UnitLet

Data Processing Terms

Last updated 31 July 2026

These terms form part of the Terms & Conditions and satisfy Article 28(3) of the UK GDPR. They apply automatically to every account — you do not need to sign anything, and there is nothing to request. If your accountant, insurer or a parent company asks whether you have a data processing agreement with your software supplier, this page is it.

In these terms “we” and “us” mean Property Workflow Systems Ltd (registered in England and Wales, company no. 17376073), registered office Unit 6, Orchard Business Units, Cockaynes Lane, Alresford CO7 8BZ. “You” means the operator running a account. Terms such as controller, processor, personal data and processing have the meanings given in the UK GDPR.

1. Who is who

You are the controller of the records you put into the app about your own customers. You decide what to collect, why, how long to keep it and who to share it with, and you are responsible for having a lawful basis to hold it.

We are your processor for that data: we store it and act on it only to provide the service to you.

Separately, we are the controller of your own account details — the account holder’s name and email, the site name, the login credentials and the subscription record. That processing is described in our Privacy Policy and is not covered by these processor terms.

2. What we process, and why

Subject matterProviding the UnitLet service to you
DurationFor as long as your account exists, plus the deletion period in section 8
Nature and purposeStoring, organising, displaying, backing up, exporting and transmitting records so you can run your site — including sending messages to your occupiers at your instruction
Types of personal dataNames, postal addresses, email addresses, phone numbers; vehicle and insurance details; contract, payment and deposit records; identity-document details and images where you choose to store them; photographs; notes, diary entries and message history
Categories of data subjectYour customers, their named secondary contacts, people on your waiting list, and your own staff users
Special category dataNone is required by the service. Free-text fields could contain it if you type it there; you decide, and you remain the controller if you do.

3. Our obligations to you

We will:

  1. Process only on your documented instructions. Your instructions are these terms, the Terms & Conditions, and your use of the app’s features. We will not process the data for any other purpose — we do not mine it, profile it, sell it, or use it to train anything. If we are ever required by law to process it otherwise, we will tell you first unless the law forbids that.
  2. Keep it confidential. Access is limited to people who need it to run or support the service, and they are bound by confidentiality obligations.
  3. Secure it with appropriate technical and organisational measures — see section 4.
  4. Use sub-processors only as set out in section 5.
  5. Help you answer your customers. The app’s export and record-deletion features are designed so you can satisfy access, rectification, erasure and portability requests yourself, immediately. Where a request cannot be handled that way, we will assist you.
  6. Help you meet your own obligations on security, breach notification, impact assessments and consultation with the ICO, taking into account what we know and what is available to us.
  7. Tell you about a personal data breach without undue delay after becoming aware of one, with the detail you need to make your own notification within your 72-hour window.
  8. Delete or return the data at the end — see section 8.
  9. Make available the information you need to demonstrate our compliance, and submit to audits — see section 7.

4. Security measures

We may change these measures as technology moves, provided the level of protection is not reduced.

5. Sub-processors

You give general authorisation for us to use the sub-processors below. Each is bound by a written agreement with data protection obligations no less protective than these terms.

Sub-processorWhat it doesWhere
Cloudflare, Inc.Hosting, database, file storage, network security Database and files in Western Europe; global network
Resend (Plus Five Five, Inc.)Sending email — your reminders, notices, invoices, agreement and portal linksUnited States
Twilio Inc.Sending and receiving text messages — only if you connect your own Twilio accountUnited States / your chosen region

GoCardless and Stripe are not our sub-processors. If you connect one, you contract with them directly and they act as controller or processor under their own agreement with you. Paddle is our reseller and Merchant of Record for your subscription and is a controller of your billing data under its own terms.

We will give you at least 30 days’ notice by email before adding or replacing a sub-processor. If you reasonably object on data protection grounds, tell us within those 30 days and we will either propose a change or you may cancel your subscription without penalty and export your data.

6. International transfers

Where personal data is transferred outside the UK — principally to the United States providers named above — the transfer is covered by the UK Information Commissioner’s International Data Transfer Addendum to the EU Standard Contractual Clauses, or another safeguard approved under Article 46 of the UK GDPR, in each provider’s data processing agreement. We do not transfer your data anywhere else.

7. Audits and information

We will answer reasonable written questions about how we handle your data, and provide what you need to demonstrate compliance. If you require an on-site or third-party audit, we will co-operate with one audit in any twelve-month period, on at least 30 days’ notice, at your cost, during business hours, without unreasonably disrupting the service and subject to confidentiality — or more often if a supervisory authority requires it.

8. Return and deletion

You can export everything yourself at any time from Settings, as spreadsheets and as a full backup, and that stays available even if your subscription lapses and the account goes read-only.

When you tell us to close the account, we delete the account, its business records, uploaded files and its backups within 30 days, except anything we must keep by law (for example transaction records for tax). Export first — after deletion we cannot get it back.

9. Liability and precedence

These terms are subject to the limits of liability in the Terms & Conditions. If anything here conflicts with those terms, these terms win, but only for matters of data protection.

10. Contact

Data protection questions, breach notifications and audit requests: hello@unitlet.co.uk. There is no ticket system — it reaches a person.

Terms & Conditions · Privacy Policy · Refund & Cancellation · Data Processing · Home

© 2026 Property Workflow Systems Ltd, trading as UnitLet · Registered in England and Wales, company no. 17376073 · Registered office: Unit 6, Orchard Business Units, Cockaynes Lane, Alresford CO7 8BZ