Privacy Policy

Ratcliffe & Sons Ltd trading as JRM Compliance · Last updated 15 July 2026

Ratcliffe & Sons Ltd, trading as JRM Compliance ("we", "us", "our"), provides an online landlord and letting-agent compliance management service (the "Service"). This policy explains what personal data we collect, why, and your rights under the UK GDPR and the Data Protection Act 2018.

Who we are (data controller)

The data controller is Ratcliffe & Sons Ltd (company number 12925329), a company registered in England and Wales, trading as JRM Compliance, of 7 Hill View Drive, Coppull, PR7 5DG. We are registering with the Information Commissioner's Office (registration: application pending). For any privacy question, or to exercise your rights, contact joe@jrmcompliance.com or call 07849 504682.

Our roles

Ratcliffe & Sons Ltd (JRM Compliance) is the controller for the account data of customers who sign up (landlords and letting agents) and for operating the platform. Where a customer stores information about their own tenants and contractors, that customer is the controller of that data and we act as a processor on their behalf.

The personal data we collect

CategoryExamples
Account & identityName, email, password (stored only as a secure hash), role (landlord, letting agent, tenant, contractor, administrator, or a landlord's read-only client login), and any two-factor settings.
Landlord / letting agentBusiness and contact details, an optional company logo used for branding on tenant-facing pages and PDFs, portfolio properties, and — for letting agents — the landlord "clients" they manage and which properties belong to each.
TenantName and contact details, associated property, maintenance and hazard reports (including any photos submitted), in-app messages exchanged with the landlord or agent, and documents shared with them.
Property & compliance documentsProperty details and uploaded certificates and records (Gas Safety/CP12, EICR, EPC, PAT, Legionella, smoke/CO, fire safety, tenancy paperwork), some of which may contain personal data.
Regulatory & licensing recordsPRS Database / Property Portal registration, PRS Landlord Ombudsman membership, HMO / selective licensing details, Right to Rent checks, deposit-protection records, and Awaab's Law hazard reports.
Inventory & conditionRoom-by-room notes and photographs for check-in / check-out reports and the PDFs generated from them.
Electronic signaturesWhen a tenant signs a document, we record the signer's name, the date and time, IP address, browser (user-agent) and, if drawn, a signature image, as an audit trail.
ContractorName or company, contact details, trade, accreditation, job and certificate records.
Support & billingContact-form messages and correspondence; subscription plan and status (card payments are handled by Stripe — we do not store full card numbers).
TechnicalA session cookie to keep you logged in, plus security and operational logs (for example an audit log).
Website analytics (public pages)Anonymous page-view records: the page visited, time, referrer, device type, and your browser language and timezone. No cookies are set and your IP address is not stored (a short per-day hash is used only for approximate unique counts).

On-device processing: our optional certificate reader recognises text in your browser to suggest a document's type and dates; the document is not sent to us or a third party for that step.

Why we use it, and lawful bases

PurposeLawful basis (UK GDPR Art. 6)
Creating and running your account; providing the Service (including e-signing, messaging, inventories and reminders)Performance of a contract
Securing accounts (passwords, 2FA, audit logs, rate limiting)Legitimate interests
Service emails (verification, password reset, notifications, signing requests)Contract / legitimate interests
Responding to support messagesLegitimate interests
Billing and taking payment for subscriptionsPerformance of a contract
Understanding how our public website is used (anonymous visitor counts)Legitimate interests
Legal and accounting obligationsLegal obligation

Who we share it with (sub-processors)

We do not sell personal data. We use these providers under contract and appropriate safeguards:

ProviderPurposeLocation
RailwayApp hosting, PostgreSQL database, and storage of uploaded documents and photos on a persistent volumeEuropean Union (Amsterdam, Netherlands)
Google (Gmail SMTP)Sending service emailsUS / global
StripeSubscription paymentsUS / global
Firebase Cloud Messaging (Google) — only if mobile push is enabled; not currently activeMobile push notificationsUS / global

International transfers

Your account data, uploaded compliance documents and photos are hosted within the European Economic Area (EEA), in Amsterdam, Netherlands. Transfers of personal data from the UK to the EEA are covered by the UK's data-bridge (adequacy) regulations, so no additional transfer safeguards are required. A small number of ancillary providers (transactional email and payment processing) may process limited data in the United States or globally; where they do, we rely on appropriate safeguards recognised under UK law (for example the UK International Data Transfer Agreement, or the Addendum to the EU Standard Contractual Clauses).

How long we keep it

We keep data while your account is active. After an account is deactivated or your subscription ends, we delete or anonymise personal data within 30 days, except records we must keep longer for legal or tax reasons (for example, billing records for around 6 years). Backups are overwritten on a rolling cycle.

How we protect it

Encrypted connections (HTTPS), hashed passwords, optional administrator two-factor authentication, role-based access controls (including read-only client logins scoped to their own properties), rate limiting and audit logging.

Your rights

You have the right to access, correct, erase (in some cases), restrict or object to processing, request portability, and withdraw consent where we rely on it. You can complain to the Information Commissioner's Office (ico.org.uk). If you are a tenant or contractor whose data was entered by a landlord or letting agent, please contact them first (they are the controller of that data); we will help them respond. To exercise a right, contact joe@jrmcompliance.com; we aim to respond within one month.

Changes

We may update this policy and will change the "last updated" date above.


This page is provided for general information and is not legal advice.

← Back to home · Privacy · Terms · Cookies · Data Processing · Compliance checklist · Contact