Privacy Policy

Letably Privacy Policy

Last updated: [DATE]


1. Introduction

This Privacy Policy explains how Letably Ltd ("Letably", "we", "us", or "our") collects, uses, discloses, and protects personal data when you use our website and cloud-based property management platform (the "Service").

We are committed to protecting your privacy and handling your personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

Please read this Privacy Policy carefully. By accessing or using the Service, you acknowledge that you have read and understood this Privacy Policy.


2. Data Controller Information

For personal data relating to our customers (letting agencies, property managers, and their staff), Letably is the Data Controller.

Letably Ltd Company Number: [NUMBER] Registered Address: [ADDRESS]

Data Protection Contact: [EMAIL] ICO Registration Number: [NUMBER]


3. Important Information for Tenants

If you are a tenant, prospective tenant, guarantor, or landlord whose data has been processed through the Letably platform by a letting agency, please note:

  • The letting agency is the Data Controller responsible for your personal data
  • Letably acts as a Data Processor on behalf of the letting agency
  • You should direct any requests regarding your personal data to the letting agency
  • The letting agency's own privacy policy governs how your data is handled

This Privacy Policy primarily describes how we handle the personal data of our customers (letting agencies and their staff), not tenant data.


4. Personal Data We Collect

4.1 Information You Provide

Account Registration Data:

  • Full name
  • Email address
  • Phone number
  • Company/business name
  • Business address
  • Job title/role

Billing Information:

  • Billing name and address
  • VAT number (if applicable)
  • Payment card details are collected and processed directly by our payment processor and are not stored on our systems

Communications:

  • Support requests and correspondence
  • Feedback and survey responses
  • Any other information you choose to provide

4.2 Information Collected Automatically

Usage Data:

  • Features accessed and actions taken within the Service
  • Time, frequency, and duration of activities
  • Browser type and version
  • Operating system
  • Device information

Technical Data:

  • IP address
  • Login timestamps
  • Access logs
  • Error logs and diagnostic data

Cookies and Similar Technologies:

  • See Section 10 (Cookies) for details

4.3 Information from Third Parties

We may receive personal data from:

  • Payment processors (transaction confirmations, not full card details)
  • Analytics providers (aggregated usage data)
  • Business partners (referral information, with your consent)

5. How We Use Your Personal Data

5.1 Purposes and Legal Bases

PurposeLegal Basis
Providing and maintaining the ServicePerformance of contract
Processing payments and billingPerformance of contract
Creating and managing your accountPerformance of contract
Responding to support requestsPerformance of contract
Sending service-related communications (e.g., maintenance notices, security alerts)Performance of contract / Legitimate interests
Improving and developing the ServiceLegitimate interests
Analysing usage patterns and trendsLegitimate interests
Preventing fraud and ensuring securityLegitimate interests / Legal obligation
Complying with legal obligationsLegal obligation
Sending marketing communications (where consented)Consent
Enforcing our Terms of ServiceLegitimate interests

5.2 Legitimate Interests

Where we rely on legitimate interests as a legal basis, we have conducted a balancing assessment to ensure our interests do not override your rights and freedoms. Our legitimate interests include:

  • Operating and improving our business and Service
  • Understanding how customers use the Service
  • Ensuring the security and integrity of the Service
  • Preventing fraud and abuse
  • Marketing our services to existing customers (with opt-out)

You have the right to object to processing based on legitimate interests. See Section 8 for details.

5.3 Marketing Communications

We will only send you marketing communications where:

  • You have given your consent; or
  • You are an existing customer and we are marketing similar services, and you have not opted out.

You can opt out of marketing communications at any time by:

  • Clicking the "unsubscribe" link in any marketing email
  • Contacting us at [EMAIL]
  • Updating your preferences in your Account settings

Opting out of marketing will not affect service-related communications.


6. Data Sharing and Disclosure

6.1 Service Providers

We share personal data with third-party service providers who perform services on our behalf, including:

Provider TypePurposeData Shared
Cloud hosting providerInfrastructure and data storageAll Service data
Payment processorPayment processingBilling data
Email service providerTransactional and marketing emailsEmail address, name
Analytics providerUsage analyticsAnonymised/pseudonymised usage data
Customer support toolsSupport ticket managementContact details, support correspondence

All service providers are contractually bound to protect personal data and may only process it for the specified purposes.

6.2 Legal Requirements

We may disclose personal data where required by law or in response to:

  • Court orders, subpoenas, or legal process
  • Requests from law enforcement or regulatory authorities
  • To protect our rights, property, or safety, or that of others
  • To detect, prevent, or address fraud, security, or technical issues

6.3 Business Transfers

In the event of a merger, acquisition, reorganisation, or sale of assets, personal data may be transferred to the successor entity. We will notify you of any such transfer and any choices you may have.

6.4 With Your Consent

We may share personal data with third parties where you have given your explicit consent.

6.5 No Sale of Personal Data

We do not sell personal data to third parties.


7. International Data Transfers

7.1 Location of Data

We primarily store and process personal data within the United Kingdom and European Economic Area (EEA).

7.2 Transfers Outside UK/EEA

Where we transfer personal data outside the UK or EEA, we ensure appropriate safeguards are in place, including:

  • Transfers to countries with an adequacy decision from the UK government
  • Standard Contractual Clauses (SCCs) approved by the UK Information Commissioner
  • Other safeguards permitted under UK GDPR

7.3 Sub-processor Locations

Our current sub-processors and their locations are listed in Section 6.1. We will update this Privacy Policy if there are material changes to sub-processor locations.


8. Your Rights

Under UK GDPR, you have the following rights regarding your personal data:

8.1 Right of Access

You have the right to request a copy of the personal data we hold about you, along with information about how we process it.

8.2 Right to Rectification

You have the right to request that we correct any inaccurate personal data or complete any incomplete personal data.

8.3 Right to Erasure

You have the right to request that we delete your personal data in certain circumstances, including:

  • The data is no longer necessary for the purposes for which it was collected
  • You withdraw consent (where consent was the legal basis)
  • You object to processing and there are no overriding legitimate grounds
  • The data has been unlawfully processed

We may retain certain data where we have a legal obligation or legitimate need to do so.

8.4 Right to Restriction

You have the right to request that we restrict processing of your personal data in certain circumstances, including:

  • You contest the accuracy of the data
  • The processing is unlawful but you do not want erasure
  • We no longer need the data but you need it for legal claims
  • You have objected to processing pending verification of legitimate grounds

8.5 Right to Data Portability

You have the right to receive your personal data in a structured, commonly used, machine-readable format and to transmit it to another controller, where:

  • Processing is based on consent or contract; and
  • Processing is carried out by automated means.

8.6 Right to Object

You have the right to object to processing based on legitimate interests or for direct marketing purposes. Where you object to direct marketing, we will stop processing for that purpose.

8.7 Rights Related to Automated Decision-Making

We do not currently make decisions based solely on automated processing that produce legal or similarly significant effects. If this changes, we will update this Privacy Policy and provide appropriate safeguards.

8.8 Exercising Your Rights

To exercise any of these rights, please contact us at:

Email: [EMAIL]

We will respond to your request within one month. This period may be extended by two months where requests are complex or numerous, in which case we will inform you of the extension and reasons.

We may request information to verify your identity before processing your request.

There is no fee for exercising your rights unless requests are manifestly unfounded or excessive, in which case we may charge a reasonable fee or refuse to act.

8.9 Right to Complain

You have the right to lodge a complaint with the Information Commissioner's Office (ICO) if you believe we have not handled your personal data in accordance with data protection law:

Information Commissioner's Office Wycliffe House, Water Lane Wilmslow, Cheshire SK9 5AF

Website: ico.org.uk Helpline: 0303 123 1113

We would appreciate the opportunity to address your concerns before you contact the ICO, so please contact us first.


9. Data Retention

9.1 Retention Periods

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including to satisfy legal, accounting, or reporting requirements.

Data CategoryRetention Period
Account data (active customers)Duration of customer relationship
Account data (after termination)30 days (export period) then deleted
Billing and financial records7 years (legal requirement)
Support correspondence3 years from last interaction
Security and access logs12 months
Marketing preferencesUntil consent withdrawn or account deleted
Anonymised analytics dataIndefinitely

9.2 Deletion After Termination

When a customer terminates their account:

  • Customer Data (including any personal data stored by the customer) will be available for export for 30 days
  • After the 30-day export period, Customer Data will be deleted within 90 days
  • Backup copies will be deleted in accordance with our backup rotation schedule
  • We may retain certain data where legally required or to resolve disputes

9.3 Criteria for Retention

In determining retention periods, we consider:

  • The nature and sensitivity of the data
  • The purposes for which we process the data
  • Applicable legal and regulatory requirements
  • Legitimate business needs
  • Potential risks of harm from unauthorised use or disclosure

10. Cookies and Similar Technologies

10.1 What Are Cookies

Cookies are small text files placed on your device when you visit a website. They are widely used to make websites work efficiently and provide information to website owners.

10.2 Cookies We Use

Strictly Necessary Cookies

These cookies are essential for the Service to function and cannot be disabled. They include:

CookiePurposeDuration
Session IDMaintains your logged-in sessionSession
CSRF tokenSecurity - prevents cross-site request forgerySession
Cookie consentRemembers your cookie preferences12 months

Functional Cookies

These cookies enable enhanced functionality and personalisation:

CookiePurposeDuration
Language preferenceRemembers your language setting12 months
UI preferencesRemembers display settings12 months

Analytics Cookies (with consent)

These cookies help us understand how visitors use the Service:

CookiePurposeDuration
[Analytics cookies as applicable]Usage analytics[Duration]

10.3 Your Cookie Choices

When you first visit the Service, you will be presented with a cookie banner allowing you to:

  • Accept all cookies
  • Reject non-essential cookies
  • Customise your preferences

You can change your cookie preferences at any time through [cookie settings link/location].

You can also control cookies through your browser settings. Note that disabling certain cookies may affect the functionality of the Service.

10.4 Do Not Track

Some browsers have a "Do Not Track" feature. We currently do not respond to Do Not Track signals.


11. Data Security

11.1 Security Measures

We implement appropriate technical and organisational measures to protect personal data, including:

Technical Measures:

  • Encryption of data in transit using TLS 1.2 or higher
  • Encryption of data at rest using AES-256 or equivalent
  • Secure password hashing
  • Multi-factor authentication (where available)
  • Regular security assessments and vulnerability scanning
  • Intrusion detection and monitoring
  • Regular software updates and security patches
  • Secure backup procedures

Organisational Measures:

  • Access controls based on the principle of least privilege
  • Staff training on data protection and security
  • Confidentiality obligations for all personnel
  • Incident response procedures
  • Regular security reviews and audits
  • Vendor security assessments

11.2 No Guarantee

While we implement robust security measures, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security.

11.3 Your Responsibilities

You are responsible for:

  • Maintaining the confidentiality of your Account credentials
  • Using strong, unique passwords
  • Enabling multi-factor authentication where available
  • Notifying us immediately of any suspected security breach
  • Keeping your devices and software secure

12. Children's Privacy

The Service is not intended for individuals under the age of 18. We do not knowingly collect personal data from children. If we become aware that we have collected personal data from a child, we will take steps to delete such data.


13. Third-Party Links

The Service may contain links to third-party websites or services. We are not responsible for the privacy practices of these third parties. We encourage you to read the privacy policies of any third-party websites you visit.


14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.

We will notify you of material changes by:

  • Posting the updated Privacy Policy on our website with a new "Last updated" date
  • Sending an email to the address associated with your Account (for material changes)

We encourage you to review this Privacy Policy periodically.

Your continued use of the Service after any changes indicates your acceptance of the updated Privacy Policy.


15. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:

Data Protection Contact Letably Ltd [ADDRESS]

Email: [EMAIL]

We aim to respond to all enquiries within 5 working days.


This Privacy Policy was last updated on [DATE].