Data Handling and Confidentiality Statement: Hesketh & Son
What this statement is, and isn't
This page covers what happens to the material you send us when you engage Hesketh & Son to draft a tender, grant, or award submission. It is not the same as our website privacy policy (heskethandson.com/privacy), which only covers people browsing the site. This one is about your bid evidence: the documents, figures, and evidence you hand over so we can write your submission.
Who we are
Hesketh & Son is the trading name of Daniel Hesketh International, a company registered in Norway (org. no. 996 936 619, Brønnøysund Register Centre, Norway's equivalent of Companies House, based at Vitaminveien 26, 0483 Oslo). Our UK correspondence address is 29 Oatlands Drive, Harrogate HG2 8JT. We draft tender, grant, and award submissions for small and mid-sized firms, mainly in the UK's care sector.
What we collect, and why
To draft a competitive submission, we need to see the evidence an evaluator would want to see: things like your CQC ratings, financial figures, service specifications, org charts, past-performance examples, and policy documents. We collect this because it is the raw material of the bid itself, nothing more.
Most of what buyers hand over falls into that commercial-evidence category: it describes your business, not named individuals, so it does not carry the extra legal weight that "personal data" carries under GDPR. If your evidence does include information about named individuals (staff CVs for a people-section, named case studies, named referees), that is personal data, and it is handled under a stricter process described below in "When a formal Data Processing Agreement applies."
Where your material is stored and processed
We are a small operation. At launch, one person (Dan Hesketh, Founder) works on your material. We store what you send us using standard commercial cloud storage and standard business email; nobody outside the person doing your work has access to it. We do not hold ISO 27001 or Cyber Essentials certification, and we are not going to imply otherwise. If a specific security certification is a hard requirement for you, tell us early in the conversation and we will be straight with you about whether we can meet it.
Our confidentiality commitment
Two plain commitments, both binding on every engagement:
- Your material is used only to write your submission. We do not reuse the substance of one client's evidence, wording, or figures in another client's work. Method and structure (how we map a rubric, how we tag evidence) are ours and get reused; your actual content never does.
- We do not disclose that you are a client, or your name, to anyone else, without your permission. This includes not naming you as a reference or case study without asking first.
This commitment sits inside a mutual confidentiality clause in our standard terms of engagement, agreed before any evidence changes hands.
AI use disclosure
We are upfront about how the work gets made, on our own site and here: drafting is AI-assisted, evidence-tagged, and human-reviewed. In practice, that means AI tools help structure the draft, map your evidence against the buyer's scoring criteria, and produce first-pass text, and a named person (Dan Hesketh, Founder) reviews, edits, and signs off every draft before it reaches you. We are upfront about this because you are the one putting your name on the final submission.
Whether and how you mention AI in your own submission is your decision, not ours. What happens inside your engagement is confidential, and we will never tell a buyer, or anyone else, how your particular submission was produced. If your tender or grant notice asks a direct question about AI use, we will give you accurate wording matched to how the question is framed; what you declare is yours to decide and yours to stand behind. This is how we describe our own working method, not legal advice; if a notice sets a specific compliance requirement, confirming you meet it is yours to do.
UK GDPR and Norway data protection posture
Norway is part of the European Economic Area (EEA). Under the UK's Data Protection Act 2018 (Schedule 21), EEA states are automatically treated as an approved destination for personal data, no extra paperwork required. In plain terms: moving data between the UK and Norway is not a legal problem, it is already covered.
If you are in the UK, UK GDPR applies to how we handle your data, and the Information Commissioner's Office (ICO, ico.org.uk) is the relevant regulator. If you are in Norway or elsewhere in the EEA, GDPR as it applies there covers you, and Datatilsynet (the Norwegian data protection authority) is the relevant regulator. We would rather you came to us first if something is wrong: see contact details below.
Separately, and for completeness: we are not currently registered with the ICO as a data controller. That registration would relate to how we hold our own client list and contact details, not to how we handle your bid evidence under a confidentiality clause or a Data Processing Agreement. If ICO controller registration matters to your own due diligence, ask us and we will confirm our current status honestly.
Retention and deletion
Our standard is simple: we keep your bid evidence for twelve months after the engagement ends, then delete it. The twelve months exist for one reason, reuse: most organisations bid again, and the mapped, tagged evidence pack we built for you is a head start on the next one. If you would rather it went sooner, ask and we will delete it at any point, during or after the engagement. Deletion here is something we do by hand on request, not an automated self-service button.
We keep the basic records of the engagement itself (the agreement, correspondence about it, invoices) for longer, because legal and accounting rules require that. Those records are about the engagement, not your bid evidence.
When a formal Data Processing Agreement applies
Most bid evidence, things like CQC ratings, financial figures, service specifications, and org charts, is commercial information rather than personal data, and our standard mutual confidentiality clause covers it. That is proportionate and sufficient for the majority of engagements.
If your evidence includes personal data processed on your behalf, for example named staff CVs used in a people-section, or named service-user case examples, UK GDPR Article 28 requires a formal Data Processing Agreement (a contract that sets out how we may use that data, how we keep it secure, and what happens to it afterwards). We hold a template ready for this and will provide a signed copy before any such data changes hands. If you would like to see it regardless of whether your engagement needs one, just ask.
Questions or requests
Write to hello@heskethandson.com. A named person reads and answers every message sent there, and that is where a deletion request, a data-protection question, or a request for our Data Processing Agreement template should go.