Privacy policy
Last updated 27 July 2026
comply2let is a compliance record-keeping service for landlords of Welsh rental property. This policy explains what personal data we hold, why we hold it, and what you can do about it.
It covers two groups of people: landlords, who hold an account with us, and contract-holders and guarantors, whose details appear in the documents landlords upload. If you are a tenant who has been told your details are stored here, the section on people who don't have an account is the one that applies to you.
Who we are
comply2let is operated by SJSC Group Ltd (company number 13099071), registered at 84 Cathedral Road, Cardiff, CF11 9LN.
For questions about this policy or to exercise any of the rights below, email privacy@comply2let.com.
For your account and the record of your portfolio, we are the controller — we decide how that data is used. For the contents of documents you upload about your contract-holders, we are a processor acting on your instructions, and you are the controller. The terms governing that relationship are in the data processing agreement.
What we collect
| Data | Why we hold it | Lawful basis |
|---|---|---|
| Email address and password | To create your account, sign you in and reset your password | Contract |
| Property addresses and attributes | To work out which documents the law requires for each property | Contract |
| Tenancy details — start date, rent, deposit, contract-holder and guarantor names | To track which requirements apply to the current occupation contract | Contract; legitimate interests of the landlord |
| Uploaded documents — certificates, occupation contracts, licences | To store your compliance evidence, read the dates from it and warn you before it expires | Contract; legitimate interests of the landlord |
| Reminder settings — whether you want renewal emails and how far ahead | To email you before a document expires, and to record which warnings we've already sent so you aren't emailed twice | Contract |
| Technical logs — IP address, browser, timestamps | To keep the service running and secure | Legitimate interests |
We do not use your data for advertising, we do not sell it, and we do not profile you.
How the automated document check works
When you upload a document, we send a copy to Anthropic's Claude API to identify what the document is, read its issue and expiry dates, check the address matches the property, and flag obvious problems. This means the contents of the document — including any names in it — are transmitted to Anthropic for processing.
Anthropic processes the document to return a result and does not use it to train its models. The check is advisory: it produces a suggestion you confirm or correct, and it never decides anything about you or anyone else on its own. There is no automated decision-making with legal effects.
If you would rather a particular document was not checked this way, do not upload it.
Who we share it with
We use a small number of suppliers to run the service. Each is bound by a contract that limits them to acting on our instructions.
- Supabase — database, sign-in and document storage. Your data is held in their London (eu-west-2) region.
- Vercel — hosting for the website itself.
- Anthropic — the automated document check described above.
- Resend — sending account emails such as confirmation and password reset, and your renewal reminders.
- Postcoder — UK address lookup when you add a property. Only a postcode is sent.
We will also disclose data where the law requires it. Otherwise we share it with nobody.
Transfers outside the UK
Your database and documents are stored in the UK. Some suppliers, including Anthropic, process data in the United States. Where that happens we rely on the transfer terms in that supplier's data processing agreement, which incorporate the UK International Data Transfer Addendum to the EU Standard Contractual Clauses.
How long we keep it
Compliance records exist to prove what was true at a point in time, so the service is deliberately built not to throw things away. Replacing a certificate supersedes the old one rather than deleting it, and superseded versions stay visible to you as evidence of past compliance.
- While your account is open — we keep your properties, tenancies and documents, including superseded versions.
- If you delete a document — the file and its check history are removed from storage promptly and permanently.
- If you close your account — we delete your account and its contents within 30 days, unless we are required to keep something for longer by law.
Keeping it safe
Documents are held in private storage that is not publicly reachable — every file request is authorised against your account first. The database enforces row-level security, so one landlord's data is not retrievable by another even if the application is at fault. Passwords are stored hashed and we never see them. All traffic is encrypted in transit.
Your rights
You have the right to:
- ask for a copy of the personal data we hold about you;
- have inaccurate data corrected;
- ask us to delete data, in some circumstances;
- object to or ask us to restrict how we use it;
- receive your data in a portable format;
- withdraw consent, where we relied on it.
Email privacy@comply2let.com and we will respond within one month.
If you are unhappy with how we have handled your data you can complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113. We would rather you came to us first.
If you don't have an account with us
Landlords upload occupation contracts and certificates that may name contract-holders and guarantors. If that is you, we did not collect your details from you — we received them from your landlord, who decides what is held and why. We hold them only to store the document and read its dates.
You have the same rights listed above. Because your landlord is the controller of that data, the quickest route is usually to ask them directly. You are equally welcome to contact us at privacy@comply2let.com and we will pass the request to them and help them answer it.
Cookies
comply2let uses one cookie, and only once you have signed in.
| Cookie | Purpose | Expires |
|---|---|---|
sb-…-auth-token | Keeps you signed in as you move between pages. Set by Supabase, our authentication provider. | On sign-out, or after a period of inactivity |
This is a strictly necessary cookie: without it the service cannot know who you are and you would be signed out on every click. Cookies of this kind are exempt from the consent requirement in the Privacy and Electronic Communications Regulations, which is why comply2let has no cookie banner. Blocking it will prevent you from signing in.
We use no analytics, advertising or tracking cookies, and no third-party tags. If that ever changes we will ask for your consent first and update this page.
Changes to this policy
If we change anything significant we will tell account holders by email before it takes effect. The date at the top shows when this version was published.