Legal
Tenote ("we", "us", "our") operates the property maintenance reporting platform available at www.tenote.co.uk. We are the data controller for the personal data described in this policy, subject to the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, overseen by the Information Commissioner's Office (ICO).
We are not legally required to appoint a Data Protection Officer under UK GDPR Article 37 and have not done so. All data protection queries should be directed to the contact address above.
When a letting agency signs up for or enquires about Tenote, we collect:
We also collect usage data through session analytics — pages visited, features used, and session duration — to understand how agents interact with the platform and to improve the product.
Tenants submit maintenance reports via a unique link provided by their letting agent. Tenants do not create an account and are not required to register. When a tenant submits a report, we collect:
We do not collect tenant names, email addresses, or contact details unless voluntarily included in the body of the report. Tenant submissions are associated with the property and the relevant letting agency, not with a personal identity.
We use Google Firebase Analytics to understand usage patterns across the platform. Firebase Analytics processes approximate location derived from IP, browser type, device type, operating system, and pages visited. Raw IP addresses are processed server-side by Google and are not accessible to us through the analytics dashboard. This data is used in aggregated form and is not linked to individual identities. Analytics only runs with your consent and sets cookies (see section 8).
Standard server logs (including IP addresses, request timestamps, and response codes) are generated automatically by our hosting infrastructure and retained for security and debugging purposes.
We rely on the following legal bases under UK GDPR to process personal data:
Where we rely on your consent to process personal data, you may withdraw that consent at any time by contacting us at hello@tenote.co.uk or by using the unsubscribe link in any marketing communication. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
We use the personal data we collect for the following purposes:
We do not sell personal data to third parties. We do not use personal data for automated decision-making or profiling that produces legal or similarly significant effects on individuals.
We work with a small number of carefully chosen third-party service providers who process data on our behalf. All processors are contractually bound under Article 28 UK GDPR to handle data only as instructed by us and in accordance with applicable data protection law.
| Processor | Purpose | Data processed | Location |
|---|---|---|---|
| Vercel | Frontend hosting and content delivery | All data passing through the web application | USA (safeguards below) |
| Fly.io | Backend API hosting and application runtime | Agent and tenant data processed by the API | USA (safeguards below) |
| Resend | Transactional email delivery | Recipient email addresses and message content | USA (safeguards below) |
| Google Firebase / Analytics | Platform analytics and usage insights | Aggregated usage data, approximate location | USA (safeguards below) |
| Cloudflare | DNS, CDN, and DDoS protection | Network traffic metadata | USA (safeguards below) |
Your data is stored in the UK (London) and the EU, and some of our suppliers process it in the US. Where a provider outside the UK can access it, we rely on UK adequacy regulations, the UK–US data bridge, or the ICO's International Data Transfer Agreement or UK Addendum.
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by law.
Under UK GDPR, you have the following rights in relation to your personal data. We will respond to all data subject requests within one calendar month of receipt. In complex cases we may extend this by a further two months, in which case we will notify you within the first month.
You have the right to request a copy of the personal data we hold about you (a Subject Access Request). Submit your request to hello@tenote.co.uk.
If any data we hold about you is inaccurate or incomplete, you have the right to ask us to correct it. Account holders can update most information directly within the platform.
You have the right to request deletion of your personal data where it is no longer necessary for the purpose it was collected, where you withdraw consent, or where processing is unlawful. We may retain certain data to comply with legal obligations or resolve disputes.
Where we process your data by automated means on the basis of contract or consent, you have the right to receive your data in a structured, commonly used, machine-readable format, and to transmit it to another controller. Account holders can export their maintenance report data from within the platform at any time.
You have the right to object to processing based on our legitimate interests. We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or where processing is necessary for legal claims.
You may request that we restrict processing of your data — for example, while we investigate a dispute about its accuracy or our legal basis for processing it.
You have the right not to be subject to decisions made solely by automated processing that produce legal or similarly significant effects. We do not conduct such processing.
If you are unhappy with how we have handled your personal data, you have the right to lodge a complaint with the Information Commissioner's Office:
We would appreciate the opportunity to address your concerns directly before you contact the ICO. Please reach out to us first at hello@tenote.co.uk.
With your consent, we use Google Analytics, which sets cookies (such as _ga). It stays off unless you click Accept, and you can change your choice any time under Cookie settings.
We may use essential browser storage (localStorage or sessionStorage) for strictly functional purposes — for example, to maintain your login session or store UI preferences. Under the Privacy and Electronic Communications Regulations 2003 (PECR), consent is not required for strictly necessary storage.
We take reasonable technical and organisational measures to protect personal data against unauthorised access, loss, or disclosure. These include HTTPS encryption in transit, access controls on our backend systems, and network-level protection via Cloudflare. No system is completely secure, and we cannot guarantee absolute security.
If we become aware of a personal data breach likely to result in a risk to individuals' rights and freedoms, we will notify the ICO within 72 hours and affected individuals without undue delay where required under UK GDPR Article 33.
Tenote is a business-to-business platform intended for use by professional letting agents and their tenants. Our service is not directed at children under the age of 18, and we do not knowingly collect personal data from children. If you believe we have received data from a child, please contact us and we will delete it promptly.
We may update this Privacy Policy from time to time. When we make material changes, we will update the version number and "Last updated" date at the top of this page and, where appropriate, notify active account holders by email at least 30 days before changes take effect. If you object to any material changes, you may close your account and request deletion of your data in accordance with Section 6.
To exercise any of your rights, make a Subject Access Request, or raise a data protection concern:
Tenote — Property maintenance reporting for UK letting agents. Privacy Policy v1.0 — last reviewed 6 October 2026.