Privacy Policy
This policy explains what personal data My HMOs collects, how we use it, and how we keep it safe.
Updated 29 July 2026Who we are
RED ALGORITHMS LTD
Company number: 17152098 · Registered in England & Wales
Registered Address: 82 A James Carter Road, Mildenhall, Suffolk, England, IP28 7DE
Under UK GDPR, we may act as a data controller where you deal with us directly, for example when you create an account, contact us, subscribe, or use support. We may act as a data processor where a landlord, letting agent, property manager, or their team uses My HMOs to store property and occupant records and send access notices.
What information we collect
Depending on how you use the service, we may collect:
- Account and team data: name, email address, business or organisation name, role, profile details, login activity and support requests.
- Property data: property names, addresses, room or unit counts, access workflow details and notice history.
- Occupant data: occupant names, email addresses, phone numbers, room or unit details, tenancy-related status and notice delivery records.
- Billing data: subscription plan, Stripe customer and subscription identifiers, invoices, payment status and billing events.
- Technical data: IP address, device and browser information, audit logs, security logs, error reports, webhook events and usage data.
Where we get personal data from
We may collect personal data directly from you, from your organisation, or from service providers used to operate My HMOs.
- From account users who enter property, room, unit or occupant data into the platform
- From occupants where they respond to or interact with supported notice communications
- From Stripe when a subscription, invoice, payment, refund, or billing event occurs
- From email, hosting, analytics, security and infrastructure providers used to deliver the service
How we use your information
We use personal data to:
- Create and manage accounts, teams and subscriptions
- Store property and occupant records for authorised account users
- Prepare, send and record HMO access notices
- Maintain delivery evidence, audit trails and support records
- Process payments, issue invoices and manage subscription access through Stripe
- Secure the platform, prevent misuse, investigate faults and improve reliability
- Respond to contact requests, support tickets and lawful requests from authorities
- Use optional analytics, where consent has been given, to understand website and product usage
Lawful basis under UK GDPR
We process personal data using one or more of the following lawful bases:
- Contract where we need data to provide accounts, subscriptions, billing, support and notice workflows.
- Legitimate interests where we secure the platform, prevent misuse, troubleshoot delivery, improve workflows and support customers.
- Legal obligation where we need to keep records, handle tax or accounting requirements, or respond to lawful requests.
- Consent where required, for example optional analytics cookies or optional marketing communications.
Third-party processors
We use trusted third-party providers to operate the service. These may include:
- Stripe: payments, billing, invoices and subscription events
- Brevo: transactional email delivery and delivery event webhooks
- PostHog: optional analytics where consent has been given
- Sentry: application error monitoring and diagnostics
- Hosting, database, storage and queue providers: infrastructure used to run the application securely
We take steps to use providers with appropriate security and data protection commitments. Where data is transferred outside the UK, we rely on appropriate safeguards such as contractual transfer mechanisms.
Data retention
We keep personal data only for as long as reasonably needed for the service, support, dispute handling and legal or regulatory compliance. Typical retention periods include:
- Account and billing records: up to 6 years after the relevant account, invoice, or transaction
- Property, occupant and notice records: while the account is active, then for a reasonable period needed for records, support, disputes, or legal obligations
- Contact enquiries: typically up to 24 months unless a longer business relationship follows
- Security, audit and error logs: for a limited operational period based on the purpose of the log
- Analytics consent records: until consent is withdrawn or no longer needed to demonstrate compliance
Marketing and transactional messages
Transactional messages are messages needed to provide the service, such as account, billing, support, notice delivery, or security communications. Marketing messages are optional and can be opted out of at any time.
Opting out of marketing does not stop essential transactional messages relating to active accounts, subscriptions, support, or notice workflows.
Your rights
Depending on the circumstances, you may have the right to ask for access to your personal data, correction of inaccurate data, deletion, restriction of processing, portability, objection to processing, and withdrawal of consent where consent is relied on.
If your data was entered by a landlord, letting agent, property manager, or other My HMOs customer, we may need to refer your request to that customer where they are the data controller.
Security
We use technical and organisational measures designed to protect personal data, including access controls, secure hosting practices, audit logs, backups and provider security controls. No system can be guaranteed completely secure, but we work to reduce risk and respond promptly to issues.
Questions and complaints
If you have questions about this policy or how we use personal data, please contact us through the contact page.
You also have the right to complain to the UK Information Commissioner's Office at ico.org.uk/make-a-complaint.