Privacy Policy
Last updated: 19 June 2026
This page is maintained by EstateVera Ltd to answer common questions about how the EstateVera service handles your information. It is editable content, not an independent certification.
EstateVera Ltd ("EstateVera", "we", "us") operates the EstateVera property compliance platform. This policy explains what personal data we collect, how we use it, and the rights you have under the UK GDPR and the Data Protection Act 2018.
1. Who is the data controller
For account data (name, email, billing, settings) EstateVera is the controller. For information you upload about your tenants, contractors and properties, you remain the controller and EstateVera acts as a processor under our Data Processing Addendum.
2. What data we collect
- Account data: name, email, phone, company, password hash.
- Portfolio data: property addresses, certificates, tenant records, deposit details, maintenance jobs, contractor details.
- Documents: files you upload (certificates, photos, tenancy agreements) and AI-extracted metadata.
- Billing data: handled by our payment processor — we store invoice references only.
- Technical data: IP address, browser, device, logs needed to run and secure the service.
3. How we use it
- To provide the compliance, document vault, reminder and reporting features you sign up for.
- To send service emails (renewal alerts, maintenance updates) and, with consent, product updates.
- To detect abuse, debug issues, and improve the product.
- To comply with our legal obligations.
4. Legal bases
We rely on (a) contract to deliver the service you've subscribed to, (b) legitimate interests to secure, improve and market the product, (c) consent for optional cookies and marketing, and (d) legal obligation for tax and accounting records.
5. Sharing & subprocessors
We share data only with vetted subprocessors who help run the service — including cloud hosting, database, email delivery, AI document extraction, and payment providers. A current list is available on request.
6. International transfers
Data is hosted in the UK/EU where possible. Where data is transferred outside the UK/EEA we rely on UK Addenda to the EU Standard Contractual Clauses.
7. Retention
Account and portfolio data is kept while your subscription is active and for 90 days after cancellation to allow recovery, then deleted or anonymised. Invoices are kept for 6 years to meet HMRC requirements.
8. Your rights
- Access, rectify, erase or port your personal data.
- Restrict or object to certain processing.
- Withdraw consent at any time.
- Complain to the ICO (ico.org.uk).
9. Contact
Privacy questions: privacy@EstateVera.app.
