Data Protection
HMO KIT takes the security and privacy of your personal data seriously. This page explains our data protection measures, retention policies, and your rights under UK data protection law.
1. Our Legal Basis for Processing
HMO KIT (trading name of Your Realty Ltd, company number 12991664) processes personal data under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. We process your data on the following legal bases:
- Contractual necessity — to deliver the services you have requested (e.g. licence applications, compliance inspections).
- Legitimate interests — to improve our services, respond to enquiries, and maintain the security of our systems.
- Consent — for marketing communications and non-essential cookies. You can withdraw consent at any time.
- Legal obligation — where we are required to retain data by law (e.g. anti-money laundering regulations, HMRC requirements).
2. Data We Collect
We collect only the minimum data necessary to deliver our services. The specific data depends on how you interact with us:
| Category | Data Collected | Purpose |
|---|---|---|
| Contact forms | Name, email, phone, message | Responding to enquiries |
| Compliance tools | Email, optional mobile number | Expiry reminders and lead capture |
| Service clients | Name, address, property details, ID documents | Licence applications and compliance services |
| Website analytics | Anonymised browsing data | Site improvement and traffic analysis |
3. Data Security Measures
We implement the following technical and organisational measures to protect your data:
- Encryption in transit — all data transmitted between your browser and our servers uses TLS/SSL encryption (HTTPS).
- Encryption at rest — personal data stored in our database is encrypted using industry-standard AES-256 encryption provided by Supabase.
- Access controls — access to personal data is restricted to authorised staff on a role-based, least-privilege basis.
- Row-Level Security (RLS) — our database enforces per-user data isolation at the database level, ensuring users can only access their own records.
- API key security — all external API keys are stored as SHA-256 hashes, never in plain text. Raw keys are returned once at creation and never persisted.
- Regular audits — we conduct periodic security reviews of our codebase and infrastructure to identify and remediate vulnerabilities.
- Incident response — in the event of a data breach, we will notify the ICO within 72 hours and inform affected individuals without undue delay where required by law.
4. Data Retention Policy
We retain personal data only for as long as necessary for the purpose for which it was collected:
| Data Type | Retention Period | Reason |
|---|---|---|
| Contact enquiries | 2 years from last contact | Follow-up and service quality |
| Tool reminder records | Duration of active reminder + 1 year | Reminder delivery and audit trail |
| Licence application records | 7 years from completion | Legal and regulatory compliance |
| Financial records | 7 years | HMRC requirements |
| Website analytics | 26 months | Google Analytics default retention |
When data is no longer required, it is securely deleted or anonymised. We do not retain personal data beyond the period necessary for its stated purpose.
5. Data Sharing
We do not sell or rent your personal data. We share data only in the following circumstances:
- Local authorities — as required for licence applications and compliance submissions on your behalf.
- Service providers — trusted processors (e.g. Supabase for database hosting, Resend for email delivery) who are contractually bound to process data in accordance with UK GDPR.
- Legal requirement — where disclosure is required by law, regulation, or court order.
6. International Transfers
Our primary data hosting is provided by Supabase, which stores data in the EU (Frankfurt, Germany). Where third-party processors transfer data outside the UK, we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) or equivalent mechanisms approved by the ICO.
7. Your Rights
Under UK GDPR, you have the following rights regarding your personal data:
- Right of access — request a copy of the personal data we hold about you (Subject Access Request).
- Right to rectification — request correction of inaccurate or incomplete data.
- Right to erasure — request deletion of your data where there is no compelling reason for continued processing.
- Right to restrict processing — request that we limit how we use your data in certain circumstances.
- Right to data portability — request your data in a structured, commonly used, machine-readable format.
- Right to object — object to processing based on legitimate interests or for direct marketing purposes.
- Right to withdraw consent — where processing is based on consent, you may withdraw it at any time.
To exercise any of these rights, email us at contact@hmokit.co.uk. We will respond within 30 calendar days and may request proof of identity before processing your request. Subject Access Requests are processed free of charge.
8. Data Protection Officer
For any questions or concerns about how we handle your data, contact our Data Protection Officer at contact@hmokit.co.uk.
9. ICO Registration
HMO KIT (Your Realty Ltd) is registered with the Information Commissioner's Office (ICO) as a Data Controller.
ICO Registration Number: ZB590748
Registered Address: 86-90 Paul Street, London, England, EC2A 4NE
You can verify our registration on the Official ICO Register. If you are dissatisfied with our response to a data protection concern, you have the right to lodge a complaint with the ICO at ico.org.uk/concerns.
10. Changes to This Page
We review our data protection practices regularly and update this page when necessary. The date of the most recent revision will be displayed at the top of the page.
Last updated: June 2026