Data Processing Agreement

Letably Data Processing Agreement

Last updated: 22 March 2026


1. Introduction

This Data Processing Agreement ("DPA") forms part of the Terms of Service ("Agreement") between Letably ("Processor", "we", "us") and the customer agreeing to the Terms of Service ("Controller", "Customer", "you").

This DPA sets out the terms on which the Processor will process Personal Data on behalf of the Controller in connection with the provision of the Letably platform services ("Services").

This DPA reflects the requirements of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.


2. Definitions

In this DPA, the following terms shall have the meanings set out below:

"Controller" means the entity that determines the purposes and means of Processing Personal Data.

"Data Protection Laws" means all applicable laws and regulations relating to the Processing of Personal Data, including (i) the UK GDPR; (ii) the Data Protection Act 2018; and (iii) any other applicable national data protection laws, in each case as amended or replaced from time to time.

"Data Subject" means an identified or identifiable natural person to whom Personal Data relates.

"Personal Data" means any information relating to an identified or identifiable natural person that is Processed by the Processor on behalf of the Controller in connection with the Services.

"Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data transmitted, stored, or otherwise Processed.

"Processing" means any operation or set of operations performed on Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction.

"Processor" means the entity that Processes Personal Data on behalf of the Controller.

"Sub-processor" means any third party engaged by the Processor to Process Personal Data on behalf of the Controller.

"Supervisory Authority" means the Information Commissioner's Office (ICO) or any other regulatory authority with jurisdiction over the Processing of Personal Data.

"UK GDPR" means the General Data Protection Regulation (EU) 2016/679 as it forms part of the law of England and Wales, Scotland, and Northern Ireland by virtue of section 3 of the European Union (Withdrawal) Act 2018, together with the Data Protection Act 2018.


3. Scope and Roles

3.1 Roles of the Parties

The parties acknowledge and agree that:

(a) The Controller is the Data Controller in respect of Personal Data Processed through the Services; (b) The Processor is the Data Processor acting on behalf of the Controller; (c) The Controller determines the purposes and means of Processing Personal Data; (d) The Processor Processes Personal Data only on the Controller's documented instructions.

3.2 Controller's Responsibilities

The Controller warrants and represents that:

(a) It has complied, and will continue to comply, with all applicable Data Protection Laws; (b) It has obtained, and will maintain, all necessary consents, authorisations, and legal bases required for the Processing of Personal Data by the Processor; (c) It has provided, and will continue to provide, all required notices to Data Subjects; (d) Its instructions to the Processor will comply with Data Protection Laws; (e) It is responsible for the accuracy, quality, and legality of Personal Data provided to the Processor.

3.3 Processing Details

The details of the Processing are set out in Schedule 1 to this DPA.


4. Processor Obligations

4.1 Compliance with Instructions

The Processor shall:

(a) Process Personal Data only on the documented instructions of the Controller, including with regard to transfers of Personal Data to a third country or international organisation, unless required to do so by applicable law, in which case the Processor shall inform the Controller of that legal requirement before Processing (unless prohibited by law); (b) Immediately inform the Controller if, in the Processor's opinion, an instruction infringes Data Protection Laws.

4.2 Confidentiality

The Processor shall ensure that persons authorised to Process Personal Data:

(a) Have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality; (b) Process Personal Data only on instructions from the Controller, unless required by applicable law.

4.3 Security

The Processor shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including as appropriate:

(a) Encryption of Personal Data in transit and at rest; (b) The ability to ensure the ongoing confidentiality, integrity, availability, and resilience of Processing systems and services; (c) The ability to restore the availability and access to Personal Data in a timely manner in the event of a physical or technical incident; (d) A process for regularly testing, assessing, and evaluating the effectiveness of technical and organisational measures for ensuring the security of the Processing.

The specific security measures implemented by the Processor are set out in Schedule 2 to this DPA.

4.4 Sub-processing

(a) The Controller provides general authorisation for the Processor to engage Sub-processors to Process Personal Data on behalf of the Controller. (b) The Processor shall maintain a list of current Sub-processors, which is set out in Schedule 3 to this DPA. (c) The Processor shall notify the Controller of any intended changes concerning the addition or replacement of Sub-processors at least thirty (30) days in advance, giving the Controller the opportunity to object to such changes. (d) If the Controller objects to a new Sub-processor on reasonable grounds relating to data protection, the parties shall discuss the Controller's concerns in good faith. If the parties cannot reach a resolution, the Controller may terminate the affected Services without penalty by providing written notice within thirty (30) days of the Processor's notice of the new Sub-processor. (e) The Processor shall impose data protection obligations on any Sub-processor that are no less protective than those set out in this DPA. (f) The Processor shall remain fully liable to the Controller for the performance of the Sub-processor's obligations.

4.5 Assistance with Data Subject Rights

The Processor shall, taking into account the nature of the Processing, assist the Controller by implementing appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of the Controller's obligation to respond to requests from Data Subjects exercising their rights under Data Protection Laws, including:

(a) Right of access; (b) Right to rectification; (c) Right to erasure; (d) Right to restriction of Processing; (e) Right to data portability; (f) Right to object.

The Processor shall:

(g) Promptly notify the Controller if the Processor receives a request from a Data Subject, unless prohibited by law; (h) Not respond directly to any Data Subject request unless authorised by the Controller or required by law; (i) Provide reasonable assistance to enable the Controller to respond to Data Subject requests within the timeframes required by Data Protection Laws.

4.6 Assistance with Compliance

The Processor shall assist the Controller in ensuring compliance with the obligations pursuant to Articles 32 to 36 of the UK GDPR, taking into account the nature of Processing and the information available to the Processor, including:

(a) Security of Processing; (b) Notification of Personal Data Breaches to the Supervisory Authority; (c) Communication of Personal Data Breaches to Data Subjects; (d) Data protection impact assessments; (e) Prior consultation with the Supervisory Authority.

4.7 Personal Data Breach Notification

In the event of a Personal Data Breach, the Processor shall:

(a) Notify the Controller without undue delay, and in any event within forty-eight (48) hours of becoming aware of the Personal Data Breach; (b) Provide the Controller with sufficient information to enable the Controller to meet any obligations to notify the Supervisory Authority and/or Data Subjects; (c) Provide ongoing updates as further information becomes available; (d) Cooperate with the Controller and take reasonable steps to assist in the investigation, mitigation, and remediation of the Personal Data Breach; (e) Not notify any Supervisory Authority or Data Subject directly unless required by law or instructed by the Controller.

The notification shall include at least:

(f) A description of the nature of the Personal Data Breach, including where possible the categories and approximate number of Data Subjects concerned and the categories and approximate number of Personal Data records concerned; (g) The name and contact details of the Processor's data protection contact; (h) A description of the likely consequences of the Personal Data Breach; (i) A description of the measures taken or proposed to be taken to address the Personal Data Breach, including measures to mitigate its possible adverse effects.

4.8 Audit Rights

The Processor shall:

(a) Make available to the Controller all information necessary to demonstrate compliance with the obligations set out in this DPA and Data Protection Laws; (b) Allow for and contribute to audits, including inspections, conducted by the Controller or an auditor mandated by the Controller, subject to reasonable advance notice (not less than thirty (30) days unless a shorter period is required due to a regulatory investigation or Personal Data Breach); (c) At the Controller's request, provide copies of relevant certifications, audit reports, or other evidence of compliance with security standards.

The Controller shall:

(d) Give reasonable notice of any audit or inspection; (e) Conduct audits during normal business hours with minimal disruption to the Processor's operations; (f) Ensure that auditors are bound by confidentiality obligations; (g) Bear its own costs of conducting audits.

4.9 Deletion and Return of Data

Upon termination or expiry of the Agreement, and subject to the Controller's instructions, the Processor shall:

(a) Provide the Controller with the ability to export Personal Data in a structured, commonly used, machine-readable format (CSV), including the ability to download associated files and attachments, for a period of thirty (30) days following termination; (b) After the thirty (30) day export period, delete all Personal Data within ninety (90) days, except where retention is required by applicable law; (c) Upon request, provide written confirmation of deletion.

The Processor may retain Personal Data where:

(d) Required by applicable law (in which case the Processor shall inform the Controller of the legal requirement and limit Processing to that required by law); (e) Contained in backup archives, which shall be deleted in accordance with the Processor's standard backup rotation schedule; (f) Necessary to resolve disputes or enforce the Agreement.


5. International Transfers

5.1 Transfers Outside UK

The Processor shall not transfer Personal Data to a country outside the United Kingdom unless:

(a) The transfer is to a country that has been deemed to provide an adequate level of protection by the UK government; (b) Appropriate safeguards are in place, such as Standard Contractual Clauses approved by the UK Information Commissioner; (c) One of the derogations in Article 49 of the UK GDPR applies; (d) The Controller has provided prior written authorisation.

5.2 Sub-processor Transfers

Where Sub-processors are located outside the United Kingdom, the Processor shall ensure that appropriate safeguards are in place for such transfers in accordance with Section 5.1.

5.3 Notification of Changes

The Processor shall notify the Controller of any changes to the location of Processing or the safeguards in place for international transfers.


6. Liability

6.1 Liability Cap

The liability of each party under this DPA shall be subject to the limitations and exclusions of liability set out in the Agreement.

6.2 Indemnification

Each party shall indemnify the other against all liabilities, costs, expenses, damages, and losses (including legal fees) arising out of or in connection with any breach of this DPA by that party.


7. Term and Termination

7.1 Term

This DPA shall commence on the date the Controller first accesses the Services and shall continue for the duration of the Agreement.

7.2 Survival

Sections 4.9 (Deletion and Return of Data), 6 (Liability), and any other provisions that by their nature should survive, shall survive termination of this DPA.


8. General

8.1 Amendments

This DPA may be amended by the Processor from time to time to reflect changes in Data Protection Laws, regulatory guidance, or our Processing activities. Material changes will be notified to the Controller in accordance with the Agreement.

8.2 Conflict

In the event of any conflict between this DPA and the Agreement, this DPA shall prevail with respect to the Processing of Personal Data.

8.3 Governing Law

This DPA shall be governed by and construed in accordance with the laws of England and Wales.


Schedule 1: Details of Processing

1. Subject Matter

The Processing of Personal Data in connection with the provision of the Letably lettings and property management platform.

2. Duration

The duration of the Agreement plus the data retention period specified in Section 4.9.

3. Nature and Purpose of Processing

The Processor will Process Personal Data for the purpose of providing the Services, including:

  • Storage and retrieval of Personal Data
  • Display of Personal Data within the platform interface
  • Transmission of Personal Data (e.g., email notifications, agreement signing links)
  • Generation of documents containing Personal Data (tenancy agreements, financial statements, inventory reports)
  • Facilitating digital signatures
  • File storage (identity documents, certificates, photographs)
  • Backup and disaster recovery
  • Technical support and troubleshooting

4. Categories of Data Subjects

  • Tenants and prospective tenants
  • Guarantors
  • Landlords and property owners
  • Letting agency staff and employees
  • Viewing request applicants
  • Other individuals whose data is uploaded by the Controller

5. Categories of Personal Data

Tenant/Applicant Data:

  • Name, date of birth, nationality
  • Contact details (address, email, phone)
  • Address history
  • Identity document information (passport, driving licence)
  • Identity document images/scans
  • Right to Rent check information
  • Employment and income details
  • University and student details (student applicants)
  • Previous tenancy history and landlord references
  • Payment schedules and payment history
  • Digital signatures and signing audit trails
  • Maintenance requests and communications
  • Inventory check-in/check-out reports with photographs

Guarantor Data:

  • Name, date of birth, contact details
  • Address
  • Relationship to tenant
  • Identity document information
  • Digital signatures

Landlord Data:

  • Name and contact details
  • Property ownership details
  • Financial statements and payment records

Staff Data:

  • Name and contact details
  • Login credentials (passwords are hashed, never stored in plain text)
  • Activity and audit logs

6. Special Categories of Personal Data

The Controller may upload identity documents that reveal:

  • Racial or ethnic origin (from photographs)
  • Nationality and immigration status

The Controller warrants that it has obtained explicit consent or has another lawful basis for Processing any special category data.

7. Retention

Personal Data will be retained for the duration of the Agreement. Upon termination, Personal Data will be handled in accordance with Section 4.9 of this DPA.


Schedule 2: Security Measures

The Processor implements the following technical and organisational security measures:

1. Infrastructure Security

  • Application hosted on cloud infrastructure with ISO 27001 certified data centres
  • DDoS protection via Cloudflare
  • HTTPS/TLS 1.2+ enforced on all connections
  • Network-level firewalls and access controls

2. Access Controls

  • Role-based access control (RBAC) with agency-scoped data isolation
  • PostgreSQL Row-Level Security (RLS) as secondary data isolation layer
  • Unique user accounts with hashed passwords (bcrypt)
  • JWT-based authentication with configurable expiry
  • Super admin access separated from agency user access

3. Encryption

  • Data in transit: TLS 1.2 or higher on all connections
  • Data at rest: Cloudflare R2 server-side encryption for all stored files
  • Passwords hashed with bcrypt (never stored in plain text)
  • Sensitive configuration encrypted at rest (SMTP credentials, API keys)

4. Application Security

  • Input validation and sanitisation on all user inputs
  • Protection against OWASP Top 10 vulnerabilities (SQL injection, XSS, CSRF)
  • Rate limiting on authentication and public endpoints
  • Anti-bot protection (Cloudflare Turnstile) on registration
  • File upload validation (type, size, magic bytes)
  • Blocked dangerous file extensions

5. Data Isolation

  • Multi-tenant architecture with explicit agency_id filtering on every database query
  • Row-Level Security policies as defence-in-depth
  • Agency data fully isolated — no cross-agency data access possible
  • File storage namespaced by agency ID in Cloudflare R2

6. Audit Trail

  • Digital signature audit trails (SHA-256 hash, IP address, timestamp, device details)
  • Super admin actions logged with user ID, action type, timestamp, and IP address
  • Login activity tracking

7. Business Continuity

  • Database backups (frequency determined by hosting provider)
  • File storage on Cloudflare R2 with built-in redundancy
  • Application deployable from source control

8. Incident Management

  • Platform alert system for security-relevant events
  • Support ticket system for breach reporting
  • Breach notification process aligned with 48-hour DPA requirement

9. Personnel

  • Access to production systems limited to authorised personnel
  • Confidentiality obligations in place

Schedule 3: Approved Sub-processors

The following Sub-processors are approved to Process Personal Data on behalf of the Controller:

Sub-processorPurposeLocationData Processed
OVHApplication and database hostingUK (OVH London data centre)All application and database data
CloudflareCDN, DNS, DDoS protection, SSL terminationGlobal (EU processing)All data in transit, request metadata
Cloudflare R2File storage (documents, images, certificates)Western Europe (EU)Uploaded files including identity documents
Mailgun (Sinch)Transactional email deliveryEUEmail addresses, names, email content
StripeSubscription payment processingUSA (EU-US DPF)Agency billing details (not tenant data)

This list will be updated from time to time. The Controller will be notified of any changes in accordance with Section 4.4 of this DPA.


This Data Processing Agreement was last updated on 22 March 2026.