Skip to main content

    Public Sector

    Compliance & Data Usage Framework

    How Honey-B2024 Ltd operates under UK public sector obligations — the statutory frameworks we design against, the controls we apply to authority data, and the guidance we ask officers to follow.

    Regulatory frameworks

    Statements below describe our design intent and operating practice. Certification status is stated explicitly where it is in progress.

    Procurement Act 2023

    Workflows are designed around the transparency notices, assessment summaries and record-keeping duties placed on contracting authorities.

    UK GDPR & Data Protection Act 2018

    Processing is limited to contract performance and legitimate interests under Art. 6(1)(b) and (f), with DSAR support and documented retention periods.

    Building Safety Act 2022

    Document intelligence supports the golden thread of information: version control, traceable evidence and auditable change history.

    ISO/IEC 27001 controls

    Our information security management practices are aligned to the Annex A control set. Formal certification is in progress.

    NCSC Cyber Essentials

    Endpoint hardening, access control, patching and malware protection follow the Cyber Essentials technical controls.

    Public Sector Equality Duty

    Accessibility and plain-English output guidance are part of every deployment, supporting WCAG 2.2 AA targets for public-facing material.

    Data handling principles

    Data minimisation

    Only the documents and fields required for the stated procurement or assurance task are ingested. No speculative harvesting of authority data.

    UK / EEA residency

    Customer procurement and AI data is hosted in the UK or EEA. No transfer outside adequacy regions without SCCs and the UK IDTA in place.

    No training on your data

    Authority content is never used to train foundation models. Prompts and outputs remain within the tenant boundary.

    Human in the loop

    Outputs are AI-assisted drafts. A named officer reviews and signs off before any submission, decision or publication.

    Our obligations

    • Data controller: Honey-B2024 Ltd, registered in England & Wales, company no. 15744305.
    • ICO registration ZC178845 (Tier 1).
    • Named point of contact for DSARs, FOI-related enquiries and incident notification: Info@honeyb2024.tech.
    • Personal data breach notification to the authority within 24 hours of detection.
    • Sub-processor register maintained and available to customers on request.
    • Records of processing activity (ROPA) kept under UK GDPR Art. 30.

    Guidance for authority users

    • Do not upload material classified above OFFICIAL without a written agreement covering handling requirements.
    • Redact special category data unless it is strictly necessary for the task and covered by a lawful basis.
    • Treat all generated text as a draft: verify figures, dates, statutory references and pricing against source documents.
    • Record the reviewer and review date for any AI-assisted content included in a formal decision record.
    • Do not rely on outputs as legal, financial or quantity surveying advice.
    • Report suspected inaccuracy, bias or unsafe output to Info@honeyb2024.tech so it can be logged and investigated.

    Need our compliance pack for a tender?

    We can supply a due-diligence pack covering security controls, sub-processors, data flows, retention schedules and AI transparency statements for your procurement file.