How Bundle Technologies Ltd collects, uses, and protects your personal data.
Bundle Technologies Ltd is the data controller for personal data collected through bundleiq.co.uk and the Bundle IQ platform, registered in England and Wales.
Data protection contact: privacy@bundleiq.co.uk
| Data | When | Why |
|---|---|---|
| Name, email, password | Account registration | To create and secure your account |
| Organisation, address, company number | Onboarding | Business verification and contract issuance |
| Procurement requirements | RFQ submission | Running the procurement process |
| Bid responses and pricing | Vendor response | Scoring and shortlisting |
| Payment information | Escrow funding | Processed by Stripe — we do not store card data |
| Identity and compliance documents | Vendor verification | Insurance and certification verification |
| Platform messages | Contract communications | Buyer-supplier communications and audit trail |
| Contact form submissions | Contact page | Responding to enquiries |
| Purpose | Data used | Legal basis |
|---|---|---|
| Running the platform | Account data, requirements, responses, messages | Contract |
| Processing escrow payments | Payment confirmation, milestone data | Contract |
| Vendor verification | Identity docs, insurance certificates | Legitimate interests |
| IQ scoring and benchmarking | Anonymised bid and pricing data | Legitimate interests |
| Platform security | Log data, IP addresses | Legitimate interests |
| Transactional emails | Email, name | Contract |
| Analytics | Anonymised usage data | Consent |
| Legal compliance | Contract and transaction records | Legal obligation |
| Dispute resolution | Messages, evidence, contracts | Legitimate interests |
We do not use your data for advertising, third-party profiling, or any purpose not listed above.
| Cookie | Provider | Purpose | Expiry |
|---|---|---|---|
| sb-access-token | Supabase | Keeps you authenticated | Session |
| sb-refresh-token | Supabase | Refreshes authentication | 7 days |
| biq_consent | Bundle IQ | Stores your cookie preference | 12 months |
| Cookie | Provider | Purpose | Expiry |
|---|---|---|---|
| Analytics | Plausible / Google Analytics | Anonymous page view tracking | Up to 2 years |
Withdraw analytics consent at any time via the cookie banner or by emailing us. For more on managing cookies: ico.org.uk.
| Recipient | What | Why |
|---|---|---|
| Invited vendors | Anonymised requirement only — not your identity until award | Competitive tendering |
| Awarding buyers | Organisation name, contact, compliance docs | Contract execution |
| Supabase | All platform data | Infrastructure — EU DPA in place |
| Stripe | Payment transaction data | Escrow processing — PCI DSS compliant |
| Resend | Email, name, notification content | Transactional email delivery |
| Authorities | As legally required | Legal compliance, fraud investigation |
We never sell your personal data. We never share it with advertisers.
| Data type | Period | Reason |
|---|---|---|
| Account data | Account lifetime + 2 years | Platform operation |
| Contract and transaction records | 7 years from contract end | Companies Act 2006 |
| Procurement requirements and responses | 3 years | Dispute resolution |
| Messages | 3 years from last message | Evidence and audit trail |
| Payment records | 7 years | Financial obligations |
| Analytics (anonymised) | 26 months | Platform improvement |
| Deleted accounts | 30 days then purged | Recovery window |
To exercise any right, email privacy@bundleiq.co.uk. We respond within 30 days, free of charge.
Primary infrastructure (Supabase) stores data in the EU-West region. Any transfers outside the UK or EEA use Standard Contractual Clauses approved by the ICO. Stripe operates under EU-US Data Privacy Framework. Contact us for details of specific transfer safeguards.
Data breaches likely to affect your rights will be reported to the ICO within 72 hours and to affected users without undue delay. Full details: Security page.
Bundle IQ is for business use only. We do not knowingly collect data from anyone under 18. If you believe we have, email privacy@bundleiq.co.uk and we will delete it immediately.
We notify registered users of material changes by email at least 14 days before they take effect. The version number and effective date at the top always reflect the current policy. Previous versions available on request.
Email: privacy@bundleiq.co.uk — we aim to respond within 5 business days.
If not satisfied, you can complain to the Information Commissioner's Office (ICO): ico.org.uk · 0303 123 1113 · Wycliffe House, Water Lane, Wilmslow, SK9 5AF.