Privacy Policy
Last updated: [DATE]
This Privacy Policy explains how Birdly handles personal information in connection with getbirdly.co.uk, getbirdly.uk, the Birdly Service, public-contract matching, Private Jobs, support, marketing and related features.
1. Controller
The data controller is:
Birdly.dk
CVR no. 35764283
Fjordvej 4
4300 Holbæk
Denmark
Privacy enquiries: support@birdly.dk
Birdly is established in Denmark. For processing subject to UK GDPR, Birdly also complies with applicable UK data protection rules.
2. UK representative
Where Article 27 UK GDPR requires Birdly to appoint a representative in the UK, Birdly's representative is:
[UK_REPRESENTATIVE_NAME]
[UK_REPRESENTATIVE_ADDRESS]
[UK_REPRESENTATIVE_EMAIL]
DO NOT PUBLISH WITH PLACEHOLDERS. If specialist advice confirms an exemption, replace with reviewed wording.
3. Information we process
Depending on use, Birdly may process:
Business/customer contacts
- name;
- business name;
- job title;
- email;
- mobile/phone;
- company number/business identifier;
- postcode/business address.
Subscription/matching
- services/trade;
- areas covered;
- preferred contract size;
- public/private preferences;
- plan/status;
- trial/cancellation data.
Communications
- support messages;
- emails/texts sent;
- service notices;
- feedback.
Payments
Payment providers handle full card information. Birdly does not store the full card number/security code. Birdly may receive payment status, card type/last four digits and invoice information.
Technical information
Depending on cookie choices/use: IP, browser/device, timestamps, pages viewed, consent preferences, security logs, referrer/traffic data and advertising attribution data.
Service usage
Which Matches we send, timing/channel, whether Birdly links are opened, saved/dismissed signals where supported, and product-feedback signals.
Bid templates/uploads
Text, tender documents, CVs/references, names, professional contact details, price documents, certificates and other files provided.
Private Jobs
Name, phone, email, location/postcode, job description, timing, photos, status and matched businesses.
Public/professional information
Birdly may use business/professional information from public sources such as Companies House, business websites, official procurement notices and buyer/supplier information.
4. Purposes and legal bases
Providing the paid Birdly Service
We process information to set up subscriptions, match opportunities, send notifications, provide support and manage settings.
Legal basis:
- contract/steps requested before contract where Article 6(1)(b) applies; and/or
- legitimate interests in providing/managing a B2B service, especially for company employees/representatives, Article 6(1)(f).
Billing/legal records
For charging, invoicing, disputes, accounting/tax.
Legal basis: contract, legal obligation and legitimate interests as appropriate.
Security/fraud/operation
To secure Birdly, investigate misuse, prevent fraud, diagnose incidents and protect users/systems.
Legal basis: legitimate interests and legal obligation where applicable.
Product improvement/internal statistics
To improve relevance, product performance and UX.
Legal basis: legitimate interests. Where non-essential cookies/trackers are involved, required consent also applies.
Marketing
Where permitted, Birdly may contact business prospects/Customers.
- For corporate business contacts, Birdly may rely on legitimate interests for personal-data processing where appropriate and comply with applicable electronic-marketing rules.
- Sole traders and certain partnerships have stronger PECR protections for electronic mail, so Birdly will use consent or another lawful PECR basis where required.
- Where consent is required, it can be withdrawn at any time.
- Marketing messages include a simple opt-out where required.
- Birdly may retain minimal suppression data to respect opt-outs.
Cookies/advertising
Non-essential cookies/similar technologies are used only according to the Cookie Policy and choices. Where consent is required: Article 6(1)(a).
Private Jobs
To provide the requested matching service. Legal basis may include contract/steps at request, legitimate interests in operating/securing the service, and consent for optional processing where specifically requested.
Legal claims
To establish, exercise or defend claims: legitimate interests and/or legal obligation.
5. Processor role for Customer-controlled data
Where Birdly processes personal information contained in Customer Data on behalf of a business Customer, Birdly may act as processor for that specific processing and the DPA applies.
Examples: staff CVs, references, professional contacts, qualification documents and tender-response material.
For Birdly's own account, billing, security and service-management processing, Birdly remains controller.
6. Private Jobs sharing
Under the standard flow:
- job description/non-contact information may be visible to matched businesses;
- photos may be visible where necessary for assessment;
- direct contact details are released only when a business actively takes the job; and
- no more than 3 businesses receive direct contact details.
Once an independent business receives contact information, that business is responsible for its own processing.
7. Service analytics
Birdly may record Matches sent, channel/timestamps and interactions with Birdly links to operate/improve the Service.
Birdly does not sell this information.
Third-party advertising/analytics tracking is governed by cookie/consent choices.
8. Automated matching
Birdly uses automated rules, scoring and/or software to identify relevant opportunities using trade/service, location, contract value, classifications, keywords and other criteria.
Matching does not make a legally binding decision for a buyer or Customer. The Customer decides whether to act.
9. Who we share information with
Birdly does not sell personal information.
We use suppliers supporting database/backend, hosting, texts, email, payment/subscription handling, support, security and infrastructure. The current list is on the Sub-processors page.
Depending on context, third parties may act as processors, independent controllers or joint controllers.
Examples of independent/joint-controller roles may include payment providers for some processing, advertising platforms such as Meta for some measurement/advertising, and independent businesses receiving Private Job contact details.
We may also disclose information where required by law, to regulators/law enforcement where legally required, to professional advisers under confidentiality, or as part of a sale/restructuring subject to safeguards.
10. International transfers
Birdly is based in Denmark and the primary database is currently hosted in Paris, France.
Information may move between UK and EEA.
Where UK GDPR applies, EEA transfers may rely on UK adequacy regulations; restricted transfers elsewhere use an applicable lawful mechanism such as adequacy, UK Extension to a data privacy framework, UK IDTA, UK Addendum to EU SCCs or another lawful safeguard/exception.
Where EU GDPR applies, Birdly uses mechanisms required under EU law, including adequacy, applicable frameworks or EU SCCs where relevant.
See Sub-processors for current provider information.
11. Retention
Birdly does not retain information longer than reasonably necessary.
Subscription/customer information
After a Subscription ends, general account/contact/matching data is deleted/anonymised after the current 90-day grace period, unless longer retention is required for legal obligations, billing, fraud/security, disputes or claims.
Accounting records
Birdly is established in Denmark and keeps accounting/invoice records for the period required by applicable Danish law. Current Danish standard: 5 years after the end of the relevant financial year.
Bid-template drafts/uploads
Unless a different period is shown, current intended standard: deletion after 90 days.
Private Jobs
Closed-job direct contact details, photos and unnecessary personal information: intended deletion/anonymisation within 30 days, subject to complaints, fraud/security, claims or legal retention.
Marketing suppression
Minimal email/mobile + opt-out status may be retained as needed to respect opt-outs.
Backups
Information may remain in protected backups until overwritten under the normal backup cycle and is not returned to active use except where restoration is required.
12. Security
Birdly uses technical/organisational measures including access controls, encrypted connections, controlled credentials, backups, restricted administrative access and security monitoring appropriate to the Service.
No internet service can guarantee absolute security. See Security & Operations.
13. Your UK rights
Depending on context/law, you may have rights including access, rectification, erasure, restriction, objection, data portability and withdrawal of consent.
Rights may be subject to legal exceptions.
Contact support@birdly.dk. Birdly may verify identity before fulfilling a request.
14. Complaints
Please contact Birdly first so we can try to resolve a privacy concern.
For UK GDPR matters, you may complain to the Information Commissioner's Office (ICO): https://ico.org.uk/
Because Birdly is established in Denmark, the Danish Data Protection Agency may also be relevant for EU/Danish processing: https://www.datatilsynet.dk/
15. Children
The paid B2B Service is not intended for children. A person posting a Private Job must be at least 18.
Do not knowingly submit children's personal information unless genuinely necessary/lawful.
16. Changes
Birdly may update this Privacy Policy. The current version is published on the UK website. Material changes will be highlighted where reasonably appropriate.
17. Contact
Birdly.dk
CVR no. 35764283
Fjordvej 4
4300 Holbæk
Denmark
Privacy: support@birdly.dk
UK representative: [UK_REPRESENTATIVE_DETAILS]