Ratcliffe & Sons Ltd trading as JRM Compliance · Last updated 15 July 2026
How JRM Compliance processes personal data under the UK GDPR, and the data-processing relationship with customers who hold tenant and contractor information. This supplements our Privacy Policy.
The Service is operated by Ratcliffe & Sons Ltd (company number 12925329), trading as JRM Compliance, of 7 Hill View Drive, Coppull, PR7 5DG (ICO registration: application pending).
Storing, organising, displaying, transmitting (share links, signing requests and notifications), backing up and deleting personal data to help manage property compliance — including document storage, reminders, contractor coordination, inventories, electronic signatures, tenant messaging and regulatory tracking — for the life of the account and afterwards only to delete or return it and to meet legal obligations.
Subjects: landlords, letting agents, the landlord clients an agent manages, tenants, contractors and administrators. Data: names and contact details; property associations; account, role and security data; compliance documents; regulatory/licensing records; maintenance and hazard reports and photos; inventory notes and photos; electronic-signature audit data (name, timestamp, IP, browser and any drawn signature); in-app messages; contractor records; and support correspondence. We do not intentionally collect special-category data.
Process personal data only on documented instructions; keep authorised staff under confidentiality; apply appropriate security; not engage sub-processors without authorisation and equivalent terms; assist with data-subject requests, breach notification and impact assessments; and delete or return the data at the end of the contract. We will notify the customer without undue delay of any breach affecting their data.
| Sub-processor | Function | Location |
|---|---|---|
| Railway | App hosting, PostgreSQL database, and file storage on a persistent volume | European Union (Amsterdam, Netherlands) |
| Google (Gmail SMTP) | Transactional email | US / global |
| Stripe | Subscription payment processing | US / global |
| Firebase Cloud Messaging (Google) — only if mobile push is enabled; not currently active | Mobile push notifications | US / global |
HTTPS, hashed passwords, optional administrator two-factor authentication, role-based access control (including read-only client logins scoped to their own properties), rate limiting, audit logging and restricted access.
Primary hosting, the PostgreSQL database and uploaded-file storage are located within the European Economic Area (EEA), in Amsterdam, Netherlands; transfers of personal data from the UK to the EEA are covered by the UK's data-bridge (adequacy) regulations. Where an ancillary sub-processor (transactional email or payment processing) is outside the UK and the EEA, transfers use appropriate safeguards (for example the UK International Data Transfer Agreement, or the Addendum to the EU Standard Contractual Clauses).
Requests from tenants or contractors are usually directed to the controlling landlord or agent, whom we assist. Anyone may complain to the Information Commissioner's Office (ico.org.uk). For your own account, contact joe@jrmcompliance.com.
Business customers (for example letting agents) who need a signed Data Processing Agreement can request one at joe@jrmcompliance.com.
This page is provided for general information and is not legal advice.
← Back to home · Privacy · Terms · Cookies · Data Processing · Compliance checklist · Contact