LEGAL

Privacy Policy

How we handle personal data when you use the SOURCED marketplace, and the rights you have over it.

Operator: Intentional Ventures Ltd (Company No. 17355827), trading as Sourced.

Last updated: 16 September 2026.

Sourced is an online venue that introduces business buyers to business sellers. Sourced is not a party to any contract of sale, is not a manufacturer, distributor, importer, exporter, freight forwarder, customs agent or payment institution, and does not take title to, possession of, or responsibility for any goods.

1Who is responsible

Intentional Ventures Ltd (Company No. 17355827), trading as Sourced, is the controller of personal data processed through the Platform. Where you obtain another User's contact details through the Platform, you act as an independent controller of that data.

2Data we collect

  • Account data: name, business email, password hash, role, language preference.
  • Business and verification data: company name, registered address, registration number, VAT identifier and validation status, bank identifier checks, beneficial ownership declarations, certificates and supporting documents you upload.
  • Marketplace activity: listings, RFQs, quotations, enquiries, messages, support tickets and notification history.
  • Billing data: plan and advertising purchases, invoices and payment references. Card details are handled by our payment provider and are never stored by us.
  • Technical data: IP address, device and browser information, pages viewed, advertising impressions and clicks, and security and fraud signals.

3Why we use it and our legal bases

  • Contract: to create and operate your account, publish listings, route RFQs and messages, deliver paid plans and advertising, and provide support.
  • Legitimate interests: to verify businesses, prevent fraud and invalid traffic, secure the Platform, measure and improve our services, and communicate about features relevant to your account.
  • Legal obligation: to meet accounting, tax, sanctions screening and lawful-request obligations.
  • Consent: for non-essential cookies and optional marketing, which you may withdraw at any time.

4What other Users can see

Approved supplier profiles are public and show business-card information only: company name, location, description, categories, declared certifications, trust tier and responsiveness. Registration numbers, VAT numbers, bank identifiers, onboarding submissions and internal verification records are never shown publicly. When you send an enquiry, RFQ or message, its content and your business identity are shared with the counterparty.

5Sharing with processors

We use vetted providers for hosting and database services, transactional email, payment processing, machine translation and AI-assisted support, and analytics. They act on our instructions under written terms. We also disclose data where legally required, to protect rights and safety, or in connection with a corporate transaction. We do not sell personal data.

6International transfers

Where personal data leaves the UK or EEA, we rely on adequacy decisions or the UK Addendum and EU Standard Contractual Clauses together with appropriate supplementary safeguards.

7Retention

Account and marketplace records are kept while your account is active and for up to six years afterwards to meet legal, accounting and dispute-defence needs. Verification evidence is kept for the period required to demonstrate the checks performed. Security and fraud logs are kept for up to twenty-four months. We then delete or irreversibly anonymise the data.

8Your rights

Subject to conditions in applicable law, you may request access, rectification, erasure, restriction, portability, and object to processing based on legitimate interests or direct marketing. Submit requests through the Support page. You may also complain to your supervisory authority, including the UK Information Commissioner's Office or your national EU data protection authority.

9Security

We apply access controls, row-level database authorisation, encryption in transit, least-privilege service credentials and monitoring. No system is perfectly secure; you are responsible for safeguarding your credentials and for the security of data you export from the Platform.

10Automated processing

Trust scoring, ranking and fraud filtering involve automated logic. These do not produce legal effects equivalent to a decision with significant impact on individuals; where an automated outcome affects your account you may request human review via Support.

11Changes

We may update this policy. Material changes are notified through the Platform or by email, and the current version always applies.