Your rights under the UK General Data Protection Regulation (UK GDPR) and how Rental Trust processes and protects your personal data.
Last updated: April 16, 2026
Rental Trust ("we", "us", "our") is the data controller responsible for your personal data. We are registered in England and Wales and operate the Rental Trust platform at rentaltrust.co.uk.
Our Data Protection Officer (DPO) can be contacted at: [email protected]
We collect personal data in the following categories, depending on how you use our platform:
| Category | Examples | Who It Applies To |
|---|---|---|
| Identity data | Full name, date of birth, nationality | Tenants, Landlords, Agents |
| Contact data | Email address, phone number | All users |
| Identity documents | Passport, BRP, driving licence (for Right to Rent checks) | Tenants |
| Financial data | Subscription payment records (via Stripe — we do not store card details) | Landlords, Agents |
| Employment data | Employer name, employment status, income range | Tenants (optional) |
| Tenancy history | Previous addresses, landlord references | Tenants (optional) |
| Technical data | IP address, browser type, device identifiers, cookies | All users |
| Usage data | Pages visited, features used, session duration | All users |
| Communications | Support messages, feedback, dispute records | All users |
Under UK GDPR Article 6, we rely on the following lawful bases:
Where we process special category data (e.g. nationality or immigration status for Right to Rent purposes), we rely on Article 9(2)(b) — processing necessary for employment and social security law obligations.
We use your personal data to:
We do not sell your personal data. We share it only in the following circumstances:
We retain personal data only for as long as necessary for the purposes it was collected:
| Data Type | Retention Period |
|---|---|
| Active account data | For the duration of your account, plus 30 days after deletion request |
| Right to Rent check records | Minimum 12 months after tenancy end (as required by law) |
| Payment records | 7 years (UK tax and accounting obligations) |
| Support communications | 3 years from last contact |
| Technical/log data | 90 days |
| Marketing consent records | Until consent is withdrawn, plus 3 years |
You have the following rights regarding your personal data. To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.
Request a copy of all personal data we hold about you (Subject Access Request).
Ask us to correct inaccurate or incomplete personal data.
Request deletion of your data where there is no compelling reason for us to continue processing it ('right to be forgotten').
Ask us to pause processing your data in certain circumstances (e.g. while accuracy is disputed).
Receive your data in a structured, machine-readable format and transfer it to another service.
Object to processing based on legitimate interests or for direct marketing purposes.
Not be subject to solely automated decisions that significantly affect you without human review.
Withdraw consent at any time where processing is based on consent, without affecting prior processing.
We use cookies and similar tracking technologies to operate the platform and improve your experience. You can manage your cookie preferences via the cookie banner displayed on your first visit.
| Cookie Type | Purpose | Required |
|---|---|---|
| Essential | Session management, authentication, security | Yes |
| Functional | Remembering preferences (language, theme) | No |
| Analytics | Anonymised usage statistics to improve the platform | No |
| Marketing | Personalised content and advertising (only with consent) | No |
We store and process your data primarily within the United Kingdom and the European Economic Area (EEA). Where data is transferred outside the UK/EEA (for example, to cloud service providers with global infrastructure), we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the ICO or reliance on adequacy decisions.
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, disclosure, alteration, or destruction. These include TLS encryption in transit, encrypted storage at rest, access controls, regular security reviews, and staff training. In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours and affected individuals without undue delay.
If you believe we have not handled your personal data in accordance with UK GDPR, please contact us first so we can try to resolve the matter:
We aim to respond to all data rights requests within 30 days.
You also have the right to lodge a complaint with the UK's supervisory authority, the Information Commissioner's Office (ICO):
We may update this GDPR notice from time to time to reflect changes in law or our data practices. We will notify you of material changes by email or via a prominent notice on the platform. The "Last updated" date at the top of this page indicates when the most recent changes were made.
We use cookies to enhance your experience, analyse site traffic, and serve personalised content. You can accept all, reject all, or customise your preferences below.