Last updated: 11 August 2026 · Schedule 1 · Version 1.0
This agreement is between you, the landlord using RenteRoo, and 4Real Estate Limited (company number 15119929), registered office 42 Ffordd Y Meillion, Llanelli, SA15 2EX, Wales, trading as RenteRoo.
It forms part of the Terms of Service and applies from the moment you create a landlord account. You do not need to sign anything separately — accepting the Terms accepts this, and we record which version you accepted and when.
What it is for. When you use RenteRoo to hold information about your tenants, you decide what that information is for and we act on your instructions. UK law calls you the controller and us the processor, and it requires the two of us to have a written agreement covering specific things. This is that agreement. It is the same for every landlord.
The rest of this agreement sets out, in the order UK GDPR Article 28(3) asks for them, that we will: keep tenant data confidential (§6); secure it (§7); use sub-processors only under the conditions in §8; keep it in the UK or EEA, or protect it properly if not (§9); help you answer your tenants (§10); return or delete it when you leave (§11); tell you quickly about a breach and help you handle it (§12); and show you we are doing all of it (§13).
*We are not taking on your responsibilities and we are not advising you on them — but we do need you to confirm you have met them, because we cannot run the service lawfully if you have not.*
You confirm that:
We do not advise you on any of this, and nothing in RenteRoo is that advice. If you are not sure, ask a qualified adviser. Free guidance for small organisations is at ico.org.uk.
Everyone we allow near tenant data is bound to keep it confidential, either by their contract or by a written undertaking, and that duty continues after they stop working with us.
Being straight with you about scale: RenteRoo is currently run by one person, the founder and director of 4Real Estate Limited. She is the only person with access to production systems. That is a genuine security advantage — the smallest possible number of people can see your tenants' data — and a genuine risk, which is why §7 covers what happens if that access is compromised and why every account she holds has multi-factor authentication on it.
We take the technical and organisational measures required by Article 32. Annex 2 sets out what they actually are — not a list of adjectives, the real measures, including the one place we currently fall short.
We will keep those measures under review and may change them, but we will not reduce the overall level of protection.
Your tenants have rights — to see their data, to have it corrected, to have it deleted, to object, to get a copy to take elsewhere. Those requests are yours to answer. We will help:
Every landlord could have a different view of how long records should be kept, and we cannot run a different schedule for each one. So the schedule below is a published term you accept, and accepting it is your documented instruction to us to hold the records for that long.**
While you use RenteRoo, we keep tenant data for as long as you keep it. Delete something and it goes, subject to backups ageing out.
When you close your account or stop using RenteRoo:
*UK GDPR gives you a right to audit us. An unlimited right of inspection held by every landlord is not something a one-person company can survive, and a right that cannot be honoured is worse than one that is shaped honestly. So:*
This agreement starts when you create your account and lasts as long as we hold tenant data for you. §§11, 12, 13 and 14 continue to apply afterwards, for as long as we still hold anything of yours.
We may update it — because the law changes, because the product changes, or because we improve something. We will email you and show a notice in the product at least 30 days before a material change takes effect. If you do not accept it, you may close your account and take your records, and we will not hold you to the new version.
We keep every published version. Your settings page shows which version you accepted and when, and lets you download it.
Required by UK GDPR Article 28(3).
| Subject matter | Providing RenteRoo — a compliance record-keeping and reminder service for residential landlords in Wales |
| Duration | For as long as you have an account, plus the retention periods in §11 |
| Nature of the processing | Collecting, recording, organising, storing, retrieving, displaying, generating documents from, transmitting, erasing and anonymising |
| Purpose | So you can keep track of your properties, tenancies and compliance obligations; share documents with your tenants; message them; and produce a move-in inventory |
| Types of personal data | Names; email addresses; phone numbers; dates of birth; postal addresses; property addresses; tenancy dates and terms; rent and deposit figures you record; deposit protection references; compliance certificates and the personal details on them; tenancy documents; photographs of rooms and their contents; inventory records; messages between you and your tenant; and whatever else you choose to upload |
| Categories of data subject | Your tenants and their household members; anyone named in a document you upload — a contractor, a certificate issuer, a previous occupier |
| Special category data | Not asked for and not required. Could arrive inside a document you upload — see §5.4 |
| Sub-processors | Annex 3 and /subprocessors |
Required by UK GDPR Articles 28(3)(c) and 32. Written from what is in place, not from a template. Where something is not in place, it says so.
1. In transit. Everything travels over encrypted HTTPS. There is no unencrypted route into RenteRoo.
2. At rest. Our database and file storage providers encrypt data at rest as standard.
3. Who can get in. Sign-in is handled by a specialist authentication provider. Passwords are stored as one-way hashes and we cannot read them. Multi-factor authentication is available to every landlord and we recommend it. Every administrative account that can reach production data — nine of them, across the product, the database, hosting, source control, DNS, the mailbox, email sending, rate limiting and monitoring — has multi-factor authentication enabled, confirmed on 29 July 2026, with recovery codes held separately.
4. Keeping landlords apart. Every landlord's records are separated at the database level, by row-level security policies, not only by what the interface chooses to show. A fault in a page therefore cannot expose another landlord's data. This has been tested against live accounts across account boundaries, not only in theory.
5. Documents and photographs are held in private storage and are never publicly addressable. They are reachable only through short-lived signed links issued to someone entitled to see them. Anonymous access, direct access, and access by an unrelated landlord have each been tested and denied.
6. Sensitive actions are rate-limited — tenant invitations, account deletion, document access, email sending — using a shared store so the limit holds across servers. The identifiers used are pseudonymised rather than stored raw.
7. Monitoring, built to exclude personal data. Errors are captured to a monitoring service hosted in the EU, through a strict allow-list. Request bodies, query strings, cookies, tokens, file paths, customer identities and message content are all excluded before anything leaves. There is a written incident procedure and it has been rehearsed.
8. Building it. Every route that can bypass the database's own protections must check who is asking and whether they are entitled to the specific record, before it does anything. This is enforced as a standing rule in our engineering process and checked on every change. Dependencies are audited automatically and a high-severity finding stops a release.
9. Backups — the honest bit.
We hold a demonstrated recovery path for the database and have tested a full restore. Automated scheduled backups are not currently in place on our hosting plan; we take manual exports and are moving to an automated schedule before general release. Data in a backup is deleted as that backup ages out.
10. What we do not have, said rather than hidden. No independent penetration test has been completed yet — one is planned, and we will publish the fact when it is done. No ISO 27001 or SOC 2 certification, and we will not imply otherwise.
11. Reviewing all of it. These measures are reviewed when the product changes materially, when a new supplier is added, and after any security incident.
The current list, with what each company does and where it processes data, is at /subprocessors, which forms part of this agreement.
As at 11 August 2026: Supabase (database, file storage, authentication), Vercel (hosting), Resend (transactional email), Upstash (rate limiting) and Sentry (error monitoring).
We give 30 days' notice before adding or replacing any of them, and you may object under §8.
4Real Estate Limited (company number 15119929), trading as RenteRoo · registered office 42 Ffordd Y Meillion, Llanelli, SA15 2EX, Wales · hello@renteroo.co.uk
Schedule 1 — Data Processing Agreement · Version 1.0 · 11 August 2026 · Schedule to the Terms of Service v2.0