Legal
Privacy policy
What we collect, why we are allowed to, who else touches it, how long we keep it, and what you can make us do about it. Short version: we hold what we need to run your account, we do not track you, and we do not sell anything to anyone.
Last updated 7 October 2026
1. Who is responsible for your data
Aerolytica Ltd is the data controller for the personal data described in this policy — meaning we decide why and how it is processed, and we are accountable for it under the UK GDPR and the Data Protection Act 2018.
- Operator
- Aerolytica Ltd, trading as Uncrewed Tenders
- Registered in
- England and Wales, company number 16738291
- VAT number
- GB518335883
- Registered office
- Suite A, 82 James Carter Road, Mildenhall, Bury St Edmunds, IP28 7DE, United Kingdom
- Correspondence address
- 3 High Meadow, West Broyle, Chichester, West Sussex, PO19 3FU, United Kingdom
- ICO registration
- ZC064093
- Contact
- privacy@aerolytica.com
This policy covers the uncrewedtenders.com website and the Uncrewed Tenders platform behind it.
2. What we collect about you
When you sign up
Your name, work email address, the organisation you say you work for, the country you select, anything you write in the free-text box, and the time you signed up. Your company name is also used to name your workspace.
The form also carries two simple anti-bot checks — a hidden field that should stay empty, and how long you had the page open before the form was sent. The hidden field is tested at the moment you submit and never stored. The timing check reads a cookie holding the time of your first visit to this page, described in section 9; nothing about either check is written to our records.
When you have an account
- Your email address, which is how you sign in. We do not use passwords at all, so we hold none.
- If you sign in through your organisation’s Microsoft or Google account, where those options are offered, we receive your work email address and the display name held by that account, and nothing else — no access to your mailbox, files or anything else in your organisation’s systems. If you sign in that way before you have a workspace, those two details are used only to fill in the sign-up form for you, and nothing is stored unless you complete it.
- Your display name, which you can change at any time on your account page.
- Which workspace you belong to and your role in it — owner, member or viewer.
- Your notification preferences: whether you want a digest, how often, the score threshold you care about, and whether you want deadline reminders.
- Records of what we have sent you, so that a reminder is not sent twice.
- If your organisation subscribes, which plan it is on and the identifiers Stripe assigns it — never card or bank details, which stay with Stripe.
What your team records in the platform
Statuses, notes, saved searches and similar work product. This is your organisation’s commercial information rather than personal data about you, but it is attributable to the people who wrote it, so it is covered here too. It is visible to the other members of your workspace and, by design, to nobody outside it.
If you connect an integration
The credentials you provide for a connected system, stored so that they cannot be read back out by the website — including by the person who set them — together with a record of who connected it, when, and enough of the identifier to recognise which one it is.
Technical information
Our hosting and database providers keep ordinary server logs — IP address, request, time, user agent — for security and diagnostics. We keep a session cookie so you stay signed in.
We do not profile you, and we do not sell or share anything about you. There is no advertising pixel, no tag manager, no third-party embed and no profile of you built anywhere on this site. We do count page views and measure how quickly pages loaded, in the two limited ways set out in section 9 — one of them only on our public pages and only if you agree to it, the other without cookies of any kind. Neither is ever told who you are.
3. Personal data inside procurement notices
Published procurement notices frequently name a contact at the contracting authority and give a work email or telephone number. That is personal data about someone who never dealt with us, so we should be straight about it.
- Where it comes from: official procurement publishers and portals, who published it themselves as part of a public procurement process.
- Why we hold it: our legitimate interests, and those of our customers, in operating an index of published public procurement that reproduces a notice as its publisher issued it. It is professional contact information published deliberately so that suppliers can respond.
- What we do with it: store it as part of the notice and show it to customers. We do not build marketing lists from it, sell it, or enrich it against other sources.
- If you are that person: the rights in section 8 apply to you, including the right to object. Write to us and we will deal with it — though where the notice is still published at source, that publisher is the one who can remove it there.
4. Why we process it, and what allows us to
- Creating the account you signed up for
- Steps taken at your request before entering a contract — making your workspace and your login. We also keep a record of who signed up and when, on the basis of our legitimate interests in running the service and being able to show how an account came to exist.
- Creating and running your account, and providing the service
- Performance of a contract with you or your organisation, or steps taken at your request before entering one.
- Sending sign-in links and service messages
- Performance of a contract — without them you cannot use the service.
- Digests and deadline reminders
- Consent, in the sense that they are off until you turn them on, and can be turned off again at any time on your notification settings page.
- Keeping the service secure, and preventing abuse
- Legitimate interests in protecting the service and our customers’ data.
- Indexing published procurement notices, including contact details in them
- Legitimate interests — see section 3.
- Meeting our legal and accounting obligations
- Legal obligation.
Where we rely on legitimate interests we have considered whether those interests are overridden by your rights, and we will explain that assessment if you ask.
5. Who else processes it
We use a small number of suppliers to run the service. Each acts on our instructions under a contract, and none of them is permitted to use your data for their own purposes.
- Database and authentication hosting
- Stores your account, workspace and notice data, and issues sign-in links.
- Website hosting
- Serves the site and keeps ordinary request logs.
- Transactional email
- Delivers sign-in links, reminders and service messages. It receives your email address and the content of what is sent to you.
- Payment processing (Stripe)
- If your organisation subscribes, checkout and card handling happen on Stripe’s own pages. Stripe receives your organisation’s billing details and payment method; card numbers never touch Uncrewed Tenders. Named rather than described because you meet them directly at checkout.
- AI classification provider (United States)
- Reads the text of published procurement notices to assess relevance. It receives no account data, no workspace data — no notes, statuses or saved searches — and no record of what anyone has looked at. Where a published notice contains a contact name, that name forms part of the notice text it reads.
- Web analytics (Google) — only with your consent
- Google Analytics measures how our public pages are used, and runs only for visitors who agreed to it — see section 9. Named rather than described, like Stripe, because you meet their cookies directly and consent has to be informed. It never receives anything about signed-in use of the service.
- Analytics and performance monitoring (Vercel) — no cookies, no consent needed
- Our website host provides two privacy-focused measurement tools, which we use across the service. One counts page views, so we can see which parts are used. The other records how quickly pages actually loaded and responded in your browser, so we can find and fix the slow ones. Both set no cookies and store nothing on your device, which is why neither is part of the consent question in section 9. Between them they record the page address, timing measurements, and general technical details such as your country, browser and whether you arrived from another site — never your name, your email address, or anything from your workspace. Neither runs on our operator pages.
- A CRM or other system you connect yourself
- Receives only what you instruct us to send, and only for the workspace that connected it. Once data is there it is governed by your relationship with that provider, and it remains there if you stop using Uncrewed Tenders.
We will name our current suppliers to any customer or prospective customer who asks — write to privacy@aerolytica.com. We may also disclose data where the law requires it, and to professional advisers or a purchaser in connection with a sale of the business.
We do not sell personal data, and we do not share it for advertising.
6. Where it goes
Data is stored in the United Kingdom or the European Economic Area wherever we can arrange it. Some of our suppliers are based in, or process data in, other countries — the United States in particular. Where personal data leaves the UK, we rely on UK adequacy regulations where they apply, and otherwise on the International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, with additional safeguards where they are needed. Ask us and we will tell you which applies to a particular supplier.
7. How long we keep it
- Sign-ups that were declined or never taken up
- Up to 12 months, so we can recognise a repeat sign-up and show how an account came to exist, then deleted.
- Account and workspace data
- For as long as the account is open, and up to 12 months after it closes. Ask and we will delete it sooner where no legal or accounting obligation requires us to keep it.
- Notes, statuses and saved searches
- Until you or your workspace delete them, or the account closes.
- Connected-system credentials
- Until the connection is removed, then deleted.
- The original published payload of an ingested notice
- 90 days, then automatically released. The notice itself — what we show you — is retained as part of the index.
- Server logs
- For the short retention periods our hosting providers apply.
8. Your rights
Under UK data protection law you can ask us to:
- Give you a copy of the personal data we hold about you, and tell you how we use it;
- Correct it if it is wrong or incomplete;
- Delete it, where we have no continuing reason to hold it;
- Restrict how we use it, while a question about it is resolved;
- Object to our use of it where we rely on legitimate interests — see section 4 — including any use for direct marketing, which we will always stop;
- Receive it in a portable form, where we hold it on the basis of consent or a contract; and
- Withdraw consent at any time, where we rely on it. That does not affect anything done beforehand.
Write to privacy@aerolytica.com. We will respond within one month, and it is free unless a request is manifestly unfounded or excessive. We may need to confirm who you are first.
If you are unhappy with how we have handled your data, please tell us so we can put it right. You also have the right to complain to the Information Commissioner’s Office — ico.org.uk, helpline 0303 123 1113 — at any time.
9. Cookies
Cookies of two kinds, and the difference is consent — plus one way of counting pages that uses no cookies at all, and so asks nothing of you.
Strictly necessary. Cookies that keep you signed in and let your session refresh as you move between pages; without them you would be signed out constantly. They carry no advertising or tracking function, and the law does not require consent for them. Two others are in this category. The first remembers your answer to the analytics question below — without it we would have to ask on every page. The second records the time you first opened our home or sign-in page, and exists only so that the sign-up form can tell a person filling it in from a script posting to it instantly; it holds a timestamp and nothing else, it cannot be read by any script in your browser, it is never sent anywhere or joined to anything, and it is discarded after a day.
Analytics, only if you agree. On our public pages — and only there — we ask whether we may use Google Analytics to see which pages get read. Nothing is set until you answer. If you agree, Google sets cookies (their names begin _ga) and receives technical details of your visit; that data goes to Google, including in the United States, under the transfer safeguards described in section 6. If you decline, we remember only the refusal. Either answer is kept for six months and then we ask again; clearing your cookies asks again sooner.
Nothing about your use of the service is ever sent to Google. The Google tag runs on our public pages only, and only for visitors who agreed to it; once you sign in it is not loaded at all, whatever you answered.
Measuring pages without cookies. Separately, and across the site — including inside the product — we count page views and measure how quickly pages loaded and responded, using our website host’s tools described in section 5. We do not ask your permission for these, and the reason is that they store nothing on your device and read nothing back from it: there are no cookies to agree to. They tell us that a page was viewed, how fast it was, from roughly where and in what kind of browser. They are not told who you are, and they receive nothing from your workspace. Our lawful basis is our legitimate interest in keeping the service fast and in knowing which parts of it are used; you can object at any time using the contact details in section 1. Neither runs on the pages our own staff use to administer the service.
10. Automated decisions
We score procurement notices automatically, not people. Nothing in the service makes a decision about an individual by automated means that produces a legal effect for them or similarly significantly affects them. Access requests are decided by a person, not by a machine.
11. How we protect it
Separation between customers is enforced in the database itself rather than only in application code, so one workspace cannot read another’s data even if the website asks it to. We use sign-in links, or your organisation’s own Microsoft or Google sign-in, instead of passwords — so there is no password of yours for us to lose. Credentials for systems you connect are stored so that the website cannot read them back. Access to production data is limited to those who need it, and the keys capable of bypassing customer separation never leave our servers and are never sent to a browser.
No system is perfectly secure. If a breach affects your personal data and is likely to present a risk to you, we will tell you and the ICO as the law requires.
12. Children
The service is for business use and is not directed at, or intended for, anyone under 18. We do not knowingly collect their data.
13. Changes to this policy
We will update this policy as the service changes. The date at the top moves whenever it does, and we will tell account holders about anything material rather than relying on you to notice.
14. Contact
Anything about personal data: privacy@aerolytica.com. Our terms of use cover everything else.