eSourcing DATA

Supplier Platform Privacy Notice

How personal information is handled in the supplier platform. This notice is not marketing consent or a waiver of your rights.

1. Who we are and the scope of this notice

eSourcing Data Ltd, registered in England and Wales under company number 16391108, has its registered office at 63 Mill Lane, London, NW6 1NB. Contact info@esourcingdata.com for privacy questions, rights requests or complaints, or write to that address marked Privacy.

This notice covers the eSourcing DATA supplier platform, including accounts, supplier participation and related support. Our marketing websites and optional separate products may have their own notices. This notice describes processing, not consent to every use of personal information or acceptance of a commercial liability waiver.

We are controller for our own account administration, platform security, support and legal-record purposes. For procurement information processed on a client's or buyer's instructions, the relevant organisation determines the purposes and our work is governed by the applicable processing arrangements. GBS Procure may administer a procurement for the named buyer. The buyer's privacy information explains its procurement uses; ask us if you need help identifying the responsible organisation. Actual responsibilities depend on the activity and are not changed by these supplier terms or this notice.

2. Information we collect and where it comes from

Information may include your name, business email, organisation, company number and business contact/address details; account role, password hash, verification and security records; supplier profile and eligibility information; bids, attachments and information about personnel in them; expressions of interest, clarifications, messages, support requests, and technical and audit records of access and actions.

We receive information from you, authorised colleagues, inviting buyers and their representatives, your use of the service, and public or authorised verification sources such as Companies House and Central Digital Platform data sharing where used. Information about a company may also identify an individual, including a sole trader.

Supply only relevant information you are entitled to disclose and provide appropriate privacy information to colleagues and others whose details you submit. Do not include unnecessary sensitive information in bids or shared questions. Where a buyer requires special-category or criminal-offence information, appropriate legal conditions and secure collection arrangements must apply; ordinary registration does not authorise unrestricted collection.

3. Purposes and lawful bases

For our controller activities, we use legitimate interests to administer authorised business accounts, maintain supplier contacts and send necessary account, procurement-service and security communications. Those interests are operating a reliable procurement service and enabling legitimate business participation. Where an individual is personally a contracting party, such as a sole trader, contract necessity may apply to the processing needed to provide their contracted access.

We use legitimate interests to protect the Platform and users, prevent and investigate misuse, troubleshoot problems, respond to support requests, maintain necessary acceptance and operational evidence, and establish or defend legal rights. A legal obligation applies where a specific law requires processing, including applicable rights requests and data-protection complaint handling.

Any optional marketing or non-essential tracking requires its own identified lawful basis and consent where required by UK GDPR or PECR. Accepting supplier terms is not marketing or tracking consent. If consent is relied on, it can be withdrawn without affecting earlier lawful processing.

We balance legitimate interests against individuals' rights. You may object to processing based on legitimate interests on grounds relating to your situation. You have an absolute right to object to direct marketing. Email info@esourcingdata.com to object.

For buyer-controlled procurement processing, the responsible buyer/client identifies the appropriate purposes and lawful bases. We follow its documented instructions and applicable law rather than assuming every individual has a contract with us.

4. Sharing and visibility

Relevant buyers, GBS Procure or other authorised procurement administrators, evaluators and advisers can access information needed for their functions. Supplier business/contact details may be used in the buyer-facing supplier directory and invitation workflow. Other suppliers are not entitled to private bid content merely because they hold an account.

New shared clarification questions may immediately be visible to other suppliers entitled to view an opportunity; answers may be circulated. Do not put your identity, personal details or confidential bid information into a shared question. Buyer redaction can change the shared view while the original remains in the audit record; it cannot recall copies already received.

We use Render for application hosting and PostgreSQL, Cloudflare R2 for files and backups, and Resend for email, under data-processing arrangements. These services may receive content needed for their function, not just contact details: for example procurement correspondence and attachments sent by email.

We may share information with professional advisers, competent authorities or courts where necessary and lawful, and where applicable procurement transparency or information-access obligations require disclosure. Such sharing is not always based on consent. We do not sell your personal information.

5. International processing

Our platform uses European hosting, but providers operate internationally and processing, support access or email delivery can involve the UK, the EEA and other countries. We do not promise that all information remains in the UK or EEA.

Where a restricted international transfer is made, the applicable UK transfer requirements must be met. Depending on the destination and arrangement, the relevant protection is an applicable adequacy decision or appropriate contractual safeguards, such as the UK International Data Transfer Agreement or UK Addendum to approved standard contractual clauses, with further measures where necessary. Contact info@esourcingdata.com for information about the arrangement relevant to your data and how to obtain a copy of applicable safeguards.

6. AI and separate products

External AI-assisted evaluation is not enabled on this platform at the issue date of this notice. Supplier bid responses are not sent to Anthropic through that disabled evaluation feature. Procurement decisions remain the responsibility of the buyer.

Any proposed activation involving personal information requires a review of the processing arrangements and appropriate privacy information before use. The availability of code for a feature is not consent to activate it.

Optional products you separately choose, including BidWriter, have their own terms and privacy information. They are not required to participate through this supplier portal.

7. Retention

Our standard procurement-record retention period is seven years after the procurement is closed or cancelled where no contract is awarded, or seven years after the resulting contract ends where one is awarded. Where we act as processor, the responsible client's documented retention instructions and applicable legal requirements govern. A justified legal hold, unresolved dispute, audit or other binding requirement may require longer retention; information should not be kept longer than necessary.

We keep account information while the account is active. Following closure, we retain only what is needed for outstanding procurement obligations, security investigations, acceptance evidence, legal requirements or claims, reviewing the continuing need against those purposes. Ordinary support/enquiry records are normally retained for up to three years after the last substantive contact, unless they form part of a procurement, complaint or legal record that requires longer retention.

Closing an account does not itself withdraw a bid or delete a buyer's procurement record. Deletion or anonymisation is managed through the applicable retention and review process, not an immediate deletion of every record on request. Residual backup copies may persist for their applicable backup lifecycle, are restricted from ordinary use, and remain subject to appropriate protection and retention controls. Contact us for the criteria applicable to a particular record.

8. Security, cookies and device storage

We use access controls and security measures intended to protect personal information. No internet service can promise absolute security. Use a unique password, keep access links private and report suspected compromise promptly. Do not send passwords or unnecessary confidential records in a support request.

The application uses the essential esd_token authentication cookie, normally lasting seven days, and local storage including esd_user to cache the displayed user profile and interface state. The server session remains authoritative. Clearing or blocking essential storage can affect sign-in and usability. Local storage can remain until removed by the application or cleared from your device; use trusted devices and sign out.

These essential account functions are distinct from optional analytics or advertising. Any introduction of non-essential tracking requires appropriate information and consent where required. Cookie information for a separate marketing website should not be treated as a list of the supplier portal's cookies.

9. Your rights and complaints

Depending on the processing and applicable law, you may request access, correction, erasure, restriction or portability, and object to processing. If consent is used, you may withdraw it. Rights are not absolute: lawful retention duties, legal claims or another person's rights may affect the response. We may seek proportionate identity verification and will respond within the applicable statutory period, explaining any relevant limitation.

Send requests or privacy complaints to info@esourcingdata.com or our registered office. You do not need an account to contact us. Where another organisation is responsible, we will help identify it and handle or refer the matter appropriately.

For privacy complaints for which we are responsible, we will acknowledge receipt within 30 days, investigate appropriately, keep you informed where necessary and communicate the outcome without undue delay.

You may also complain to the Information Commissioner's Office at https://ico.org.uk/make-a-complaint/. This notice does not prevent statutory complaints or court remedies, and the supplier terms do not exclude personal-data rights or liabilities which cannot lawfully be excluded.

10. Required information and changes

We need required registration information to establish and secure your account; without it we may be unable to provide access. The buyer specifies the information necessary for its procurement and the consequences of not supplying it. Optional fields should be identified as such.

We will review this notice and communicate material changes as appropriate. Updating privacy information does not itself obtain consent where required or retrospectively change an accepted supplier contract.