HMO KIT - London Property Licensing Experts

Data Protection

HMO KIT takes the security and privacy of your personal data seriously. This page explains our data protection measures, retention policies, and your rights under UK data protection law.

1. Our Legal Basis for Processing

HMO KIT (trading name of Your Realty Ltd, company number 12991664) processes personal data under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. We process your data on the following legal bases:

  • Contractual necessity — to deliver the services you have requested (e.g. licence applications, compliance inspections).
  • Legitimate interests — to improve our services, respond to enquiries, and maintain the security of our systems.
  • Consent — for marketing communications and non-essential cookies. You can withdraw consent at any time.
  • Legal obligation — where we are required to retain data by law (e.g. anti-money laundering regulations, HMRC requirements).

2. Data We Collect

We collect only the minimum data necessary to deliver our services. The specific data depends on how you interact with us:

CategoryData CollectedPurpose
Contact formsName, email, phone, messageResponding to enquiries
Compliance toolsEmail, optional mobile numberExpiry reminders and lead capture
Service clientsName, address, property details, ID documentsLicence applications and compliance services
Website analyticsAnonymised browsing dataSite improvement and traffic analysis

3. Data Security Measures

We implement the following technical and organisational measures to protect your data:

  • Encryption in transit — all data transmitted between your browser and our servers uses TLS/SSL encryption (HTTPS).
  • Encryption at rest — personal data stored in our database is encrypted using industry-standard AES-256 encryption provided by Supabase.
  • Access controls — access to personal data is restricted to authorised staff on a role-based, least-privilege basis.
  • Row-Level Security (RLS) — our database enforces per-user data isolation at the database level, ensuring users can only access their own records.
  • API key security — all external API keys are stored as SHA-256 hashes, never in plain text. Raw keys are returned once at creation and never persisted.
  • Regular audits — we conduct periodic security reviews of our codebase and infrastructure to identify and remediate vulnerabilities.
  • Incident response — in the event of a data breach, we will notify the ICO within 72 hours and inform affected individuals without undue delay where required by law.

4. Data Retention Policy

We retain personal data only for as long as necessary for the purpose for which it was collected:

Data TypeRetention PeriodReason
Contact enquiries2 years from last contactFollow-up and service quality
Tool reminder recordsDuration of active reminder + 1 yearReminder delivery and audit trail
Licence application records7 years from completionLegal and regulatory compliance
Financial records7 yearsHMRC requirements
Website analytics26 monthsGoogle Analytics default retention

When data is no longer required, it is securely deleted or anonymised. We do not retain personal data beyond the period necessary for its stated purpose.

5. Data Sharing

We do not sell or rent your personal data. We share data only in the following circumstances:

  • Local authorities — as required for licence applications and compliance submissions on your behalf.
  • Service providers — trusted processors (e.g. Supabase for database hosting, Resend for email delivery) who are contractually bound to process data in accordance with UK GDPR.
  • Legal requirement — where disclosure is required by law, regulation, or court order.

6. International Transfers

Our primary data hosting is provided by Supabase, which stores data in the EU (Frankfurt, Germany). Where third-party processors transfer data outside the UK, we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) or equivalent mechanisms approved by the ICO.

7. Your Rights

Under UK GDPR, you have the following rights regarding your personal data:

  • Right of access — request a copy of the personal data we hold about you (Subject Access Request).
  • Right to rectification — request correction of inaccurate or incomplete data.
  • Right to erasure — request deletion of your data where there is no compelling reason for continued processing.
  • Right to restrict processing — request that we limit how we use your data in certain circumstances.
  • Right to data portability — request your data in a structured, commonly used, machine-readable format.
  • Right to object — object to processing based on legitimate interests or for direct marketing purposes.
  • Right to withdraw consent — where processing is based on consent, you may withdraw it at any time.

To exercise any of these rights, email us at contact@hmokit.co.uk. We will respond within 30 calendar days and may request proof of identity before processing your request. Subject Access Requests are processed free of charge.

8. Data Protection Officer

For any questions or concerns about how we handle your data, contact our Data Protection Officer at contact@hmokit.co.uk.

9. ICO Registration

HMO KIT (Your Realty Ltd) is registered with the Information Commissioner's Office (ICO) as a Data Controller.

ICO Registration Number: ZB590748
Registered Address: 86-90 Paul Street, London, England, EC2A 4NE

You can verify our registration on the Official ICO Register. If you are dissatisfied with our response to a data protection concern, you have the right to lodge a complaint with the ICO at ico.org.uk/concerns.

10. Changes to This Page

We review our data protection practices regularly and update this page when necessary. The date of the most recent revision will be displayed at the top of the page.

Last updated: June 2026