RealFast Proposals ← Back to home
Legal · UK GDPR

Privacy Policy

Last updated 2026-09-24

This Privacy Policy explains how RealFast Proposals (“RealFast”, “we”, “us” or “our”) collects, uses and protects personal data when you visit our website at https://realfastproposals.com (the “Website”), contact us, or use our AI-assisted proposal service (the “Service”).

We handle personal data in accordance with the UK GDPR and the Data Protection Act 2018.

This policy is written for website visitors and account users. Where we process personal data contained within customer-uploaded content, we act as a processor on behalf of our business customers, not as a controller. Section 2 explains how that distinction works.

1. Who we are (data controller)

For personal data described in this policy where we act as controller, the data controller is:

We are registered with the UK Information Commissioner’s Office (ICO).

2. Controller vs processor, an important distinction

When we act as a controller. For personal data we collect directly and decide how to use, such as contact-form submissions and account and authentication data, we are the controller. This policy governs that processing.

When we act as a processor. When you use the Service, you and your team may upload proposal content, questions, answers and library materials (“Customer Content”). Any personal data contained within Customer Content, for example names or contact details inside a bid document, is processed by us as a processor, strictly on the instructions of our business customer, who is the controller of that data. That processing is governed by our Data Processing Agreement, not by this Privacy Policy. If you are an individual whose data appears in Customer Content, please contact the relevant business customer to exercise your rights.

3. What personal data we collect

We collect the following categories of personal data as a controller:

CategoryData collectedSource
Contact-form submissions Name, email address, and the message you send You, when you complete the contact form
Account data Email address and authentication data, for example credentials or authentication tokens You, when you register and use the Service
Service operation data Server logs, and a record of each AI or OCR call made on your behalf (which user, which model, for which bid and question, token counts, latency, cost and whether it succeeded) Automatically, as a necessary part of operating and billing the Service

We do not intentionally collect special category personal data through the Website. Please do not include sensitive personal data in contact-form messages.

Personal data contained within Customer Content is processed as a processor under the DPA, as described in Section 2, and is not covered by this table.

4. Purposes and lawful bases

PurposePersonal data usedLawful basis
Responding to enquiries and providing supportContact-form submissionsLegitimate interests, to respond to and manage enquiries
Creating and administering accounts and providing the ServiceAccount dataContract, to perform our agreement with you
Securing and maintaining the ServiceAccount and technical dataLegitimate interests, to keep the Service secure and reliable
Operating, securing, debugging and cost-controlling the ServiceService operation dataLegitimate interests in running a reliable service and understanding what it costs to serve each customer
Complying with legal obligationsAs relevantLegal obligation

Where we rely on legitimate interests, we have balanced those interests against your rights and freedoms. You may object to processing based on legitimate interests, as described in Section 8.

5. Sub-processors and service providers

We use the following third parties to help us provide the Service. Where they process personal data on our behalf, they do so under contractual data-protection terms. This table was reconciled against the running application on 7 September 2026; every row corresponds to an integration that exists in the product.

Sub-processorPurposeLocationSafeguard
SupabaseDatabase, authentication, and private file storage for uploaded documents, response templates and answer imagesUnited Kingdom (eu-west-2, London)Processed in the UK; DPA in place
VercelApplication hosting, serverless functions and CDNUS, with edge deliveryDPA in place
AnthropicAI reading of uploaded documents, drafting of proposal answers, and scoring of draft answers against a reconstructed evaluation standardUSDPA in place. Anthropic does not train models on data submitted through the API
Google Cloud Document AIOCR text and layout extraction from uploaded solicitation and bid documentsEuropean UnionGoogle Cloud DPA, incorporating the UK IDTA and SCCs
InngestOrchestration of the document-ingestion job queue and per-page fan-outUSDPA in place
ResendTransactional email delivery (sign-in links, password recovery, invitations, digests)USDPA accepted; UK IDTA and SCCs
SlackOperational alerts to our own workspace about newly published public-sector opportunities matched to a customer’s answer libraryUSDPA in place. Message content is opportunity metadata and a deep link. No uploaded document content and no customer staff personal data is sent
SentryError reporting, so failures become visible to usEU region (de.sentry.io)Error metadata only, meaning where the failure happened and a short context string. Uploaded document content is never included
PostHogWebsite analytics in cookieless mode, meaning page views and counts of enquiries sent. No cookies, no session recording, and IP addresses are discardedEuropean Union (Frankfurt)PostHog DPA, with the UK IDTA and SCCs
Google WorkspaceDestination inbox for contact-form and enquiry emailEU / UKGoogle Workspace DPA

Where uploaded documents are processed

When you upload proposal or solicitation documents, the contents are read by Google Cloud Document AI for OCR and layout extraction and by Anthropic for analysis and drafting, and the ingestion jobs are orchestrated by Inngest. Uploaded documents may contain personal data relating to third parties, including buyer-side evaluators named in debriefs and assessment summaries. We process that content only as a processor on our business customer’s instructions, as described in Section 2.

Services that do not process personal data

Better Stack monitors the availability of our public web addresses and powers our status page. It receives no customer data and no personal data. It makes unauthenticated requests to public endpoints and reports whether they answered.

Public-record sources we read

The Service reads public procurement records from SAM.gov, USAspending.gov and the US Government Accountability Office. These are outbound, unauthenticated reads of published public records. No personal data and no customer content is sent to them, so they are not sub-processors and no transfer arises.

We do not sell your personal data, and we do not use Customer Content to train third-party AI models.

6. International transfers

Our database, authentication and file storage are located in the United Kingdom, and OCR of uploaded documents is performed in the European Union. Some of our sub-processors are based in the United States or process data outside the UK. Where personal data is transferred outside the UK, we rely on appropriate safeguards, in particular the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses (SCCs), together with any additional measures required to protect your data.

In particular, when documents are uploaded to the Service they are read by Anthropic in the United States for AI analysis, and the ingestion queue is orchestrated by Inngest in the United States. Those transfers are covered by the safeguards described above.

You may request further information about these transfer safeguards by contacting jon@realfastproposals.com.

7. Data retention

We retain personal data only for as long as necessary, in accordance with our Data Retention Policy. Headline retention periods are:

We may retain certain data for longer where required to comply with a legal obligation or to establish, exercise or defend legal claims.

8. Your rights under UK GDPR

You have the following rights in relation to your personal data:

To exercise any of these rights, contact us at jon@realfastproposals.com. We will respond within the timeframes required by law, generally one month.

Complaints. If you are unhappy with how we handle your personal data, you have the right to complain to the UK Information Commissioner’s Office at ico.org.uk, by calling 0303 123 1113, or by writing to Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF. We would appreciate the chance to address your concerns first, so please consider contacting us before approaching the ICO.

9. Cookies and analytics

We do not set non-essential cookies, and our website analytics store nothing on your device.

We use PostHog, hosted in the European Union, to understand how the RealFast Proposals website is used, for example which pages are visited and which pages lead to an enquiry. It runs in cookieless mode. It does not set cookies or use your browser’s local or session storage, session recording is switched off, and IP addresses are discarded rather than stored. To count visits, PostHog creates a hash from your IP address and browser details on its servers, and that hash resets every day, so you cannot be followed from one day to the next or across other websites.

When you send an enquiry, we record that a form was sent, from which page and on which topic. Your name, email address and message are not sent to PostHog. They go only to our inbox and our enquiry list.

This analytics runs only on the public website. It is not loaded in the application.

The only cookies we set are strictly necessary ones required to operate the Service: your authentication session, and the cookies that record which workspace and role your session is acting in. These do not require consent.

10. Security

We take appropriate technical and organisational measures to protect personal data, including:

No system can be guaranteed completely secure, but we work to protect your data and to respond promptly to any security incident.

11. Children

The Service is a B2B product intended for business users and is not directed at children. We do not knowingly collect personal data from children.

12. Changes to this policy

We may update this Privacy Policy from time to time. Where changes are material, we will take reasonable steps to notify you. The “Last updated” date at the top shows when the policy was last revised.

13. Contact us

For any privacy question, or to exercise your rights, contact jon@realfastproposals.com.

See also our Terms of Service. Where we process personal data on a business customer’s behalf, our Data Processing Agreement governs that processing and is available on request.