Presence only — this register reflects what public authorities have reported under their legal duty to publish (Subsidy Control Act 2022, s.33) to the UK subsidy transparency register, not everything they've done. The register is statutorily incomplete: authorities can take up to a year to report, and very small awards may never appear, so absence of an entry here is not evidence nothing happened.
Privacy notice — subsidy beneficiaries
This notice explains how this service processes personal data contained in the UK subsidy transparency register, and your rights in relation to it. It is provided under Article 14 of the UK GDPR, because the data is obtained from a public source rather than from you directly. It concerns only beneficiaries who are individuals, sole traders or partnerships; awards to organisations are not personal data and are out of scope of this notice.
1. Who is responsible (the controller)
The controller for this service is 45Black Limited. Requests and questions about your personal data, including objections (see section 6), should be sent to [email protected].
2. What personal data we process, and where it comes from
We process the beneficiary name and the associated public subsidy award record — for example the granting authority, amount, dates and status — where the named beneficiary is an individual, sole trader or partnership. We process only the fields the register itself publishes: there is no enrichment, no linkage to any other dataset, and no special-category data (UK GDPR Article 9).
The source of this data is the UK subsidy transparency register, published by the Department for Business and Trade (DBT). It is a publicly accessible source, published under the statutory transparency obligations of the Subsidy Control Act 2022. We hold a verbatim, provenance-stamped copy of exactly what the register served.
3. Why we process it, and our lawful basis
Purpose. To monitor the public register and alert our authorised users to awards and changes relevant to the exercise of, or advice on, subsidy-control review rights — which carry a short statutory deadline. The service asserts only what is present on the register (presence only); the absence of a record or alert is never evidence that no such subsidy exists.
Lawful basis: legitimate interests (UK GDPR Article 6(1)(f)). The legitimate interests pursued are the timely scrutiny of publicly funded subsidies and the protection of legal rights within the statutory review window — interests aligned with the register's own statutory purpose of public scrutiny and challenge. We have assessed that these interests are not overridden by your interests or fundamental rights, principally because the data is already public, lawfully published by a public authority for the purpose of scrutiny, is ordinary (not special-category) data, and is processed without enrichment. You have the right to object to this processing — see section 6.
4. Who we share it with
The data is accessible only to the controller and its authorised users, within their own access- controlled instance of this service. We do not sell it or share it with third parties as part of this service, and it is not transferred outside the United Kingdom by this service.
5. How long we keep it
We mirror the register's own currency: the displayed data tracks what DBT publishes. The underlying verbatim, provenance-stamped record is retained for the establishment, exercise or defence of legal claims and for the public-interest scrutiny purpose above (UK GDPR Article 17(3)), and is not deleted on request — see section 6.
6. Your rights
You have the right to: access the personal data we hold about you (Article 15); ask us to rectify inaccurate data (Article 16); ask us to erase it (Article 17); restrict our processing (Article 18); and object to our processing on grounds relating to your particular situation (Article 21). The right to data portability does not apply here, because we do not process your data on the basis of consent or a contract with you.
How we handle an objection or a request. Contact us at the address in section 1. We will assess an Article 21 objection against the overriding legitimate grounds set out in section 3. Where the objection succeeds — or at our discretion — we will suppress the beneficiary from the searchable, alerting and displayed surfaces of the service, so the name no longer appears or triggers alerts. We answer an access request directly from our verbatim copy of the relevant register entry. We do not delete the underlying authentic record, which we retain on the Article 17(3) grounds in section 5; a request to erase that record may be refused to the extent Article 17(3) applies, and we will give our reasons.
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK supervisory authority (ico.org.uk), though we would welcome the chance to resolve your concern first.
7. Automated decision-making
The service matches register changes against saved monitoring filters automatically, and sends alerts. This is automated processing, but it does not make a decision that produces legal or similarly significant effects about you within the meaning of Article 22: a person decides what, if anything, to do with an alert.
8. Why you may not have been told individually
We do not notify each beneficiary individually. The data is already published on a public register, and individual notification would involve disproportionate effort (UK GDPR Article 14(5)(b)). This general notice is provided instead.
Privacy notice — as a user of this service
This part explains how the controller named in section 1 processes personal data about you as a user of this service — an account holder or invited user. Because this data is collected directly from you (or from the colleague who invited you), it is provided under Article 13 of the UK GDPR. It is separate from the beneficiary data above.
A. What we hold about you
Your email address and account role; your firm or organisation account details; the saved filters (monitoring watch-lists) you create; your search history within the service; and records of the alert emails we send you. The service does not use your IP address or device identifiers and holds no special-category data; connection details such as IP addresses may appear transiently in your organisation's routine infrastructure and security logs. Sign-in is by a sign-in link or your organisation's single sign-on — we never store a password.
B. Why we process it, and our lawful basis
Purpose. To provide the service to you and your organisation — to sign you in, to run your saved monitoring filters, to send you alerts, and to operate and secure the service. Lawful basis: performance of a contract (UK GDPR Article 6(1)(b)), namely the agreement under which your organisation uses the service; and, for keeping the service secure and preventing misuse, our legitimate interests (Article 6(1)(f)). Your saved filters can reveal your professional intentions, so we treat them as confidential and isolate each organisation's data from every other (enforced in the database, not merely by convention).
C. How long we keep it, and who it reaches
We keep your account data for as long as your organisation's account is active. When the account is closed or deleted, its personal data is removed — your organisation's administrator can delete an account's data at any time. We keep alert and delivery records only as long as needed to operate and audit the service. Your email address is disclosed to our email delivery provider solely to deliver invites and alerts to you; where that provider processes data outside the United Kingdom, the transfer is made under a recognised UK GDPR safeguard (an adequacy regulation or an international data transfer agreement). We do not sell your data or use it for third-party marketing.
D. Your rights over your own data
You have the rights to access, rectify, erase, restrict and object to the processing of your account data, and — because this data is processed to perform a contract — the right to data portability (Article 20). Your organisation's administrator can export or delete an account's data; you may also contact us directly using the address in section 1.
How to complain
If you are unhappy with how your personal data has been handled — whether you are a subsidy beneficiary or a user of this service — you can complain to us directly using the contact in section 1. We will acknowledge your complaint within 30 days and respond without undue delay. You also have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk, though we would welcome the chance to put things right first.