Privacy Policy
Last updated: 14 August 2026
1. Who we are
AgentOS Ltd (“we”, “our”, “us”) is the data controller for personal data processed through the MTD for Landlords service (“the Service”). We are based in the United Kingdom and subject to UK GDPR and the Data Protection Act 2018.
Data Protection contact: privacy@agentos.com
2. Personal data we collect
- Account data — name, email address, profile image, organisation name, and the account identifier issued by the SaaS Factory central identity provider. We do not store a password for you: sign-in is performed entirely by that identity provider.
- Tax profile data — National Insurance Number (NINO, stored encrypted), self-assessment status. Your HMRC OAuth tokens are held in the SaaS Factory Tether credential vault, not by us.
- Property data — property addresses, descriptions, and portfolio metadata.
- Financial transaction data — income and expense records imported from your letting agent or bank, and manual entries.
- Bank account data (opted-in users only) — transaction history imported via Open Banking (TrueLayer), plus the account identifier and display label. Your account number, sort code, IBAN and balance are read live from TrueLayer each time a page is rendered and are never stored by us.
- Communication data — email address (for transactional notifications). Our weekly digest email contains your year-to-date income, expenses and net profit or loss figures in the message body.
- Technical data — IP address, user ID, browser/device metadata collected for security monitoring and rate limiting.
3. Why we process your data
| Purpose | Legal basis |
|---|---|
| Providing the MTD ITSA submission service | Contract (Art. 6(1)(b)) |
| Submitting quarterly updates to HMRC on your behalf | Legal obligation (Art. 6(1)(c)) |
| Sending service notifications (confirmations, deadline reminders) | Contract (Art. 6(1)(b)) |
| Security monitoring, rate limiting, and abuse prevention | Legitimate interests (Art. 6(1)(f)) |
| Audit logging for security and dispute resolution | Legitimate interests (Art. 6(1)(f)) |
| Connecting to your bank account (Open Banking) | Consent (Art. 6(1)(a)) |
4. How long we keep your data
- Account data: duration of account + 30 days after deletion.
- Financial records and HMRC submissions: 7 years from the transaction date (HMRC statutory requirement).
- Audit logs: 7 years.
- Rate-limit counters (Vercel KV / Upstash): automatic TTL of twice the rate-limit window — about 2 minutes on the main API paths, and about 2 hours on the email-verification resend limiter. No long-term retention.
5. Recipients and sub-processors
Under UK GDPR Article 13(1)(e), we are required to inform you of all recipients of your personal data. The table below lists every sub-processor and third-party recipient we use, why they receive your data, where they are located, and the transfer mechanism that protects your data when it leaves the UK.
| Sub-processor | Role | Location | Transfer basis | DPA |
|---|---|---|---|---|
| Neon Inc. | Managed PostgreSQL database — stores all account, property, and financial data | US (AWS us-east-1) | SCCs / UK IDTA | View Neon Inc. DPA ↗ |
| Vercel Inc. | Application hosting, edge compute, CDN | US / EU edge PoPs | SCCs / UK IDTA | View Vercel Inc. DPA ↗ |
| TrueLayer Ltd. | Open Banking connectivity (bank account import — opted-in users only) | UK / EEA | No restricted transfer | View TrueLayer Ltd. DPA ↗ |
| Resend Inc. | Transactional email delivery, including the weekly digest — whose body contains your year-to-date income, expenses and net profit or loss | US | SCCs / UK IDTA | View Resend Inc. DPA ↗ |
| SaaS Factory connections proxy / SF Tether | Third-party API gateway and credential vault. Every HMRC and Open Banking request we make is routed through it — carrying your National Insurance Number in the request path and your quarterly income and expense figures in the request body — and it holds your HMRC and bank OAuth tokens, which we never store ourselves. | Not asserted — see the note below | Not asserted — see the note below | Not asserted — see the note below |
| SaaS Factory central identity provider (SF Auth) | Performs all sign-in for the Service over OIDC and returns your account identifier, email address, name and profile image. We hold no password of yours. | Not asserted — see the note below | Not asserted — see the note below | Not asserted — see the note below |
| Temporal Technologies Inc. | Workflow orchestration (submission processing, scheduled reminders) | US | SCCs / UK IDTA | View Temporal Technologies Inc. DPA ↗ |
| Upstash Inc. / Vercel KV | Distributed rate limiting — receives user IDs and IP addresses as short-lived rate-limit keys on every authenticated API request to prevent abuse | US (AWS us-east-1) | SCCs / UK IDTA | View Upstash Inc. / Vercel KV DPA ↗ |
| AgentOS Ltd. | Letting agent data source (property, tenancy, and transaction imports) | UK | No restricted transfer | In service agreement |
| HMRC | Statutory recipient of MTD quarterly income and expense updates | UK | No restricted transfer — statutory obligation | View HMRC DPA ↗ |
SCCs = Standard Contractual Clauses (UK-approved version). IDTA = UK International Data Transfer Agreement. A copy of any executed DPA is available on request at privacy@agentos.com.
A note on the SaaS Factory platform
This Service is built and hosted on the SaaS Factory platform, and three of its components receive your personal data: the connections proxy and SF Tether vault (every HMRC and Open Banking request passes through it, and it holds your HMRC and bank credentials), the central identity provider (SF Auth) (which signs you in), and SF Core’s central email relay (through which every email we send — including the weekly digest and its financial figures — is dispatched before it reaches Resend).
We are listing them here because you are entitled to know they receive your data. Their hosting locations, restricted-transfer mechanisms and DPA references are not asserted in this policy — we are confirming that position and will publish it here once settled. Ask us at privacy@agentos.com for the current answer.
6. International transfers
Some sub-processors are based in the United States. Where personal data is transferred outside the UK we rely on Standard Contractual Clauses (UK-approved) and/or the UK International Data Transfer Agreement (IDTA) as the lawful transfer mechanism. Details are listed in the sub-processor table above and in our full ROPA.
7. Your rights
Under UK GDPR you have the right to:
- Access a copy of your personal data (Subject Access Request)
- Rectify inaccurate data
- Erase your data (“right to be forgotten”) — subject to legal retention obligations
- Restrict processing in certain circumstances
- Data portability (structured, machine-readable export)
- Object to processing based on legitimate interests
- Withdraw consent at any time (where processing is consent-based)
- Lodge a complaint with the ICO at ico.org.uk
To exercise any of these rights, contact privacy@agentos.com. We will respond within one calendar month.
8. Security
We protect your data using AES-256-GCM encryption at rest for the sensitive fields we hold (most importantly your NINO), TLS 1.2+ in transit, and row-level security on the database. We store no password for you at all — sign-in is delegated to the SaaS Factory central identity provider — and your HMRC and bank credentials are held in the SaaS Factory Tether vault rather than by us. Sessions expire after 8 hours and can be revoked. Rate limiting is enforced on all authenticated API endpoints using Vercel KV (Upstash); note that a rate-limit key holds your raw user id, or your raw IP address when you are not signed in — these values are not hashed, though they are short-lived. Security events are monitored and critical incidents trigger immediate engineering escalation.
9. Cookies
We use strictly necessary session cookies for authentication (Auth.js / NextAuth). No advertising or analytics third-party cookies are set. You can manage cookies through your browser settings; disabling session cookies will prevent you from signing in.
10. Changes to this policy
We may update this policy when we add new sub-processors or change how we process data. Material changes will be notified by email. The “Last updated” date at the top of the page always reflects the most recent revision. For a full audit trail of processing activities see our Article 30 ROPA.