Legal
Data protection
Last updated August 2026
Whether [COMPANY NAME] must register with the Office of the Data Protection Commissioner as a data controller or processor is a threshold question under the Data Protection Act 2019 and its registration regulations. Establish the answer before you take a real client's portfolio, not after. Delete this box once resolved and reviewed.
This page is for the person at a managing agency or a landlord's office who has to satisfy themselves that putting tenant data into someone else's system is defensible. It is deliberately more specific than a privacy policy.
Who is the controller
You are. The tenant and landlord records in your organisation's book are yours: you decide what is collected, why, and how long it is kept. We process them on your instructions and for no other purpose.
How tenants' data is separated
Each organisation's data is isolated at the database level, enforced on every query, rather than by a filter in application code that a bug could bypass. Within an organisation, access is further bounded — staff can be scoped to the properties they are assigned, landlords see only units they own, and tenants see only their own charges and payments.
This is a design property rather than a configuration setting, which matters: a misconfiguration cannot widen it.
What we can see
Support access to a customer's data is [STATE YOUR POLICY: e.g. by explicit request only, logged, and time-limited]. State the truth here plainly — it is the question a careful client will ask, and a vague answer is worse than a restrictive one.
Sub-processors
[LIST: hosting provider and location, backup storage provider and location, email provider, SMS provider if any, error monitoring if any.] We will give notice before adding a new sub-processor that handles personal data.
Retention and deletion
Records are retained while your account exists. Note that the ledger is append-only by design: corrections are made by reversal rather than by editing, so an entry's history is preserved. Deleting an account removes the data; it is not possible to selectively erase individual historic entries while keeping the account, and you should factor that into your own retention policy.
Breach notification
If we become aware of a breach affecting your data we will notify you without undue delay, with what we know, what we are doing, and what you may need to do. [State a target time. A real number is more credible than “promptly”.]
Backups and recovery
Encrypted off-site backups, [FREQUENCY], retained [PERIOD], with restores tested [FREQUENCY]. Say when you last tested a restore — an untested backup is an assumption.
Data processing agreement
Available on request, and expected — if you are a managing agent holding data for landlords, you likely need one with us and they may need one with you. Contact hello@ravuni.com.