Privacy Policy
Last updated: 1 September 2026
1. Who we are
AgentOS Proptech Group Ltd (“we”, “our”, “us”) is the data controller for personal data processed through the MTD for Landlords service (“the Service”). We are based in the United Kingdom and subject to UK GDPR and the Data Protection Act 2018.
Data Protection contact: privacy@agentos.com
2. Personal data we collect
- Account data — name, email address, profile image, organisation name, and the account identifier issued by the SaaS Factory central identity provider. We do not store a password for you: sign-in is performed entirely by that identity provider.
- Tax profile data — National Insurance Number (NINO, stored encrypted), self-assessment status. Your HMRC OAuth tokens are held in the SaaS Factory Tether credential vault, not by us.
- Property data — property addresses, descriptions, and portfolio metadata.
- Financial transaction data — income and expense records imported from your letting agent or bank, and manual entries.
- Bank account data (opted-in users only) — transaction history imported via Open Banking (TrueLayer), plus the account identifier and display label. Your account number, sort code, IBAN and balance are read live from TrueLayer each time a page is rendered and are never stored by us.
- Communication data — email address (for transactional notifications). Our weekly digest email contains your year-to-date income, expenses and net profit or loss figures in the message body.
- Technical data — IP address, user ID, browser/device metadata collected for security monitoring and rate limiting.
3. Why we process your data
| Purpose | Legal basis |
|---|---|
| Providing the MTD ITSA submission service | Contract (Art. 6(1)(b)) |
| Submitting quarterly updates to HMRC on your behalf | Legal obligation (Art. 6(1)(c)) |
| Sending service notifications (confirmations, deadline reminders) | Contract (Art. 6(1)(b)) |
| Security monitoring, rate limiting, and abuse prevention | Legitimate interests (Art. 6(1)(f)) |
| Audit logging for security and dispute resolution | Legitimate interests (Art. 6(1)(f)) |
| Connecting to your bank account (Open Banking) | Consent (Art. 6(1)(a)) |
4. How long we keep your data
- Account data: duration of account + 30 days after deletion.
- Financial records and HMRC submissions: 7 years from the transaction date (HMRC statutory requirement).
- Audit logs: 7 years.
- Mailbox-confirmation codes for letting-agent account lookup — the address the code was sent to, the IP the request came from, and whether it was used: 30 days from the request, deleted on an unconditional daily schedule. A confirmed address itself is kept until you remove it or delete your account.
- Rate-limit counters (Vercel KV / Upstash): automatic TTL of twice the rate-limit window — about 2 minutes on the main API paths, and about 2 hours on the email-verification resend limiter. No long-term retention.
5. Recipients and sub-processors
Under UK GDPR Article 13(1)(e), we are required to inform you of all recipients of your personal data. The table below lists every sub-processor and third-party recipient we use, why they receive your data, where they are located, and the transfer mechanism that protects your data when it leaves the UK.
| Sub-processor | Role | Location | Transfer basis | DPA |
|---|---|---|---|---|
| Neon Inc. | Managed PostgreSQL database — stores all account, property, and financial data | UK — London (AWS eu-west-2) | No restricted transfer for data at rest. Neon Inc. is US-incorporated, so SCCs / UK IDTA are retained to cover any support access from the US | View Neon Inc. DPA ↗ |
| Vercel Inc. | Application hosting, serverless compute, file storage, CDN | UK — London (lhr1) for every serverless function and for the middleware, with no failover region configured. Files you upload (avatars, organisation logos, document attachments) are held in a Vercel Blob store in the US (Washington DC, iad1). CDN points of presence are worldwide and cache static assets only. | SCCs / UK IDTA — for the US Blob store, and for any support access from the US (Vercel Inc. is US-incorporated) | View Vercel Inc. DPA ↗ |
| TrueLayer Ltd. | Open Banking connectivity (bank account import — opted-in users only) | UK / EEA | No restricted transfer | View TrueLayer Ltd. DPA ↗ |
| Resend Inc. | Transactional email delivery, including the weekly digest — whose body contains your year-to-date income, expenses and net profit or loss. This Service never contacts Resend itself: every message is handed to the SaaS Factory central email relay, which delivers it through Resend. | US. We hold no region election with Resend and do not assert one — treat every message as a transfer to the United States. | SCCs / UK IDTA | View Resend Inc. DPA ↗ |
| SaaS Factory connections proxy / SF Tether | Third-party API gateway and credential vault. Every HMRC and Open Banking request we make is routed through it — carrying your National Insurance Number in the request path and your quarterly income and expense figures in the request body — and it holds your HMRC and bank OAuth tokens, which we never store ourselves. | Not asserted — see the note below | Not asserted — see the note below | Not asserted — see the note below |
| SaaS Factory central identity provider (SF Auth) | Performs all sign-in for the Service over OIDC and returns your account identifier, email address, name and profile image. We hold no password of yours. | Not asserted — see the note below | Not asserted — see the note below | Not asserted — see the note below |
| Temporal Technologies Inc. | Workflow orchestration (submission processing, scheduled reminders). This Service holds no Temporal account of its own — workflows are brokered through the SaaS Factory platform gateway onto SaaS Factory's Temporal Cloud namespace. | US. The namespace is operated by SaaS Factory and its region is not asserted to this Service, so we declare it as a transfer to the United States rather than claim a region we cannot evidence. | SCCs / UK IDTA | View Temporal Technologies Inc. DPA ↗ |
| Upstash Inc. / Vercel KV | Managed key-value store for distributed rate limiting. NOT CURRENTLY ENGAGED — no KV store is provisioned for this Service, so no personal data reaches Upstash. Rate-limit counters, the sign-out revocation list and the two-factor replay cache are held in the application's own memory, inside the UK (London) region. | Not engaged — no data is transferred. Were a managed KV store to be provisioned it would be a transfer to the United States, and this register would say so. | Not applicable while not engaged. SCCs / UK IDTA (via Vercel's DPA with Upstash) would apply if it were | View Upstash Inc. / Vercel KV DPA ↗ |
| AgentOS Proptech Group Ltd. | Letting agent data source (property, tenancy, and transaction imports) | UK | No restricted transfer | In service agreement |
| HMRC | Statutory recipient of MTD quarterly income and expense updates | UK | No restricted transfer — statutory obligation | View HMRC DPA ↗ |
SCCs = Standard Contractual Clauses (UK-approved version). IDTA = UK International Data Transfer Agreement. A copy of any executed DPA is available on request at privacy@agentos.com.
A note on the SaaS Factory platform
This Service is built and hosted on the SaaS Factory platform, and three of its components receive your personal data: the connections proxy and SF Tether vault (every HMRC and Open Banking request passes through it, and it holds your HMRC and bank credentials), the central identity provider (SF Auth) (which signs you in), and SF Core’s central email relay (through which every email we send — including the weekly digest and its financial figures — is dispatched before it reaches Resend).
We are listing them here because you are entitled to know they receive your data. Their hosting locations, restricted-transfer mechanisms and DPA references are not asserted in this policy — we are confirming that position and will publish it here once settled. Ask us at privacy@agentos.com for the current answer.
6. International transfers
Your account, property and financial records are held in the United Kingdom. The database runs in London (AWS eu-west-2), and every serverless function and every middleware request runs in Vercel’s London region (lhr1) with no failover region configured, so the application cannot silently move outside the UK.
Two things do still leave the UK, and we name them rather than imply UK-only processing. Files you upload — avatars, organisation logos and document attachments — are held in a Vercel Blob store in the United States. And transactional email, including the weekly digest, is delivered by Resend Inc. in the United States. Workflow orchestration runs on a Temporal Cloud namespace operated by SaaS Factory whose region is not asserted to us, so we declare it as a US transfer too rather than claim a region we cannot evidence.
Where personal data is transferred outside the UK we rely on Standard Contractual Clauses (UK-approved) and/or the UK International Data Transfer Agreement (IDTA) as the lawful transfer mechanism. Details are listed in the sub-processor table above and in our full ROPA.
7. Your rights
Under UK GDPR you have the right to:
- Access a copy of your personal data (Subject Access Request)
- Rectify inaccurate data
- Erase your data (“right to be forgotten”) — subject to legal retention obligations
- Restrict processing in certain circumstances
- Data portability (structured, machine-readable export)
- Object to processing based on legitimate interests
- Withdraw consent at any time (where processing is consent-based)
- Lodge a complaint with the ICO at ico.org.uk
To exercise any of these rights, contact privacy@agentos.com. We will respond within one calendar month.
8. Security
We protect your data using AES-256-GCM encryption at rest for the sensitive fields we hold (most importantly your NINO), TLS 1.2+ in transit, and row-level security on the database. We store no password for you at all — sign-in is delegated to the SaaS Factory central identity provider — and your HMRC and bank credentials are held in the SaaS Factory Tether vault rather than by us. Sessions expire after 8 hours and can be revoked. Rate limiting is enforced on all authenticated API endpoints using Vercel KV (Upstash); note that a rate-limit key holds your raw user id, or your raw IP address when you are not signed in — these values are not hashed, though they are short-lived. Security events are monitored and critical incidents trigger immediate engineering escalation.
9. Cookies
We use strictly necessary session cookies for authentication (Auth.js / NextAuth). No advertising or analytics third-party cookies are set. You can manage cookies through your browser settings; disabling session cookies will prevent you from signing in.
10. Changes to this policy
We may update this policy when we add new sub-processors or change how we process data. Material changes will be notified by email. The “Last updated” date at the top of the page always reflects the most recent revision. For a full audit trail of processing activities see our Article 30 ROPA.