Home / Legal / GDPR & Data Protection
🛡️

GDPR & Data Protection

Effective: 7th May 2026  ·  UK GDPR & Data Protection Act 2018

Our commitment to processing personal data lawfully, fairly, and transparently — in full compliance with UK data protection law.

1 Overview

BravoHomesUK is committed to protecting the privacy and personal data of all users — tenants, landlords, letting agents, and maintenance vendors. We operate as a Data Controller under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

This page explains how we uphold the seven GDPR principles in everyday platform operations and sets out your rights as a data subject in plain English.

2 Data Controller

BravoHomesUK Ltd acts as the Data Controller for all personal data processed through the platform. As Data Controller, we determine the purposes and means of processing your personal data.

  • Registered Name: BravoHomesUK Ltd
  • Registered Address: London, United Kingdom
  • ICO Registration: In progress / registered
  • Privacy Contact: info@bravohomesuk.com

Where we engage third-party processors (e.g. Stripe for payments, AWS for hosting), we ensure appropriate Data Processing Agreements (DPAs) are in place as required by Article 28 UK GDPR.

3 The Seven Data Protection Principles

Under Article 5 UK GDPR, we must comply with seven data protection principles. Here is how we apply each one:

Principle 1
Lawfulness, Fairness & Transparency
We collect data only with a valid legal basis and are open about how and why we process it.
Principle 2
Purpose Limitation
Data is collected for specified, explicit purposes and not processed incompatibly with those purposes.
Principle 3
Data Minimisation
We only collect data that is adequate, relevant, and limited to what is necessary.
Principle 4
Accuracy
We keep data accurate and up to date. Inaccurate data is corrected or erased promptly.
Principle 5
Storage Limitation
Data is retained only as long as necessary for its stated purpose.
Principle 6
Integrity & Confidentiality
We use appropriate technical and organisational measures to protect data security.

The seventh principle — Accountability — requires us to demonstrate compliance with all the above, including through DPAs, privacy impact assessments, and training.

4 Personal Data We Process
Tenant Data
  • Contact details (name, email, phone, address)
  • Financial data (rent payments, payment history)
  • Property history (tenancy dates, premises)
  • Maintenance requests and communication logs
Landlord & Agent Data
  • Contact and identity information
  • Property portfolio details
  • Financial and subscription records
  • Legal compliance documents (EPC, gas safety, EICR)
Vendor Data
  • Professional contact details and qualifications
  • Location and service area data
  • Job completion and performance records
  • Payment disbursement records
5 Legal Basis for Processing
Processing ActivityLegal Basis
User account creation & managementContract (Art. 6(1)(b))
Rent payment processingContract (Art. 6(1)(b))
Marketing communicationsConsent (Art. 6(1)(a))
Audit trail & financial recordsLegal Obligation (Art. 6(1)(c))
Fraud prevention & securityLegitimate Interests (Art. 6(1)(f))
Platform analytics & improvementLegitimate Interests (Art. 6(1)(f))
Compliance certificates storageLegal Obligation (Art. 6(1)(c))
6 Data Retention
Data CategoryRetention Period
Active user accountsDuration of account + 30 days after deletion request
Financial / payment records6 years (HMRC requirement)
Tenancy agreements6 years from tenancy end date
Maintenance records7 years for dispute resolution
Marketing consent recordsUntil withdrawal of consent
Security / access logs12 months rolling
Correspondence / emails3 years post-last contact
7 Your Rights Under UK GDPR
RightWhat It MeansHow to Exercise
AccessObtain a copy of personal data we hold about you (Subject Access Request)Email DPO — 30 days to respond
RectificationCorrect inaccurate or incomplete dataAccount settings or email DPO
ErasureRequest deletion of your data where no legal retention obligation appliesEmail DPO — 30 days to respond
RestrictionLimit processing in specific circumstances (e.g., while accuracy dispute is resolved)Email DPO
PortabilityReceive your data in a structured, machine-readable formatEmail DPO — JSON/CSV available
ObjectObject to processing based on legitimate interests or direct marketingEmail DPO or unsubscribe links
Withdraw ConsentWithdraw consent at any time where consent is the legal basisAccount settings or email DPO

All rights requests are responded to within 30 days as required by UK GDPR. There is no charge for exercising your rights unless requests are manifestly unfounded or excessive.

8 International Data Transfers

Where data is transferred outside the UK/EEA, we ensure adequate safeguards under Chapter V UK GDPR. Mechanisms include:

  • Adequacy decisions — countries deemed adequate by the UK Secretary of State
  • Standard contractual clauses (SCCs) — UK-approved clauses in third-party contracts
  • Binding corporate rules — where applicable for group transfers
  • Certification schemes — approved codes of conduct
9 Data Breaches

We have a documented Incident Response Policy. In the event of a personal data breach:

  • The breach will be assessed for risk to data subjects
  • The ICO will be notified within 72 hours if the breach poses a risk to individuals (Article 33 UK GDPR)
  • Affected data subjects will be notified without undue delay where the breach poses a high risk to their rights and freedoms (Article 34 UK GDPR)
  • All breaches are recorded in the internal Data Breach Register

If you believe your personal data has been compromised, contact us at info@bravohomesuk.com immediately and mark the subject line Security Incident.

10 Data Protection Officer

BravoHomesUK has appointed a Data Protection Officer (DPO) who is responsible for:

  • Monitoring compliance with UK GDPR and the Data Protection Act 2018
  • Advising on Data Protection Impact Assessments (DPIAs)
  • Being the point of contact for the ICO
  • Handling data subject rights requests

Privacy Contact: info@bravohomesuk.com

11 Supervisory Authority (ICO)

The supervisory authority for data protection in the UK is the Information Commissioner's Office (ICO). If you are not satisfied with our response to a data rights request, you have the right to lodge a complaint with the ICO:

We respectfully request that you contact us first to resolve any data concerns before escalating to the ICO.

Data Protection Contacts

Reach us for Subject Access Requests, data rights exercises, or general GDPR enquiries.

Privacy / Data Rights
Security Incidents
ICO (Supervisory Authority)
Registered Office
London, United Kingdom