Privacy Policy
Letably Privacy Policy
Last updated: [DATE]
1. Introduction
This Privacy Policy explains how Letably Ltd ("Letably", "we", "us", or "our") collects, uses, discloses, and protects personal data when you use our website and cloud-based property management platform (the "Service").
We are committed to protecting your privacy and handling your personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
Please read this Privacy Policy carefully. By accessing or using the Service, you acknowledge that you have read and understood this Privacy Policy.
2. Data Controller Information
For personal data relating to our customers (letting agencies, property managers, and their staff), Letably is the Data Controller.
Letably Ltd Company Number: [NUMBER] Registered Address: [ADDRESS]
Data Protection Contact: [EMAIL] ICO Registration Number: [NUMBER]
3. Important Information for Tenants
If you are a tenant, prospective tenant, guarantor, or landlord whose data has been processed through the Letably platform by a letting agency, please note:
- The letting agency is the Data Controller responsible for your personal data
- Letably acts as a Data Processor on behalf of the letting agency
- You should direct any requests regarding your personal data to the letting agency
- The letting agency's own privacy policy governs how your data is handled
This Privacy Policy primarily describes how we handle the personal data of our customers (letting agencies and their staff), not tenant data.
4. Personal Data We Collect
4.1 Information You Provide
Account Registration Data:
- Full name
- Email address
- Phone number
- Company/business name
- Business address
- Job title/role
Billing Information:
- Billing name and address
- VAT number (if applicable)
- Payment card details are collected and processed directly by our payment processor and are not stored on our systems
Communications:
- Support requests and correspondence
- Feedback and survey responses
- Any other information you choose to provide
4.2 Information Collected Automatically
Usage Data:
- Features accessed and actions taken within the Service
- Time, frequency, and duration of activities
- Browser type and version
- Operating system
- Device information
Technical Data:
- IP address
- Login timestamps
- Access logs
- Error logs and diagnostic data
Cookies and Similar Technologies:
- See Section 10 (Cookies) for details
4.3 Information from Third Parties
We may receive personal data from:
- Payment processors (transaction confirmations, not full card details)
- Analytics providers (aggregated usage data)
- Business partners (referral information, with your consent)
5. How We Use Your Personal Data
5.1 Purposes and Legal Bases
| Purpose | Legal Basis |
|---|---|
| Providing and maintaining the Service | Performance of contract |
| Processing payments and billing | Performance of contract |
| Creating and managing your account | Performance of contract |
| Responding to support requests | Performance of contract |
| Sending service-related communications (e.g., maintenance notices, security alerts) | Performance of contract / Legitimate interests |
| Improving and developing the Service | Legitimate interests |
| Analysing usage patterns and trends | Legitimate interests |
| Preventing fraud and ensuring security | Legitimate interests / Legal obligation |
| Complying with legal obligations | Legal obligation |
| Sending marketing communications (where consented) | Consent |
| Enforcing our Terms of Service | Legitimate interests |
5.2 Legitimate Interests
Where we rely on legitimate interests as a legal basis, we have conducted a balancing assessment to ensure our interests do not override your rights and freedoms. Our legitimate interests include:
- Operating and improving our business and Service
- Understanding how customers use the Service
- Ensuring the security and integrity of the Service
- Preventing fraud and abuse
- Marketing our services to existing customers (with opt-out)
You have the right to object to processing based on legitimate interests. See Section 8 for details.
5.3 Marketing Communications
We will only send you marketing communications where:
- You have given your consent; or
- You are an existing customer and we are marketing similar services, and you have not opted out.
You can opt out of marketing communications at any time by:
- Clicking the "unsubscribe" link in any marketing email
- Contacting us at [EMAIL]
- Updating your preferences in your Account settings
Opting out of marketing will not affect service-related communications.
6. Data Sharing and Disclosure
6.1 Service Providers
We share personal data with third-party service providers who perform services on our behalf, including:
| Provider Type | Purpose | Data Shared |
|---|---|---|
| Cloud hosting provider | Infrastructure and data storage | All Service data |
| Payment processor | Payment processing | Billing data |
| Email service provider | Transactional and marketing emails | Email address, name |
| Analytics provider | Usage analytics | Anonymised/pseudonymised usage data |
| Customer support tools | Support ticket management | Contact details, support correspondence |
All service providers are contractually bound to protect personal data and may only process it for the specified purposes.
6.2 Legal Requirements
We may disclose personal data where required by law or in response to:
- Court orders, subpoenas, or legal process
- Requests from law enforcement or regulatory authorities
- To protect our rights, property, or safety, or that of others
- To detect, prevent, or address fraud, security, or technical issues
6.3 Business Transfers
In the event of a merger, acquisition, reorganisation, or sale of assets, personal data may be transferred to the successor entity. We will notify you of any such transfer and any choices you may have.
6.4 With Your Consent
We may share personal data with third parties where you have given your explicit consent.
6.5 No Sale of Personal Data
We do not sell personal data to third parties.
7. International Data Transfers
7.1 Location of Data
We primarily store and process personal data within the United Kingdom and European Economic Area (EEA).
7.2 Transfers Outside UK/EEA
Where we transfer personal data outside the UK or EEA, we ensure appropriate safeguards are in place, including:
- Transfers to countries with an adequacy decision from the UK government
- Standard Contractual Clauses (SCCs) approved by the UK Information Commissioner
- Other safeguards permitted under UK GDPR
7.3 Sub-processor Locations
Our current sub-processors and their locations are listed in Section 6.1. We will update this Privacy Policy if there are material changes to sub-processor locations.
8. Your Rights
Under UK GDPR, you have the following rights regarding your personal data:
8.1 Right of Access
You have the right to request a copy of the personal data we hold about you, along with information about how we process it.
8.2 Right to Rectification
You have the right to request that we correct any inaccurate personal data or complete any incomplete personal data.
8.3 Right to Erasure
You have the right to request that we delete your personal data in certain circumstances, including:
- The data is no longer necessary for the purposes for which it was collected
- You withdraw consent (where consent was the legal basis)
- You object to processing and there are no overriding legitimate grounds
- The data has been unlawfully processed
We may retain certain data where we have a legal obligation or legitimate need to do so.
8.4 Right to Restriction
You have the right to request that we restrict processing of your personal data in certain circumstances, including:
- You contest the accuracy of the data
- The processing is unlawful but you do not want erasure
- We no longer need the data but you need it for legal claims
- You have objected to processing pending verification of legitimate grounds
8.5 Right to Data Portability
You have the right to receive your personal data in a structured, commonly used, machine-readable format and to transmit it to another controller, where:
- Processing is based on consent or contract; and
- Processing is carried out by automated means.
8.6 Right to Object
You have the right to object to processing based on legitimate interests or for direct marketing purposes. Where you object to direct marketing, we will stop processing for that purpose.
8.7 Rights Related to Automated Decision-Making
We do not currently make decisions based solely on automated processing that produce legal or similarly significant effects. If this changes, we will update this Privacy Policy and provide appropriate safeguards.
8.8 Exercising Your Rights
To exercise any of these rights, please contact us at:
Email: [EMAIL]
We will respond to your request within one month. This period may be extended by two months where requests are complex or numerous, in which case we will inform you of the extension and reasons.
We may request information to verify your identity before processing your request.
There is no fee for exercising your rights unless requests are manifestly unfounded or excessive, in which case we may charge a reasonable fee or refuse to act.
8.9 Right to Complain
You have the right to lodge a complaint with the Information Commissioner's Office (ICO) if you believe we have not handled your personal data in accordance with data protection law:
Information Commissioner's Office Wycliffe House, Water Lane Wilmslow, Cheshire SK9 5AF
Website: ico.org.uk Helpline: 0303 123 1113
We would appreciate the opportunity to address your concerns before you contact the ICO, so please contact us first.
9. Data Retention
9.1 Retention Periods
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including to satisfy legal, accounting, or reporting requirements.
| Data Category | Retention Period |
|---|---|
| Account data (active customers) | Duration of customer relationship |
| Account data (after termination) | 30 days (export period) then deleted |
| Billing and financial records | 7 years (legal requirement) |
| Support correspondence | 3 years from last interaction |
| Security and access logs | 12 months |
| Marketing preferences | Until consent withdrawn or account deleted |
| Anonymised analytics data | Indefinitely |
9.2 Deletion After Termination
When a customer terminates their account:
- Customer Data (including any personal data stored by the customer) will be available for export for 30 days
- After the 30-day export period, Customer Data will be deleted within 90 days
- Backup copies will be deleted in accordance with our backup rotation schedule
- We may retain certain data where legally required or to resolve disputes
9.3 Criteria for Retention
In determining retention periods, we consider:
- The nature and sensitivity of the data
- The purposes for which we process the data
- Applicable legal and regulatory requirements
- Legitimate business needs
- Potential risks of harm from unauthorised use or disclosure
10. Cookies and Similar Technologies
10.1 What Are Cookies
Cookies are small text files placed on your device when you visit a website. They are widely used to make websites work efficiently and provide information to website owners.
10.2 Cookies We Use
Strictly Necessary Cookies
These cookies are essential for the Service to function and cannot be disabled. They include:
| Cookie | Purpose | Duration |
|---|---|---|
| Session ID | Maintains your logged-in session | Session |
| CSRF token | Security - prevents cross-site request forgery | Session |
| Cookie consent | Remembers your cookie preferences | 12 months |
Functional Cookies
These cookies enable enhanced functionality and personalisation:
| Cookie | Purpose | Duration |
|---|---|---|
| Language preference | Remembers your language setting | 12 months |
| UI preferences | Remembers display settings | 12 months |
Analytics Cookies (with consent)
These cookies help us understand how visitors use the Service:
| Cookie | Purpose | Duration |
|---|---|---|
| [Analytics cookies as applicable] | Usage analytics | [Duration] |
10.3 Your Cookie Choices
When you first visit the Service, you will be presented with a cookie banner allowing you to:
- Accept all cookies
- Reject non-essential cookies
- Customise your preferences
You can change your cookie preferences at any time through [cookie settings link/location].
You can also control cookies through your browser settings. Note that disabling certain cookies may affect the functionality of the Service.
10.4 Do Not Track
Some browsers have a "Do Not Track" feature. We currently do not respond to Do Not Track signals.
11. Data Security
11.1 Security Measures
We implement appropriate technical and organisational measures to protect personal data, including:
Technical Measures:
- Encryption of data in transit using TLS 1.2 or higher
- Encryption of data at rest using AES-256 or equivalent
- Secure password hashing
- Multi-factor authentication (where available)
- Regular security assessments and vulnerability scanning
- Intrusion detection and monitoring
- Regular software updates and security patches
- Secure backup procedures
Organisational Measures:
- Access controls based on the principle of least privilege
- Staff training on data protection and security
- Confidentiality obligations for all personnel
- Incident response procedures
- Regular security reviews and audits
- Vendor security assessments
11.2 No Guarantee
While we implement robust security measures, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security.
11.3 Your Responsibilities
You are responsible for:
- Maintaining the confidentiality of your Account credentials
- Using strong, unique passwords
- Enabling multi-factor authentication where available
- Notifying us immediately of any suspected security breach
- Keeping your devices and software secure
12. Children's Privacy
The Service is not intended for individuals under the age of 18. We do not knowingly collect personal data from children. If we become aware that we have collected personal data from a child, we will take steps to delete such data.
13. Third-Party Links
The Service may contain links to third-party websites or services. We are not responsible for the privacy practices of these third parties. We encourage you to read the privacy policies of any third-party websites you visit.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.
We will notify you of material changes by:
- Posting the updated Privacy Policy on our website with a new "Last updated" date
- Sending an email to the address associated with your Account (for material changes)
We encourage you to review this Privacy Policy periodically.
Your continued use of the Service after any changes indicates your acceptance of the updated Privacy Policy.
15. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:
Data Protection Contact Letably Ltd [ADDRESS]
Email: [EMAIL]
We aim to respond to all enquiries within 5 working days.
This Privacy Policy was last updated on [DATE].