Privacy Policy
Last updated: 29 August 2026
This policy explains how MyRentals360 handles personal information when you use our property management software, and how we treat information that landlords add about their tenants.
Who operates MyRentals360
MyRentals360 is a trading name and product of Natanzi Group Ltd ("we", "us", "our"), a company registered in England and Wales. We provide software that helps UK landlords manage properties, tenancies, compliance records, documents and rent information.
Where we decide why and how personal information is processed — for example information about our own account holders — Natanzi Group Ltd is the data controller under UK data protection law. Where our customers upload information about their tenants and other occupants, we generally act as a processor on the customer's behalf. See “Information landlords add about tenants” below.
We have not appointed a Data Protection Officer, as we are not required to do so. Privacy queries are handled by our support team at the address below.
Contact details
For any privacy question, request or concern, contact us at support@myrentals360.co.uk.
What personal information we collect
- Account and profile information — name, email address, optional company name and phone number, and your notification preferences.
- Billing and subscription information — your plan, subscription status and billing period, and identifiers issued by our payment provider. Card details are entered directly with our payment provider and are not stored by us.
- Property information — addresses, property attributes, valuations, mortgage and insurance details you enter.
- Tenancy and tenant information — tenant names and contact details, tenancy dates and terms, deposit information and notes, as entered by you.
- Rent and payment records — expected rent, payments recorded, arrears and related finance entries.
- Compliance information — certificate types, reference numbers, issue and expiry dates and related reminders.
- Documents you upload — certificates, agreements, invoices and other files, together with the metadata you add.
- Technical and security information — information generated when you use the service, such as authentication session data and server and security logs produced by our infrastructure providers (which can include IP address and request information).
- Support communications — messages you send us and our replies.
Two different kinds of information
A. Information about our users. This is information about you as an account holder — your profile, login, subscription and support history. We decide how this is used, so we act as controller for it.
B. Information landlords upload about other people. This is tenant, occupant, guarantor or contractor information that you choose to enter. Where applicable, you (our customer) determine why that information is processed and we provide the software used to process it on your behalf.
This split reflects how the service is normally used. It may not apply in every situation, and the correct characterisation of a particular case depends on the facts. If you need certainty for your own compliance records, take your own professional advice.
Information landlords add about tenants
If you use MyRentals360 to record information about tenants and other individuals, you are responsible for making sure you have an appropriate lawful basis for doing so, and for providing those individuals with the privacy information they are entitled to receive from you.
- Only enter tenant information you genuinely need for managing the tenancy.
- Keep it accurate and up to date, and remove information you no longer need.
- Respond to your tenants' data protection requests as the person responsible for that information.
We do not sell tenant personal information, and we do not use tenant information for advertising.
If your information is held in MyRentals360 by your landlord
MyRentals360 is software used by landlords to manage property and tenancy information. If your landlord holds information about you in MyRentals360:
- Your landlord is generally responsible for explaining why they hold your information and the lawful basis for doing so.
- We process that information as necessary to provide the software service to your landlord, where we act as processor.
- Please contact your landlord first about information they have entered, including requests to see, correct or delete it.
- You can also contact us about privacy or security concerns and we will help where we can, or pass the request to the relevant customer.
Being recorded in a landlord's portfolio does not mean you have a MyRentals360 account. Accounts are only created by people who sign up themselves.
Why we process information and our lawful bases
- To provide the service you have signed up for — creating your account, storing your portfolio, generating reminders and rent schedules. Lawful basis: performance of a contract.
- To take payment and manage subscriptions — processing plan changes, renewals and cancellations. Lawful basis: performance of a contract.
- To keep the service secure and working — authentication, abuse prevention, diagnosing faults and improving reliability. Lawful basis: our legitimate interests in operating a secure, functioning service.
- To communicate with you about your account — service notices and support replies. Lawful basis: performance of a contract and our legitimate interests.
- To meet our legal duties — for example accounting and tax record keeping. Lawful basis: compliance with a legal obligation.
- Consent — we rely on consent only where it is genuinely required. We do not currently send marketing emails. If we introduce them, they will have their own separate opt-in or opt-out.
Where we act as processor for tenant information uploaded by a customer, we process it on that customer's documented instructions.
Service providers and subprocessors
We use a small number of third-party providers to run MyRentals360. The providers currently in use, and what each does, are listed on our Subprocessors page, which we keep up to date. In summary:
- Lovable — the platform used to build, host and deploy the application, provide the managed backend, send automated service emails from notify.myrentals360.co.uk and collect application error diagnostics.
- Supabase (provided through Lovable Cloud) — database, authentication and private file storage for your portfolio data and uploaded documents.
- Stripe — payment processing and subscription billing, including the billing portal and invoice history. Card details are handled by Stripe, not by us.
- Cloudflare — network, DNS, TLS and security infrastructure in front of our production domains, handling traffic routing and protection against abuse.
- Google (Google Fonts) — our pages load web fonts from Google's font servers, so your browser makes a request to Google that includes your IP address and standard request information.
We have not stated provider legal entities, certifications, audit reports or specific contractual transfer terms, because those come from each provider's own documentation rather than from our application.
International transfers
Our database, authentication and document storage run in the AWS eu-central-1 region (Frankfurt, Germany). That is where your account and portfolio records, and your uploaded documents, are held.
This does not mean all personal information stays inside the UK or EEA. Our other providers — including payment, hosting, email, error reporting, content delivery and font services — operate internationally, and information such as billing details, email content and connection data may be processed outside the UK. Where personal information is transferred outside the UK, an appropriate safeguard recognised under UK data protection law must be in place.
We have not named the specific transfer mechanism used by each provider here, because that detail comes from provider documentation and contracts. If you need it for your own compliance records, contact us and we will point you to the relevant provider terms.
Security
We take a defence-in-depth approach appropriate to a small SaaS platform. Measures currently in place include:
- Database-level access rules so each account can only read and write its own records.
- Uploaded documents stored in private storage, served only through short-lived signed links to the account that owns them.
- Authentication required for every application route that shows portfolio data.
- Secrets and payment credentials held server-side and never exposed in the browser.
- Encryption in transit (HTTPS/TLS) across all of our domains.
No online service can be guaranteed completely secure. We do not claim to be, and we will tell affected users promptly if a security incident affects their information.
Retention, deleting and archiving records
We keep your account and portfolio information for as long as your account is open, and afterwards only for as long as necessary for legitimate business or legal purposes such as accounting records, security, or resolving disputes.
Not every record works the same way inside the application, so it is worth being precise:
- Records you can delete outright — individual documents, recorded rent payments and certain rent charges can be deleted from the application.
- Records that are archived rather than deleted — properties, tenancies, compliance records, finance entries, documents you replace and property notes are archived so that history stays intact. Archived records remain in your account until you delete your account.
- Account deletion — deleting your account removes your account and its records, including archived ones, as described below.
- Records retained separately — payment and invoice records held by our payment provider, and information we must keep for accounting, tax, legal or security reasons, are retained independently of your account.
We do not currently operate an automated retention or purge schedule, and we have not yet set fixed retention periods for each category of information. Until we do, we keep information only for as long as it is needed for the purpose it was collected for, or for as long as the law requires. Formal retention periods are a follow-up item for us.
Closing your account
You can delete your account yourself from Settings → Privacy & Data. Deletion is confirmed explicitly before it runs and cannot be undone.
When it completes, we remove from the active service:
- Your MyRentals360 sign-in and profile.
- Your properties, tenancies, compliance records, rent and finance records, tasks and notes, including archived ones.
- The document files you uploaded, which are removed from our document storage.
Any active subscription is cancelled as part of the process so you are not billed again. If a step of the process cannot be completed, we tell you it has not completed rather than reporting success.
We keep one minimal internal record of the deletion itself, for audit and security purposes. It holds only an internal account identifier, timestamps, the outcome, and counts of what was cleaned up. It deliberately contains no name, email address, portfolio content or tenant information.
We cannot promise deletion from everything, everywhere. Payment and invoice records held by our payment provider are retained by them independently, and routine infrastructure backups operated by our providers age out on their own schedules rather than being edited on request. We also keep information where the law requires it.
Your rights
Under UK data protection law you may have the right to:
- Ask for access to the personal information we hold about you.
- Ask us to correct information that is inaccurate or incomplete.
- Ask us to delete information.
- Ask us to restrict how we use information.
- Object to processing based on our legitimate interests.
- Ask for a copy of certain information in a portable format.
- Withdraw consent where we rely on consent.
These rights are not absolute — some apply only in certain circumstances, and we may need to keep information where the law requires it. If you are a tenant and your landlord entered the information, please contact your landlord first.
To exercise a right, email support@myrentals360.co.uk.
Exporting your data
From Settings → Privacy & Data you can download a structured JSON file of your own records: profile, subscription details, properties, tenancies, compliance records, rent charges and payments, finance records, tasks, notes, notifications and the details you recorded about each document.
The export includes document details, but not the contents of the files themselves. Uploaded files stay in secure storage and can be downloaded individually from the Documents area, so download anything you need separately before closing your account.
Cookies and similar technologies
We do not run advertising trackers, marketing pixels or behavioural analytics products in MyRentals360.
We do use strictly necessary storage in your browser — the session information needed to keep you signed in securely. In addition, the security and network layer in front of our site (Cloudflare) may set necessary cookies such as __cf_bm for bot management and abuse protection, and our pages load fonts from Google's font servers, which means your browser sends a request to Google containing your IP address and standard request information. Our application also reports technical errors to our hosting platform so we can fix faults.
So it would not be accurate to say no third party receives any information: providers involved in delivering, securing and supporting the service necessarily do. If we ever introduce non-essential technologies, we will update this policy and add an appropriate consent mechanism first.
Complaints
Please contact us first so we can put things right. You also have the right to complain to the UK Information Commissioner's Office (ICO) at ico.org.uk.
Related documents
See our Terms of Service, Data Processing Terms and Subprocessors list.