Skip to main content

My Projectz

Book Your Consultation
Book Your Consultation

GDPR Policy

GDPR Policy for My Projectz

1. Introduction

My Projectz respects your privacy and is committed to protecting your personal information.

This Privacy and GDPR Policy explains how we collect, use, store, disclose and protect personal information when you:

  • visit or interact with our website;
  • create or use a Tender Portal account;
  • contact us, request a consultation or submit an enquiry;
  • purchase, enquire about or receive our services;
  • attend training, meetings, events or consultations;
  • apply for a role or work with us;
  • subscribe to marketing communications; or
  • otherwise interact with My Projectz.

This policy also explains your rights under UK data-protection law and how you can contact us about the use of your personal information.

2. Who We Are

For the purposes of applicable data-protection law, the organisation responsible for your personal information is:

Legal entity: My Projectz
Trading name: My Projectz
Registered office: Foundry, Wandsworth, 4 New Acres Lane, London, United Kingdom
Head office: Office 205, Foundry Wandsworth, 4 New Acres Lane, London, SW18 1HT
Company number: 14435435
ICO registration number: ZB515391
Email: info@myprojectz.co.uk
Telephone: +44 (0)20 3897 9191

Our Data Protection Lead can be contacted using the details above or at:

Data-protection email: info@myprojectz.co.uk

3. Our Role as Controller and Processor

My Projectz may act as either a data controller or a data processor, depending on the circumstances.

We normally act as a controller when we decide why and how personal information is used, including information relating to:

  • website visitors;
  • prospective and existing clients;
  • Tender Portal users;
  • suppliers and professional contacts;
  • job applicants;
  • trainees and course participants;
  • marketing subscribers; and
  • individuals who contact us directly.

We may act as a processor when we handle personal information solely on behalf of a client while delivering services such as:

  • medical transcription;
  • care coordination;
  • daily log auditing;
  • data entry and management;
  • billing and accounting support;
  • receptionist or administrative support;
  • recruitment administration;
  • HR and compliance support; and
  • other outsourced operational services.

Where we act as a processor, the relevant client is normally the controller. Our processing will be governed by a written contract or data-processing agreement, and requests concerning that information may need to be directed to the client.

4. Data-Protection Laws

We process personal information in accordance with applicable UK legislation, including:

  • the UK General Data Protection Regulation;
  • the Data Protection Act 2018;
  • the Privacy and Electronic Communications Regulations 2003;
  • the Data (Use and Access) Act 2025; and
  • other applicable privacy, confidentiality, employment and healthcare requirements.

5. Personal Information We Collect

Depending on how you interact with us, we may collect the following categories of personal information.

5.1 Identity and contact information

This may include:

  • name;
  • job title;
  • organisation name;
  • postal address;
  • email address;
  • telephone number;
  • username or account identifier; and
  • identity-verification information.

5.2 Client and service information

This may include:

  • enquiry and consultation details;
  • service requirements;
  • contracts, proposals and project records;
  • tender information and submission documents;
  • correspondence and meeting notes;
  • information about your organisation, workforce or operations;
  • training registrations and completion records; and
  • feedback, reviews and complaints.

5.3 Tender Portal information

Where you register for or use our Tender Portal, we may collect:

  • account-registration details;
  • login and authentication information;
  • subscription and payment status;
  • saved tenders and search preferences;
  • tender alerts and notification settings;
  • usage history; and
  • account-support communications.

5.4 Financial and transaction information

This may include:

  • billing address;
  • invoices and payment records;
  • bank or payment information;
  • transaction history;
  • subscription details; and
  • accounting and tax-related records.

Payment-card details may be processed directly by an authorised payment provider rather than stored by My Projectz.

5.5 Technical and website information

This may include:

  • IP address;
  • browser type and version;
  • device type;
  • operating system;
  • referral source;
  • pages viewed;
  • dates and times of access;
  • cookie identifiers;
  • website interactions; and
  • technical diagnostic information.

5.6 Recruitment and employment information

Where you apply for a vacancy or take part in recruitment, we may collect:

  • CV and employment history;
  • education and qualifications;
  • references;
  • interview notes;
  • right-to-work information;
  • professional registrations;
  • salary expectations;
  • background-screening information; and
  • other information relevant to your application.

5.7 Special-category and sensitive information

Because some of our services relate to healthcare, HR, recruitment and clinical administration, we may process more sensitive information where necessary, including:

  • health or medical information;
  • disability information;
  • racial or ethnic origin;
  • religious or philosophical beliefs;
  • trade-union membership;
  • biometric information used for identification;
  • sexual orientation;
  • safeguarding information; and
  • criminal-conviction or DBS information.

We will process this information only where an appropriate legal condition applies and where suitable safeguards are in place.

Please do not provide patient, employee or other sensitive information through a general website contact form unless we have specifically asked you to do so and have provided an approved secure method.

6. How We Collect Personal Information

We may obtain personal information:

  • directly from you;
  • from your organisation or employer;
  • through website forms, telephone calls, email or meetings;
  • when you create or use a Tender Portal account;
  • through contracts, questionnaires and project documentation;
  • through training and recruitment applications;
  • from payment and subscription providers;
  • from analytics, cookies and similar technologies;
  • from publicly available sources, including company websites, Companies House, professional registers and procurement portals;
  • from clients who appoint us to process information on their behalf;
  • from suppliers, recruitment partners and professional advisers; and
  • from social media or advertising platforms where permitted by law.

7. How and Why We Use Personal Information

We may use personal information to:

  • respond to enquiries and arrange consultations;
  • provide quotations, proposals and contracts;
  • deliver and manage our services;
  • create and administer Tender Portal accounts;
  • process subscriptions, payments and invoices;
  • provide tender alerts and saved-search functionality;
  • manage client relationships and customer support;
  • communicate about projects, deadlines and service delivery;
  • deliver training and maintain course records;
  • manage recruitment and employment processes;
  • maintain accurate business and financial records;
  • protect our systems, website, portal and users;
  • detect fraud, misuse or security incidents;
  • monitor service performance and improve our offerings;
  • manage complaints, disputes and legal claims;
  • comply with regulatory, contractual and legal obligations; and
  • send relevant marketing communications where lawful.

We will not use personal information for a purpose that is incompatible with the purpose for which it was collected unless the law permits or requires us to do so.

8. Our Lawful Bases

We rely on one or more of the following lawful bases.

Contract

We process information where necessary to:

  • take steps at your request before entering into a contract;
  • provide services you have requested;
  • administer a Tender Portal subscription;
  • manage payments and accounts; or
  • fulfil our contractual obligations.

Legal obligation

We process information where necessary to comply with obligations relating to:

  • tax and accounting;
  • employment;
  • data protection;
  • regulatory requirements;
  • fraud prevention;
  • court orders; or
  • other applicable laws.

Legitimate interests

We may process information where it is necessary for our legitimate business interests and those interests are not overridden by your rights. These interests may include:

  • managing client and supplier relationships;
  • improving our services and website;
  • maintaining network and information security;
  • preventing fraud and misuse;
  • managing business administration;
  • establishing or defending legal claims; and
  • promoting relevant services to existing business contacts where permitted.

Where required, we carry out a legitimate-interests assessment.

Consent

We may rely on your consent for activities such as:

  • optional marketing;
  • non-essential cookies;
  • certain uses of sensitive information; or
  • another activity where consent is the most appropriate basis.

You may withdraw consent at any time. Withdrawal does not affect processing carried out before consent was withdrawn.

Vital interests

In exceptional circumstances, we may process information where necessary to protect someone’s life or physical safety.

Public task or recognised legitimate interests

Where applicable, we may process information where necessary for a task in the public interest or under another lawful basis recognised by current UK data-protection law.

9. Special-Category and Criminal-Offence Information

Where we process special-category information, we will identify both:

  • a lawful basis under Article 6 of the UK GDPR; and
  • an additional condition under Article 9 of the UK GDPR or Schedule 1 of the Data Protection Act 2018.

Depending on the circumstances, this may include processing that is necessary for:

  • employment, social security or social-protection obligations;
  • health or social-care management;
  • protecting vital interests;
  • establishing, exercising or defending legal claims;
  • substantial public-interest reasons;
  • safeguarding vulnerable individuals; or
  • explicit consent.

Criminal-offence and DBS information will be processed only where authorised by law, subject to appropriate safeguards and, where required, an appropriate policy document.

10. Direct Marketing

We may send you information about relevant My Projectz services where:

  • you have consented;
  • the law permits us to contact you as an existing client or business contact; or
  • we have another valid lawful basis.

You may opt out at any time by:

  • using the unsubscribe link in an email;
  • contacting us at info@myprojectz.co.uk; or
  • updating your communication preferences where available.

We will not sell your personal information to third parties for their own marketing.

11. Cookies and Similar Technologies

Our website may use:

  • strictly necessary cookies;
  • preference cookies;
  • analytics cookies;
  • functionality cookies; and
  • advertising or marketing cookies.

Non-essential cookies will be used only where permitted by law and, where required, after you have provided consent through our cookie controls.

More information is available in our separate Cookies Policy. You should ensure that the Cookies Policy and consent banner accurately identify every cookie and tracking service used on the website.

12. Who We Share Personal Information With

Where necessary and lawful, we may share information with:

  • employees, workers and authorised contractors;
  • hosting, cloud-storage and IT-support providers;
  • CRM, communications and project-management providers;
  • website analytics and marketing providers;
  • payment processors and financial institutions;
  • accounting, payroll and professional-service providers;
  • training-platform providers;
  • recruitment, screening and compliance providers;
  • tender-data and procurement-platform providers;
  • client organisations where we act on their behalf;
  • insurers, auditors, solicitors and other professional advisers;
  • public authorities, courts, regulators or law-enforcement bodies; and
  • prospective purchasers or investors in connection with a business sale, restructuring or acquisition.

We require service providers to protect personal information, process it only for authorised purposes and comply with applicable data-protection requirements.

13. International Data Transfers

Some of our staff, contractors, service providers, systems or business operations may be located outside the United Kingdom, including in the United States and Pakistan.

Where personal information is transferred outside the UK, we will ensure that an appropriate transfer mechanism and safeguards are in place. These may include:

  • UK adequacy regulations;
  • the UK International Data Transfer Agreement;
  • the UK Addendum to approved standard contractual clauses;
  • another legally recognised transfer mechanism; and
  • appropriate transfer-risk assessments and technical or organisational safeguards.

You may contact us for further information about the safeguards applying to a particular transfer.

14. Data Security

We use appropriate technical and organisational measures designed to protect personal information against:

  • unauthorised access;
  • accidental loss;
  • misuse;
  • alteration;
  • destruction; and
  • unlawful disclosure.

Depending on the information and service involved, measures may include:

  • role-based access controls;
  • secure authentication;
  • encryption;
  • staff confidentiality obligations;
  • secure backups;
  • system monitoring;
  • incident-response procedures;
  • supplier due diligence;
  • security awareness training; and
  • access and retention reviews.

No internet or electronic-storage system can be guaranteed to be completely secure. However, we regularly assess our safeguards and take reasonable steps to reduce risks.

15. Personal Data Breaches

We maintain procedures for identifying, investigating and responding to suspected personal data breaches.

Where required by law, we will:

  • notify the Information Commissioner’s Office within the applicable period; and
  • notify affected individuals where the breach is likely to present a high risk to their rights and freedoms.

Where we act as a processor, we will notify the relevant controller without undue delay after becoming aware of a breach.

16. How Long We Keep Personal Information

We keep personal information only for as long as reasonably necessary for the purpose for which it was collected, including legal, accounting, regulatory and contractual requirements.

Our retention periods may include:

  • General enquiries: normally up to 24 months after the last meaningful contact;
  • Client contracts and project records: normally six years after the end of the relationship;
  • Invoices, payments and tax records: normally six years after the relevant financial year;
  • Tender Portal account information: for the account term and a reasonable period after closure;
  • Marketing records: until consent is withdrawn, an objection is received or the information is no longer required;
  • Unsuccessful recruitment records: normally six months after the recruitment process, unless a longer period is agreed or justified;
  • Training records: for the applicable contractual, regulatory or certification period;
  • Complaints and legal claims: for as long as required to investigate the matter and meet limitation periods;
  • Website security logs: for a limited period proportionate to security needs; and
  • Client-controlled healthcare or workforce data: according to the client’s written instructions and applicable contract.

These periods are indicative and must be confirmed against our formal retention schedule. Information may be kept longer where necessary for a legal claim, regulatory investigation, safeguarding matter or other lawful reason.

At the end of the relevant retention period, information will be securely deleted, anonymised or returned to the controller, as appropriate.

17. Your Data-Protection Rights

Depending on the circumstances, you may have the right to:

  • be informed about how your information is used;
  • request access to your personal information;
  • request correction of inaccurate or incomplete information;
  • request deletion of your information;
  • request restriction of processing;
  • object to processing based on legitimate interests;
  • object to direct marketing at any time;
  • request transfer of information in a portable format;
  • withdraw consent;
  • challenge certain solely automated decisions; and
  • complain about the way we use your information.

These rights are not absolute. Legal exemptions may apply, and we may need to retain certain information to comply with legal obligations or establish, exercise or defend legal claims.

18. Exercising Your Rights

To exercise a data-protection right, contact:

Email: info@myprojectz.co.uk
Post: Data Protection Lead, My Projectz, Office 205, Foundry Wandsworth, 4 New Acres Lane, London

Please state the right you wish to exercise and provide enough information to help us identify the relevant records.

We may request reasonable evidence of identity or authority before responding. We will normally respond within one month, although the law permits an extension in certain circumstances. We will tell you if an extension is required.

We will not normally charge a fee. However, a reasonable fee may be charged, or a request may be refused, where permitted by law, for example, where a request is manifestly unfounded or excessive.

19. Automated Decision-Making

We do not currently make decisions that produce legal or similarly significant effects about individuals solely by automated means.

If this changes, we will provide clear information about:

  • the decision involved;
  • the logic and information used;
  • the possible consequences;
  • the applicable lawful basis; and
  • the safeguards available, including human review where required.

20. Children’s Information

Our website and commercial services are primarily intended for adults and organisations.

We do not knowingly collect personal information directly from children through general website services. Where children’s information is processed as part of a client service, we will do so only under appropriate instructions, contractual safeguards and lawful authority.

If you believe that a child has provided information to us without appropriate authority, please contact us promptly.

21. Third-Party Links

Our website may contain links to external websites, portals or social-media services.

We are not responsible for the privacy practices of third parties. You should review the privacy information provided by each external service before providing personal information.

22. Data-Protection Complaints

You may complain to us if you believe we have infringed data-protection law or handled personal information incorrectly.

A complaint may be submitted by:

  • emailing info@myprojectz.co.uk with the subject line “Data Protection Complaint”;
  • writing to our Data Protection Lead at the address above; or
  • using our website contact form and clearly stating that your message is a data-protection complaint.

Please include:

  • your name and contact details;
  • a clear explanation of your concern;
  • relevant dates and correspondence;
  • the outcome you are seeking; and
  • proof of authority if you are acting for someone else.

We will:

  1. provide a clear route for submitting the complaint;
  2. acknowledge receipt within 30 days;
  3. take appropriate steps to investigate;
  4. keep you informed where the investigation takes time; and
  5. communicate the outcome without unjustifiable or excessive delay.

Where appropriate, we will explain any remedial action taken.

23. Complaining to the Information Commissioner

You also have the right to raise a concern with the Information Commissioner’s Office, the UK supervisory authority for data protection.

We encourage you to contact us first so that we have an opportunity to investigate and resolve the concern. However, this does not affect your right to contact the Information Commissioner.

Information about submitting a concern is available through the Information Commissioner’s Office.

24. Changes to This Policy

We may update this policy to reflect:

  • changes to our services;
  • changes to our systems or suppliers;
  • changes to legal or regulatory requirements; or
  • improvements to our privacy practices.

The revised version will be published on our website with an updated revision date. Where a change materially affects how we use personal information, we will take reasonable steps to bring it to the attention of affected individuals.

25. Contact Us

For questions about this policy, our privacy practices or the use of your personal information, contact:

Data Protection Lead
My Projectz
Foundry, Wandsworth, 4 New Acres Lane, London, United Kingdom

Email: info@myprojectz.co.uk
Telephone: +44 (0)20 3897 9191

Stay Ahead of New Tender Opportunities

Receive newly published tender opportunities and key deadlines, and relevant procurement updates directly in your inbox.