Data Processing Terms
Last updated 31 July 2026
These terms form part of the Terms & Conditions and satisfy Article 28(3) of the UK GDPR. They apply automatically to every account — you do not need to sign anything, and there is nothing to request. If your accountant, insurer or a parent company asks whether you have a data processing agreement with your software supplier, this page is it.
In these terms “we” and “us” mean Property Workflow Systems Ltd (registered in England and Wales, company no. 17376073), registered office Unit 6, Orchard Business Units, Cockaynes Lane, Alresford CO7 8BZ. “You” means the operator running a account. Terms such as controller, processor, personal data and processing have the meanings given in the UK GDPR.
1. Who is who
You are the controller of the records you put into the app about your own customers. You decide what to collect, why, how long to keep it and who to share it with, and you are responsible for having a lawful basis to hold it.
We are your processor for that data: we store it and act on it only to provide the service to you.
Separately, we are the controller of your own account details — the account holder’s name and email, the site name, the login credentials and the subscription record. That processing is described in our Privacy Policy and is not covered by these processor terms.
2. What we process, and why
| Subject matter | Providing the UnitLet service to you |
|---|---|
| Duration | For as long as your account exists, plus the deletion period in section 8 |
| Nature and purpose | Storing, organising, displaying, backing up, exporting and transmitting records so you can run your site — including sending messages to your occupiers at your instruction |
| Types of personal data | Names, postal addresses, email addresses, phone numbers; vehicle and insurance details; contract, payment and deposit records; identity-document details and images where you choose to store them; photographs; notes, diary entries and message history |
| Categories of data subject | Your customers, their named secondary contacts, people on your waiting list, and your own staff users |
| Special category data | None is required by the service. Free-text fields could contain it if you type it there; you decide, and you remain the controller if you do. |
3. Our obligations to you
We will:
- Process only on your documented instructions. Your instructions are these terms, the Terms & Conditions, and your use of the app’s features. We will not process the data for any other purpose — we do not mine it, profile it, sell it, or use it to train anything. If we are ever required by law to process it otherwise, we will tell you first unless the law forbids that.
- Keep it confidential. Access is limited to people who need it to run or support the service, and they are bound by confidentiality obligations.
- Secure it with appropriate technical and organisational measures — see section 4.
- Use sub-processors only as set out in section 5.
- Help you answer your customers. The app’s export and record-deletion features are designed so you can satisfy access, rectification, erasure and portability requests yourself, immediately. Where a request cannot be handled that way, we will assist you.
- Help you meet your own obligations on security, breach notification, impact assessments and consultation with the ICO, taking into account what we know and what is available to us.
- Tell you about a personal data breach without undue delay after becoming aware of one, with the detail you need to make your own notification within your 72-hour window.
- Delete or return the data at the end — see section 8.
- Make available the information you need to demonstrate our compliance, and submit to audits — see section 7.
4. Security measures
- All traffic is served over HTTPS; the database and stored files are encrypted at rest by the underlying platform.
- Each site’s data is held under its own tenant identity, on its own web address, with every database query scoped to that tenant. Cross-tenant access is tested automatically as part of our release checks.
- Passwords are stored hashed and salted with a server-side secret; they are never stored or logged in plain text and cannot be read by us.
- Staff logins have roles, so an operator can limit who sees money and settings. Sessions are cookie-based, HTTP-only and expire.
- Repeated failed logins are rate-limited. Form submissions are protected against cross-site request forgery. Inbound webhooks are signature-verified.
- Backups are taken automatically each night to separate object storage and retained for up to 30 days.
- Significant actions are recorded in an activity log visible to you inside the app.
We may change these measures as technology moves, provided the level of protection is not reduced.
5. Sub-processors
You give general authorisation for us to use the sub-processors below. Each is bound by a written agreement with data protection obligations no less protective than these terms.
| Sub-processor | What it does | Where |
|---|---|---|
| Cloudflare, Inc. | Hosting, database, file storage, network security | Database and files in Western Europe; global network |
| Resend (Plus Five Five, Inc.) | Sending email — your reminders, notices, invoices, agreement and portal links | United States |
| Twilio Inc. | Sending and receiving text messages — only if you connect your own Twilio account | United States / your chosen region |
GoCardless and Stripe are not our sub-processors. If you connect one, you contract with them directly and they act as controller or processor under their own agreement with you. Paddle is our reseller and Merchant of Record for your subscription and is a controller of your billing data under its own terms.
We will give you at least 30 days’ notice by email before adding or replacing a sub-processor. If you reasonably object on data protection grounds, tell us within those 30 days and we will either propose a change or you may cancel your subscription without penalty and export your data.
6. International transfers
Where personal data is transferred outside the UK — principally to the United States providers named above — the transfer is covered by the UK Information Commissioner’s International Data Transfer Addendum to the EU Standard Contractual Clauses, or another safeguard approved under Article 46 of the UK GDPR, in each provider’s data processing agreement. We do not transfer your data anywhere else.
7. Audits and information
We will answer reasonable written questions about how we handle your data, and provide what you need to demonstrate compliance. If you require an on-site or third-party audit, we will co-operate with one audit in any twelve-month period, on at least 30 days’ notice, at your cost, during business hours, without unreasonably disrupting the service and subject to confidentiality — or more often if a supervisory authority requires it.
8. Return and deletion
You can export everything yourself at any time from Settings, as spreadsheets and as a full backup, and that stays available even if your subscription lapses and the account goes read-only.
When you tell us to close the account, we delete the account, its business records, uploaded files and its backups within 30 days, except anything we must keep by law (for example transaction records for tax). Export first — after deletion we cannot get it back.
9. Liability and precedence
These terms are subject to the limits of liability in the Terms & Conditions. If anything here conflicts with those terms, these terms win, but only for matters of data protection.
10. Contact
Data protection questions, breach notifications and audit requests: hello@unitlet.co.uk. There is no ticket system — it reaches a person.
© 2026 Property Workflow Systems Ltd, trading as UnitLet · Registered in England and Wales, company no. 17376073 · Registered office: Unit 6, Orchard Business Units, Cockaynes Lane, Alresford CO7 8BZ