Privacy Policy
What we do with personal data when you enquire, email us or browse this website — written to be read, not to be skimmed past.
1. Who we are
Tenderboss is a trading name of IT Simple Solutions Ltd, a company registered in England & Wales under company number 08934237. For the purposes of the UK GDPR and the Data Protection Act 2018, IT Simple Solutions Ltd is the controller of the personal data described in this policy.
IT Simple Solutions LtdStudio 9, 50-54 St Paul's Square
Birmingham
B3 1QS
United Kingdom
- Data protection enquiries: info@tenderboss.co.uk
- General enquiries: info@tenderboss.co.uk · 0345 216 0008
We have not appointed a statutory Data Protection Officer, as we are not required to. Data protection questions are handled by the company's directors at the address above.
2. Controller or processor — which one we are matters
This policy covers data we hold as a controller — enquiries, correspondence, supplier and client contacts, and website analytics.
It does not cover your clients' data.When we deliver IT support, hosting or software to a law firm and handle personal data inside that firm's systems — matter files, client records, documents — we act as a processoron the firm's instructions. That relationship is governed by a written data processing agreement under Article 28 UK GDPR, not by this policy. If you are a client firm and need a copy of our DPA, sub-processor list or security schedule, email info@tenderboss.co.uk.
3. What we collect
When you submit the demo or contact form
- Your name
- The name of your firm
- Your work email address
- Your phone number (optional)
- The service you are interested in
- Anything you choose to write in the message box
- Whether you opted in to occasional marketing email
Please don't put confidential client details, case facts or special category data in the message box — it's an enquiry form, not a secure channel, and we don't need that information to arrange a demo.
When you email or call us
Your contact details and the content of the correspondence. We do not record telephone calls. We may keep a short written note of a call.
When you browse this website
- Server logs. Our hosting provider records IP address, timestamp, requested URL, HTTP status, referrer and user-agent for every request. These are generated automatically and are needed to run and secure the site.
- Analytics — only if you accept. If you accept analytics in the cookie banner we load PostHog, which records pages viewed, approximate location (country/region derived from IP), device and browser type, and a session recording in which all form inputs are masked. Decline and none of it loads. Full detail is in our Cookie Policy.
- Anti-spam checks. When a form is submitted we check the request origin, apply a rate limit per IP address and run a hidden honeypot field, to stop automated abuse.
We do not use advertising or cross-site tracking cookies, we do not buy personal data from list brokers, and we do not carry out automated decision-making or profiling that has legal or similarly significant effects on you.
4. Why we use it, and our lawful basis
| Purpose | Data | Lawful basis (UK GDPR Art. 6) |
|---|---|---|
| Responding to your enquiry and arranging a demo or consultation | Enquiry form data, correspondence | Legitimate interests (Art. 6(1)(f)) — you asked us to get in touch, and answering a business enquiry is what we both expect |
| Preparing a quote, statement of work or contract | Enquiry data, correspondence | Steps prior to entering a contract (Art. 6(1)(b)) |
| Providing and supporting the services you buy | Client and user contact details | Performance of a contract (Art. 6(1)(b)) |
| Occasional marketing email about our services | Name, email, firm | Consent (Art. 6(1)(a)) — ticked by you, withdrawable at any time |
| Website analytics and improving the site | Analytics events, approximate location, device | Consent (Art. 6(1)(a)), given via the cookie banner |
| Keeping the site available, secure and free of spam | Server logs, IP address | Legitimate interests (Art. 6(1)(f)) — security and service integrity |
| Accounting, tax and statutory record-keeping | Client and supplier contact and billing records | Legal obligation (Art. 6(1)(c)) |
Where we rely on legitimate interests we have balanced those interests against your rights, and we have concluded that handling a business enquiry you initiated, and keeping our own website secure, does not override them. You can object at any time — see section 8.
5. How long we keep it
| Record | Retention |
|---|---|
| Enquiry that does not become a client | 24 months from the last contact, then deleted |
| Client records, contracts and correspondence | 7 years after the end of the engagement (limitation and tax periods) |
| Accounting records | 6 full financial years, per the Companies Act 2006 and HMRC requirements |
| Marketing consent and opt-out records | Kept for as long as needed to honour your choice |
| Website server logs | Up to 30 days |
| Analytics data (if accepted) | Up to 12 months, then deleted or aggregated |
6. Who else sees it
We do not sell personal data and we do not share it for anyone else's marketing. We use the service providers below, each under a written contract that limits them to acting on our instructions:
| Provider | What they do | Where |
|---|---|---|
| Vercel Inc. | Website and application hosting, request logs | London (lhr1) region; support access from the United States under the UK Addendum to the EU SCCs |
| PublishOS | Enquiry and CRM records — the platform where your demo request is stored and worked | United Kingdom / European Economic Area |
| PostHog (EU Cloud) | Website analytics — only if you accept analytics cookies | European Economic Area (Frankfurt, Germany) |
| Email hosting (mailboxes for @tenderboss.co.uk) | Receiving, storing and replying to your enquiry by email | United Kingdom |
| Brevo | Transactional email delivery — enquiry notifications and confirmations | European Union (France) |
We may also disclose personal data to our professional advisers (accountants, solicitors, insurers) where needed, and to a regulator, court or law enforcement body where we are legally required to. If the business is sold or restructured, records may transfer to the buyer, who would remain bound by this policy.
7. Transfers outside the UK
Enquiry data submitted through this website is processed in the United Kingdom and the European Economic Area. The EEA benefits from UK adequacy regulations, so no additional safeguard is needed for those transfers.
Our hosting provider, Vercel Inc., is a US company. Our site and its functions are configured to run in Vercel's London region, but Vercel personnel in the United States may access data for support and platform operations. That access is covered by Vercel's data processing agreement incorporating the EU Standard Contractual Clauses and the UK International Data Transfer Addendum, as approved under Article 46 UK GDPR. You can ask us for a copy of the transfer mechanism at info@tenderboss.co.uk.
8. Your rights
Under the UK GDPR you have the right to:
- be told how your data is used — this policy
- get a copy of the data we hold about you (a subject access request)
- have inaccurate data corrected
- have data erased, where we have no continuing reason to keep it
- restrict how we use it while a dispute is resolved
- receive it in a portable, machine-readable format, where the right applies
- object to processing based on legitimate interests, including any direct marketing
- withdraw consent at any time, without affecting anything done before you withdrew it
To exercise any of these, email info@tenderboss.co.uk. We will respond within one month. Exercising your rights is free, and we will not treat you any differently for doing so. We may ask you to confirm your identity first.
If you are unhappy with how we have handled your data, please tell us so we can put it right. You also have the right to complain to the Information Commissioner's Office at any time — ico.org.uk/make-a-complaint or 0303 123 1113.
9. Marketing email
We only send marketing email to people who have asked for it, or who have enquired about a similar service and have not opted out (the "soft opt-in" permitted by regulation 22 of the Privacy and Electronic Communications Regulations 2003). Every marketing email carries a one-click unsubscribe, and you can also opt out by replying or emailing us. Replies to your own enquiry are not marketing and will be sent regardless.
10. Security
The site is served over HTTPS with HSTS. Enquiry submissions are validated, rate-limited and restricted to requests from this site, and are transmitted over TLS to our CRM. Access to enquiry and client records is limited to the people who need it and protected by multi-factor authentication. No internet service can be guaranteed to be perfectly secure, and we do not claim otherwise — but if a breach affects your rights we will notify the ICO within 72 hours and tell you where the law requires it.
11. Cookies
Cookies and similar storage are covered separately in our Cookie Policy, which also explains how to change or withdraw your choice.
12. Children
This is a business-to-business website and is not directed at children. We do not knowingly collect data about anyone under 18.
13. Changes
If we change how we use personal data we will update this page and move the "last updated" date. Where a change materially affects you and we hold your contact details, we will tell you directly.