S SSM TeamsSimple Supplier Management
Login Start Free
ADL Consulting Limited Company No. 06684621 · 6 Hinckley Road, Ibstock, Leicestershire, LE67 6PB, United Kingdom
Legal Simple Supplier Management

Privacy Policy

Last updated: 20/05/2026 Effective from: 20/05/2026 Version: 1.0
Terms and Conditions

On this page

  1. 1. About this policy
  2. 2. Who we are
  3. 3. When we are a controller, and when we are a processor
  4. 4. The personal data we collect
  5. 5. Why we use your data and our lawful basis
  6. 6. Who we share your data with
  7. 7. International data transfers
  8. 8. How long we keep your data
  9. 9. How we keep your data secure
  10. 10. Cookies and similar technologies
  11. 11. Marketing communications
  12. 12. Your rights under the UK GDPR
  13. 13. Right to complain
  14. 14. Changes to this policy
  15. 15. How to contact us

1. About this policy

This privacy policy explains how ADL Consulting Limited ("we", "us", "our") collects, uses, shares and protects personal data in connection with Simple Supplier Management ("SSM", the "Platform" or the "Service"), a supplier management SaaS product owned and operated by ADL Consulting Limited.

We handle personal data in a transparent, lawful and secure manner. This policy is written in plain language so that you understand what we do with your data and what rights you have.

If anything in this policy is unclear, contact us using the details in section 15.

A note on our role. In SSM, we act as a data controller for some personal data and as a data processor for other personal data. Section 3 explains the distinction. The remainder of this policy applies primarily to the personal data for which we are the controller.

2. Who we are

Legal EntityADL Consulting Limited
Company Registration Number06684621
Registered Address6 Hinckley Road, Ibstock, Leicestershire, LE67 6PB, United Kingdom
ICO Registration NumberZA240809
Privacy Contact Emaillegal@adlconsulting.co.uk

We are not required to appoint a Data Protection Officer (DPO) under Article 37 of the UK GDPR. Data protection enquiries sent to the privacy contact email are reviewed and answered by the appropriate person within ADL Consulting Limited.

3. When we are a controller, and when we are a processor

SSM is a business-to-business platform used by buyer or company customers ("Customers") to manage their suppliers ("Suppliers"). Two categories of personal data flow through the Platform, and our role under UK and EU data protection law differs between them.

3.1 We act as a controller when:

  • You create an SSM account, whether by email registration or by Microsoft single sign-on (SSO).
  • You log in, use the Platform's features, or correspond with our support team.
  • We process your data to operate, secure, bill for and improve the Service.
  • We send you service emails such as password resets, security notices and product updates.

In these situations, this privacy policy applies in full and we are responsible for how your personal data is handled.

3.2 We act as a processor when:

A Customer uploads, enters or otherwise loads personal data into SSM about its own suppliers, contacts, employees or third parties. Examples include primary contact names and email addresses, billing contacts, document uploaders, and names recorded in form responses, due diligence comments and supplier profiles.

We process that personal data only on the documented instructions of the Customer and only to provide the Service to them.

In these situations, the Customer is the controller of the personal data and the Customer's own privacy notice (not this one) governs how that data is handled. We process the data on the Customer's behalf under our Data Processing Agreement (DPA), which is available on request and incorporated into our Terms of Service.

If you are a Supplier contact whose details have been added to SSM by one of our Customers, and you wish to know what personal data is held about you, contact the Customer in the first instance. Where personal data is obtained indirectly in this way, Article 14 of the UK GDPR requires the controller (the Customer) to provide the relevant transparency information within one month, at the time of first communication, or before any further disclosure (whichever is earliest). We support our Customers in meeting that obligation under our DPA.

4. The personal data we collect

We collect only the personal data that is necessary to provide and improve SSM, to keep it secure, and to meet our legal obligations. We do not collect special category data (such as health, biometric or political opinion data). SSM is a business-to-business product and is not directed at, or intended for, anyone under the age of 18.

The categories below describe what we collect when we act as a controller.

4.1 Account and identity data

When you register for an SSM account or log in, we collect:

  • Your full name.
  • Your work email address.
  • A hashed and salted password, if you register by email.
  • Your account type (Buyer/Company or Supplier).
  • Your organisation's name and company registration number.
  • Your role and any phone number you choose to provide.
  • If you sign in with Microsoft SSO: the work or school account identifier issued by your organisation's Microsoft tenant, and the basic profile information Microsoft returns (name and email). Personal Microsoft accounts (Outlook.com, Hotmail, Live.com) are not supported.

4.2 Profile and business contact data

If you complete your profile, or are added as a primary contact, billing contact or supplier user within an organisation's SSM account, we also hold:

  • Job title or role.
  • Phone number.
  • Business address.
  • VAT number, where added at organisation level.

4.3 Service usage and account activity

To deliver and secure the Service we record:

  • Pages and features you access within SSM.
  • Records of actions you take (for example, uploading a document, submitting a form, completing a due diligence step, or leaving a comment).
  • The date and time of logins, password changes and other security-relevant events.
  • The IP address you connect from and basic device and browser information needed to maintain your session and detect suspicious activity.

We use this data to operate the Service and keep it secure. We do not use it to build a profile of your browsing behaviour or to serve advertising.

4.4 Content you put into SSM

You and your colleagues upload, enter or generate content within SSM, including:

  • Compliance documents (such as ISO 27001, SOC 2, GDPR, PCI DSS certificates and similar credentials).
  • Product information, descriptions and pricing models.
  • Form questions and supplier responses.
  • Due diligence comments, uploaded documents and workflow notes.
  • Spend records.

Where this content contains personal data (for example, the name of a person who signed a certificate, or a contact email recorded in a form response), we handle it as a processor on behalf of the Customer that owns the account (see section 3.2).

4.5 Communications

If you contact our support team or correspond with us, we keep a record of those communications and any information you choose to share with us.

4.6 Billing data

If your organisation pays for SSM, we hold the billing contact details and the records of invoices and payments. Card details are handled directly by our payment processor; we do not store full card numbers ourselves. See section 6 for the list of sub-processors involved.

5. Why we use your data and our lawful basis

Article 6 of the UK GDPR requires a lawful basis for every processing activity. The following table sets out what we do, why, and the legal basis we rely on.

PurposePersonal data usedLawful basis (UK GDPR Art. 6)
Create, manage and secure your SSM accountAccount and identity data (4.1); profile data (4.2)Contract (Art. 6(1)(b))
Authenticate you when you log in, including via Microsoft SSOAccount credentials; SSO identifiers; session and IP dataContract (Art. 6(1)(b))
Deliver the Platform's features (dashboards, forms, due diligence, risk scoring and similar)Profile data; content (4.4); usage data (4.3)Contract (Art. 6(1)(b)) where you are the account holder. Where you are a Supplier contact, we act as a processor (section 3).
Send service emails (password resets, security alerts, billing notifications, form reminders, due diligence notifications)Name and emailContract (Art. 6(1)(b))
Keep the Service secure, prevent fraud and abuse, investigate incidentsAccount activity (4.3); IP and device dataLegitimate interests (Art. 6(1)(f))
Maintain audit logs and accountability recordsAccount activity (4.3)Legitimate interests (Art. 6(1)(f)); Legal obligation (Art. 6(1)(c)) where applicable
Provide customer supportCommunications (4.5); account dataContract (Art. 6(1)(b)); Legitimate interests (Art. 6(1)(f))
Improve SSM, fix bugs and develop new featuresUsage data in aggregated or pseudonymised form (4.3)Legitimate interests (Art. 6(1)(f))
Send service-related product updates to account holdersName, email, organisationLegitimate interests (Art. 6(1)(f)). You can opt out at any time. See section 11.
Comply with legal, tax and accounting obligationsBilling data; account data; communicationsLegal obligation (Art. 6(1)(c))
Establish, exercise or defend legal claimsWhatever is relevant to the claimLegitimate interests (Art. 6(1)(f))

We do not rely on consent (Art. 6(1)(a)) for routine processing inside SSM, because the Service is provided under a contract. Where consent is the correct basis (for example, an optional marketing campaign), we will ask for it separately and you can withdraw it at any time.

We do not use automated decision-making that produces legal or similarly significant effects on individuals (Art. 22). The risk scores that SSM calculates relate to supplier organisations and products as a tool for our Customers' procurement and compliance teams. They are not automated decisions about individuals.

6. Who we share your data with

We do not sell your personal data. We do not share it for advertising purposes.

We share personal data only with the sub-processors that help us run SSM, with other parties to the extent you direct through the Platform, and in the limited additional circumstances described below.

6.1 Our sub-processors

We engage the following categories of sub-processor. A current, full list is available on request from our privacy contact and forms an annex to our Data Processing Agreement.

CategoryWhat they doLocation
Cloud hosting and infrastructureHost SSM and store its dataAWS, UK / EU-West
Microsoft Identity (SSO)Authenticate users signing in via Microsoft work or school accountsEU / UK / US (Microsoft global infrastructure)
Transactional email deliverySend password resets, form reminders, due diligence notificationsAWS SES
Company registration lookupVerify company registration numbers and pre-fill company names during sign-upCompanies House API
Payment processingProcess subscription payments (we do not store full card details)Stripe
Error monitoring and observabilityHelp us detect bugs and outagesTo be confirmed
Backups and disaster recoveryMaintain secure backupsTo be confirmed

All sub-processors are bound by written contracts that meet the requirements of Article 28 of the UK GDPR.

6.2 Other Customers and Suppliers within the Platform

SSM is designed for Customers to share information with their Suppliers and vice versa. When you use SSM features that involve sharing data, for example, sending a form, requesting a document, or marking a document as visible to all companies you work with, the receiving organisation will see that data. You control who sees what through the Platform's sharing settings.

6.3 Professional advisers, auditors and regulators

We share personal data with our lawyers, accountants, auditors, insurers and other professional advisers, and with regulators or law enforcement, where we are legally required or permitted to do so.

6.4 Links to other services

SSM contains links to third-party services that you may use in connection with your account, such as Microsoft (for SSO) and the websites of your own suppliers. Those services operate under their own privacy policies, and this policy does not apply to them. We encourage you to review the privacy notices of any third-party services you interact with through SSM.

6.5 Business transfers

If ADL Consulting Limited is involved in a merger, acquisition, financing or sale of assets, personal data may be transferred as part of that transaction. We will give you notice in advance and ensure that your rights remain protected.

7. International data transfers

SSM is hosted primarily in the United Kingdom or the European Economic Area. Some of our sub-processors may process personal data outside the UK and EEA such as Microsoft, for SSO authentication, as the most obvious example.

Where personal data is transferred outside the UK or EEA, we put an appropriate safeguard in place under Articles 44 to 49 of the UK GDPR. This safeguard takes one of the following forms:

  • The destination country has been recognised by the UK government (or by the European Commission for EU data subjects) as providing an adequate level of protection.
  • We rely on the UK International Data Transfer Agreement (IDTA), or the UK Addendum to the EU Standard Contractual Clauses (SCCs), supported by a transfer risk assessment.
  • Another lawful safeguard such as Binding Corporate Rules applies.

You can request a copy of the relevant safeguard using the contact details in section 15.

8. How long we keep your data

We keep personal data only for as long as we need it for the purposes set out in this policy. We then delete or anonymise it.

Type of dataRetention period
Account data (name, email, profile, organisation)For as long as your account is active, and then 12 months after closure or termination of the subscription, to address post-termination queries, disputes and data recovery requests.
Content uploaded by Customers (documents, forms, due diligence, products, suppliers)While the Customer's subscription is active. After termination, data is returned or deleted in line with our DPA, normally within 90 days.
Service usage and audit logsTypically 12 months. Longer where required for security investigations or legal obligations.
Billing and tax records6 years after the end of the tax year to which they relate (UK statutory requirement).
Support communications36 months after the last interaction.
BackupsBackups are overwritten on a rolling 90 day cycle. Personal data persists in backups for up to that period after deletion from the live system.
Marketing dataUntil you opt out or unsubscribe, with a short suppression-list retention period after opt-out so that we can honour your preference.

Where we anonymise data (so that it can no longer be linked to you), we retain it for longer for analytics and product improvement.

9. How we keep your data secure

We take the security of your personal data seriously and have implemented appropriate technical and organisational measures, in line with Article 32 of the UK GDPR. These measures include:

  • Encryption in transit (TLS) for all connections to SSM.
  • Encryption at rest for personal data and uploaded documents in our production database and object storage.
  • Strong authentication: hashed and salted passwords, support for Microsoft SSO with multi-factor authentication, and session management designed to limit unauthorised access.
  • Role-based access control inside the Platform and inside ADL Consulting Limited, applied on the principle of least privilege.
  • Audit logging of security-relevant activity.
  • Regular backups with restoration testing.
  • Vulnerability management, software patching and dependency monitoring.
  • Vetted sub-processors bound by data processing contracts.
  • Staff training on data protection and confidentiality, with confidentiality obligations in employment and contractor agreements.

No system can be guaranteed entirely secure. If we become aware of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner's Office (ICO) within 72 hours where required by Article 33 of the UK GDPR, and we will notify affected individuals without undue delay where the risk to them is high, in line with Article 34.

10. Cookies and similar technologies

We do not use cookies, pixels, fingerprinting or any other technology to track your browsing behaviour across SSM or across the wider web. We do not use analytics, advertising or behavioural-profiling cookies. We do not sell or share information about your activity with advertising networks.

Like every web application that requires you to log in, SSM uses a small number of strictly necessary cookies, also known as essential cookies, for the Service to function. These cookies keep you signed in during a session, remember your login preference, and protect against cross-site request forgery (CSRF) and similar security threats. They do not require your consent under the Privacy and Electronic Communications Regulations (PECR), because they are strictly necessary to provide the Service you have asked us to provide.

If we ever introduce non-essential cookies or similar technologies, we will update this policy and obtain your consent first.

11. Marketing communications

We send service-related communications to account holders to keep them informed about the SSM Service they use. These include important security notices, billing notifications, product updates and announcements about meaningful changes to the Platform. We rely on our legitimate interests (Article 6(1)(f)) to send these communications, as they are necessary to keep you informed about a service you use.

You can object to receiving non-essential service communications at any time by contacting us at legal@adlconsulting.co.uk or by using the unsubscribe link in any such message. Security and billing notifications, and other communications strictly necessary to provide the Service, are part of the contract between us and cannot be opted out of while your account remains active.

We do not run any external marketing campaigns, and we do not share your personal data with any third party for marketing purposes.

12. Your rights under the UK GDPR

You have a number of rights over your personal data under the UK GDPR and the Data Protection Act 2018:

  • Right to be informed (Articles 13 and 14) about how we use your data. This policy is the principal way we meet that obligation.
  • Right of access (Article 15) you can request a copy of the personal data we hold about you.
  • Right to rectification (Article 16) you can ask us to correct inaccurate or incomplete data.
  • Right to erasure (Article 17) in certain circumstances, you can ask us to delete your data ("the right to be forgotten").
  • Right to restrict processing (Article 18) you can ask us to limit how we use your data in certain circumstances.
  • Right to data portability (Article 20) you can ask us to provide the data you gave us in a structured, machine-readable format, or to transmit it to another controller, where the processing is based on consent or contract and carried out by automated means.
  • Right to object (Article 21) you can object to processing based on our legitimate interests, or to direct marketing, at any time.
  • Right to withdraw consent (Article 7(3)) where we rely on consent, you can withdraw it at any time. This does not affect the lawfulness of processing carried out before withdrawal.
  • Rights related to automated decision-making and profiling (Article 22) we do not currently make automated decisions of this kind, but you have the right to be informed if that changes.

How to exercise your rights

To exercise any of these rights, email us at legal@adlconsulting.co.uk. We will respond within one month of receiving your request, as required by Article 12(3). For complex or numerous requests we may extend this by up to a further two months, and we will let you know within the first month if we need to do so.

We may ask you to verify your identity before we act on a request, to protect against unauthorised disclosure.

There is no fee for exercising your rights, except where a request is manifestly unfounded or excessive, in which case Article 12(5) permits a reasonable fee or refusal.

If you are a Supplier contact whose details have been added to SSM by one of our Customers, your rights are normally exercised against the Customer (the controller of that data). Contact the Customer in the first instance. We will support the Customer in responding to you under our DPA. If you cannot reach the Customer, contact us and we will assist where we reasonably can.

13. Right to complain

If you believe we have not handled your personal data properly, contact us first using the details in section 15 and we will do our best to resolve the issue.

You also have the right to lodge a complaint with the UK Information Commissioner's Office:

  • Website: ico.org.uk
  • Helpline: 0303 123 1113
  • Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

If you are based in the EEA, you also have the right to complain to the data protection authority in your country of residence or place of work.

14. Changes to this policy

We update this policy from time to time, for example when our Service changes, our sub-processors change, or the law changes. When we update the policy, we revise the "Last updated" date at the top and, for material changes, give advance notice by email or through the Platform.

We recommend reviewing this policy periodically. Earlier versions are available on request.

15. How to contact us

For any privacy question, request or concern, contact:

ADL Consulting Limited
Email: legal@adlconsulting.co.uk
Postal address: 6 Hinckley Road, Ibstock, Leicestershire, LE67 6PB, United Kingdom

We aim to respond to all privacy enquiries within five working days, and to formal data subject requests within the one-month period required by the UK GDPR.

SSSM TeamsSimple Supplier Management

Simple supplier management for teams who would rather run their own compliance than depend on someone else's.

Start Free Login

Platform

FeaturesRisk ManagementCompliance VaultSpend Intelligence

Company

How it WorksPricingAboutContact

Legal

Privacy PolicyTermsGDPRSecurity
© 2026 SSM Teams ISO 27001 Ready · GDPR Compliant · SOC 2 Aligned