Skip to main content

Privacy Policy

Last updated: 14 August 2026

1. Who we are

AgentOS Ltd (“we”, “our”, “us”) is the data controller for personal data processed through the MTD for Landlords service (“the Service”). We are based in the United Kingdom and subject to UK GDPR and the Data Protection Act 2018.

Data Protection contact: privacy@agentos.com

2. Personal data we collect

  • Account data — name, email address, profile image, organisation name, and the account identifier issued by the SaaS Factory central identity provider. We do not store a password for you: sign-in is performed entirely by that identity provider.
  • Tax profile data — National Insurance Number (NINO, stored encrypted), self-assessment status. Your HMRC OAuth tokens are held in the SaaS Factory Tether credential vault, not by us.
  • Property data — property addresses, descriptions, and portfolio metadata.
  • Financial transaction data — income and expense records imported from your letting agent or bank, and manual entries.
  • Bank account data (opted-in users only) — transaction history imported via Open Banking (TrueLayer), plus the account identifier and display label. Your account number, sort code, IBAN and balance are read live from TrueLayer each time a page is rendered and are never stored by us.
  • Communication data — email address (for transactional notifications). Our weekly digest email contains your year-to-date income, expenses and net profit or loss figures in the message body.
  • Technical data — IP address, user ID, browser/device metadata collected for security monitoring and rate limiting.

3. Why we process your data

PurposeLegal basis
Providing the MTD ITSA submission serviceContract (Art. 6(1)(b))
Submitting quarterly updates to HMRC on your behalfLegal obligation (Art. 6(1)(c))
Sending service notifications (confirmations, deadline reminders)Contract (Art. 6(1)(b))
Security monitoring, rate limiting, and abuse preventionLegitimate interests (Art. 6(1)(f))
Audit logging for security and dispute resolutionLegitimate interests (Art. 6(1)(f))
Connecting to your bank account (Open Banking)Consent (Art. 6(1)(a))

4. How long we keep your data

  • Account data: duration of account + 30 days after deletion.
  • Financial records and HMRC submissions: 7 years from the transaction date (HMRC statutory requirement).
  • Audit logs: 7 years.
  • Rate-limit counters (Vercel KV / Upstash): automatic TTL of twice the rate-limit window — about 2 minutes on the main API paths, and about 2 hours on the email-verification resend limiter. No long-term retention.

5. Recipients and sub-processors

Under UK GDPR Article 13(1)(e), we are required to inform you of all recipients of your personal data. The table below lists every sub-processor and third-party recipient we use, why they receive your data, where they are located, and the transfer mechanism that protects your data when it leaves the UK.

Sub-processorRoleLocationTransfer basisDPA
Neon Inc.Managed PostgreSQL database — stores all account, property, and financial dataUS (AWS us-east-1)SCCs / UK IDTAView Neon Inc. DPA ↗
Vercel Inc.Application hosting, edge compute, CDNUS / EU edge PoPsSCCs / UK IDTAView Vercel Inc. DPA ↗
TrueLayer Ltd.Open Banking connectivity (bank account import — opted-in users only)UK / EEANo restricted transferView TrueLayer Ltd. DPA ↗
Resend Inc.Transactional email delivery, including the weekly digest — whose body contains your year-to-date income, expenses and net profit or lossUSSCCs / UK IDTAView Resend Inc. DPA ↗
SaaS Factory connections proxy / SF TetherThird-party API gateway and credential vault. Every HMRC and Open Banking request we make is routed through it — carrying your National Insurance Number in the request path and your quarterly income and expense figures in the request body — and it holds your HMRC and bank OAuth tokens, which we never store ourselves.Not asserted — see the note belowNot asserted — see the note belowNot asserted — see the note below
SaaS Factory central identity provider (SF Auth)Performs all sign-in for the Service over OIDC and returns your account identifier, email address, name and profile image. We hold no password of yours.Not asserted — see the note belowNot asserted — see the note belowNot asserted — see the note below
Temporal Technologies Inc.Workflow orchestration (submission processing, scheduled reminders)USSCCs / UK IDTAView Temporal Technologies Inc. DPA ↗
Upstash Inc. / Vercel KVDistributed rate limiting — receives user IDs and IP addresses as short-lived rate-limit keys on every authenticated API request to prevent abuseUS (AWS us-east-1)SCCs / UK IDTAView Upstash Inc. / Vercel KV DPA ↗
AgentOS Ltd.Letting agent data source (property, tenancy, and transaction imports)UKNo restricted transferIn service agreement
HMRCStatutory recipient of MTD quarterly income and expense updatesUKNo restricted transfer — statutory obligationView HMRC DPA ↗

SCCs = Standard Contractual Clauses (UK-approved version). IDTA = UK International Data Transfer Agreement. A copy of any executed DPA is available on request at privacy@agentos.com.

A note on the SaaS Factory platform

This Service is built and hosted on the SaaS Factory platform, and three of its components receive your personal data: the connections proxy and SF Tether vault (every HMRC and Open Banking request passes through it, and it holds your HMRC and bank credentials), the central identity provider (SF Auth) (which signs you in), and SF Core’s central email relay (through which every email we send — including the weekly digest and its financial figures — is dispatched before it reaches Resend).

We are listing them here because you are entitled to know they receive your data. Their hosting locations, restricted-transfer mechanisms and DPA references are not asserted in this policy — we are confirming that position and will publish it here once settled. Ask us at privacy@agentos.com for the current answer.

6. International transfers

Some sub-processors are based in the United States. Where personal data is transferred outside the UK we rely on Standard Contractual Clauses (UK-approved) and/or the UK International Data Transfer Agreement (IDTA) as the lawful transfer mechanism. Details are listed in the sub-processor table above and in our full ROPA.

7. Your rights

Under UK GDPR you have the right to:

  • Access a copy of your personal data (Subject Access Request)
  • Rectify inaccurate data
  • Erase your data (“right to be forgotten”) — subject to legal retention obligations
  • Restrict processing in certain circumstances
  • Data portability (structured, machine-readable export)
  • Object to processing based on legitimate interests
  • Withdraw consent at any time (where processing is consent-based)
  • Lodge a complaint with the ICO at ico.org.uk

To exercise any of these rights, contact privacy@agentos.com. We will respond within one calendar month.

8. Security

We protect your data using AES-256-GCM encryption at rest for the sensitive fields we hold (most importantly your NINO), TLS 1.2+ in transit, and row-level security on the database. We store no password for you at all — sign-in is delegated to the SaaS Factory central identity provider — and your HMRC and bank credentials are held in the SaaS Factory Tether vault rather than by us. Sessions expire after 8 hours and can be revoked. Rate limiting is enforced on all authenticated API endpoints using Vercel KV (Upstash); note that a rate-limit key holds your raw user id, or your raw IP address when you are not signed in — these values are not hashed, though they are short-lived. Security events are monitored and critical incidents trigger immediate engineering escalation.

9. Cookies

We use strictly necessary session cookies for authentication (Auth.js / NextAuth). No advertising or analytics third-party cookies are set. You can manage cookies through your browser settings; disabling session cookies will prevent you from signing in.

10. Changes to this policy

We may update this policy when we add new sub-processors or change how we process data. Material changes will be notified by email. The “Last updated” date at the top of the page always reflects the most recent revision. For a full audit trail of processing activities see our Article 30 ROPA.