Draft — not yet in force. The company details are still placeholders, and a solicitor has not reviewed this wording. Fill in PROVIDER in src/lib/legal/types.ts before relying on it.

For landlords — part of the terms of service

Data processing agreement

Last updated 20 September 2026

When you put a tenant's details into Inlet, you decide why they are held and we hold them for you. Data protection law calls you the controller and us the processor, and requires a written agreement between us. This is it.

It forms part of the terms of service between you and [COMPANY NAME] LIMITED, and you accept it by opening an account. If your own arrangements need a signed copy, email support@inlet-homes.com and we will sign one.

Words defined in UK GDPR — controller, processor, personal data, data subject, processing, supervisory authority — have the same meaning here.

1. What we process, and for how long

Subject matterHolding and processing personal data so you can let and manage your property through Inlet
DurationWhile your account is open, plus the retention periods set out in the privacy policy
Nature and purposeStoring, organising, displaying, sending reminders about, and deleting the records you enter
Types of personal dataNames, contact details, addresses, tenancy and rent records, bank statement lines naming a payer, repair descriptions and messages, photographs, identity and address documents, proof of income, employer references, Right to Rent share codes and outcomes
Special category dataNot asked for by Inlet, but repair messages may reveal health, and Right to Rent evidence reveals immigration status
Categories of data subjectYour tenants, their household members where named, applicants, guarantors, and contractors you add yourself

2. We act only on your instructions

We process this personal data only to provide Inlet to you, and on your documented instructions. Using the features of Inlet is an instruction; so is a written request to us.

If the law requires us to process it some other way, we will tell you first unless the law forbids that.

If we think an instruction breaks data protection law, we will tell you and may decline to carry it out.

We will never sell this data, use it for our own marketing, or use it to train artificial intelligence models.

3. Confidentiality

Everyone we allow near this data is bound by confidentiality, and only reaches what their job requires.

Today that is one person. Inlet's own dashboard shows us your account — your properties, your counts, what is overdue — and writes every such visit to your access log, so you can always ask who looked and when. It does not show us your tenants' names, documents or messages; to see those we would have to ask you.

4. Security

We keep the measures set out in the privacy policy under "How it is protected", and at least:

  • Separation of every landlord's records, enforced by the database on each read and write, and covered by automated tests.
  • Private document storage, reachable only through links that expire in 60 seconds and are issued after an ownership check.
  • Encryption in transit; encryption at rest by the hosting platform.
  • Passwords handled by a specialist authentication service, stored only as one-way hashes.
  • A log of access to sensitive records.
  • Automatic deletion of Right to Rent and referencing paperwork on the dates in the privacy policy.

We will not weaken these measures. We may change how they are achieved, provided protection is not reduced.

5. Other companies we use

You give us general permission to use other processors. We remain responsible to you for what they do.

WhoWhat they doWhere
SupabaseStores the database and the uploaded documents, and handles logins and passwordsLondon, United Kingdom (data at rest). Supabase Inc is a US company
VercelRuns the Inlet website itselfUnited States
StripeTakes subscription payments from landlordsIreland and the United States
ResendSends Inlet's emailsUnited States
TwilioSends text message alerts for emergency repairsUnited States
Apple, Google, Mozilla and Microsoft push servicesDeliver phone notifications to the device that asked for themUnited States

Each is bound by written terms that are no weaker than these.

If we intend to add or replace one, we will email you at least 30 days beforehand. If you reasonably object on data protection grounds, tell us within those 30 days: we will look for an alternative, and if there is none you may cancel and we will refund the unused part of what you have paid.

6. Transfers outside the UK

Your records are stored in the United Kingdom. Where one of the companies above handles data outside the UK, we rely on UK adequacy or on the International Data Transfer Addendum to the standard contractual clauses, and you authorise those transfers.

7. Helping you meet your duties

We will help you, at no charge for anything reasonable:

  • To answer a request from a tenant, applicant or contractor to see, correct, delete or move their data. Inlet shows you what is held; where a deletion has to be done in the database, we will do it.
  • To keep data accurate and to delete it when its time is up.
  • To assess security, report a breach, and carry out a data protection impact assessment if you need one.

If a request reaches us directly, we will not answer it ourselves. We will tell the person to ask you, and pass it on to you promptly.

8. If something goes wrong

If personal data we hold for you is lost, exposed or altered without authority, we will tell you without undue delay and in any event within 48 hours of becoming aware.

We will tell you what happened, who is likely affected, what the likely consequences are, and what we are doing about it — and keep you updated as we learn more.

Reporting to the Information Commissioner, and telling the people affected, is your decision as controller. We will give you everything you need to make it.

9. Showing you we comply

We will give you the information you reasonably need to show that we meet this agreement.

You may audit us, or appoint someone independent to, no more than once a year unless a breach or a regulator's instruction makes another necessary. Give us 30 days' notice, keep what you learn confidential, and cover your own costs.

10. When your account ends

You can take your documents out at any time, and ask us for a full copy of your data.

After your account closes we delete the personal data we held for you within 30 days, along with copies in backups as those backups age out, which takes no longer than 90 days.

We keep only what the law requires us to keep, such as records of payments, and it stays protected by this agreement for as long as we hold it.

11. What you are responsible for

As controller, you must:

  • Have a lawful basis for the data you put into Inlet, and tell your tenants, applicants and contractors what you do with it. Our notice for them, at /legal/portal, explains Inlet's part and is not a substitute for your own.
  • Ask for no more than you need. Inlet deliberately does not ask for the date of birth a Home Office check needs — do not collect it here either.
  • Keep what you enter accurate, and act on requests from the people it concerns.
  • Give access only to people who should have it, and withdraw it when they should not.
  • Decide and act on any report to the Information Commissioner.

12. Responsibility between us

Each of us is responsible for our own compliance with data protection law.

The limits in section 14 of the terms of service apply to this agreement too, except where the law does not allow a limit — including a claim by a data subject, or a fine, in so far as it results from our own breach of this agreement.

13. Changes

We may update this agreement to keep it accurate or to meet a change in the law. If a change reduces your rights we will email you at least 30 days beforehand.

Where this agreement and the terms of service disagree about personal data, this agreement wins.

It is governed by the law of England and Wales.