GDPR overview

Last updated: 21 July 2026

This page explains how Tenlord approaches UK GDPR and EU GDPR when providing software to landlords, tenants, and website visitors. It summarises roles, lawful bases, rights, and practical expectations. It is not legal advice. For full detail on collection and use of personal data, see our privacy policy. For cookies, see our cookie policy.

1. Scope
This overview applies to personal data processed in connection with:

  • Accounts, authentication, billing, and product administration.
  • Landlord–tenant messaging, maintenance, documents, and compliance workflows.
  • Website visits, support requests, and (where consented) analytics.

2. Controller and processor roles

Under GDPR, the “controller” decides why and how personal data is processed. A “processor” processes data on a controller's documented instructions.

  • Tenlord as controller: for account registration, login security, subscription billing, website operations, support tickets you send to us, and product analytics where we determine the purposes (subject to consent for non-essential cookies).
  • Landlord as controller / Tenlord as processor: when a landlord uses Tenlord to store or process tenant details, tenancy records, maintenance media, documents, or messages about a tenancy, the landlord typically determines the purpose (managing their properties and tenancies). In that capacity, Tenlord processes that data on the landlord's instructions as a processor.
  • Tenants: when you create or use a tenant account, Tenlord may be controller for your account data, while tenancy content managed through a landlord workspace may remain under the landlord's controllership for GDPR purposes.

Landlords using Tenlord for tenant personal data should ensure they have a lawful basis, provide appropriate privacy information to tenants, and only upload data they are entitled to process. If you need a formal Data Processing Addendum (DPA), contact privacy@tenlord.uk.

3. Categories of personal data
Depending on how the Service is used, processing may include:

  • Identity and contact data (name, email, phone).
  • Account and authentication data (hashed credentials, roles, session metadata).
  • Property and tenancy operational data (addresses, units, invites, maintenance requests, messages, uploaded documents and images).
  • Billing and subscription metadata (plan, status, payment references via Stripe).
  • Technical logs (IP address, device/browser information, security events).
  • Support correspondence and feedback you send us.

4. Lawful bases
Where Tenlord acts as controller, we typically rely on:

  • Contract — to create and operate your account and deliver the Service you signed up for.
  • Legitimate interests — for security, fraud prevention, service reliability, and limited product improvement, balanced against your rights.
  • Legal obligation — where we must retain or disclose information to comply with law.
  • Consent — for optional analytics cookies and any other processing that requires consent.

Where Tenlord acts as processor for landlord-controlled tenancy data, the landlord is responsible for establishing and documenting their own lawful basis (commonly contract with the tenant and/or legitimate interests in property management, depending on context).

5. Purpose limitation and data minimisation
We design Tenlord so personal data is collected for stated product purposes — communication, maintenance, documents, compliance reminders, billing, and security — rather than unrelated secondary uses. Landlords should only upload data necessary for those tenancy-management purposes.

6. Sub-processors and sharing
We use trusted service providers to operate Tenlord. Categories typically include:

  • Cloud hosting and infrastructure.
  • Transactional email delivery.
  • Payment processing (Stripe).
  • Error and performance monitoring (for example Sentry).
  • Analytics providers (Google Analytics) — only where consent is granted.

Providers process data under contracts that require appropriate confidentiality and security measures. We do not sell personal data.

7. International transfers
Personal data may be processed in the United Kingdom, the EEA, or other countries where our providers operate. Where transfers leave the UK/EEA, we use appropriate safeguards required by applicable law, such as adequacy regulations or standard contractual clauses, together with supplementary measures where needed.

8. Retention
We retain personal data only as long as needed for the purposes described in our privacy policy, to resolve disputes, enforce agreements, and meet legal retention duties. Retention periods vary by data type (for example account records vs security logs vs billing records). When data is no longer required, we delete or anonymise it where practicable.

Landlords who close their account or remove tenant relationships should consider what data they still need for their own legal obligations before requesting deletion.

9. Security measures
We apply technical and organisational measures appropriate to the risk, including:

  • Encrypted connections (HTTPS/TLS) in transit.
  • Hashed password storage and session cookie controls.
  • Access controls and monitoring for abuse or unauthorised access.
  • Vendor due diligence for key sub-processors.

No online service can guarantee absolute security. Please use strong unique passwords and report suspected incidents promptly to privacy@tenlord.uk.

10. Personal data breaches
If a personal data breach occurs that is likely to result in a risk to individuals' rights and freedoms, we will assess and, where required by UK/EU GDPR, notify the relevant supervisory authority without undue delay and, where required, affected individuals. Where Tenlord acts as processor, we will notify the relevant controller (typically the landlord) without undue delay after becoming aware of a breach affecting their data.

11. Your rights
Depending on applicable law and our role (controller vs processor), individuals may have rights to:

  • Access personal data.
  • Rectify inaccurate data.
  • Erase data in certain circumstances.
  • Restrict or object to certain processing.
  • Data portability.
  • Withdraw consent where processing is consent-based.
  • Lodge a complaint with the ICO (UK) or another supervisory authority.

To exercise rights against Tenlord as controller, email privacy@tenlord.uk. We may need to verify identity. If your request relates to data a landlord controls in their workspace, we may direct you to that landlord or handle the request in coordination with them as required by GDPR.

12. Children
Tenlord is intended for users aged 18 and over. We do not knowingly offer the Service to children.

13. Related documents

14. Contact and complaints
Privacy and data protection: privacy@tenlord.uk
Support: support@tenlord.uk

You can also contact the UK Information Commissioner's Office (ICO) at ico.org.uk. EEA users may contact their local supervisory authority.

Tenlord - GDPR overview