Legal
Privacy policy
Tender Gazette is a news publication. We hold very little personal data, and we have built the site that way deliberately. There is no reader account, no paywall, no login and no advertising network. If you never subscribe to the newsletter and never write to us, the only personal data we are likely to hold about you is an analytics identifier, and only if you agreed to it.
This policy explains what we do collect, why, what we do with it and what you can require us to do about it. It covers www.tendergazette.com and the email we send you.
Contents
- Who we are and how to contact us
- The people this policy covers
- What we collect, why, and on what legal basis
- Where your data comes from
- Cookies and analytics
- Who we share your data with
- Sending data outside the United Kingdom
- How long we keep it
- How we protect it
- Your rights
- People we write about
- Complaints
- Changes to this policy
- Other sites we link to
1. Who we are and how to contact us
www.tendergazette.com is operated by Tender Gazette, an unincorporated body, of 9-10 Cross Street, Preston, England, PR1 3LT. In this policy, "Tender Gazette", "we", "us" and "our" mean that body. Tender Gazette is the controller of the personal data described in this policy.
For anything to do with your personal data, including exercising any of the rights in section 10, write to:
- Email: privacy@tendergazette.com
- Post: Privacy, Tender Gazette, 9-10 Cross Street, Preston, England, PR1 3LT
We have not appointed a data protection officer, because we are not required to. Privacy questions go to the address above and are handled by the editor.
Tender Gazette is not intended for children, and we do not knowingly collect personal data about anyone under 18. If you believe a child has given us their details, tell us and we will delete them.
2. The people this policy covers
- Readers. Anyone who visits the site.
- Subscribers. Anyone who signs up to the weekly briefing.
- Correspondents. Anyone who writes to us: tip-offs, corrections, questions, security reports, sponsorship enquiries.
- Sponsors and commercial contacts. People at organisations that sponsor or ask about sponsoring the publication.
- People we write about. Section 11 deals with this separately, because the rules are different for journalism.
3. What we collect, why, and on what legal basis
The law requires us to have a legal basis for every use of your personal data. The bases we rely on are consent, legitimate interests (our own or a third party's, weighed against your rights), performance of a contract, and legal obligation.
Readers
| What we collect | Why | Legal basis |
|---|---|---|
| An analytics identifier held in a cookie, together with the pages you viewed, the approximate location derived from your IP address, and your device and browser type | To understand which coverage readers find useful, so we can produce more of it | Consent. Collected only if you press Accept on the cookie banner. You can withdraw consent at any time, as described in our cookie policy |
| Your reader persona, if you choose one | To order the homepage sections to suit you | Legitimate interests, being the interest in presenting the publication in a way that is useful to you. It records a choice you made and identifies nobody |
| Server and security logs, including IP address, kept by our hosting and content delivery providers | To keep the site available, to diagnose faults, and to defend against attacks | Legitimate interests, being the interest in running a secure and functioning website |
We do not use your reading behaviour to build a profile of you, and we take no automated decisions about you that produce legal or similarly significant effects.
Subscribers to the weekly briefing
| What we collect | Why | Legal basis |
|---|---|---|
| Your email address | To send you the weekly briefing you asked for | Consent, given when you complete the signup form and confirm your address by clicking the link in the confirmation email |
| A record of your consent: the date and time, the page you signed up from, and the campaign or referral information in the link you arrived by | To prove that we had your permission to email you, as the direct marketing rules require | Legal obligation and legitimate interests, being the interest in evidencing compliance with regulation 22 of the Privacy and Electronic Communications (EC Directive) Regulations 2003 |
| Whether you opened an email or clicked a link in it, and delivery failures | To tell whether the briefing is working, to stop sending to addresses that no longer exist, and to protect our sending reputation | Legitimate interests, being the interest in producing an email people actually read and in maintaining deliverability. You can ask us to stop measuring this |
Every email carries a one-click unsubscribe link. Unsubscribing is immediate and free. We never sell, rent or share your email address, and we do not send you anyone else's marketing.
We do not feed subscriber data into any AI system. The models we use to draft coverage have no access to subscriber records.
Correspondents
| What we collect | Why | Legal basis |
|---|---|---|
| Your name, email address and whatever you put in your message, including any attachments | To read your message and reply to it, and to keep a record of what was said | Legitimate interests, being the interest in answering correspondence, correcting the record, and keeping an audit trail of corrections and security reports |
If you send us a correction request, we keep a record of it, because our corrections policy commits us to fixing errors visibly rather than silently.
Sponsors and commercial contacts
| What we collect | Why | Legal basis |
|---|---|---|
| Name, work email, employer, job title and the substance of the discussion | To respond to sponsorship enquiries and to negotiate, agree and administer sponsorship | Legitimate interests before any agreement, and performance of a contract once there is one |
| Records needed for our accounts | To keep proper financial records | Legal obligation |
4. Where your data comes from
Almost everything we hold, you gave us: you typed your email into the signup form, or you sent us a message. The exceptions are:
- analytics data, which is collected automatically by Google Analytics when you consent;
- technical and security data, collected automatically by our hosting providers;
- information about people we write about, which comes from official published sources. See section 11.
5. Cookies and analytics
What we store on your device, and how to control it, is set out in full in our cookie policy. In summary: nothing is stored until you accept analytics or choose a reader persona, and if you press Reject, no analytics cookie is set.
6. Who we share your data with
We do not sell your personal data, and we do not share it with anyone for their own marketing.
We use the following suppliers, who process personal data on our instructions and under a contract that requires them to keep it secure and use it only for us:
| Supplier | What they do for us | What they handle |
|---|---|---|
| Vercel | Hosts and serves the website | Technical and log data |
| Cloudflare | Domain name service, network security, file storage and inbound email routing | Technical and log data, and email you send to us |
| Railway | Runs our editorial pipeline and our database | Subscriber records and consent records |
| Mailchimp (Intuit) | Sends the weekly briefing | Your email address, consent record, and open and click data |
| Postmark (ActiveCampaign) | Sends confirmation and service emails, and our internal alerts | Your email address |
| Google Analytics | Analytics identifiers and usage data, only if you consent | |
| Google (Gmail) | Receives and stores the email you send to our published addresses | Your name, email address and message |
| Sentry | Error and performance monitoring | Technical data about faults |
We will also disclose personal data where we are legally required to do so, for example in response to a court order, or where we need to in order to establish, exercise or defend legal claims. If the publication is ever transferred to a different operator or entity, personal data will pass to it, and it will be bound by this policy until it tells you otherwise.
7. Sending data outside the United Kingdom
Several of the suppliers listed above are based in, or store data in, the United States. That means your personal data may be transferred outside the United Kingdom.
Where a supplier is certified under the UK Extension to the EU-US Data Privacy Framework, we rely on the adequacy regulations the UK has made for that framework. Where a supplier is not certified, we rely on the International Data Transfer Addendum to the European Commission's standard contractual clauses, or on the International Data Transfer Agreement, together with an assessment of the risks of the transfer.
You can ask us which mechanism applies to a particular supplier, and for a copy of the relevant safeguards, by writing to privacy@tendergazette.com.
8. How long we keep it
| Data | How long |
|---|---|
| Your email address and subscription record, while you are subscribed | Until you unsubscribe |
| Your email address after you unsubscribe | We keep it on a suppression list so that we never email you again. That is the only way to honour your unsubscribe reliably. You can ask us to erase it entirely instead, and we will |
| Consent records | 24 months after your subscription ends, so that we can answer any question about whether we had permission to email you |
| Google Analytics event data | 14 months, after which Google deletes it |
| Email correspondence | 24 months, unless it relates to a correction or a security report, which we keep for 6 years |
| Sponsorship and financial records | 6 years, as our accounting and tax obligations require |
| Server and security logs | No longer than 12 months |
9. How we protect it
Access to subscriber records is restricted to the editorial dashboard, which sits behind a separate identity check and is not reachable from the public site. Data is encrypted in transit. Our database roles are configured so that the automated parts of the publishing pipeline cannot read subscriber records at all. We publish a security contact at /.well-known/security.txt, and you can report a vulnerability to security@tendergazette.com.
We have a process for dealing with a personal data breach, and we will notify the Information Commissioner's Office, and you, where the law requires it.
10. Your rights
Under data protection law you have the right to:
- ask for a copy of the personal data we hold about you;
- ask us to correct anything that is wrong or incomplete;
- ask us to erase your personal data, where there is no good reason for us to keep it;
- object to us using your data where we rely on legitimate interests, and to object at any time, and absolutely, to direct marketing;
- ask us to restrict what we do with your data while a dispute about it is resolved;
- ask us to transfer your data to you or to someone else in a machine-readable format, where we rely on your consent or on a contract and the processing is automated;
- withdraw your consent at any time, where consent is the basis we rely on. This does not affect anything we did lawfully before you withdrew it.
To exercise any of these, email privacy@tendergazette.com. It is free. We will respond within one month, and we will tell you if we need longer because the request is complex. We may ask you to confirm your identity first, so that we do not disclose your data to somebody else.
Some of these rights are limited where we hold the data for journalism. See section 11.
11. People we write about
Tender Gazette reports on public procurement. Our coverage is built from official published sources, principally Find a Tender, Contracts Finder, Public Contracts Scotland, Sell2Wales, Tenders Electronic Daily and GOV.UK policy publications, used under the Open Government Licence v3.0 and always attributed.
Those notices are mostly about organisations rather than individuals, but they sometimes name people, such as a named contact for a procurement, and our journalism sometimes names people in public roles. Where that is personal data, we process it for journalism.
Our legal basis is legitimate interests: the public interest in reporting accurately on how public money is spent, and the interest of our readers in that information, which we consider outweighs the limited impact on individuals who are named in a document that a public authority has already published. Where a special category of data is involved, we rely on the substantial public interest condition for journalism.
The data protection law contains an exemption for processing for the special purposes, which include journalism. It applies where personal data is processed with a view to publication of journalistic material, where we reasonably believe publication is in the public interest, and where complying with the provision in question would be incompatible with journalism. Where that exemption applies, some of the rights in section 10 do not, or do not fully, apply to material we hold for publication.
That is not a licence to be careless, and we do not treat it as one. Our editorial standards require every figure to be checked against the official notice and every story to be approved by a named human editor before publication. If we have got something wrong about you, tell us at corrections@tendergazette.com and we will correct it visibly. If you object to being named, write to privacy@tendergazette.com and we will consider it properly.
12. Complaints
If you are unhappy with how we have handled your personal data, tell us first at privacy@tendergazette.com. We would rather fix it.
You also have the right to complain to the Information Commissioner's Office, the UK supervisory authority for data protection, at ico.org.uk, by telephone on 0303 123 1113, or by post to Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF. The Information Commissioner's Office will normally expect you to have raised the matter with us first.
13. Changes to this policy
We keep this policy under review. If we change what we collect or what we do with it, we will update this policy before the change takes effect, and we will change the version number and date at the top. If the change is significant and you are a subscriber, we will tell you by email.
Please keep us informed if your details change.
14. Other sites we link to
Our coverage links to official notices, to government publications and to reporting by other outlets. Those sites have their own privacy policies, and we are not responsible for them. When you leave Tender Gazette, you leave this policy behind with it.