Legal
Privacy Notice
Introduction
This Privacy Notice explains how VEYLO X® processes personal data in connection with its platform and services.
We are committed to processing data in accordance with the UK GDPR and Data Protection Act 2018.
Role of VEYLO X
VEYLO X is the data controller for the personal data processed through the platform. We decide what is collected, why, how long it is kept and who it is shared with.
A landlord or agent is a separate, independent controller for what they do with information once they have received it, for their own purposes and under their own responsibility. We are not joint controllers with them, and neither of us decides the other's purposes.
We are not responsible for what a landlord or agent does with information after they have received it, and they are not responsible for how we run the platform. If you have a question about their use of your information, you can raise it with them directly, and you can also raise it with us.
Nature of Data Processing
We process personal data necessary to:
- operate and maintain the platform
- enable account functionality
- support property and tenancy workflows
- generate system outputs (e.g. alerts, summaries)
We may also process technical and usage data for system performance and security.
Network addresses, account limits, and when we refuse requests
Every time your device asks our systems for something, it tells us the network address it is asking from. Data protection law treats that address as information about you, even though it does not carry your name.
Why we keep it. We keep a record of a network address so that we can notice when our service is being attacked or abused, and stop it. The record holds the address, the time of the request, what was asked for, and whether it worked. Where we refuse an address, we also record who decided, why, and when the refusal ends. We do not use the network-address record to build a picture of you, and we do not try to work out who you are from that record.
Our lawful basis is our legitimate interests, under Article 6(1)(f) of the UK GDPR. The interest is keeping the service running and safe for the people using it. We have written down our assessment of that, and you can ask us to explain it.
We may refuse requests coming from a particular network address where we believe that address is being used to attack or abuse our service. That particular refusal is based on the network address rather than the identity of the account. Separately, some of our security controls limit how often an account can make particular requests, and those controls may refuse a request when those limits are reached. For a network-address refusal we normally set an end date. Where we need to keep one in place without an end date, a named person has to decide that and write down why.
We also keep a count of refusals against the account they came from. We keep how many times an account was refused on a day, when the last one was, and which feature refused it. We keep it so we can tell the difference between our own checks wrongly shutting out genuine use and one account repeatedly hitting our abuse controls. It is used only for security monitoring and investigation, troubleshooting, and handling rights requests, complaints and regulatory enquiries. We do not use this count to make or support decisions about tenancy, listings, pricing or eligibility. Where a security investigation leads us to restrict an account, that decision is made by two of our people on the evidence of what happened, and a count on its own is never a reason to restrict anybody. Unlike the record of a network address above, this count is kept against your account, so it does identify you. We look up whose account it is only where we need to for a rights request, a complaint, a security investigation or a question from a regulator, and that access is restricted and logged.
What a network-address refusal does not do. It only affects requests that reach our own servers, and that is a smaller thing than it sounds. It does not stop you opening our website, which our hosting provider answers before any rule of ours runs. It does not stop you signing in. It does not stop you reading or updating your records in the app, because your device fetches those from our platform provider directly. It is not a block on the internet, and it does not stop your device reaching anything else.
What a network-address refusal can stop. Some parts of the service are answered by our own servers rather than by our providers, and a refusal does reach those. The clearest example is downloading a document we hold for you, such as a compliance certificate, a photograph, or a tenancy pack. If a network-address refusal is stopping you getting a document you need, tell us and we will look at it.
One address is often shared by many people. Everyone in an office, in a hall of residence or in a hotel can be using one address, and so can everyone on the same mobile network at the same time. That means refusing one address can affect people who have done nothing at all. Where that is happening we will lift the refusal promptly.
If we have refused your address, tell us and we will look at it again. Write to support@veylox.uk, which is the same address the refusal message itself gives you. Email always reaches us, whatever we have refused, because a refusal only applies to requests your device makes to our servers. We will not ask you to prove which device was yours. We will look at whether the refusal is still needed, and lift it if it is not. That is how we handle a request to lift a refusal, and it does not change any checks we may need to make before we answer your other privacy requests.
How long we keep the network-address record. Six months, counted from the last time the record changed. Where we have refused an address, the six months start on the day the refusal ended rather than the day it began. We keep each day’s record of refusals against an account for 30 days after the most recent refusal included in it. The retention table below sets out both periods.
Your right to object. You can object to us using your information in this way, both the network-address record and the count kept against your account. Write to privacy@veylox.uk, and see Your Rights below. Neither a network-address refusal nor an account limit stops you writing to either address.
The early-access list on veylox.uk
Our website at veylox.uk has a form for joining the early-access list. This section covers that form only. It is the sole personal information the marketing website collects, and it is separate from anything described elsewhere in this notice.
When you join the list we store:
- your email address, so we can write to you
- whether the page you signed up from was written for renters or for landlords, so that what we send is relevant
- the path of the page you were on, so we know which of our guides people find useful. The path only, never the query string
- the website you arrived from, if any, recorded as the site name alone. Any search terms in the link are discarded before it is stored
- the date you joined, and your browser's user agent string, for record keeping and to tell real sign-ups from automated ones
We do not ask for your name, your address, your telephone number or anything about your tenancy, and the marketing website has no other form.
Our lawful basis is consent, under Article 6(1)(a) of the UK GDPR, for everything in that list. The page you signed up from and the site you arrived from are held as part of the same single record, not separately and not for any other purpose, so one consent covers the whole entry. Giving us your email address is entirely optional; nothing on the website requires it, and the only consequence of not giving it is that we cannot write to you.
What we send. A short plain-English guide to what the Renters' Rights Act 2025 changed, sent as soon as you join. After that, the occasional short email while we get ready, and a message when VEYLO X opens. Every message carries a one-click way to stop receiving them, and we do not sell, rent or pass your address to anyone else for their own marketing.
Withdrawing consent. Email us and we will remove you. Withdrawal is as easy as joining, it does not affect anything done before you withdrew, and we delete the entire entry rather than keeping the rest of it.
How long we keep it. Until the earlier of two years from the day you joined, or the day you ask us to remove you. If VEYLO X opens and you do not go on to create an account, we delete the entry within six months of that announcement.
Where it is held. In the same infrastructure as the rest of the platform, described under Who handles your data and International transfers below. The marketing website itself sets no cookies of its own; page views are counted by Cloudflare Web Analytics, which is the only third party the website loads anything from.
Tenant and Applicant Data
Where tenant or applicant data is processed:
- where a landlord or agent gives us information about an applicant or tenant, we are the controller for what we then do with it on the platform, and we decide how long it is kept and who it goes to
- the landlord or agent remains separately responsible for what they do with that information for their own purposes, and for having been entitled to give it to us
- a named tenant's own legal name, which the tenant gives us directly, is covered under Your legal name when you join a tenancy below
We do not independently verify identity documents or legal eligibility.
Users remain responsible for:
- Right to Rent compliance
- identity verification
- lawful processing of personal data
Where you provide Right to Rent information through VEYLO X, we use it to keep a tenancy record and, where a follow-up check is legally required, to show your landlord a limited reminder that a Right to Rent re-check is due. We do not show your passport image, share code, document number, nationality, immigration route or visa/BRP class in the landlord dashboard.
If the date is wrong, contact us so it can be checked and corrected.
Your search preferences
When you use Find a place to rent, we ask what you are looking for so we can show you places that fit. Where you are looking, your budget, bedrooms, property type, move-in date, household size and lifestyle choices are used to produce those matches, and we need them to carry out the search you asked us for.
The same questionnaire also asks, optionally, about your income source, your income and your savings. We store your income source so that your preferences stay complete and you do not have to retype it. Where you give us an income or savings figure, we use that figure to show a rough comparison against the advertised rent, and to help order your matches. Leave them blank and we skip that comparison. We do not verify these figures and we make no approval decision.
Our lawful basis for your search preferences is UK GDPR Article 6(1)(b): processing necessary to take steps at your request before entering into a contract. That covers the optional income and savings figures only where you choose to give them as part of this matching feature.
We do not ask for your Right to Rent or immigration status when you search. We explain that a landlord has to carry out a Right to Rent check before a tenancy starts in England, so that you know what to expect, but we do not record an answer, and it plays no part in which properties you are shown.
Your answers are stored against your own account. A landlord or agent does not see them. Information reaches a landlord only when you choose to send it as part of an application. You can change or delete your answers at any time in More › AI Property Preferences.
Showing your name to your tenant
When you accept a prospective tenant's application, we show that person the name you have confirmed on your profile, so they know who their landlord is. If you let through a limited company, we show the company's registered name as it appears at Companies House, rather than a personal name.
We do not show your name earlier in the process. It is not shown while your property is listed, and it is not shown to people who only enquire about your property or attend a viewing.
You manage your own name in your profile. If you update it, we update the name shown on your accepted applications so it stays current. We store it on those applications and on the resulting tenancy record. We keep it for the life of the tenancy and for six years afterwards; where an application is accepted but does not go on to a tenancy, we keep it for six years from the application.
We do this to perform our agreement with you. A landlord also has their own legal duties to give their name to a tenant on a written request, and on any written rent demand (Landlord and Tenant Act 1985, sections 1 and 47). Those duties apply to you directly. VEYLO X records and displays the information you provide; it does not act on your behalf, and does not give legal advice.
You will see the landlord's name once the landlord accepts your application. If the landlord lets through a limited company, we show the company's registered name as it appears at Companies House.
Your legal name when you join a tenancy
If you join a tenancy as a named tenant, for example as a joint tenant with other people, we ask you for your full legal name. We ask for it because it goes on the tenancy agreement, alongside the other named tenants, and on the deposit protection record if a deposit is protected, so a deposit can be protected and registered as the law requires (Housing Act 2004). An account display name or nickname is not suitable for those formal records. You give us this name yourself, so for this information VEYLO X is the data controller.
We process your legal name to perform our agreement with you and to provide the tenancy platform, and, where a deposit is protected, so that your landlord can protect and register it as the law requires (Housing Act 2004).
We ask for your name as a single entry, rather than separate first and last name boxes, so that names in any script, single-word names, and names that include punctuation are all accepted, and your spelling and capitalisation are kept. Please enter it as it appears on your identity documents, including any middle names. VEYLO X records the name you provide. We do not verify your identity, and we do not check the name against any document.
When you add your name, you confirm that it is your full legal name, and we keep a dated record of that confirmation. You can choose to do this later if you are not ready, and we will ask again next time you sign in. If you do not provide it, we cannot add you as a named tenant on the tenancy agreement or on the deposit protection record.
Your name also appears on a transcript of your messages if you or the other party download one. That document can be given to a deposit adjudicator, the Property Ombudsman or a court.
Your legal name is used on your tenancy record and, where a deposit is protected, is sent to the deposit protection scheme so the deposit can be registered in your name. This is the statutory deposit protection described under Who handles your data below, where the scheme acts as an independent organisation responsible for the data in its own right. Where your name is also used for a referencing or identity check, that happens in the way described in that section: we ask your permission first, and the organisation runs its check under its own privacy notice.
When your name is locked
Once your tenancy agreement is signed, or your deposit is registered with the scheme, your legal name is fixed on those records. From that point you can no longer edit it yourself in the app, because it now sits on a signed agreement and, where relevant, on a statutory deposit record that VEYLO X does not change.
If a locked name is spelt wrong, or your legal name later changes, speak to your landlord. Your landlord holds your identity information and is responsible for the tenancy agreement and for the deposit registration, so a correction is made through them. Where your landlord confirms a correction, we update the name we hold to match, and we keep a record of the previous name, because your signed agreement and deposit record still carry it. We will tell you when the name we hold for you has been updated.
You can also ask us directly to correct your name at any time, whether or not your landlordhas acted. Contact us at privacy@veylox.uk and we will handle your request as set out under Your Rights below. We will not change a tenancy agreement or a deposit registration ourselves, and we cannot give you legal advice, but we can correct the name we hold, and where we have already shared it with an organisation such as the deposit protection scheme, we or your landlord will let them know where we are required to, so their record can be updated too.
We keep your legal name on your tenancy record for the life of the tenancy and for six years afterwards, as set out in the named-tenant legal name row in the retention table below. As a field on your account profile, your legal name is kept for the life of your account and for 12 months afterwards, in line with the account record row in the same table. We keep the dated record of your confirmation, and of any later correction, for seven years, as set out in the compliance attestations row.
VEYLO X records and displays the legal name you provide. We do not act for you or for your landlord, we do not verify identity, and we do not give legal advice.
Council tax when you move in
When you move into a rented home, your local council needs to know who now lives there so that council tax can be billed to the right people. Your landlord can use VEYLO X to notify the council of the change of tenancy. Where they do, the notification includes your name and the date your tenancy starts. Your landlord types your name into the notification and sends it themselves, from their own council account, online form or email. VEYLO X provides the template and prepares the wording, but it does not fill your name in from your record, and it does not send anything to the council for your landlord or for you. VEYLO X is a neutral platform. It does not act for your landlord or for you, and it does not give legal advice.
We do not ask for your consent to this, and it does not depend on your consent. Council tax, and keeping a council informed of who is liable to pay it, are set by law under the Local Government Finance Act 1992. Your landlord makes the notification to meet their responsibilities under that system, in their legitimate interests as the person letting the property to you, so that the council can bill the right people. We hold your name and your tenancy dates so that we can provide the tenancy platform to you under our agreement. Because the law provides for this, you are not asked to agree to it or to opt in.
The name used is the one your landlord types in. That is a separate thing from the legal name you give us directly when you join a tenancy, which is described under Your legal name when you join a tenancy above, and for which VEYLO X is the data controller. Once your landlord has notified the council, your landlord is separately responsible for what they have sent and for dealing with the council, as explained under Role of VEYLO X above.
The notification is about the move from the previous tenancy to yours. It shows your name and your tenancy start date, and, where your landlord provides them, the name and end date of the tenant who is moving out. Your landlord may also choose to add the number of adults living in the home, a forwarding address for the tenant who is moving out, and their own telephone number. Those extra details are optional and are the landlord's choice. VEYLO X does not add them, and it does not take them from your account.
If your name or your tenancy dates are shown incorrectly, the quickest way to put it right is usually through your landlord, who prepares and sends the notification and can send the council a correction. You can also contact us at privacy@veylox.uk, and we will deal with your request as set out under Your Rights below. We can correct the name and details we hold, but we cannot change what your landlord has already sent to the council, and we cannot give you legal advice. You can also contact your local council yourself to register for council tax, and VEYLO X can provide wording you can use for that. Either way, VEYLO X records and provides the wording only. It does not deal with the council for you and does not verify anything with the council.
Signing a document electronically
When you sign a tenancy agreement or a deed of guarantee on the Platform, we record what happened so that each party can later show that the document was signed. We record the time you signed, the email address on your VEYLO X account, the IP address your device was using at the time, the fingerprint of the terms you agreed, the wording you confirmed before signing, and the fact that you confirmed who you are again immediately before signing. We record the same facts for the other parties.
The other party can see this. Each party to the document can download a Certificate of Completion and can see the signing record on screen. Your name, your email address, the time you signed and the IP address you signed from appear on it, and you can see the same details for the other parties. Where more than one tenant signs the same agreement, a tenant does not see another tenant's email address or IP address.
We do this in our legitimate interests, and in the legitimate interests of both parties, in being able to evidence that an agreement was signed if it is ever questioned (UK GDPR Article 6(1)(f)). We record that the email address on the account was confirmed and that you signed in again immediately before signing. That is evidence of control of the account and the mailbox. It is not an identity check, and VEYLO X does not tell anyone that it has established who you are.
The Certificate of Completion is only ever downloaded by a party to the document, after signing in. We do not send it by email. How long we keep the signing record is set out under Data Retention below.
When somebody complains about you, and what we write down
Somebody may complain to us about you. If they do, we open a case and write down what was said. Our Terms explain what happens next, in the section titled Temporarily pausing part of your account. That section tells you the two things we may pause while we look into it, the long list of things we will never pause, how long a pause can last, and how to reply. This section is about the information side of the same thing: what we write down, where it came from, why we are allowed to hold it, how long we keep it, and what you can ask us for.
A case is not a finding about you. Opening one is not a decision that you did anything, and we do not keep score. How many complaints have been made about you is never a reason to pause part of your account, and it is not something we count, work out, or hold as a total anywhere. We also never pause your account because the other party to a tenancy says you behaved badly as a landlord or as a tenant. That is not ours to decide.
What we write down. Who the complaint is about, which is you. What was alleged, in words, written as an allegation and not as a fact. Which of the reasons listed in our Terms we are relying on. What harm we think may carry on if we pause nothing. Where in our own records we can see something that bears the allegation out. Whether we considered if the decision would treat you unfairly because of who you are, and what we concluded. Which of the two things in our Terms we paused, if we paused anything. Which of our people proposed it, which of them agreed to it, and when. When we wrote to you, and what we told you. When it ended, and why. Where one of our people later lifts a pause, we write down who did it and how they saw the risk at that point.
Where it comes from. Most of this does not come from you. What was alleged comes from the person who complained, and what bears it out comes from records we already hold. We also keep a way of finding the complaint we are acting on, and that reference may carry information about the person who made it. We hold it because a decision to pause part of somebody's account has to be traceable back to what prompted it. A decision nobody can trace back is a decision nobody can review, including you.
Sensitive information can end up in what we write. Some of the reasons in our Terms concern an allegation that something unlawful was done, so what we write down can concern an alleged offence. Separately, where we have written down whether a decision would treat you unfairly because of who you are, that reasoning can touch something the law treats as especially sensitive, such as your health, your beliefs, your race, or your sex life. We do not ask you for any of it, we do not go looking for it, and we never use it to decide anything about you. Where it appears, it is there because it was needed in order to answer whether we were being fair to you, and it is among the first things we delete.
Our lawful basis is our legitimate interests, under Article 6(1)(f) of the UK GDPR. The interest is protecting people from harm being carried on through our platform, and being able to show that a decision to pause part of an account was properly made, properly recorded and open to review. Where we are required to pause an account by law, or by a body entitled to require it, our basis is our legal obligation, under Article 6(1)(c). For the especially sensitive information described above, our condition is Article 9(2)(f) of the UK GDPR, which permits it where it is necessary for the establishment, exercise or defence of legal claims. Where what we write concerns an alleged offence, Article 10 of the UK GDPR applies, and our condition is the one for legal claims at paragraph 33 of Schedule 1 to the Data Protection Act 2018. Both come to the same thing in practice. We hold it so that a decision we made can be answered for, to you, to the Information Commissioner's Office or to a court, and for nothing else.
No pause is ever decided by a computer. Two of our people have to agree before a pause takes effect, and whoever proposes it cannot be the one who agrees to it. In an emergency one of our people may act alone, and that pause ends by itself within twenty-four hours unless a second person has agreed to it by then.
What we tell you, and when. A pause has no effect until we have written to you. We tell you what is paused and from when, exactly what you can still do, the reason in words, the date it lifts by itself, how to reply and to whom, how to complain, and that your rights in law are not affected. We may hold the reason back for a time, where telling you would tip somebody off, destroy evidence, or create a risk to somebody's safety. We will never hold back the fact that something is paused, we write down why we held the reason back, and we tell you the reason once it is safe to do so.
We do not tell you who complained. You can ask us for a copy of the information we hold about you, and this record is part of it. What we will not give you is anything that would tell you who complained, or anything that is information about another person. Where we hold something back for that reason, we will tell you that we have done so and why, so you know the copy you have is not the whole of the record. The right that gives you a copy of your own information does not give you somebody else's, and we would answer a request from them about you in exactly the same way.
How long we keep it. We keep what was alleged for 12 months, and the record of what we decided for 6 years. Both are counted from the day the case ended, and where a case never went anywhere at all, from the day we opened it. At 12 months we delete what was alleged, where in our own records we could see something that bore it out, what harm we thought might carry on, and what we concluded about whether the decision would treat you unfairly. What is left is the record of the decision itself: that there was a case, which of the reasons in our Terms we relied on, what we paused if we paused anything, which of our people proposed it and which agreed to it, when we wrote to you, and how it ended. At 6 years we delete that as well, and what stays after that is our own internal note that a member of our staff took each step, with you taken out of it. Six years is the period in which a claim about something we did can still be brought, under the Limitation Act 1980, and it is the period we already use for other records for the same reason. Twelve months is shorter on purpose, because a pause can last twenty-eight days at the very most, and holding an unproven allegation about you for six years to account for twenty-eight days is longer than we can justify. This happens by itself, once a day, rather than waiting for one of our people to remember. The one thing that stops it is a dispute that is still live. Where you are challenging a pause, or a complaint, a request about your own information or a claim is still running, we keep the whole record until that is finished, and then delete it as soon as the periods above have run out.
Your rights, and how to use them. You can ask us for a copy of this record, ask us to correct it, ask us to limit how we use it while you dispute what it says, ask us to erase it, and object to us holding it at all. Write to privacy@veylox.uk. Your Rights below sets out each of those rights in full, together with the route for complaining to us about how we have handled information about you and the times we work to. Replying to a pause, exercising your rights over your own data, and getting in touch with us are all among the things a pause never stops.
Lawful Basis
Processing is carried out on the basis of:
- contractual necessity
- legal obligations
- legitimate interests
Where required, consent will be obtained.
Data Sharing
We may share data with:
- infrastructure providers
- third-party integrations (e.g. referencing, payment, tenancy services)
We do not sell personal data.
Who handles your data
We work with four different kinds of organisation, and the law treats them differently. We set them out separately so it is clear what each one does and who is responsible.
These providers process personal data only on our instructions, under a written data-processing contract. We remain responsible for your data.
Processors acting on our behalf (UK GDPR Article 28)
| Provider | Purpose | Region | Transfer safeguard |
|---|---|---|---|
| Google Cloud / Firebase | PurposeHosting, authentication, Firestore database, file storage, App Check, Cloud Functions | RegionDatabase and hosting: United Kingdom (London). Files you upload, such as documents and photographs, are currently stored in the United States. We are moving that storage to the United Kingdom. Sign-in data for Firebase Authentication is processed in the United States by Google. | Transfer safeguardStandard Contractual Clauses with the UK Addendum, plus Google LLC's EU-US Data Privacy Framework (UK Extension) |
| Google (Gemini API) | PurposeReading the content you send to our assistant, so that it can answer you. Reading compliance certificates and other property documents you upload, so that we can pick out the dates and reference numbers and save you typing them in. Writing a draft listing description from the property details a landlord has entered, including the address. Reading a listing description as it is written, so that wording which conflicts with letting rules can be pointed out before the listing is published. Until 3 September 2026, translating text on screen, which could include text you or another user had entered. It was triggered by the language setting in your own browser when a page loaded, for signed-in users, and not by anything you switched on. It was removed from the Platform on 3 September 2026 and no text is sent to Google to be translated now. We do not use this to make any decision about you, and we do not use your content to train Google's models. | RegionYour content may be stored briefly, or held in a temporary cache, in any country in which Google or its agents maintain facilities. | Transfer safeguardOur contract is with Google Cloud EMEA Limited in Ireland, which the United Kingdom recognises as providing an adequate level of protection. For onward transfers, Google relies on its certification under the EU-US Data Privacy Framework, UK Extension, and on standard contractual clauses with the United Kingdom International Data Transfer Addendum. |
| Cloudflare (Turnstile) | PurposeProtecting the sign-up flow, and certain secure areas of the service, against automated abuse. The check loads only once you start creating an account, or when you open one of those secure areas. It does not load when you are simply browsing the site or when you sign in to an existing account. It runs in the background, normally completes without you noticing, and only shows you a challenge if something about the visit looks unusual. It receives your IP address and basic technical information about your browser. It does not receive your name, your email address, your password, or anything else you type into the form. Cloudflare also uses what it learns from these checks for its own purposes, which we explain separately below. | RegionYour connection is normally handled at Cloudflare’s UK data centre. Cloudflare, Inc. is based in the United States and may access the data from there. | Transfer safeguardStandard Contractual Clauses with the UK Addendum, under Cloudflare’s published data processing agreement. |
| Private Email (Namecheap) | PurposeSending service emails (verification, receipts, notices) | RegionUS | Transfer safeguardUK IDTA |
| Daily (Daily.co) | PurposeRunning live video viewings. When you join a viewing, Daily carries the live picture and sound between you and the other party, along with anything you choose to share on screen, anything typed into the chat during the call, the display name you enter before joining, and your IP address and basic device information. VEYLO X never joins the call. Recording is switched off for every room and for every person joining, and the room setting is checked again before anyone is issued a pass to join. Daily has confirmed to us in writing that a room setting overrides the settings on our account, so recording cannot be turned back on by a setting elsewhere in our Daily account. Because we do not record the call, there is no picture or sound from the call for Daily to keep. Daily does keep technical records about the call itself, such as when it ran and how well the connection performed. Its published policy is not consistent about how long: the same document says data is stored indefinitely, and also says usage data is kept for one year and performance data is deleted after one month. Daily has not told us which of those applies to the records it keeps about a video call, so we are asking, and we will update this notice once we know. We do not receive or keep any picture, sound, screen share or chat from the call. We keep only a record that the viewing took place, which people took part, and when the room expired. | RegionWe set every viewing room to run on Daily servers in London. That is not the same as saying nothing leaves the United Kingdom, and we are not telling you that it is. Daily is a United States company and uses other United States companies to run its service. Two of those provide relay servers. When the two devices cannot reach each other directly, the picture and sound are carried through one of those relay servers instead, so part of a call can travel through the United States. Our contract is with Daily, Co., of San Francisco, California. We have not yet confirmed where Daily holds its own technical records about the call. We are establishing that with the provider and will update this notice as soon as we have. | Transfer safeguardStandard Contractual Clauses with the UK Addendum, under our signed data processing agreement with Daily, Co. |
| Mapbox | PurposeMap tiles for property listings, and the walking-distance overlay that shows what is within a few minutes’ walk (location data, which can be personal data when linked to your session) | RegionUK / US | Transfer safeguardUK IDTA |
| PostHog | PurposeAnonymous product analytics. We use it to see which steps people reach and where problems happen, so we can fix bugs and improve the service. Events are anonymous and are never linked to your name or email. | RegionEU (European Union servers) | Transfer safeguardStandard Contractual Clauses with the UK Addendum, where any provider support takes place outside the UK or EU |
| Stripe (Stripe Payments Europe, Ltd / Stripe, Inc.) | PurposeSubscription billing and card / payment processing. We never store your full card number; Stripe handles it. | RegionUnited Kingdom and European Economic Area, with transfers to Stripe, LLC in the United States and to Stripe affiliates and sub-processors in other jurisdictions. Under the Stripe Data Processing Agreement, Stripe may transfer personal data on a global basis as necessary to provide its services. | Transfer safeguardEU-US Data Privacy Framework; the European Commission's standard contractual clauses; and the United Kingdom International Data Transfer Addendum, under the Stripe Data Processing Agreement. |
Our database and hosting are in the United Kingdom (London). Files you upload are currently stored in the United States, and we are moving that storage to the United Kingdom. Some providers may also need to access data from outside the United Kingdom for support, monitoring, or through their own sub-processors. Where that happens we rely on the transfer safeguards recorded against each provider in the table above, and on the safeguards described under International transfers below.
These organisations decide for themselves how they use your data and are responsible for it in their own right. What is listed here is their own use of your data, not work they carry out for us as our processor. Where we share your data for a credit or referencing check, we ask your permission first, and you should also read their own privacy notice. Those that carry out credit, referencing or identity checks run them under their own regulatory permissions.
Independent organisations we share your data with, or introduce you to
| Organisation | Purpose | Role |
|---|---|---|
| Let Alliance (a trading name of Barbon Insurance Group Limited, FCA 308724) | PurposeFull tenant reference and affordability assessment, including income and affordability checks, identity authentication and fraud screening, and Open Banking where requested as part of the Let Alliance reference. You authorise Let Alliance to carry out the check under its own privacy notice and permissions. This may involve credit reference agencies. It may include a quotation (soft) credit search, which can leave a soft-search record on your credit file but does not affect your credit score. Let Alliance returns the referencing result. VEYLO X records the result as a neutral record-keeper and does not score, approve or recommend your application. | RoleIndependent controller |
| Credas Technologies Ltd | PurposeIdentity verification (document, address and liveness), AML, sanctions and PEP screening, bank account and source-of-funds checks, and company verification (KYB). You authorise Credas to run each check under its own privacy notice and permissions. Credas returns the screening result. VEYLO X records the result as a neutral record-keeper and does not interpret, clear, guarantee or remediate any AML, sanctions or PEP result. | RoleIndependent controller |
| Fena (Fena Labs Ltd) | PurposeOpen Banking payment initiation through Fena, the FCA-authorised Payment Initiation Service Provider, for rent and deposit payments. You authorise each payment in your own bank app. VEYLO X does not receive, hold or transfer your money. | RoleIndependent controller |
| TDS (Tenancy Deposit Scheme) | PurposeStatutory deposit protection. We send your tenancy and deposit details to the scheme to register the protection; we never hold the deposit money itself | RoleIndependent controller |
| Tuxa (Marks Out Of Tenancy Ltd) | PurposeTelling us whether a property needs a licence from its council. We send the property's address and postcode. We do this in our legitimate interests under Article 6(1)(f) of the UK GDPR, in helping a landlord see what a property needs; you can object, and Your Rights below says how. We hold an account with Tuxa and pay for each lookup. | RoleIndependent controller |
| PolicyBee, Hiscox, ARAG | PurposeInsurance and legal-advice helpline, engaged only when a claim is notified | RoleIndependent controller. This row says "controller to controller" elsewhere in our records; the two mean the same thing, that they decide for themselves what they do with your data rather than acting on our instructions. |
| Cloudflare, Inc. (Turnstile) | PurposeImproving Cloudflare’s own systems for telling people apart from automated traffic. Cloudflare uses what it learns from the checks described above across the many websites it protects, so this is its own use of that information rather than something we ask it to do. It is the same check you have already passed, not an extra one, and it involves no further information about you beyond what that check already sees. Cloudflare is responsible for this use in its own right, and you should read Cloudflare’s own privacy notice for it. | RoleIndependent controller |
A referral partner is an organisation we can introduce you to. You apply to them directly, under their own terms and their own privacy notice. We do not send them your application, your documents or your contact details. We may receive a referral fee if you take up their service.
Referral partners
| Partner | Service | How it works |
|---|---|---|
| RentGuarantor | ServiceOptional rent guarantor service. A landlord may suggest it, and you decide whether to use it. You are never required to use it, and your application does not depend on it. | How it works You apply to RentGuarantor directly and we do not send them your personal data. Where you open RentGuarantor from the Platform, we record that the link was opened, and which application it related to. That record holds your account identifier only. It does not hold your name, your email address or your contact details. RentGuarantor tells us whether you have taken out or cancelled a guarantee, and a member of our staff records what they tell us. That status therefore reaches us from RentGuarantor rather than from you. We record it and show it to the landlord you applied to, so that the landlord knows the position on your application. RentGuarantor does not tell us anything else about you, and we do not receive your application to them, their assessment of it, or any information about your finances. We process these records to receive and check the referral fee RentGuarantor pays us, which is 7.5% of the fee you pay them, and to keep the accounting records the law requires us to keep. We do this in our legitimate interests in being paid correctly and in meeting our own record-keeping obligations, and, as to the status we show the landlord, to take the steps you have asked us to take on your application. We delete the record that you opened the link 24 months after it was opened, and we delete the guarantee status 6 years after it was last updated. We keep the accounting records for six years. You can object to processing carried out in our legitimate interests; see Your Rights below. |
This last group works the other way round from the three above. We are not sending your information to an organisation so that it can do something for you. We are looking something up about a property, in a public register or in open data, and recording the answer on that property's record.
To look something up we have to send the property's postcode, and for some of them its full address. We do not send your name, your email address, your account details, your documents or anything about your finances. What comes back is information about the property, or about the area around it, rather than about you. Where it is recorded against a property we can link to you, for example because you are the landlord who listed it, we treat it as your personal data and the rights set out below apply to it in the ordinary way.
Article 14 of the UK GDPR is about personal data a company obtains from somewhere other than the person it is about, and it is the reason this group is written out here. Every source in the table is a public register or a publicly accessible open data service. We use these lookups in our legitimate interests, under Article 6(1)(f) of the UK GDPR, in describing a property accurately and in helping a landlord see what a property needs. You can object; see Your Rights below. What comes back is kept on the property record, under the retention rules for that record in the table above. Nine of the eleven sources in the table are United Kingdom public bodies and are provided from the United Kingdom. The other two are private services: postcodes.io and OpenStreetMap. The map data lookup is made to overpass-api.de, which is operated outside the United Kingdom, so when that lookup runs the property's coordinates are transferred out of the United Kingdom. We have not established which country that service is provided from, and we have not established where postcodes.io is provided from either. We do not rely on adequacy regulations under Article 45A of the UK GDPR for any of these lookups, and there is no data-processing contract or other safeguard under Article 46 or Article 47 behind them, so there is no copy of a safeguard for us to give you. We would rather say that than name a protection we have not checked. What we send is the property's postcode, coordinates or address, and not your name or your contact details. These transfers are set out again under International transfers below. Where the table says your own device makes the lookup, the service you are looking up can see your device's network address.
Some of these your own device contacts directly, rather than our servers doing it for you. Where that happens the service receives your device's network address, because that is how a connection is made, and the table says which ones. We send them nothing else about you.
Public registers and open data we look up about a property
| Source | What we send | What comes back | Who makes the connection |
|---|---|---|---|
| postcodes.io | What we sendThe property's postcode | What comes backThe map coordinates for that postcode, and the local authority area it sits in | Who makes the connectionOur servers, and your own device |
| Energy certificate register | What we sendThe property's address and postcode | What comes backThe energy performance certificate held on the public register for that property, including its rating and when it was lodged | Who makes the connectionOur servers |
| Environment Agency flood map | What we sendThe property's coordinates | What comes backWhether the property sits in an area recorded as being at risk of flooding | Who makes the connectionOur servers |
| Environment Agency flood warnings | What we sendThe property's coordinates | What comes backThe flood warnings in force near the property at that moment | Who makes the connectionYour own device |
| Mining Remediation Authority | What we sendThe property's coordinates | What comes backWhether the property sits over recorded former coal workings | Who makes the connectionOur servers |
| Historic England | What we sendThe property's coordinates | What comes backWhether the building is listed | Who makes the connectionOur servers |
| Planning data | What we sendThe property's coordinates | What comes backWhether the property sits inside a conservation area | Who makes the connectionOur servers |
| Police open data | What we sendThe property's coordinates | What comes backThe recorded street level crime figures for the streets around it | Who makes the connectionOur servers |
| NHS organisation directory | What we sendThe property's coordinates | What comes backThe doctors' surgeries near the property | Who makes the connectionOur servers |
| OpenStreetMap | What we sendThe property's coordinates | What comes backThe shops and other amenities near the property | Who makes the connectionOur servers, and your own device |
| Transport for London | What we sendThe property's coordinates | What comes backThe stations and bus stops near the property | Who makes the connectionYour own device |
Companies House. If you let through a limited company, we look that company up on the public register at Companies House. We do it to confirm that the company exists and that you are recorded as one of its officers, because that is what lets us show your tenant a company name in place of a personal name. What comes back is the company's registered details together with the names and roles of its officers, which can include people other than you. This is personal data we have obtained from a public register rather than from you, and Article 14 of the UK GDPR is why it is set out here. We do it to perform our agreement with you, and in our legitimate interests in recording accurately who a landlord is. What comes back is kept on the account and property record, under the retention rules in the table above.
E-signature of tenancy documents is handled on VEYLO X's own infrastructure, so it is not a third party.
We last checked these lists against the organisations we actually use on 4 September 2026. A new organisation can be in use before it appears here, and we would rather you knew that was possible than be told it never is. If you want to know whether a particular organisation handles your data, ask us at privacy@veylox.uk and we will tell you.
International transfers
We intend to transfer personal data to countries outside the United Kingdom. Where we do, we make sure the transfer is protected in one of the ways the law allows.
Our database and hosting are in the United Kingdom (London). Personal data is transferred outside the United Kingdom in the following circumstances.
Files you upload. Documents, certificates and photographs you upload to the Platform are currently stored in the United States by our infrastructure provider, Google. That transfer is covered by the safeguard recorded against Google in the complete list of service providers above. We are moving this storage to the United Kingdom, and we will update this notice when we have.
Signing in to your account. When you create an account, sign in, or confirm who you are again immediately before you sign a document electronically, that sign-in data is processed in the United States by our authentication provider, Google. That transfer is covered by the Standard Contractual Clauses with the UK Addendum, plus Google LLC's EU-US Data Privacy Framework (UK Extension).
Security checks when you create an account. Our security check provider, Cloudflare, normally handles your connection at its UK data centre, but Cloudflare, Inc. is based in the United States and may access the information from there. That transfer is covered by the Standard Contractual Clauses with the UK Addendum, under Cloudflare's data processing addendum.
Live video viewings. When you take part in a live video viewing, the picture and sound travel from your device to our video provider, Daily, and usually straight between the two devices on the call. We set every viewing room to run on Daily servers in London. That is not the same as saying nothing leaves the United Kingdom, and we are not telling you that it is. Daily is a United States company and uses other United States companies to run its service. Two of those provide relay servers. When the two devices cannot reach each other directly, the picture and sound are carried through one of those relay servers instead, so part of a call can travel through the United States. Our contract is with Daily, Co., of San Francisco, California. That transfer is covered by the Standard Contractual Clauses with the UK Addendum, under our signed data processing agreement with them. We have not yet confirmed where Daily holds its own technical records about the call. We are establishing that with the provider and will update this notice as soon as we have. We do not receive or keep any picture, sound or chat from the call.
Looking a property up in a public register or in open data. When we look a property up in one of the sources listed under Who handles your data above, we send the property's postcode, coordinates or address. The map data lookup is made to overpass-api.de, which is operated outside the United Kingdom, so those coordinates leave the United Kingdom. We have not established which country that service is provided from, and we have not established where postcodes.io is provided from either. We do not rely on adequacy regulations under Article 45A of the UK GDPR for these lookups, and there is no safeguard under Article 46 or Article 47 behind them, so there is no copy of a safeguard for us to provide. We do not send your name or your contact details with a lookup. Where your own device makes the lookup rather than our servers, the service can see your device's network address.
Transfers to the European Economic Area. Some of our providers process personal data on servers in the European Economic Area. The United Kingdom government has decided that the European Economic Area provides an adequate level of protection for personal data, so no further safeguard is required for those transfers.
Transfers to the United States and elsewhere. Some of our providers, and some of their own sub-processors, process personal data in the United States or in other countries. The United Kingdom has not made an adequacy decision covering those transfers generally. We therefore rely on the safeguards permitted by Article 46 of the UK GDPR. Depending on the provider, the safeguard is one or more of the following:
- the United Kingdom International Data Transfer Agreement;
- the European Commission's standard contractual clauses, together with the United Kingdom International Data Transfer Addendum;
- the provider's certification under the EU-US Data Privacy Framework, UK Extension.
The safeguard that applies to each provider is recorded against that provider in the complete list of service providers above.
You can ask us for a copy of the safeguard that applies to any transfer of your personal data. Contact us at privacy@veylox.uk and we will provide it, or tell you where it is published, within one month. Where a document contains commercially confidential terms, we will provide a copy with those terms removed.
Data Retention
We retain personal data only for as long as necessary to operate the service, meet legal obligations, and protect ourselves and our users from regulatory or contractual claims. The table below sets out our standard retention periods. Where a record is legally required for longer (e.g. tax, court evidence), the longer period applies.
| Data type | Retention | Why |
|---|---|---|
| Account record (name, email) | Account life + 12 months | Service operation, support follow-up |
| Search preferences (where and what you are looking for, and any income or savings figures you chose to give) | Until you delete them; otherwise for as long as your account is open | They are only useful while you are looking for a home, so you hold them and you can erase them yourself at any time in More › AI Property Preferences. Deleting them does not close your account |
| Messages between you and your landlord or tenant, and anything attached to them (the Conversations screen) | Tenancy chat messages and attachments: kept for six years from the end of the tenancy, then permanently deleted. We use this as our standard retention period because it reflects the usual six-year limitation period for many tenancy-related civil claims, including simple contract claims under the Limitation Act 1980, section 5. We email both parties 30 days before deletion, and again 7 days before deletion, so either of you can download a copy first. Deletion is permanent and we do not keep a copy afterwards | The thread is the record of what the two of you agreed, and either of you can download it if there is a dispute. A download takes full copies of the messages, and of anything attached to them, out of VEYLO X. Once that file is saved we cannot recall it or delete it, including the copy the other person takes, which is why whoever downloads it is asked whether to include the photographs. Where both names are on file, the document names both of you, as landlord and as tenant, using the names recorded on this tenancy. Where either name is missing it names neither. The document is designed to be given to a deposit adjudicator, the Property Ombudsman or a court. Your contact details are not included. Once sent, a message cannot be deleted through the chat by either side. Authorised VEYLO X staff can read these messages for support, safety, security, compliance and dispute-record purposes |
| Compliance attestations & declarations | 7 years from creation | Records supporting our own legal and tax position. HMRC requires records to be kept for six years from the end of the accounting period they relate to; we keep them for seven years from the date the record was created, which is how we apply that rule, because we work from the date a record was made rather than from an accounting period. It also covers the six-year limitation period for a contractual claim (Limitation Act 1980), so that a record is not destroyed while a claim can still be brought |
| Property certificates (EPC, EICR, gas safety record) | Lifetime of the certificate + 2 years. If a certificate was in force during one or more tenancies recorded on VEYLO X, we keep the tenancy copy until 6 years after the last recorded tenancy it covered has ended, if that is later. If a certificate was never in force during a recorded tenancy, only the certificate-period rule applies. | Statutory inspection records and evidence of compliance. A certificate that covered a tenancy forms part of that tenancy record because it may evidence what the landlord gave the tenant and what was in force during the tenancy. The landlord and the tenant for that tenancy can download the tenancy copy while that tenancy record is kept, including after the tenancy has ended. Removing a certificate from the property record does not delete a tenancy copy that is still within its retention period. |
| Tenancy records (parties, rent, deposit) | Tenancy end + 6 years | Limitation Act 1980: recoverable claim window |
| Named-tenant legal name (on a tenancy) | Tenancy end + 6 years | On the tenancy agreement party list and, where a deposit is protected, the statutory deposit-protection record (Limitation Act 1980; Housing Act 2004) |
| Electronic signature record (the Certificate of Completion, the times each party signed and confirmed who they are, the email address on each signer's account, and the IP address each signature came from) | Tenancy end + 6 years | Limitation Act 1980: the period during which a claim arising from the tenancy may be brought, and during which a party may need to show that the document was signed and by whom. It runs on the same clock as the tenancy records above, because the signing record is part of that tenancy's record. It is not the seven-years-from-creation period used for compliance attestations |
| References we seek about a tenant from a named referee (a previous landlord or employer): the referee's name, their reply, answers and comments | Tenancy end + 6 years; where no tenancy results, 6 years from the application | Limitation Act 1980: the period during which a claim arising from the tenancy or the application may be brought, and during which VEYLO X may need to evidence how it handled the application. This row covers replies VEYLO X seeks directly from a referee. The outcomes of checks run through our providers (identity, referencing and credit, right to rent, and Open Banking) are covered by the next row |
| VEYLO X record of a check outcome (identity, right to rent, tenant referencing and credit, affordability, and Open Banking checks run through our providers): which provider, the type of check, the result or status, the date, and a reference id | 6 years from the check | A minimal, outcome-only record kept in VEYLO X's legitimate interests (UK GDPR Article 6(1)(f)) to defend its own legal position within the limitation period (Limitation Act 1980) and to be able to show that it handled applications consistently and without discrimination (Equality Act 2010). It does not include your identity documents, photograph or facial or biometric data, share code, nationality, visa or immigration details, credit report, bank statement data, or any free-text notes. Each provider keeps the underlying check data for its own, shorter period under its own privacy notice (see Who handles your data). Your landlord remains responsible in law for carrying out and keeping the Right to Rent check |
| Referral partner: record that you opened the link | 24 months from when you opened the link | Checking the referral fee we are paid, and guarding against misuse of the referral link |
| Referral partner: guarantee status | 6 years from the last update | The limitation period for a claim arising from the guarantee you took out (Limitation Act 1980) |
| Referral fee accounting records | 6 years | Our own tax and accounting records, and the limitation period for a contractual claim (Limitation Act 1980) |
| Notifications & system messages | 24 months | Audit trail, dispute support |
| Analytics events (if consented) | 12 months | Aggregated product improvement |
| Support correspondence (messages to our support address that are not complaints) | 36 months | Quality, training, dispute support. A message that is, or later becomes, a complaint about our service or about how we have handled your personal information is a complaint record and the row below applies to it instead, from the day we close the complaint. A complaint usually reaches us by email, so the two look alike in your inbox; what decides which period applies is whether we treated it as a complaint, not which address you sent it to |
| Complaint records (a complaint you make to us about our service or about how we have handled your personal information, anything you send with it, our investigation, and our response) | 6 years from the day we close the complaint | This is a period we have chosen. Neither the law nor the Property Redress Scheme requires us to keep a complaint file for six years, and we are not telling you that they do. We keep it in our legitimate interests (UK GDPR Article 6(1)(f)) so that we can establish, exercise or defend a legal claim arising from the complaint while one can still be brought, which for a contract claim is six years (Limitation Act 1980, section 5), and so that we can produce the file if the Property Redress Scheme, a court or an enforcement authority asks us for it. If you ask us to erase a complaint file we may refuse for that reason, which is the exemption in Article 17(3)(e) of the UK GDPR, and we will tell you that is the ground we are relying on |
| Backup copies | 30 days rolling | Disaster recovery; auto-purged thereafter |
| Record of a network address (the address a request came from, the time, what was asked for and whether it worked; and, where we have refused an address, the decision, who made it, and why) | 6 months from the last time the record changed. Where an address was refused, the 6 months start when the refusal ended | So we can recognise a pattern of abuse, and so we can answer a complaint or a question from the regulator about a refusal we made. A refusal that is still running is not deleted, because deleting it would quietly let the address back in |
| Record of an account we refused (which account was refused, how many times, when the last refusal was, and which feature refused it) | 30 days after the most recent refusal included in that day’s record | So we can see short-term patterns showing whether our security checks are wrongly blocking genuine use, or one account is repeatedly hitting our abuse controls. We keep the totals for each day separately, and those name no account |
| Record of a case opened after somebody complained about you (what was alleged, the reason we relied on, our view of the harm, where our own records bore it out, the fairness check, what was paused, which of our people decided and when, what we told you and when, and how it ended) | 12 months for what was alleged, our view of the harm, where our own records bore it out, and the fairness check. 6 years for the record of the decision. Both counted from the day the case ended, or from the day we opened the case where it never led to a decision. Where a dispute about the pause is still running, nothing is deleted until it is finished | So we can answer you if you challenge a pause, answer a complaint or a question from the regulator about a decision we made, and show that a decision to pause part of somebody's account was properly made and properly reviewed. 6 years is the period in which a claim can still be brought (Limitation Act 1980). 12 months is shorter for what was alleged because a pause lasts 28 days at the most, and holding an unproven allegation about a named person for 6 years to account for that is longer than can be justified |
For this table, the lifetime of a certificate means the period for which that certificate or report is treated by VEYLO X as current for the relevant property record, based on the certificate type, the inspection date and any stated next-inspection date.
Live video viewings. We keep a technical record of each live video viewing: who joined, when, and the room's settings. We delete that record automatically 90 days after the viewing. We do not record the call, so there is no picture or sound to delete.
You may request deletion at any time (see Your Rights). Some of the periods in this table are required of us by law. Others are periods we have chosen, so that we can answer a claim while one can still be brought. Where we keep something after you have asked us to erase it, we keep only what the ground we are relying on actually needs, we limit what else we do with it, and we tell you the ground.
Cookies & similar technologies
We use a small number of cookies and similar technologies that are necessary to deliver the service you have asked for, and which do not require your consent. These keep you signed in, remember the cookie choice you make, remember your display theme once you have chosen one, and confirm that requests come from a genuine browser rather than an automated script. That last check is Firebase App Check, which uses Google reCAPTCHA Enterprise: it stores a value on your device and Google receives your IP address and technical information about your device and browser. We also keep a local copy of property listings on your device so that pages load faster.
Where you have opted in through the cookie banner, we also use anonymous analytics, which is processed on our behalf by PostHog on European Union servers. The analytics records which steps you reach and any errors, so we can improve the service. It is never linked to your name or email. We do not use advertising cookies, we do not sell your data, we do not use session recording, and we do not track you across other websites for marketing purposes. You can change your choice any time in Settings, then Cookie preferences.
The Cloudflare security check that protects our sign-up flow and certain secure areas of the service does not store anything on your device.
Artificial intelligence and automated processing
We use an artificial intelligence service provided by Google for the purposes set out below.
The assistant. Where you use the assistant in your message inbox, what you type is sent to Google so that a reply can be generated. Do not send the assistant anything you would not want processed in this way. The assistant provides general information about using the Platform. It does not give legal advice, it does not make any decision about you, your application or your tenancy, and nothing it says binds VEYLO X or your landlord.
Reading documents. Where you upload a compliance certificate or a similar property document, the document is sent to Google so that the dates, reference numbers and other details can be read out of it and filled in for you. You can always enter those details yourself instead, and you can correct anything that is read incorrectly. We do not treat what is read as verified, and it is recorded as your entry, not as a check we have carried out.
Writing a listing description. Where you ask us to draft a description for a property you are listing, the details you entered in the listing steps, including the address, are sent to Google so that a draft can be written for you. The draft is yours to edit or replace, and nothing goes on the listing until you publish it. You can always write the description yourself instead.
Checking listing wording. Where a listing description is being written, the text is sent to Google so that wording which conflicts with letting rules can be pointed out before the listing is published. What comes back is a prompt to the person writing the listing. It is not a decision about anyone, we do not treat it as a check we have carried out, and the landlord remains responsible for what they publish.
Translating text. This stopped on 3 September 2026. Until 3 September 2026 the Platform read your browser's own language setting when a page loaded and picked a language from it. If you were signed in, and that setting was one of the five it recognised, which covered four languages, Chinese in its traditional and simplified forms, Spanish, Arabic and French, text on the screen was sent to Google to be translated. It happened without you asking for it and before you could choose. If the setting was English, or any other language, nothing was sent. You had to be signed in for any of it to happen, because the function that carried out the translation refused requests from anyone who was not signed in, so a logged-out visitor's text never reached the model. What was sent could include things you or another user had typed, including names and figures on a tenancy. There was a language menu, but the choice you made in it was held in memory only and did not survive a reload, so it did not stop this.
That feature was removed from the Platform on 3 September 2026, and text on the screen is no longer sent anywhere to be translated. Two things about it are still true. Translations that were made are still stored on the device that made them, and nothing removes them. And the language menu still works, in More and on the landing page: it reads a fixed table of wording held inside the app, so choosing a language from it sends nothing anywhere.
Google processes this content as our service provider, on our instructions, under a written contract. Your content is not used to train Google's models.
None of this processing produces a decision that has a legal effect on you, or that similarly significantly affects you, within the meaning of Articles 22A to 22D of the UK GDPR. If you would rather not use the assistant, do not use it; nothing on the Platform depends on it. If you would rather not have a document read automatically, enter the details yourself. If you would rather write your listing description yourself, do not ask us to draft one. The check on listing wording is not optional, because it runs on the description whenever one is being written.
Security
We take appropriate technical and organisational measures to protect personal data against unauthorised access, loss, alteration and disclosure. The measures we take include the following.
Encryption. Personal data is encrypted while it is travelling between your device and the Platform, and while it is stored, by our infrastructure provider. In addition, we apply our own encryption to certain contact details before they are stored, so that they cannot be read from the underlying database.
Access control. Access to personal data is restricted by rule, at the level of each individual record. Our default position is that access is denied unless a rule expressly permits it, and we test those rules automatically. Certain sensitive operations additionally require the request to be verified as coming from our own application.
Audit records. Where a landlord, an agent or a member of our staff views a tenant's personal information through the Platform, we aim to record that access. Where a member of our staff looks up your contact details, our systems require them to give a written reason first, and that reason is recorded against their account before the details are shown to them. You can ask us for a copy of the record of who has accessed your information; see Your Rights below.
Two-factor authentication. You can turn on two-factor authentication for your account using an authenticator app. We do not currently require it.
Deletion. Where we delete personal data at your request, and a copy is held in an encrypted form, we destroy the key so that the copy cannot be read.
Personal data breaches. If a personal data breach occurs, we will assess it. Where the law requires it, we will report it to the Information Commissioner's Office within 72 hours of becoming aware of it, and where a breach is likely to result in a high risk to your rights and freedoms we will tell you without undue delay.
No system can be made completely secure, and we do not represent that ours is.
Insurance Alignment (Data Protection Context)
VEYLO X maintains cyber and data protection insurance.
This insurance:
- supports incident response
- does not guarantee prevention of breaches
- does not extend to user-controlled data risks
Users remain responsible for secure handling of their own data.
Data protection contact
We have a single point of contact for privacy queries and for requests about your rights. Contact us at:
Data protection contact
privacy@veylox.uk
VEYLO X Limited, 66 Paul Street, London, EC2A 4NA
We aim to acknowledge data protection enquiries, rights requests and complaints sent to this address within 3 working days. Where you are exercising a right over your own data, we will respond substantively within the statutory period of one month, which may be extended by up to two further months where the request is complex or where we have received a number of requests from you. If we extend, we will tell you within one month and explain why.
VEYLO X has not designated a Data Protection Officer under Article 37 of the UK GDPR. We have assessed that we are not required to designate one. The contact above handles the same enquiries.
Your Rights
Under UK GDPR you have the following rights in respect of your personal data:
- Access: a copy of the personal data we hold about you (subject access request).
- Rectification: correction of inaccurate or incomplete data. You can usually correct your details yourself in your profile. Some information that sits on a formal record cannot be edited in the app once it is fixed there, for example your legal name once your tenancy is signed or your deposit is registered. You can still ask us to correct it, and we will action a valid request within one month, whether or not anyone else has acted. Where we have already shared the corrected information with an organisation such as the deposit protection scheme, we or your landlord will let them know where we are required to, so their record can be updated too, and you can ask us who we have shared your name with.
- Erasure: deletion of your data. We may refuse to erase a record where one of the exemptions in Article 17(3) of the UK GDPR applies. Two of them come up here. The first is where we have to keep something to comply with a legal obligation, for example the accounting records HMRC requires us to keep. The second is where we need the record to establish, exercise or defend a legal claim, and that is the ground for the records we keep for the period in which a claim can still be brought, including your tenancy records, our record of a check outcome, our record of a complaint, and our record of a case opened after somebody complained about you. Those are periods we have chosen, not obligations imposed on us. Where the ground covers only part of a record we erase the rest, and we tell you which ground we have relied on.
- Restriction: limitation of how we process your data in certain circumstances. For example, if you dispute the accuracy of something we have recorded, you can ask us to restrict its use while we check it, or to note your disagreement alongside it.
- Portability: receipt of your data in a structured, machine-readable format.
- Objection: to processing carried out under legitimate interests or for direct marketing.
- Rights related to automated decision-making and profiling: under Articles 22A-22D of the UK GDPR (inserted by the Data (Use and Access) Act 2025). We use a deterministic, preference-based fit indicator that compares the search preferences you set against a landlord's declared listing fields, to show how well a property lines up with them. This does not make a decision about you, is not shared with landlords to screen you, and does not produce a legal or similarly significant effect on you. It runs under our legitimate interests; you can object at any time (see Objection above) or clear your saved preferences to switch it off.
- Withdraw consent: where processing is based on your consent, you may withdraw it at any time without affecting prior lawfulness.
To exercise any right, contact us at privacy@veylox.uk.
You have the right to complain to us if you consider that there has been a breach of data protection law in connection with your personal data. This right is in section 164A of the Data Protection Act 2018. To complain, email privacy@veylox.uk or write to us at the address at the end of this notice. You do not need to use any particular wording.
We aim to acknowledge your complaint within 3 working days. The law requires us to acknowledge it within 30 days, so our own promise is the shorter one. We aim to look into your complaint and tell you the outcome within 15 working days. The law requires us to respond without undue delay rather than by a fixed date, so this is our own promise too. If we need longer than 15 working days, we will tell you why and when to expect our answer.
If your complaint is about what a landlord or agent did with your information after they received it, they are a separate controller for that and may need to answer that part. We will answer for our own part.
You also have the right to lodge a complaint with the UK supervisory authority, the Information Commissioner's Office, at ico.org.uk/make-a-complaint or on 0303 123 1113. You can contact the ICO at any time. You do not have to complain to us first, and complaining to us does not affect your right to go to the ICO.
Changes
This Notice may be updated from time to time.
We keep the earlier versions of this notice, with the dates each one was in force. If you want to read the version that applied to you on a particular date, ask us at info@veylox.uk and we will send it to you.
12 September 2026: Earlier versions of this notice are published again, each at its own fixed address that does not change. Until today this record said we had stopped publishing them, and from 11 September 2026 that was no longer true. You can now read the version that applied to you on a particular date yourself, and you can still ask us for it.
4 September 2026, later the same day: Stopped publishing earlier versions of this notice as pages on this site. Until today the head of this notice linked to a page that listed them. We still keep every earlier version, with the dates each one was in force, and if you want to read the version that applied to you on a particular date you can ask us at info@veylox.uk and we will send it to you. Nothing about how we handle your personal data changes with this release, and no earlier version has been destroyed.
One thing about that page is worth recording, because it was live and it mattered. From the morning of 4 September 2026, when privacy-v1.8-2026-09-04 was published, until later the same day, the page named privacy-v1.7-2026-08-29 as a version we held but did not link to it and no copy of it was published, so for those hours a reader covered by that version could not read it there. The copy was published, and the page has now been withdrawn in favour of asking us. This is a separate version from privacy-v1.8-2026-09-04, published earlier today, rather than an edit to it, because a version that has been published is not rewritten.
Summary of changes
11 August 2026: Updated the property-certificate retention wording to clarify that tenancy copies of certificates are retained on the tenancy-record retention clock; both tenancy parties can download the tenancy copy while the tenancy record is kept; and removing a certificate from the property record does not delete a tenancy copy still within its retention period. Also corrected the version/date metadata for this substantive update.
Metadata correction: a substantive certificate-retention update was published under privacy-v1.3-2026-08-09 on 11 August 2026 at 22:28. VEYLO X corrected the label to privacy-v1.4-2026-08-11 on 11 August 2026.
20 August 2026: Added the right to complain to VEYLO X about how your personal data has been handled, and the times in which we aim to acknowledge and answer a complaint. That right is in section 164A of the Data Protection Act 2018 and has applied to complaints received on or after 19 June 2026. This notice did not state it before today. Also shortened the time in which we aim to acknowledge messages sent to our data protection address from 5 working days to 3 working days, and removed a sentence that asked readers to come to us before the Information Commissioner's Office, which is not a condition of going to the ICO.
29 August 2026: Added a section on network addresses. It says that we keep a record of the address a request comes from, with the time, what was asked for and whether it worked, so that we can notice and stop abuse of our service; that we may refuse requests coming from a particular address; that a refusal is a decision about an address rather than about a person; what a refusal does and does not reach; how to ask us to lift one; and that one address is often shared by many people, so we will lift a refusal promptly where it is affecting people who have done nothing wrong. Added a retention row for that record. This notice did not state any of it before today. Nothing was being recorded and no request had been refused before this section was published.
4 September 2026: Six changes.
Added a retention row for complaint records. We keep the record of a complaint, and of what we did about it, for 6 years from the day we close it. That is a period we have chosen and not one that the law or the Property Redress Scheme requires, and the row says so. Amended the support correspondence row so that it is clear which of the two applies to a message that is a complaint.
Rewrote the erasure right. It previously said that erasure was subject to any overriding legal retention obligation listed in the retention table. That was not accurate. Several of the periods in that table are periods we have chosen so that we can answer a claim while one can still be brought, rather than obligations imposed on us. The right is now described by reference to the exemptions in Article 17(3) of the UK GDPR, and it names the two we rely on. Replaced the sentence at the end of the retention table which said that where deletion would conflict with a statutory retention obligation we keep only the legally required minimum, for the same reason. That section now says that some of the periods are required of us by law and others are periods we have chosen.
Removed a sentence at the end of Who handles your data. It said that we update the list whenever an organisation is added or removed, and that the version published here is always the current one. Neither half was true. Tuxa, which tells us whether a property needs a licence from its council, has been in use since 29 May 2026 and was not listed here until today, and there was no process that would have caught that. In its place the notice now says when we last checked the lists, says plainly that an organisation can be in use before it appears, and asks you to write to us if you want to know whether a particular organisation handles your data.
Added a fourth group, public registers and open data we look up about a property, with a table of twelve sources and a paragraph about Companies House. These are places we look information up rather than organisations we send your information to, and this notice had no section for them. Article 14 of the UK GDPR covers personal data obtained from a source other than the person it is about, and this notice did not state any of it before today. Moved postcodes.io out of the processor table into the new group at the same time: the heading of that table says that everything under it is covered by a written data-processing contract, and there is no such contract with postcodes.io, which is a free public service with no account and nothing to sign. It was in the wrong table. Added Tuxa (Marks Out Of Tenancy Ltd), which tells us whether a property needs a licence from its council, to the list of independent organisations. It has been in use since 29 May 2026 and had never appeared in this notice. It is listed as an independent organisation rather than as a processor because its published policy lists the addresses it is asked about among the data it collects, and gives its own legitimate interests as the basis for using them, which is a decision it takes for itself rather than on our instructions.
Corrected what this notice says about translation, and put it in the past tense. Until 3 September 2026 the Platform read your browser's own language setting when a page loaded, and for a signed-in reader whose setting was one of five, covering four languages, it sent text on the screen to Google to be translated. This notice said instead that text was sent when you switched the Platform to another language, and that no text was sent while you stayed in English. Neither was right: nothing was switched, and a reader in that position was never in English to stay in. The feature was removed from the Platform on 3 September 2026, so the notice now describes it in the past tense, both in the section on artificial intelligence and in the row for Google in the table of processors. It also records that translations already made remain stored on the device that made them, and that the language menu still works because it reads a fixed table of wording held in the app rather than sending anything anywhere. Removed the sentence telling you to stay in English if you would rather no text was sent for translation. There is nothing left to opt out of.
Said what we do and do not know about these lookups leaving the United Kingdom. Nine of the eleven sources in the new group are United Kingdom public bodies and are provided from the United Kingdom; the other two are private services. The map data lookup is made to overpass-api.de, which is operated outside the United Kingdom. We have not established which country it or postcodes.io is provided from; we do not rely on adequacy regulations under Article 45A of the UK GDPR for these lookups; and there is no safeguard under Article 46 or Article 47 behind them. International transfers now lists these lookups alongside the other circumstances in which personal data leaves the United Kingdom, so that the two sections say the same thing. None of this was stated before today.
4 September 2026, privacy-v1.10-2026-09-04. Two presentational changes and no change to how we handle your personal data or to any right you have. The sentence about earlier versions has moved from the top of the page into this section, which is where the version history already is. And the entries before the most recent one are now behind a control marked Summary of changes, which you open to read them. Nothing has been removed: this section was already about fifteen hundred words and grows with every release. The most recent entry stays in plain view.
9 September 2026: We corrected this section to say that some of our security controls limit how often an account can make particular requests. Those account limits have been in use since 28 June 2026, but this section did not previously describe them. From 9 September 2026 we also keep a record for each day of refusals against an account: how many refusals happened that day, when the last one was, and which feature refused the request. We use that record for security monitoring and investigation and for troubleshooting, and for handling rights requests, complaints and regulatory enquiries. Access to the identifiable records is restricted and logged. We added a retention row saying that each day’s account record is kept for 30 days after the most recent refusal included in it. We also made clear which sentences in this section are about a network-address refusal and which are about an account limit.
7 September 2026: Added a section about what we write down when somebody complains about you. It says that a complaint opens a case, that a case is not a finding about you and that we do not count complaints; what we write down, including what was alleged, the reason we relied on, our view of the harm, the fairness check and what was paused; that most of it comes from the person who complained rather than from you; that the reference we keep to the complaint may carry information about the person who made it; that especially sensitive information can end up in what we write, and why; our lawful basis, including the condition we rely on for especially sensitive information and the condition we rely on where what we write concerns an alleged offence; that no pause is ever decided by a computer; what we tell you and when, and the limited grounds on which we may hold the reason back; that we will not tell you who complained, and that we will tell you when we have held something back for that reason; that we keep what was alleged for 12 months and the record of the decision for 6 years, counted from the day the case ended; and how to use your rights over it. Added a retention row for that record. Added that record to the list in the erasure right of records we may keep while a claim can still be brought. This notice did not state any of it before today.
Contact
VEYLO X Limited
66 Paul Street, London, EC2A 4NA
info@veylox.uk
Company number: 17203848 · ICO registration: ZC156986
Need a hand?
We reply to every email. Usually within one working day. Monday-Friday, 09:00-18:00 UK.
support@veylox.uk