Data Processing (UK GDPR)

Ratcliffe & Sons Ltd trading as JRM Compliance · Last updated 15 July 2026

How JRM Compliance processes personal data under the UK GDPR, and the data-processing relationship with customers who hold tenant and contractor information. This supplements our Privacy Policy.

Controller and processor roles

The Service is operated by Ratcliffe & Sons Ltd (company number 12925329), trading as JRM Compliance, of 7 Hill View Drive, Coppull, PR7 5DG (ICO registration: application pending).

Nature, purpose and duration

Storing, organising, displaying, transmitting (share links, signing requests and notifications), backing up and deleting personal data to help manage property compliance — including document storage, reminders, contractor coordination, inventories, electronic signatures, tenant messaging and regulatory tracking — for the life of the account and afterwards only to delete or return it and to meet legal obligations.

Data subjects and data

Subjects: landlords, letting agents, the landlord clients an agent manages, tenants, contractors and administrators. Data: names and contact details; property associations; account, role and security data; compliance documents; regulatory/licensing records; maintenance and hazard reports and photos; inventory notes and photos; electronic-signature audit data (name, timestamp, IP, browser and any drawn signature); in-app messages; contractor records; and support correspondence. We do not intentionally collect special-category data.

Our obligations as a processor

Process personal data only on documented instructions; keep authorised staff under confidentiality; apply appropriate security; not engage sub-processors without authorisation and equivalent terms; assist with data-subject requests, breach notification and impact assessments; and delete or return the data at the end of the contract. We will notify the customer without undue delay of any breach affecting their data.

Sub-processors

Sub-processorFunctionLocation
RailwayApp hosting, PostgreSQL database, and file storage on a persistent volumeEuropean Union (Amsterdam, Netherlands)
Google (Gmail SMTP)Transactional emailUS / global
StripeSubscription payment processingUS / global
Firebase Cloud Messaging (Google) — only if mobile push is enabled; not currently activeMobile push notificationsUS / global

Security measures

HTTPS, hashed passwords, optional administrator two-factor authentication, role-based access control (including read-only client logins scoped to their own properties), rate limiting, audit logging and restricted access.

International transfers

Primary hosting, the PostgreSQL database and uploaded-file storage are located within the European Economic Area (EEA), in Amsterdam, Netherlands; transfers of personal data from the UK to the EEA are covered by the UK's data-bridge (adequacy) regulations. Where an ancillary sub-processor (transactional email or payment processing) is outside the UK and the EEA, transfers use appropriate safeguards (for example the UK International Data Transfer Agreement, or the Addendum to the EU Standard Contractual Clauses).

Data-subject rights and complaints

Requests from tenants or contractors are usually directed to the controlling landlord or agent, whom we assist. Anyone may complain to the Information Commissioner's Office (ico.org.uk). For your own account, contact joe@jrmcompliance.com.

Data Processing Agreement

Business customers (for example letting agents) who need a signed Data Processing Agreement can request one at joe@jrmcompliance.com.


This page is provided for general information and is not legal advice.

← Back to home · Privacy · Terms · Cookies · Data Processing · Compliance checklist · Contact