Privacy Policy
Last updated: 9 September 2026.
This Privacy Policy explains how Rabtech Ltd ("we", "us", "our") collects, uses, stores and protects personal data when you use contractscanner.co.uk and the Contract Scanner service (the "Service").
We are committed to protecting your personal data and processing it fairly, lawfully and transparently in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, together with other applicable data protection and privacy legislation.
1. Who we are
The data controller responsible for personal data collected through contractscanner.co.uk and the Contract Scanner Service is:
Legal entity: Rabtech Ltd
Company number: 11703677
Privacy contact: [email protected]
For the purposes of UK data protection legislation, we are the data controller of the personal data described in this Privacy Policy.
If you have questions about how we process your personal data, or wish to exercise any of your data protection rights, you can contact us using the details above.
2. What personal data we collect
The personal data we collect depends on how you interact with the Service.
2.1 Account and identity information
When you create or use a Contract Scanner account, we may collect:
- name;
- username;
- email address;
- mobile telephone number, where provided;
- password credentials;
- account status;
- notification preferences;
- subscription and account preferences; and
- information necessary to administer your account.
Passwords are not stored in plain text. Passwords are processed using appropriate cryptographic hashing mechanisms designed to prevent the original password from being recovered from the stored value.
2.2 Service configuration and usage information
To provide the Contract Scanner Service, we may process information such as:
- keyword rules and search criteria you configure;
- CPV codes selected by you;
- contract categories or other search preferences;
- procurement notices matched against your configured criteria;
- notices you view, save, dismiss or otherwise interact with;
- notification preferences;
- notification history; and
- other information required to operate and improve your configured Service.
Some of this information may relate to your business activities rather than being personal data. Where information identifies or can reasonably be associated with an identifiable individual, we will treat it as personal data where required by applicable law.
2.3 Login, session and security information
We collect technical and security information necessary to protect accounts and the Service, which may include:
- IP address;
- browser and user-agent information;
- login timestamps;
- session identifiers or tokens;
- authentication events;
- account security events;
- failed login attempts; and
- information relating to suspicious or potentially abusive activity.
We use this information for purposes including authentication, account security, fraud and abuse prevention, investigation of security incidents, and enforcement of account security controls such as session restrictions.
2.4 Information submitted through enquiry or registration forms
If you submit a registration, enquiry, contact or access-request form before becoming a customer, we may collect information such as:
- name;
- email address;
- company name;
- telephone number, where provided;
- the Service or plan you are interested in; and
- information contained in your enquiry.
We use this information to respond to your enquiry, provide requested information and, where appropriate, assist with setting up an account.
2.5 Subscription and billing information
Where you purchase a paid subscription, we process information necessary to administer your subscription and billing relationship.
Payment processing is handled by Stripe, a third-party payment processor. Depending on your payment method, the information we process may include:
- subscription type;
- billing status;
- transaction or payment identifiers;
- invoices and billing records;
- payment dates and amounts;
- renewal and cancellation information; and
- limited billing information supplied by Stripe (such as subscription and transaction status) for account administration purposes.
Payment card details are not stored on our own application servers. Card and payment details are collected and processed directly by Stripe, in accordance with Stripe's own privacy policy and its PCI-DSS compliance obligations as a payment processor.
2.6 Communications
If you contact us, we may retain the content of your communications and information associated with those communications for the purposes of responding to you, providing support, maintaining appropriate business records and resolving disputes.
2.7 Cookies and similar technologies
We may use cookies and similar technologies to operate the Service, maintain sessions, remember preferences, protect accounts and understand how the Service is used.
Essential cookies may be used where they are necessary to provide functionality you have requested or to operate the Service.
Where required by law, we will obtain your consent before using non-essential cookies or similar technologies.
Further information is provided in our Cookie Policy.
3. How and why we use your personal data
We only process personal data where we have a lawful basis to do so.
The purposes and lawful bases for processing may include the following.
3.1 Providing the Service - Contract
We process personal data where necessary to perform our contract with you, including to:
- create and manage your account;
- authenticate you;
- provide access to Contract Scanner;
- apply your keyword and CPV search criteria;
- identify relevant procurement opportunities;
- send notifications and alerts;
- administer your subscription;
- process cancellations;
- provide customer support; and
- manage our contractual relationship with you.
3.2 Service security - Legitimate interests
We may process technical, account and security information where necessary for our legitimate interests in:
- protecting Contract Scanner against unauthorised access;
- detecting and preventing fraud, abuse and misuse;
- investigating suspicious activity;
- protecting our infrastructure and systems;
- maintaining service integrity;
- enforcing reasonable account-security controls; and
- preventing attacks or other security incidents.
Where we rely on legitimate interests, we consider and balance those interests against your rights and interests.
3.3 Legal and regulatory compliance - Legal obligation
We may process personal data where necessary to comply with legal or regulatory obligations, including requirements relating to:
- taxation and accounting;
- financial and transaction records;
- lawful requests from competent authorities;
- prevention or detection of unlawful activity; and
- other applicable legal obligations.
3.4 Communications and service administration - Contract or legitimate interests
We may use your contact information to send service-related communications, including:
- account verification messages;
- password-reset messages;
- security notifications;
- service alerts;
- subscription and billing communications;
- important changes to the Service; and
- other communications necessary to administer your account.
These communications are not treated as marketing communications.
3.5 Marketing - Consent or legitimate interests where permitted
Where permitted by applicable law, we may send information about Contract Scanner, new features, services or relevant offers.
Where consent is required, we will ask for your consent before sending such communications.
You can withdraw marketing consent at any time by using the unsubscribe mechanism included in the communication or by contacting us.
Withdrawing consent does not affect the lawfulness of processing carried out before consent was withdrawn.
3.6 Improving the Service - Legitimate interests
We may use appropriate service and usage information to monitor performance, identify problems, improve functionality, develop new features and maintain the reliability and security of Contract Scanner.
Where possible, we will use aggregated, anonymised or otherwise minimised information for analytical purposes.
4. Automated matching and decision-making
Contract Scanner uses automated rules and matching mechanisms to identify procurement notices that may be relevant to the search criteria configured by a customer.
For example, the Service may automatically compare procurement notices against keywords, CPV codes or other criteria configured within an account.
These automated processes are used to provide the Service and generate alerts.
The Service does not make decisions about individuals that produce legal effects or similarly significant effects on individuals based solely on automated processing.
Where this position changes, we will review and update this Privacy Policy and implement any safeguards required by applicable data protection legislation.
5. Who we share personal data with
We do not sell your personal data.
We may share personal data with trusted third-party service providers where this is necessary to operate Contract Scanner, provide the Service, process payments, communicate with customers, maintain security or comply with legal obligations.
These organisations generally act as data processors on our behalf and are required to process personal data in accordance with our instructions and applicable data protection requirements.
Our service providers may include:
Email delivery provider
We use Resend to deliver account, service and notification emails. The information shared with the email provider may include your email address, name and information necessary to generate and deliver the relevant message.
Telegram
If you voluntarily choose to connect a Telegram account to Contract Scanner, we may share the information necessary to deliver notifications through Telegram. Telegram is only used for this purpose where you have enabled or requested Telegram notifications.
Payment provider
We use Stripe to process subscription payments. Stripe acts as an independent data controller for the payment information it collects directly from you (such as card details), and also processes certain data as our processor for billing administration. See Stripe's privacy policy for how Stripe handles this information.
Professional advisers and legal authorities
We may disclose personal data where reasonably necessary to:
- professional advisers;
- auditors;
- insurers;
- law enforcement agencies;
- regulators;
- courts or tribunals; or
- other competent authorities,
where we are legally required or permitted to do so, or where necessary to establish, exercise or defend legal rights.
6. International transfers
Some of our service providers or infrastructure may process personal data outside the United Kingdom.
Where personal data is transferred outside the UK, we will ensure that an appropriate lawful transfer mechanism and appropriate safeguards are in place as required by applicable data protection legislation.
Depending on the circumstances, this may include:
- an adequacy regulation or decision;
- the UK International Data Transfer Agreement (IDTA);
- the UK Addendum to EU Standard Contractual Clauses; or
- another legally recognised transfer mechanism.
Further information about relevant international transfers can be requested by contacting us using the details in Section 1.
7. How long we retain personal data
We retain personal data only for as long as reasonably necessary for the purposes for which it was collected, including to satisfy legal, accounting, regulatory and contractual requirements.
Our retention periods will depend on the type of information and the purpose for which it is processed.
Unless a longer period is required by law or reasonably necessary for the establishment, exercise or defence of legal claims:
- Active account information is retained while your account remains active.
- Account information following cancellation is retained for 12 months for legitimate business, security, legal and record-keeping purposes.
- Billing and financial records are retained for 6 years, in line with UK statutory accounting and tax record-keeping requirements.
- Security and audit logs are retained for 12 months, subject to legitimate security and legal requirements.
- Marketing/enquiry information where no customer relationship is established is retained for 12 months unless it is no longer required or you request deletion where applicable.
- Support communications are retained for 24 months where necessary for support, dispute resolution, legal or record-keeping purposes.
At the end of the applicable retention period, information will be securely deleted, anonymised or otherwise rendered inaccessible, subject to technical and legal limitations.
8. Your data protection rights
Subject to applicable legal conditions and exemptions, you may have the following rights under UK data protection legislation:
- Right of access - to request a copy of the personal data we hold about you.
- Right to rectification - to ask us to correct inaccurate or incomplete personal data.
- Right to erasure - to ask us to delete personal data in certain circumstances.
- Right to restriction - to ask us to restrict processing in certain circumstances.
- Right to data portability - to receive certain personal data in a structured, commonly used and machine-readable format and, where technically feasible, request that it is transferred to another organisation.
- Right to object - to object to certain processing, including processing based on legitimate interests and, where applicable, direct marketing.
- Right to withdraw consent - where we rely on your consent as the lawful basis for processing.
- Rights relating to automated decision-making - where applicable under UK data protection legislation.
These rights are not absolute and certain legal conditions or exemptions may apply.
You can manage certain information directly through your account settings: My Account → Account Settings.
For requests that cannot be completed through your account, contact [email protected].
We may need to verify your identity before completing certain requests in order to protect personal data from unauthorised disclosure.
9. How to make a Data Subject Access Request
You may request access to the personal data we hold about you by contacting [email protected].
Please provide sufficient information to allow us to identify your account and understand the nature of your request.
We will normally respond to valid requests within the period required by applicable data protection legislation.
10. Complaints
If you have concerns about how we process your personal data, we encourage you to contact us first so that we have an opportunity to investigate and address your concerns.
You also have the right to complain to the UK's data protection supervisory authority:
Information Commissioner's Office (ICO)
ico.org.uk
The ICO provides information about data protection rights and how to make a complaint.
11. Data security
We take appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or unauthorised access.
Our security measures include, where appropriate:
- password hashing rather than storing passwords in plain text;
- server-side session management;
- the ability to revoke sessions;
- secure authentication mechanisms;
- optional two-factor authentication using TOTP;
- access controls;
- encryption in transit;
- appropriate protection of credentials and secrets;
- system monitoring and logging;
- vulnerability and security management;
- backup and recovery controls; and
- procedures for responding to security incidents and personal data breaches.
Access to personal data is restricted to those who require access for legitimate business or service-delivery purposes.
No internet-based service can be guaranteed to be completely secure. We nevertheless continuously review and improve our technical and organisational security measures.
12. Personal data breaches
If we become aware of a personal data breach, we will assess and manage it in accordance with applicable data protection legislation.
Where required by UK GDPR, we will notify the ICO without undue delay and, where feasible, within 72 hours of becoming aware of a reportable personal data breach.
Where a breach is likely to result in a high risk to the rights and freedoms of affected individuals, we will also consider whether affected individuals must be notified.
13. Children's privacy
Contract Scanner is intended for business and professional use and is not directed at children.
We do not knowingly seek to collect personal data from children where doing so would be inappropriate or unlawful.
If you believe that a child has provided personal data to us, please contact us so that we can investigate and take appropriate action.
14. Third-party websites and services
Contract Scanner may contain links to third-party websites, services or applications.
We are not responsible for the privacy practices, security or content of third-party services.
You should review the privacy policy of any third-party service before providing personal data to it.
15. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes to:
- the Contract Scanner Service;
- the personal data we process;
- our processing purposes;
- our service providers;
- applicable laws or regulatory requirements; or
- our privacy and security practices.
When we make material changes, we will update the "Last updated" date at the beginning of this policy and, where appropriate, provide additional notice.
Your continued use of the Service after an updated Privacy Policy takes effect will be subject to the updated policy, to the extent permitted by applicable law.
16. Contact us
If you have questions about this Privacy Policy, your personal data, or how Contract Scanner processes personal information, please contact:
Rabtech Ltd
Privacy contact: [email protected]
Company number: 11703677