Ratcliffe & Sons Ltd trading as JRM Compliance · Last updated 15 July 2026
Ratcliffe & Sons Ltd, trading as JRM Compliance ("we", "us", "our"), provides an online landlord and letting-agent compliance management service (the "Service"). This policy explains what personal data we collect, why, and your rights under the UK GDPR and the Data Protection Act 2018.
The data controller is Ratcliffe & Sons Ltd (company number 12925329), a company registered in England and Wales, trading as JRM Compliance, of 7 Hill View Drive, Coppull, PR7 5DG. We are registering with the Information Commissioner's Office (registration: application pending). For any privacy question, or to exercise your rights, contact joe@jrmcompliance.com or call 07849 504682.
Ratcliffe & Sons Ltd (JRM Compliance) is the controller for the account data of customers who sign up (landlords and letting agents) and for operating the platform. Where a customer stores information about their own tenants and contractors, that customer is the controller of that data and we act as a processor on their behalf.
| Category | Examples |
|---|---|
| Account & identity | Name, email, password (stored only as a secure hash), role (landlord, letting agent, tenant, contractor, administrator, or a landlord's read-only client login), and any two-factor settings. |
| Landlord / letting agent | Business and contact details, an optional company logo used for branding on tenant-facing pages and PDFs, portfolio properties, and — for letting agents — the landlord "clients" they manage and which properties belong to each. |
| Tenant | Name and contact details, associated property, maintenance and hazard reports (including any photos submitted), in-app messages exchanged with the landlord or agent, and documents shared with them. |
| Property & compliance documents | Property details and uploaded certificates and records (Gas Safety/CP12, EICR, EPC, PAT, Legionella, smoke/CO, fire safety, tenancy paperwork), some of which may contain personal data. |
| Regulatory & licensing records | PRS Database / Property Portal registration, PRS Landlord Ombudsman membership, HMO / selective licensing details, Right to Rent checks, deposit-protection records, and Awaab's Law hazard reports. |
| Inventory & condition | Room-by-room notes and photographs for check-in / check-out reports and the PDFs generated from them. |
| Electronic signatures | When a tenant signs a document, we record the signer's name, the date and time, IP address, browser (user-agent) and, if drawn, a signature image, as an audit trail. |
| Contractor | Name or company, contact details, trade, accreditation, job and certificate records. |
| Support & billing | Contact-form messages and correspondence; subscription plan and status (card payments are handled by Stripe — we do not store full card numbers). |
| Technical | A session cookie to keep you logged in, plus security and operational logs (for example an audit log). |
| Website analytics (public pages) | Anonymous page-view records: the page visited, time, referrer, device type, and your browser language and timezone. No cookies are set and your IP address is not stored (a short per-day hash is used only for approximate unique counts). |
On-device processing: our optional certificate reader recognises text in your browser to suggest a document's type and dates; the document is not sent to us or a third party for that step.
| Purpose | Lawful basis (UK GDPR Art. 6) |
|---|---|
| Creating and running your account; providing the Service (including e-signing, messaging, inventories and reminders) | Performance of a contract |
| Securing accounts (passwords, 2FA, audit logs, rate limiting) | Legitimate interests |
| Service emails (verification, password reset, notifications, signing requests) | Contract / legitimate interests |
| Responding to support messages | Legitimate interests |
| Billing and taking payment for subscriptions | Performance of a contract |
| Understanding how our public website is used (anonymous visitor counts) | Legitimate interests |
| Legal and accounting obligations | Legal obligation |
We do not sell personal data. We use these providers under contract and appropriate safeguards:
| Provider | Purpose | Location |
|---|---|---|
| Railway | App hosting, PostgreSQL database, and storage of uploaded documents and photos on a persistent volume | European Union (Amsterdam, Netherlands) |
| Google (Gmail SMTP) | Sending service emails | US / global |
| Stripe | Subscription payments | US / global |
| Firebase Cloud Messaging (Google) — only if mobile push is enabled; not currently active | Mobile push notifications | US / global |
Your account data, uploaded compliance documents and photos are hosted within the European Economic Area (EEA), in Amsterdam, Netherlands. Transfers of personal data from the UK to the EEA are covered by the UK's data-bridge (adequacy) regulations, so no additional transfer safeguards are required. A small number of ancillary providers (transactional email and payment processing) may process limited data in the United States or globally; where they do, we rely on appropriate safeguards recognised under UK law (for example the UK International Data Transfer Agreement, or the Addendum to the EU Standard Contractual Clauses).
We keep data while your account is active. After an account is deactivated or your subscription ends, we delete or anonymise personal data within 30 days, except records we must keep longer for legal or tax reasons (for example, billing records for around 6 years). Backups are overwritten on a rolling cycle.
Encrypted connections (HTTPS), hashed passwords, optional administrator two-factor authentication, role-based access controls (including read-only client logins scoped to their own properties), rate limiting and audit logging.
You have the right to access, correct, erase (in some cases), restrict or object to processing, request portability, and withdraw consent where we rely on it. You can complain to the Information Commissioner's Office (ico.org.uk). If you are a tenant or contractor whose data was entered by a landlord or letting agent, please contact them first (they are the controller of that data); we will help them respond. To exercise a right, contact joe@jrmcompliance.com; we aim to respond within one month.
We may update this policy and will change the "last updated" date above.
This page is provided for general information and is not legal advice.
← Back to home · Privacy · Terms · Cookies · Data Processing · Compliance checklist · Contact