1. Who we are
LETLOGIC SOFTWARE LTD is the controller of personal data used to run our website, manage prospective and existing customer relationships, administer accounts, bill customers, keep the service secure and understand service performance.
Letting agencies also enter personal data about their staff, tenants, landlords, contractors and other contacts into LetLogic. For that operational Customer Data, the agency is normally the controller and we act as its processor. Requests about records held by an agency should usually be made to that agency first. Our Data Processing Agreement explains this relationship.
2. Personal data we collect
Depending on how you interact with us, we may collect:
- identity and contact data, including name, work email, telephone number, employer, job role and agency details;
- account data, including user ID, role, permissions, sign-in records, authentication and security information;
- commercial data, including trial, plan, managed-property allowance, subscription, invoice, payment status and correspondence;
- support and communication data, including messages, feedback and records of help requests;
- technical data, including IP address, browser, device, operating system, page or feature activity, timestamps, error and security logs; and
- cookie choices and analytics data where you allow optional analytics.
When we act for an agency, Customer Data may include property and tenancy records, dates of birth, contact details, landlord payment references, rent and deposit information, maintenance and access notes, messages, documents, appointments and portal activity. The agency decides what it enters and why it is processed.
The agency name, account administrator's name and work email are contractually required to create a trial workspace and administer the service. If they are not provided, we cannot create or manage that account. Other fields are identified as optional where they are not needed for signup.
3. Where data comes from
We receive data directly from you, from the organisation that creates or manages your account, from activity within the service, from our payment and infrastructure providers and, where appropriate, from public business sources. Portal-user data is commonly supplied by or collected on behalf of the relevant letting agency.
4. Why we use data and our legal bases
- Trials, accounts and the service: to take steps at a business customer's request, perform our contract and pursue our legitimate interest in providing the service.
- Billing and business records: to perform the contract, collect charges and comply with tax, accounting and legal duties.
- Support and service messages: to perform the contract and pursue our legitimate interests in helping users and operating the service.
- Security, fraud prevention and diagnostics: for our legitimate interests in protecting users, the service and our business, and to meet legal duties.
- Product improvement and basic service measurement: for our legitimate interests in understanding reliability and improving the service, using proportionate data.
- Optional analytics: with consent where consent is required. You can change this choice at any time.
- Legal claims and regulatory requests: to comply with law and for our legitimate interests in establishing, exercising or defending legal rights.
Where we rely on legitimate interests, we consider the purpose, necessity and impact on individuals. You may object to this processing in the circumstances described below.
5. When an agency controls the data
An agency is responsible for giving its own privacy information, selecting appropriate access permissions, establishing a lawful basis and responding to requests about Customer Data. We process that data only on documented instructions, to provide and secure the service, as required by law, or as otherwise set out in the Data Processing Agreement.
6. Who receives personal data
We do not sell personal data. We may disclose it to:
- authorised users within the relevant agency workspace, according to their assigned role and permissions;
- hosting, database, authentication, storage, email, analytics and technical-support providers;
- Stripe and related providers for checkout, subscription administration, fraud prevention and payment processing;
- our professional advisers, insurers, auditors and prospective purchasers under appropriate confidentiality duties; and
- courts, regulators, law-enforcement bodies or other parties where disclosure is legally required or necessary to protect rights and security.
Providers that process Customer Data for us are listed on our Subprocessor List.
7. International transfers
Some providers may process data outside the United Kingdom. Where required, we use an adequacy regulation or appropriate safeguards such as the UK International Data Transfer Agreement or UK Addendum to approved standard contractual clauses, together with supplementary measures where appropriate. You may ask us for information about the safeguard relevant to your data.
8. How long we keep data
We keep personal data only for as long as needed for the purpose for which it was collected. In general:
- account and customer-relationship records are kept during the subscription and for a reasonable period afterwards to deal with queries, disputes and legal claims;
- billing, contract and tax records may be kept for up to six years after the relevant transaction or relationship ends, or longer if law requires;
- unsuccessful trial and enquiry details are reviewed and deleted or anonymised when no longer needed for follow-up or legal records;
- security and diagnostic logs are retained for proportionate periods and longer where an incident must be investigated; and
- Customer Data is returned or deleted under the agency's instructions and our Data Processing Agreement, subject to legal retention requirements and protected backup cycles.
9. Security
We use proportionate technical and organisational measures designed to protect personal data, including role-based access, authentication controls, encrypted connections, managed infrastructure, access restrictions, backups, logging and procedures for responding to incidents. No internet service is completely secure, so we cannot guarantee absolute security.
10. Your data-protection rights
Depending on the circumstances, UK data-protection law gives you rights to be informed; request access, correction or erasure; restrict processing; object to processing; receive certain data in a portable format; and withdraw consent without affecting earlier lawful processing. These rights can be limited where an exemption applies.
Email chris.harris@letlogic.co.uk to exercise a right. We may need to verify your identity. If the request concerns an agency's Customer Data, we may refer it to that agency or assist the agency in responding.
Your right to object: where we rely on legitimate interests, you may object because of your particular situation. We will stop the relevant processing unless we have compelling legitimate grounds that override your interests, rights and freedoms, or the processing is needed for legal claims.
11. Complaints
To make a data-protection complaint, email chris.harris@letlogic.co.uk and identify it as a data-protection complaint. We will acknowledge it within 30 days, investigate without undue delay, keep you appropriately informed and communicate the outcome without undue delay.
You also have the right to complain to the Information Commissioner's Office at ico.org.uk/make-a-complaint or by calling 0303 123 1113.
12. Cookies and analytics
We use necessary storage for authentication, security, session continuity and preferences. Optional analytics is not loaded unless the relevant consent choice permits it. Our Cookie Notice lists the technologies used and explains how to change your choice.
13. Automated decisions and children
We do not use personal data to make solely automated decisions that produce legal or similarly significant effects. The service is for business and property-management use and is not directed to children. An agency should not enter children's data unless it has a lawful, necessary reason and appropriate safeguards.
14. Changes and contact
We may update this notice to reflect changes in the service, providers or law. We will change the effective date and give additional notice where a change materially affects how we use personal data.
Privacy questions may be sent to chris.harris@letlogic.co.uk.