UK GDPR & Data Protection Compliance

Privacy Policy

Last Updated: September 2026 • Effective Date: September 2026

1Overview & Data Controller

This Privacy Policy explains how Property Due Diligence (“we”, “us”, or “our”), operating the platform at propertyduediligence.co.uk, collects, processes, stores, and protects personal data in compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

If you have any questions about this policy or your data rights, please contact our data protection team electronically at support@propertyduediligence.co.uk or via our Contact Page.

2Statutory Public Sector Data Notice

Public Register Information Is Not Private Personal Data:

Property Risk Briefs aggregate publicly available statutory registers released by UK public sector bodies under the Open Government Licence (OGL v3.0). This includes HM Land Registry Price Paid records, Environment Agency flood risk designations, British Geological Survey GeoSure ground stability models, UK Health Security Agency radon classifications, DEFRA air quality measurements, planning applications, and official MHCLG Council Tax setting resolutions.

These records relate to real property and geographic locations rather than identifiable natural living individuals. We do not publish private mortgage details, title deeds, owner contact numbers, or personal banking data.

3Information We Collect

We collect only the minimum personal data required to provide our service:

  • Account Credentials: When you register an account, we collect your email address and password hash (managed securely via encrypted authentication).
  • Corporate Letterhead & Custom Branding (Optional): If you choose to configure white-label PDF export (available on Starter and Teams plans), you may provide your company name, logo URL, corporate phone number, brand color, and website URL.
  • Search & Report History: We maintain a record of searches performed within your account so that you can view, re-download, or print saved reports from your dashboard.
  • Billing Information: Payments for Starter and Teams plans are processed directly and securely by Stripe Inc. We never store, process, or have access to full debit or credit card numbers. Stripe provides us only with transaction identifiers, subscription status, and billing cycle dates.
  • Technical & Telemetry Logs: Standard web server logs, IP addresses (hashed or anonymised for rate limiting and free quota management), browser user agent, and timestamp data to safeguard our infrastructure from denial-of-service abuse.

4Lawful Bases for Processing

Under UK GDPR Article 6, we rely on the following lawful bases:

  • Contractual Necessity: To deliver the diligence reports, maintain your account, and provide access to features included in your subscription tier.
  • Legitimate Interests: To ensure network security, prevent automated scraping abuse, enforce free search quotas, and optimize service reliability.
  • Legal Obligation: To maintain standard financial transaction records and VAT/tax documentation required under UK statutory law.

5Third-Party Data Processors

We work with trusted infrastructure providers subject to strict data protection agreements:

  • Cloudflare Inc.: Content Delivery Network (CDN), edge routing, and Web Application Firewall (WAF) security.
  • Supabase Inc.: Encrypted cloud database and identity management for registered user accounts.
  • Stripe Payments UK, Ltd.: PCI-DSS Level 1 compliant subscription processing.
  • Formspree Inc.: Secure processing and dispatch of user inquiries submitted via our contact form.

6Cookies & Local Storage

We prioritize privacy and minimize tracking. We use strictly necessary cookies to authenticate sessions and keep you signed in securely. We also utilize browser local storage to temporarily cache your recent searches on your local device. We do not sell user data, nor do we deploy cross-site advertising tracking networks.

7Data Retention

Account data and saved reports are retained for as long as your account remains active. If you delete your account, your personal details, custom letterhead branding, and saved property records are permanently purged from active databases within 30 days. Financial audit records are retained for the statutory period mandated by HMRC.

8Your Statutory Rights Under UK GDPR

You have the following rights regarding your personal data:

  • Right of Access: Request a copy of the personal information we hold about you.
  • Right to Rectification: Request correction of inaccurate or incomplete personal records.
  • Right to Erasure: Request deletion of your account and associated personal data (“right to be forgotten”).
  • Right to Restriction & Objection: Object to or restrict certain types of data processing.
  • Right to Data Portability: Obtain an electronic export of your data in a structured, machine-readable format.

To exercise any of these rights, please email us at support@propertyduediligence.co.uk. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.

9Updates to this Policy

We may revise this Privacy Policy periodically to reflect enhancements to our platform, additions of new statutory registers, or updates in legal requirements. Any modifications will be posted to this page with an updated “Last Updated” date.