01Privacy notice

How TenancyKit handles your data, plainly.

This notice explains who we are, what personal data we collect from you, why we collect it, who we share it with, how long we keep it, and what rights you have. Written under UK GDPR Article 13. Last updated 2026-05-06.

Data controllerMorgan and Co. Enterprise Limited, a company registered in England.
Trading nameTenancyKit (tenancykit.org)
DirectorCai Morgan
Contact for privacycai@tenancykit.org
ICO registrationPending — registration in progress under Tier 1 of the Data Protection (Charges and Information) Regulations 2018
Last updated2026-05-06
02What we collect

The personal data TenancyKit processes.

To produce a Renters Rights Act 2026 Information Sheet for you, we process the following categories of personal data:

03Lawful basis

Why we are allowed to process it.

Our lawful basis under UK GDPR Article 6(1)(b) is performance of a contract — you have asked us to produce a regulated document for your property, and we cannot do that without the data above. Tenant data specifically is processed under Article 6(1)(f) legitimate interest, balanced against tenant rights as set out in our internal Legitimate Interest Assessment available on request.

We do not process personal data on the basis of your consent for marketing — we do not run marketing communications at Stage 1.

04Who we share with

Recipients of your data.

We do not sell personal data. We do not share it with marketing partners, data brokers, or analytics platforms beyond what's listed above. Stage 1 has no third-party analytics installed.

05International transfers

Where your data goes.

Stripe and Brevo process EU/UK customer data within the EU. Supabase customer data is hosted in EU-West. Netlify is US-based — IP addresses and server logs may be processed in the US under the UK Extension to the EU-US Data Privacy Framework. No customer order content (your intake data, the Information Sheet, the audit trail) is transferred to the US — those are stored in Supabase EU-West only.

06Retention

How long we keep it.

You can request earlier deletion at any point — see your rights below — except where retention is mandated by tax law (Stripe transaction records).

07Your rights

What you can ask us to do.

Under UK GDPR you have the right to:

Email cai@tenancykit.org with your request. We respond within one calendar month, free of charge for the first request.

08Cookies + tracking

What we do not do.

This site uses no third-party analytics, no advertising pixels, no behavioural tracking cookies. The only cookies are functional (Stripe checkout session, Netlify form submission). No consent banner is required because no consent-bearing tracking is in place. If we add analytics in future, we will publish a cookie banner and update this notice before the change goes live.

09Changes to this notice

How we update it.

Material changes will be announced by email to all customers with active orders, at least 14 days before they take effect. The "Last updated" date at the top of this page reflects every revision. Prior versions are kept on request.