SafeLet

Privacy notice

Last updated 28 August 2026

SafeLet is operated by the account holder named in your contract. Company registration details are not yet published on this deployment. This notice explains what personal data we process, why, on what lawful basis, who we share it with and how long we keep it. It covers two different relationships: the letting agents who hold SafeLet accounts, and the people those agents screen.

Who we are

Operator details not configured

Company registration details are not configured on this deployment. Set COMPANY_LEGAL_NAME, COMPANY_NUMBER, COMPANY_REGISTERED_OFFICE, COMPANY_GENERAL_EMAIL and COMPANY_PRIVACY_EMAIL before publishing this page.

You can reach our privacy team at info@safelet.online.

We are registered with the Information Commissioner’s Office as a data controller for our own account and marketing data. Where we handle screening subject data on your behalf we act as your processor, as described below.

Controller and processor: who decides what

Screening subjects. When you screen a landlord, tenant or guarantor, that person’s data is supplied by you. You decide who to screen, why, and what to do with the outcome. You are therefore the controller of that data and SafeLet is your processor, acting only on your instructions and under our data processing agreement. Your own privacy notice, not this one, is what you should show to the people you screen.

Account data. For the data we need to run SafeLet as a business — the email addresses of your staff, your organisation record, billing details, support correspondence and server logs — SafeLet is the controller.

What personal data we process

About screening subjects, supplied by you: full name as you enter it, date of birth where you hold one, nationality where you hold one, the person’s role in the tenancy (tenant, landlord, guarantor or other), any tenancy or property reference you choose to add, and the results of screening them — the outcome, the score, the names matched from a sanctions list, the versions of each list screened, the timestamp, which of your users ran the check and any review note they recorded.

About your staff, as controller: name and email address, authentication records and sign-in timestamps, role in your organisation, actions written to the audit log, billing contact and subscription data held with our payment processor, and support messages you send us.

Technical data: request logs and error reports, plus a salted, one-way hash of the IP address used to rate-limit the free check. We do not store the free-check IP address itself and the hash cannot be reversed to recover it.

We do not use advertising cookies or third-party analytics trackers. The only cookies we set are the session cookies required to keep you signed in and to protect forms against cross-site request forgery.

Why we process it, and our lawful basis

To carry out sanctions screening you have asked for. As processor we act on your instruction. As controller, your basis will normally be compliance with a legal obligation, or your legitimate interests in meeting that obligation and avoiding a breach: since 14 May 2025 UK letting agents must screen all landlords, tenants and guarantors against the UK sanctions list, at any rent level, and must report suspected designated persons to OFSI. Screening also supports the substantial public interest of preventing unlawful acts. You should record your own assessment; this notice is not legal advice.

To provide and secure the service — accounts, certificates, the audit log, rate limiting and fraud prevention: our legitimate interests in operating a secure product, and performance of our contract with you.

To bill you — performance of our contract, and our legal obligation to keep accounting records.

To email you about the service — sign-in links, monitoring alerts and service notices are necessary for the contract. Product marketing goes only to business contacts under legitimate interests, with an unsubscribe link in every message.

A sanctions match is not a criminal-offence record: it means a name resembles a name on a published designation list. SafeLet does not make any automated decision that has a legal or similarly significant effect on the person screened. The tool scores name similarity; a human at your firm reviews every match and decides what to do.

How long we keep it

Screening records are kept for the retention period configured by your organisation. The default is six years from the date of the check, which reflects how long letting agents are generally expected to be able to evidence their compliance work. An owner can change the period in settings.

A daily retention job hard-deletes subjects, checks, certificate files and monitoring history once they pass the configured period. Deletion is permanent: rows are removed, not flagged, and the certificate file is deleted from storage, after which the verification id no longer resolves. Encrypted database backups age out within 30 days.

Account records are kept while your account is open and for six years after closure where we need them for tax and accounting. Error reports are kept for 90 days. Free-check IP hashes are kept for 24 hours, which is the rate-limit window.

Who we share it with

We do not sell personal data and we never share screening subject data with anyone except the sub-processors below, which are engaged under written contracts containing UK GDPR Article 28 terms. Reporting a suspected designated person to OFSI is your decision and your submission; SafeLet does not report on your behalf and does not send your data to OFSI or to any other authority unless we are legally compelled to.

Sub-processorPurposeLocation of processingTransfer mechanism
NeonManaged PostgreSQL database holding subjects, checks and the audit logUnited Kingdom (London)No routine transfer outside the UK; support access under the UK IDTA
NetlifyApplication hosting, edge delivery and certificate file storageUnited Kingdom and European Union edge, United States control planeUK Addendum to the EU standard contractual clauses
ResendTransactional email: sign-in links, monitoring alerts and receiptsEuropean Union and United StatesUK Addendum to the EU standard contractual clauses
Dodo PaymentsMerchant of record for subscriptions and per-check billing: card payments, VAT handling and invoicing. Appears as "Dodo" on your card statement.United Kingdom, European Union, United States and IndiaUK Addendum to the EU standard contractual clauses
SentryError and performance monitoring of the applicationEuropean UnionUK Addendum to the EU standard contractual clauses; personal data scrubbed before send

Sanctions list data itself is downloaded from the publishers — the UK Sanctions List, the US OFAC SDN list and the EU consolidated list — and stored by us. We send nothing to the publishers, so screening a person does not disclose their name to anyone.

International transfers

Screening data is stored in United Kingdom (London) and is not routinely transferred outside the UK. Some sub-processors operate support or control-plane functions from the European Union and the United States. Where personal data leaves the UK we rely on the UK adequacy regulations for the EEA, or on the International Data Transfer Agreement or the UK Addendum to the EU standard contractual clauses, together with a transfer risk assessment. The mechanism for each sub-processor is listed in the table above and you can request a copy of the relevant clauses.

How we protect it

Data is encrypted in transit with TLS and at rest by the database and storage providers. Access to production data is limited to named staff using multi-factor authentication and is logged. Every check, review decision, export and settings change is written to an append-only audit log which application code cannot amend or delete. Certificates are served only to signed-in members of the organisation that owns them, except for the verification page, which confirms that a certificate id is genuine and shows the outcome and date without exposing the underlying match detail. We test restores, we patch on a schedule, and we run an incident process with a named owner.

Your rights and how to exercise them

Under the UK GDPR you have the right to be informed, to access a copy of your data, to rectify inaccurate data, to erasure, to restrict or object to processing, to data portability, and not to be subject to solely automated decisions with legal effect. You can also withdraw consent where consent is the basis, which for us is limited to optional marketing.

If you were screened by a letting agent, the agent is the controller. Ask them first: they can see, correct and delete the record from their SafeLet account. If you contact us directly we will pass your request to them without delay and will help them answer it, but we cannot disclose or delete their records on our own initiative.

If you hold a SafeLet account, email info@safelet.online and we will respond within one month, extendable by two further months for complex requests, and we will tell you if we need the extension. We may ask you to verify your identity. There is no charge unless a request is manifestly excessive.

One right has a limit worth stating plainly: erasure does not override a legal obligation to keep records. Where you must be able to evidence that a check was carried out, deleting the record early may leave you unable to do so. That is your decision as controller.

If you are unhappy with how we have handled your data you can complain to the Information Commissioner’s Office at ico.org.uk or on 0303 123 1113. We would rather you told us first so we can put it right.

Changes to this notice

We will update this page when our processing changes and will change the “Last updated” date. For changes that materially affect you we will email account owners at least 30 days in advance. Sub-processor changes are announced the same way, which is also how the data processing agreement requires us to give you the chance to object.

This notice describes our practices; it is not legal advice about your own obligations as a letting agent. If you need that, take advice from a solicitor or your professional body.