Privacy

Privacy Policy

What we collect, why we collect it, who else sees it, how long we keep it, and what you can ask us to do about it.

Last updated: 30 July 2026 · Version 1.0

1. Who is responsible for your data

Procurement Force ("we", "us", "our") is the data controller for personal data processed through procurementforce.uk and its associated tools.

2. What we collect

We only hold what the product actually uses. Everything below is something the site genuinely stores — nothing here is speculative.

CategoryWhat it includesHow we get it
Account Email address, and a unique account identifier. You, when you sign in.
Identity Name and profile photo, and the fact that your identity is LinkedIn-verified. LinkedIn, if you choose to sign in with it (OpenID Connect).
Professional profile Job title, employer, team size, procurement categories you manage, industry, annual spend band, years of experience, and the procurement tools you use. You, on the profile page. All optional.
Salary Your current salary, if you choose to enter it. You. Optional, never shown publicly, and used only to place you against market benchmark ranges for your role.
Usage and results Simulation transcripts, scores, debriefs, diagnostic answers and results (PFI, PAI), session counts and dates. Generated as you use the product.
Membership and billing Plan, session allowance, purchased top-ups, purchase records and payment references. Generated on purchase. We never see or store your card details — those go directly to Stripe.
Communications Waitlist and early-access registrations, and emails we send you. You, when you register or purchase.

3. Why we collect it, and our lawful basis

PurposeLawful basis
Providing your account, running simulations, storing your results and administering your membership. Contract — we cannot provide the service without it.
Taking payment and keeping purchase records. Contract, and legal obligation for tax and accounting records.
Matching you to salary benchmarks and peer cohorts. Consent — these fields are optional and only used if you fill them in. You can clear them at any time.
Improving the simulations and diagnostics using anonymised session data. Legitimate interests — improving a product you use, balanced against your privacy by anonymising first. You can object (see section 8).
Verifying that members are real practitioners, which is what makes peer benchmarking meaningful. Legitimate interests in the integrity of the benchmark data.
Security, fraud prevention, and preventing abuse of paid features. Legitimate interests.

We do not sell your personal data, and we do not share individual-level data with other users. Where benchmark or community figures are shown, they are aggregated and only published once enough submissions exist in a category that no individual can be identified from them.

4. Simulations, diagnostics and AI processing

The negotiation simulations are powered by a third-party AI model provider. When you use them, the content you enter — including any supplier situation you paste in — is sent to that provider to generate the response, the score and the debrief. Your content is not used to train their models.

Please do not paste anything into a simulation that you are not free to share. Do not enter supplier pricing subject to a confidentiality agreement, personal data about third parties, or anything covered by an NDA. The product is designed so it never needs that information, and the Peer Benchmark rules in our Terms say the same.

We retain transcripts and debriefs against your account so you can see your progress over time. We may also use them, anonymised, to improve the simulations. If you would rather we did not, contact us and we will exclude your sessions.

5. Who else processes your data

We use a small number of carefully selected providers to run the service. Each is bound by a data processing agreement, processes data only on our instructions, and receives only what it needs to do its job.

Category of recipientWhat they receive
Cloud hosting and database Your account, profile, results, and server logs including IP address
AI model provider The content you enter into a simulation, and the answers you give when booking a call
Email delivery Your email address and the content of emails we send you
Customer relationship management Your name, email address, company name, and what you told us you need help with
Scheduling Your name and email address, to pre-fill the booking form, plus anything you add when choosing a time
Payment processing — Stripe Your email and payment details. We never see or store your card details. Stripe is a controller in its own right for payment data — see stripe.com/privacy
Identity verification — LinkedIn Only what you approve at sign-in: name, email, profile photo

We do not publish the individual suppliers behind each category, for security reasons. If you need that detail — for a supplier assessment, a DPIA, or your own compliance records — email connect@procurementforce.uk and we will provide it.

A note on the discovery call. When you book one, we ask an AI model to research your company from publicly available sources and prepare notes for the call. It sees the answers you gave us and your company name, and it searches the open web — the same information anyone could look up. No decision is made about you automatically, and nothing it produces is shared outside our team. If you would rather we did not do this, say so when you book, or email us and we will delete the notes.

We do not sell your personal data. We will also disclose data where we are legally required to, or to establish or defend legal claims.

6. Where your data goes

Email delivery is processed in the EU (Ireland). Some of our providers — including the AI model provider and payment processor — process data in the United States. Where personal data leaves the UK, it is protected by the safeguards those providers offer, such as the UK Addendum to the EU Standard Contractual Clauses, or the UK Extension to the EU–US Data Privacy Framework.

7. How long we keep it

DataRetention
Account and profileWhile your account is open, then deleted within 30 days of you asking us to close it.
Simulation transcripts, scores and debriefsWhile your account is open, so you can track progress. Deleted with your account.
Anonymised session data used for improvementRetained after account deletion, because it is no longer personal data and cannot be linked back to you.
Purchase and payment recordsSix years, as required for UK tax and accounting.
Waitlist and marketing registrationsUntil you unsubscribe or ask us to remove you.
Server logsAs retained by our hosting provider, typically a short rolling window.

8. Your rights

Under UK GDPR you have the right to:

  • Access the personal data we hold about you.
  • Correct anything inaccurate — most of your profile you can edit yourself at any time.
  • Delete your data, and have your account closed.
  • Restrict or object to processing based on legitimate interests, including our use of anonymised session data.
  • Portability — receive the data you gave us in a machine-readable format.
  • Withdraw consent at any time for anything based on consent, such as your salary figure. Withdrawing consent does not affect processing already carried out.

To exercise any of these, email connect@procurementforce.uk. We will respond within one month. There is no charge.

9. Cookies and local storage

We do not use advertising or tracking cookies, and we do not run third-party analytics.

When you sign in, your browser stores an authentication token in local storage. That is strictly necessary to keep you signed in — without it you would be signed out on every page. Signing out removes it.

Our hosting and payment providers may set their own strictly necessary cookies when you use a checkout page.

10. Security

Access to the database is controlled by row level security, so one member cannot read another's data. Card details never touch our systems. Sign-in uses LinkedIn or a single-use email link, so there is no password for anyone to steal. Traffic is encrypted in transit.

No system is perfectly secure. If we become aware of a breach affecting your rights, we will notify the ICO within 72 hours where required, and tell you if the risk to you is high.

11. Children

This is a product for working procurement professionals. It is not intended for anyone under 18, and we do not knowingly collect data from children. If you believe a child has given us personal data, contact us and we will delete it.

12. Changes to this policy

We may update this policy as the product changes. The version and date at the top will always tell you which version you are reading. If a change materially affects how we use your data, we will tell you by email before it takes effect.

13. Contact and complaints

For anything in this policy, email connect@procurementforce.uk.

If you are unhappy with how we have handled your data, you can complain to the Information Commissioner's Office at ico.org.uk/make-a-complaint, or call 0303 123 1113. We would rather you came to us first so we can put it right.