Last updated: [Date this is first published, e.g. 1 June 2026]
This privacy policy explains how [Legal entity name, e.g. Aivio Ltd] ("we", "us", "our") collects, uses, and protects personal information when you use the Aivio property compliance platform ("the Service").
We are the data controller for the personal data we collect from managers, tenants, and contractors using the Service. We are registered with the UK Information Commissioner's Office under registration number [ICO registration number, or delete this sentence if not yet registered].
[Legal entity name]
[Registered office address, including postcode]
Contact: [privacy@yourdomain.co.uk]
We collect different types of data depending on how you use the Service:
If you're a managing agent or staff member:
If you're a tenant:
If you're a contractor:
General:
We do not collect special category data (health, biometrics, etc.) and the Service is intended for adult use.
| Purpose | Lawful basis |
|---|---|
| Providing the Service to managing agents | Contract |
| Tracking property compliance obligations | Legitimate interest (property safety) and legal obligation |
| Operational emails (repair updates, reminders, invitations) | Legitimate interest (service operation) |
| Account security and fraud prevention | Legitimate interest |
| Responding to your data subject requests | Legal obligation |
We use your data to:
We do not use your data for marketing, profiling, or automated decision-making with legal effects.
Other users of the same organisation — your managing agent's staff can see tenants and contractors associated with their portfolio. Tenants see only their own data. Contractors see only jobs allocated to them.
Service providers (data processors) acting on our instructions:
Each processor is bound by a data processing agreement that meets UK GDPR requirements.
Legal authorities — if we receive a valid legal request (court order, regulator).
We do not sell your data or share it with advertising networks.
| Data | Retention |
|---|---|
| Active account data | Whilst your account is active |
| Compliance certificates and documents | [Specify per document type — e.g. gas safety 2 years, EICR 5 years, etc. — or "until your managing agent deletes them"] |
| Audit log entries | 7 years (typical UK record-keeping period) |
| Email delivery logs | 90 days |
| Backups | Up to 30 days after deletion |
When you request erasure (see Section 8), we delete personal data within 30 days unless we're legally required to retain it — in which case we tell you what we're keeping and why.
Your data is primarily stored in the UK / EU. Some of our service providers may transfer data to other regions:
We've assessed each transfer under the UK transfer rules and consider the safeguards adequate.
Under UK GDPR you have the right to:
Email us at [privacy@yourdomain.co.uk] with:
We'll respond within 30 days. If we need longer (complex requests), we'll tell you why and when to expect a response.
We use only strictly necessary cookies:
We do not use analytics, marketing, or tracking cookies.
Because all our cookies are strictly necessary, no consent is required to set them under UK PECR rules. We still inform you about them via this policy and the cookie notice shown on first visit.
We protect your data using:
If we discover a breach affecting your personal data, we'll notify you and the ICO within 72 hours where legally required.
If we make material changes, we'll notify you by email and post the updated policy here. Continued use of the Service after notification means you accept the updated policy.
For any questions about this policy or your data:
[Legal entity name]
[Registered office address]
Email: [privacy@yourdomain.co.uk]
Yellow-highlighted fields above are template placeholders — they MUST be replaced before this policy is treated as published. Search the source file for Placeholder to find them all.