A hosting-provider infrastructure backup, if present, is put beyond ordinary use and expires within the provider DPA’s maximum 14-day period.
  • Secure portal ended-session records: 30 days; encrypted browser profiles are deleted when the connection or workspace is removed.
  • Pursuit documents: the workspace-selected period, normally one year, then file content and extracted text are purged.
  • Short-lived pseudonymous inputs used to calculate daily participant totals: no more than 48 hours.
  • Anonymous workspace usage totals: up to two years; low-participant results are suppressed in reports.
  • Necessary shared-work audit records: normally one year, unless a security, legal or dispute hold applies.
  • Read or archived notifications and invitation records: 12 months; old unread notifications: no more than 24 months.
  • Privacy request, preference and incident accountability records: six years unless a legal hold applies.
  • Official procurement and corporate-register evidence: while necessary for sourced historical intelligence, subject to periodic necessity, accuracy and objection review.

Legal, tax, fraud-prevention or dispute records may be kept longer where necessary and access remains restricted.

8. Your rights

Depending on the circumstances, you may request access, correction, erasure, restriction or portability, or object to processing. You can object to anonymous usage statistics at any time under Settings → Privacy and data; the choice takes effect for new statistics immediately. Authenticated users can also download an account portability bundle and lodge a formal privacy request there.

You may also email privacy@blackreach.co. We normally respond within one calendar month after receiving the request or any information reasonably required to verify identity. Rights are not absolute; if an exemption applies, we will explain the decision and available complaint route.

9. Complaints, children and changes

You can complain to the UK Information Commissioner’s Office at ico.org.uk. We would appreciate the opportunity to address your concern first.

BlackReach is a business service and is not intended for children. We update this notice when processing materially changes and will bring significant changes to account users’ attention.