Legal

Privacy Policy

Version 1.0 · Last updated 6 October 2026

1. Who we are

Tenote ("we", "us", "our") operates the property maintenance reporting platform available at www.tenote.co.uk. We are the data controller for the personal data described in this policy, subject to the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, overseen by the Information Commissioner's Office (ICO).

Data controller contact details
Tenote
Email: hello@tenote.co.uk
Correspondence address: Available on request

We are not legally required to appoint a Data Protection Officer under UK GDPR Article 37 and have not done so. All data protection queries should be directed to the contact address above.

2. What data we collect

2.1 Letting agents (account holders)

When a letting agency signs up for or enquires about Tenote, we collect:

  • Agency or business name
  • Contact person's name
  • Business email address
  • Phone number (optional)
  • Approximate number of managed properties (for service sizing)
  • Current software or workflow used (optional, onboarding only)
  • Billing information (processed by our payment provider — we do not store full card details)

We also collect usage data through session analytics — pages visited, features used, and session duration — to understand how agents interact with the platform and to improve the product.

2.2 Tenants (report submitters)

Tenants submit maintenance reports via a unique link provided by their letting agent. Tenants do not create an account and are not required to register. When a tenant submits a report, we collect:

  • A description of the maintenance issue they are reporting
  • Photographs or images they choose to upload to support their report
  • Any other information they voluntarily include in their submission

We do not collect tenant names, email addresses, or contact details unless voluntarily included in the body of the report. Tenant submissions are associated with the property and the relevant letting agency, not with a personal identity.

2.3 Technical and analytics data

We use Google Firebase Analytics to understand usage patterns across the platform. Firebase Analytics processes approximate location derived from IP, browser type, device type, operating system, and pages visited. Raw IP addresses are processed server-side by Google and are not accessible to us through the analytics dashboard. This data is used in aggregated form and is not linked to individual identities. Analytics only runs with your consent and sets cookies (see section 8).

Standard server logs (including IP addresses, request timestamps, and response codes) are generated automatically by our hosting infrastructure and retained for security and debugging purposes.

3. Legal basis for processing

We rely on the following legal bases under UK GDPR to process personal data:

  • Contract (Article 6(1)(b)): Processing agent account data is necessary to provide the Tenote service under our Terms of Service.
  • Legitimate interests (Article 6(1)(f)): We process usage analytics and server logs to maintain platform security, fix bugs, and improve the service. We have conducted a Legitimate Interests Assessment and concluded that our interests are not overridden by the rights and freedoms of individuals, given the minimal and aggregated nature of the data involved.
  • Legitimate interests (Article 6(1)(f)): Tenant maintenance report content is processed on behalf of the letting agent to enable the core service — logging and communicating property issues. Both the agent and the tenant have a legitimate interest in having maintenance issues properly recorded and acted upon.
  • Legal obligation (Article 6(1)(c)): We may process data where required by applicable UK law, for example in response to a court order or regulatory demand.

Where we rely on your consent to process personal data, you may withdraw that consent at any time by contacting us at hello@tenote.co.uk or by using the unsubscribe link in any marketing communication. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

4. How we use your data

We use the personal data we collect for the following purposes:

  • Providing and operating the Tenote platform, including account setup and management
  • Sending transactional emails such as account confirmations, login links, and report notifications
  • Generating landlord-ready maintenance reports from tenant submissions on behalf of letting agents
  • Processing subscription payments and sending billing-related communications
  • Responding to support requests and enquiries
  • Analysing platform usage to improve features, fix issues, and inform product development
  • Complying with our legal and regulatory obligations

We do not sell personal data to third parties. We do not use personal data for automated decision-making or profiling that produces legal or similarly significant effects on individuals.

5. Third-party data processors

We work with a small number of carefully chosen third-party service providers who process data on our behalf. All processors are contractually bound under Article 28 UK GDPR to handle data only as instructed by us and in accordance with applicable data protection law.

ProcessorPurposeData processedLocation
VercelFrontend hosting and content deliveryAll data passing through the web applicationUSA (safeguards below)
Fly.ioBackend API hosting and application runtimeAgent and tenant data processed by the APIUSA (safeguards below)
ResendTransactional email deliveryRecipient email addresses and message contentUSA (safeguards below)
Google Firebase / AnalyticsPlatform analytics and usage insightsAggregated usage data, approximate locationUSA (safeguards below)
CloudflareDNS, CDN, and DDoS protectionNetwork traffic metadataUSA (safeguards below)

Your data is stored in the UK (London) and the EU, and some of our suppliers process it in the US. Where a provider outside the UK can access it, we rely on UK adequacy regulations, the UK–US data bridge, or the ICO's International Data Transfer Agreement or UK Addendum.

6. Data retention

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by law.

  • Agent account data: Retained for the duration of the active subscription and for up to 12 months following account closure, after which it is deleted or anonymised.
  • Tenant maintenance reports: Retained for the duration of the letting agency's active subscription. When an agency's account is closed, associated maintenance report data is deleted within 90 days of closure, unless the agency has exported or requested retention for legitimate legal purposes. Where a subscription lapses due to non-payment, the same 90-day window applies from the date of account closure.
  • Analytics data: Aggregated analytics data is retained for up to 14 months in line with Firebase Analytics' default retention configuration.
  • Server logs: Typically retained for 30 days for security and debugging, then automatically purged.

7. Your rights under UK GDPR

Under UK GDPR, you have the following rights in relation to your personal data. We will respond to all data subject requests within one calendar month of receipt. In complex cases we may extend this by a further two months, in which case we will notify you within the first month.

Right of access (Article 15)

You have the right to request a copy of the personal data we hold about you (a Subject Access Request). Submit your request to hello@tenote.co.uk.

Right to rectification (Article 16)

If any data we hold about you is inaccurate or incomplete, you have the right to ask us to correct it. Account holders can update most information directly within the platform.

Right to erasure (Article 17)

You have the right to request deletion of your personal data where it is no longer necessary for the purpose it was collected, where you withdraw consent, or where processing is unlawful. We may retain certain data to comply with legal obligations or resolve disputes.

Right to data portability (Article 20)

Where we process your data by automated means on the basis of contract or consent, you have the right to receive your data in a structured, commonly used, machine-readable format, and to transmit it to another controller. Account holders can export their maintenance report data from within the platform at any time.

Right to object (Article 21)

You have the right to object to processing based on our legitimate interests. We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or where processing is necessary for legal claims.

Right to restriction of processing (Article 18)

You may request that we restrict processing of your data — for example, while we investigate a dispute about its accuracy or our legal basis for processing it.

Right not to be subject to automated decisions (Article 22)

You have the right not to be subject to decisions made solely by automated processing that produce legal or similarly significant effects. We do not conduct such processing.

Right to complain to the ICO

If you are unhappy with how we have handled your personal data, you have the right to lodge a complaint with the Information Commissioner's Office:

Information Commissioner's Office
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Telephone: 0303 123 1113
Website: ico.org.uk

We would appreciate the opportunity to address your concerns directly before you contact the ICO. Please reach out to us first at hello@tenote.co.uk.

8. Cookies and local storage

With your consent, we use Google Analytics, which sets cookies (such as _ga). It stays off unless you click Accept, and you can change your choice any time under Cookie settings.

We may use essential browser storage (localStorage or sessionStorage) for strictly functional purposes — for example, to maintain your login session or store UI preferences. Under the Privacy and Electronic Communications Regulations 2003 (PECR), consent is not required for strictly necessary storage.

9. Security

We take reasonable technical and organisational measures to protect personal data against unauthorised access, loss, or disclosure. These include HTTPS encryption in transit, access controls on our backend systems, and network-level protection via Cloudflare. No system is completely secure, and we cannot guarantee absolute security.

If we become aware of a personal data breach likely to result in a risk to individuals' rights and freedoms, we will notify the ICO within 72 hours and affected individuals without undue delay where required under UK GDPR Article 33.

10. Children's data

Tenote is a business-to-business platform intended for use by professional letting agents and their tenants. Our service is not directed at children under the age of 18, and we do not knowingly collect personal data from children. If you believe we have received data from a child, please contact us and we will delete it promptly.

11. Changes to this policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the version number and "Last updated" date at the top of this page and, where appropriate, notify active account holders by email at least 30 days before changes take effect. If you object to any material changes, you may close your account and request deletion of your data in accordance with Section 6.

12. Contact us

To exercise any of your rights, make a Subject Access Request, or raise a data protection concern:

Tenote — Data Enquiries
Email: hello@tenote.co.uk
Correspondence: Tenote, 71–75 Shelton Street, Covent Garden, London, WC2H 9JQ
We will respond to all data subject requests within one calendar month.

Tenote — Property maintenance reporting for UK letting agents. Privacy Policy v1.0 — last reviewed 6 October 2026.