Privacy Policy
Your privacy is important to us. This policy explains how we collect, use, and protect your personal information when you use Property Software.
This policy is issued by Property Software Services Ltd.
Last updated: August 2026
UK GDPR & Data Protection Act 2018
We process personal data in line with the UK GDPR, the Data Protection Act 2018, and ICO guidance.
1. Information We Collect
We collect information that you provide directly to us, including:
- Account Information: Name, email address, phone number, company details
- Property Data: Property addresses, rental amounts, tenancy details
- Financial Information: Payment history, bank account details for Direct Debit
- Usage Data: Log files, device information, and interaction with our platform
- Communications: Messages, support tickets, and feedback you send us
- Compliance Evidence: Right to Rent, AML, sanctions, audit, and statutory-defence records where required by law
2. How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve our property management services
- Process payments and manage financial transactions
- Send important notifications about your properties and tenancies
- Comply with legal obligations (e.g., Right to Rent checks, compliance certificates)
- Detect, investigate, and prevent fraudulent or unauthorized activities
- Respond to your requests and provide customer support
- Minimise diagnostic and support data before it is sent to non-essential subprocessors
The legal reason we are allowed to use your information for each of these purposes is set out in section 9.
3. Data Security
We implement industry-standard security measures to protect your data:
- Encryption of data in transit (TLS 1.2+)
- Encryption of data at rest (AES-256)
- Multi-factor authentication support
- Regular internal security reviews
- Hosted on Google Cloud Platform
4. Your Rights
Under GDPR and UK data protection law, you have the following rights:
Right of Access
Ask for a copy of the personal data we hold about you. We can produce a full export covering every system that stores personal data.
Right to Rectification
Ask us to correct personal data that is wrong or incomplete. Our team makes the correction for you — there is no self-service correction tool.
Right to Erasure
Ask us to delete your personal data. Some records must be kept longer where the law requires it, such as anti-money-laundering and accounting records, so erasure is not always possible in full. We tell you what was kept and why.
Right to Data Portability
Receive the personal data you gave us in a structured, machine-readable file you can reuse elsewhere.
Right to Restrict Processing
Ask us to pause how we use your personal data while a question about it is resolved. Our team applies the restriction manually.
Right to Object
Object to us using your personal data where we rely on legitimate interests. For marketing you can also stop it immediately using the unsubscribe link in any marketing message.
Right to Withdraw Consent
Where we rely on your consent, you can withdraw it at any time. Withdrawing does not undo processing already carried out. Marketing consent can be withdrawn using the unsubscribe link; other consents can be changed by contacting us.
Rights About Automated Decisions
We do not make automated credit or affordability decisions about you. One automated check can block onboarding on its own: a financial-sanctions screening match scored above our confidence threshold. You can ask for that result to be reviewed by a person, give your side of it, and ask us to overturn it.
To use any of these rights, contact us using the details at the bottom of this page. We normally respond within one month and we do not charge a fee. We may ask you to confirm your identity first. If we cannot do what you asked, we will tell you why and how to complain — see section 10.
5. Data Retention
We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, including to satisfy legal, accounting, immigration, AML, audit, and reporting requirements. Right to Rent evidence is retained for the tenancy duration plus at least one year. Tenancy and financial records may be retained for statutory limitation or accounting periods, then deleted, placed beyond operational use, or irreversibly anonymised according to the applicable legal basis.
6. Subprocessors
We use selected subprocessors for hosting, payments, email delivery, diagnostics, and regulated integrations. Non-essential telemetry is minimised before egress so raw names, addresses, free-text notes, identity numbers, bank details, and payment-provider identifiers are not sent in diagnostic payloads.
7. Data Storage & International Transfers
At our 13 July 2026 live check, the production Firestore database used for primary application records and the console serving compute were in Google Cloud's London region. The default application bucket and the named Firestore backup bucket were also located in London. These dated checks do not prove the location of every stored object, policy, archive, secret, or provider system, so we do not claim that all data stays in the UK or EU.
Firebase Authentication is US-only. Authentication data, such as account identifiers and login information, is therefore processed in the United States. Our production-account data processing terms, service coverage, subprocessor evidence, and the applicable UK transfer basis are still being completed. We do not describe any transfer mechanism as approved until that evidence exists.
Certain subprocessors (for example, card-payment processing) may also process limited personal data outside the UK/EU. We have not yet completed and evidenced the transfer basis for every such subprocessor, so we do not represent those transfers as covered by an approved safeguard. Contact us for the current subprocessor and transfer position.
8. Google Calendar Data
If you choose to connect Google Calendar, we access your calendar-list information so you can select a calendar, and event data in the selected calendar so we can read, create, update, or cancel events for the sync settings you enable. We use this data only to provide and support the Calendar integration.
We store encrypted OAuth credentials, the selected calendar identifier, your sync settings, linked event identifiers, synced event details, and sync status. Access is limited to authorised users for your organisation and the services needed to run the integration. We do not sell Google user data or use it for advertising, lending decisions, or training general AI models.
Disconnecting asks Google to revoke the token and removes the stored Google credentials even if the remote revocation request cannot complete. Synced business records remain subject to the retention rules in section 5 and your legal rights in section 4.
Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
9. Our Lawful Bases for Using Personal Data
UK data protection law requires us to have a legal reason — a “lawful basis” — for every purpose we use personal data for. Who is responsible depends on whose data it is. Property Software Services Ltd is the controller for the accounts of people who use the console, and for our own billing and support records. For information about tenants, applicants, landlords, and guarantors, our customer — the letting agent or landlord using the platform — is the controller, and we act as their processor on their instructions. The bases below are the ones the platform is built to rely on.
- Running the platform and your account — performance of a contract (Article 6(1)(b))
- Managing tenancies, rent, maintenance, and documents for our customer — performance of a contract (Article 6(1)(b)) where you are a party to that contract, and legitimate interests in managing the property (Article 6(1)(f)) where you are not
- Right to Rent immigration checks — legal obligation (Article 6(1)(c)), Immigration Act 2014
- Anti-money-laundering checks, customer due diligence, sanctions screening, and the related record keeping — legal obligation (Article 6(1)(c)), Money Laundering Regulations 2017, including Regulation 40 (five-year record keeping)
- Tax, accounting, and financial records — legal obligation (Article 6(1)(c)), HMRC six-year record keeping
- Keeping tenancy records to bring or defend legal claims — legitimate interests (Article 6(1)(f)), reflecting the six-year period in the Limitation Act 1980
- Taking and reconciling payments, including Direct Debit and card payments — performance of a contract (Article 6(1)(b)), with legal obligation (Article 6(1)(c)) for the accounting record that follows
- Marketing emails and marketing text messages — consent (Article 6(1)(a)) and the Privacy and Electronic Communications Regulations. Consent is recorded, checked before every send, and can be withdrawn at any time
- Creating tenant, applicant, and maintenance records where the form requires a data-protection tick box — consent (Article 6(1)(a)) is recorded at the point of collection, alongside the contract or legal-obligation basis for the underlying record
- Connecting Google Calendar — consent (Article 6(1)(a)); see section 8
- Security, fraud prevention, audit trails, and service diagnostics — legitimate interests (Article 6(1)(f)); audit records are also kept under legal obligation (Article 6(1)(c)) where a rule requires them
- Keeping proof that consent was given or withdrawn — legal obligation and accountability (Article 6(1)(c) and Article 7(1))
Special category and criminal-offence information. We do not ask for, and the platform is not built to store, information about your health, biometrics, racial or ethnic origin, religion, political opinions, trade-union membership, or sex life. Right to Rent checks involve nationality and immigration status, which we process only to meet the Immigration Act 2014 duty. Where anti-money-laundering or sanctions work involves information about suspected unlawful acts, we rely on the substantial public interest conditions in Schedule 1 of the Data Protection Act 2018 covering the prevention or detection of unlawful acts and compliance with regulatory requirements.
10. How to Complain
If you are unhappy with how we have handled your personal data, please tell us first using the contact details at the bottom of this page, so we have a chance to put it right.
You also have the right to complain to the Information Commissioner's Office (ICO), the UK's data protection regulator. You do not have to complain to us first, and complaining to the ICO does not stop you taking your own legal action.
Information Commissioner's Office — ico.org.uk
Data Protection Contact
For any privacy-related question, or to exercise any of the rights in section 4, contact our data-protection contact at:
dpo@property-software.com