Legal

Privacy Policy

How Bundle Technologies Ltd collects, uses, and protects your personal data.

Version: 2.0
Effective: April 2026
Controller: Bundle Technologies Ltd
Framework: UK GDPR · Data Protection Act 2018
Plain English summary. We collect only what we need to run the platform. We never sell your data. Analytics only load with your consent. You can request deletion at any time: privacy@bundleiq.co.uk
Contents

1. Who we are

Bundle Technologies Ltd is the data controller for personal data collected through bundleiq.co.uk and the Bundle IQ platform, registered in England and Wales.

Data protection contact: privacy@bundleiq.co.uk

2. What we collect

2.1 Information you provide

DataWhenWhy
Name, email, passwordAccount registrationTo create and secure your account
Organisation, address, company numberOnboardingBusiness verification and contract issuance
Procurement requirementsRFQ submissionRunning the procurement process
Bid responses and pricingVendor responseScoring and shortlisting
Payment informationEscrow fundingProcessed by Stripe — we do not store card data
Identity and compliance documentsVendor verificationInsurance and certification verification
Platform messagesContract communicationsBuyer-supplier communications and audit trail
Contact form submissionsContact pageResponding to enquiries

2.2 Automatically collected

2.3 From third parties

3. How we use your data

PurposeData usedLegal basis
Running the platformAccount data, requirements, responses, messagesContract
Processing escrow paymentsPayment confirmation, milestone dataContract
Vendor verificationIdentity docs, insurance certificatesLegitimate interests
IQ scoring and benchmarkingAnonymised bid and pricing dataLegitimate interests
Platform securityLog data, IP addressesLegitimate interests
Transactional emailsEmail, nameContract
AnalyticsAnonymised usage dataConsent
Legal complianceContract and transaction recordsLegal obligation
Dispute resolutionMessages, evidence, contractsLegitimate interests

We do not use your data for advertising, third-party profiling, or any purpose not listed above.

4. Legal bases for processing

5. Cookies

Essential cookies — always active

CookieProviderPurposeExpiry
sb-access-tokenSupabaseKeeps you authenticatedSession
sb-refresh-tokenSupabaseRefreshes authentication7 days
biq_consentBundle IQStores your cookie preference12 months

Analytics cookies — consent required

CookieProviderPurposeExpiry
AnalyticsPlausible / Google AnalyticsAnonymous page view trackingUp to 2 years

Withdraw analytics consent at any time via the cookie banner or by emailing us. For more on managing cookies: ico.org.uk.

6. Who we share your data with

RecipientWhatWhy
Invited vendorsAnonymised requirement only — not your identity until awardCompetitive tendering
Awarding buyersOrganisation name, contact, compliance docsContract execution
SupabaseAll platform dataInfrastructure — EU DPA in place
StripePayment transaction dataEscrow processing — PCI DSS compliant
ResendEmail, name, notification contentTransactional email delivery
AuthoritiesAs legally requiredLegal compliance, fraud investigation

We never sell your personal data. We never share it with advertisers.

7. Retention periods

Data typePeriodReason
Account dataAccount lifetime + 2 yearsPlatform operation
Contract and transaction records7 years from contract endCompanies Act 2006
Procurement requirements and responses3 yearsDispute resolution
Messages3 years from last messageEvidence and audit trail
Payment records7 yearsFinancial obligations
Analytics (anonymised)26 monthsPlatform improvement
Deleted accounts30 days then purgedRecovery window

8. Your rights under UK GDPR

To exercise any right, email privacy@bundleiq.co.uk. We respond within 30 days, free of charge.

📋 Access
Request a copy of all personal data we hold about you (Subject Access Request).
✏️ Rectification
Ask us to correct inaccurate or incomplete data.
🗑️ Erasure
Request deletion where we have no compelling reason to continue. Some data is retained for legal reasons — we will explain.
⏸️ Restriction
Ask us to pause processing while a complaint is resolved or accuracy verified.
📦 Portability
Receive your data in machine-readable format where processing is based on consent or contract.
🚫 Object
Object to legitimate interests processing. We stop unless we can demonstrate compelling grounds.
🤖 Automated decisions
IQ scoring is automated but not solely determinative — you make the final award decision. Request human review of any score.
↩️ Withdraw consent
Withdraw analytics consent at any time via the cookie banner. Does not affect prior processing.

9. International transfers

Primary infrastructure (Supabase) stores data in the EU-West region. Any transfers outside the UK or EEA use Standard Contractual Clauses approved by the ICO. Stripe operates under EU-US Data Privacy Framework. Contact us for details of specific transfer safeguards.

10. Security

Data breaches likely to affect your rights will be reported to the ICO within 72 hours and to affected users without undue delay. Full details: Security page.

11. Children

Bundle IQ is for business use only. We do not knowingly collect data from anyone under 18. If you believe we have, email privacy@bundleiq.co.uk and we will delete it immediately.

12. Changes

We notify registered users of material changes by email at least 14 days before they take effect. The version number and effective date at the top always reflect the current policy. Previous versions available on request.

13. Contact and complaints

Email: privacy@bundleiq.co.uk — we aim to respond within 5 business days.

If not satisfied, you can complain to the Information Commissioner's Office (ICO): ico.org.uk · 0303 123 1113 · Wycliffe House, Water Lane, Wilmslow, SK9 5AF.

Bundle Technologies Ltd · Privacy Policy v2.0 · April 2026 · privacy@bundleiq.co.uk