Privacy Notice
What Mendlet collects, why, who sees it, and what you can do about it — for our customers, for the tenants and contractors they work with, and for anyone who visits this website.
The short version
- We only collect what the product needs. No advertising, no tracking, no analytics scripts, no selling of data — to anyone, ever.
- If you are a tenant or a contractor, your landlord or agent is in charge of your information. We hold it for them. Ask them first about anything to do with it; if you ask us, we will help.
- If you run a company on Mendlet, we are in charge of your account details and act on your instructions for everything else.
- Data leaves when you do. Thirty days after an account closes, it is deleted.
- You can always write to us at privacy@mendlet.co.uk, and you can always complain to the ICO.
1. Who we are
Mendlet is operated by Mendlet Ltd, registered in England and Wales under company number [COMPANY NUMBER — fill in on incorporation], registered office [REGISTERED OFFICE ADDRESS — fill in on incorporation]. For anything about personal data, write to privacy@mendlet.co.uk.
2. Two roles: controller and processor
Data protection law distinguishes the organisation that decides why and how personal data is used (the controller) from one that handles it on that organisation's instructions (the processor). Mendlet is both, for different data.
| Data about | Our role | Who decides |
|---|---|---|
| Visitors to this website, and people who use the contact form | Controller | We do |
| Customers — the people who create and run a company account (name, email, sign-in, billing, support) | Controller | We do |
| Everything a customer puts into the product: tenants, occupiers, landlords, contractors, properties, repairs, messages, photographs | Processor | The customer — your letting agent, landlord or property manager |
Where we are the processor, the customer's own privacy notice tells you the full story, and section 4 below explains how to reach them. The contract that binds us to handle your data properly on their behalf is Schedule 1 of our Terms of Service.
3. What we collect and why
3.1 If you visit the website
Our web pages are served by Cloudflare, which keeps standard server logs (IP address, browser, page requested, time) for security and to keep the service running. We do not run analytics, advertising or social-media scripts. The site loads two typefaces from Google Fonts, which involves your browser requesting them from Google; Google's Fonts privacy statement applies to that request.
Lawful basis: our legitimate interest in running a secure website.
3.2 If you use the contact form
We collect what you type — your name, email address, company, phone number, portfolio size and message — and the page you sent it from, and we email it to ourselves so we can reply. We keep the email for as long as the conversation is live and for up to two years afterwards.
Lawful basis: our legitimate interest in answering enquiries, and taking steps at your request before entering a contract.
3.3 If you are a customer
To create and run your account we hold your company name, the names and email addresses of your office users, hashed passwords, sign-in sessions, your settings, your billing and usage records, support correspondence, and an audit log of significant actions taken in your account (who did what, when, and the IP address the action was taken from — the address itself, not a hash of it). We use this to provide the service, to bill you, to secure your account, to support you, and to tell you about changes to the service that affect you. We do not send marketing email unless you have asked for it, and you can stop it at any time.
Lawful basis: performance of our contract with you; our legitimate interests in security, fraud prevention and improving the service; and legal obligation for tax and accounting records.
3.4 Address lookup
When a customer saves a property address, the service looks the address up to place a pin on a map. That lookup sends the property's address line, its town and its postcode — never a person's name, never a tenancy, and never anything from a repair report — to Google's Geocoding service, Ordnance Survey, OpenStreetMap's Nominatim service, or postcodes.io. The keys used are ours, not the customer's: there is no per-customer key anywhere in the product, so where this deployment holds a Google key, Google is asked first for every customer and the address is sent by us, on our own account, to Google in the United States. Ordnance Survey is asked next where we hold an OS key; the two free services are asked only when neither has placed the building. None of it happens for a customer who has turned the map off (Settings → Maps and address lookup). Some of those requests are made by our servers and some by the browser of the office user who is looking at the map, in which case that user's own IP address reaches the service as well. Section 5 says which of these we have a contract with, and which we do not. The address of a property is not personal data in most cases; where it identifies a person it is processed under the customer's instructions as described in section 2.
4. Tenants and contractors
If you are a tenant using the tenant portal, or a contractor using the contractor portal, the letting agent, landlord or business that gave you access is the controller of your information. They decided to collect it and how to use it; we hold and process it on their behalf under a written contract.
What the product holds about you is what they and you have entered: your name and contact details; your address or the addresses you work at; the repairs you have reported or been asked to do; messages, photographs and videos; and for contractors, the qualifications and notes the customer has recorded and the times you signed in. The tenant portal also keeps the six-digit sign-in codes it sends you for a short period so it can check them.
Free text and photographs. A repair report, a message and a photograph are whatever the person writing them chooses to say. Someone explaining why damp matters may mention a child’s asthma; a photograph of a room shows the room. The product does not ask for health information and has no field for it, but it cannot stop it being volunteered, and information like that is special category data under UK GDPR — it needs a lawful condition on top of a lawful basis. That condition is the customer’s to hold, because the customer is the controller. What we do is hold it under the same contract as everything else, keep it to the people the customer has given access, and delete it when they tell us to. If you would rather not put something in writing here, tell your agent or landlord another way.
To exercise any right over this information — to see it, correct it, have it deleted, or object to something — contact your letting agent or landlord directly. If you contact us instead, we will tell them and help them answer you, but we cannot act on their data without their instruction.
Messages. The service sends you emails and, where the customer has enabled it, text messages on the customer's behalf: appointment reminders, updates about a repair, sign-in codes. These come from Mendlet's sending address with the customer's name on them, and replies go to the customer. The service does not send marketing to tenants or contractors on anyone's behalf.
5. Who we share it with
Mendlet runs on services provided by other companies. These are our sub-processors, each engaged under a written contract that binds them to protect personal data and to use it only for us:
| Provider | What for | Where |
|---|---|---|
| Cloudflare, Inc. | Hosting the application, database, file storage and network security | Global network; see section 6 |
| Cloudflare Workers AI (Cloudflare, Inc.) | Translating text inside the contractor and tenant portals, where somebody has chosen a language other than English. Two kinds of text go to it: what the office wrote about a repair, so the reader can follow it, and what a contractor or tenant wrote, so the office can. It runs on the same Cloudflare account as the rest of the service. Emails and text messages are never translated — they are written and sent in English. | Global network; see section 6 |
| Postmark (ActiveCampaign, LLC) | Sending transactional email | United States |
| Twilio Inc. | Sending text messages, where a customer has enabled them | United States and EU |
| Google LLC | Turning a property address into a map pin (the Geocoding API), and map imagery. The key is ours and is used for every customer who has not turned the map off — there is no per-customer key and no arrangement between a customer and Google. Where this deployment holds a Google key, Google is asked first, so every UK address a customer saves is sent by us to Google. What is sent is the address line, the town and the postcode: never a name, never a tenancy, never anything from a repair report. | United States — see section 6 |
| Ordnance Survey Ltd | The same lookup against the UK address register (the OS Places API), and OS map imagery, where this deployment holds an OS key. Asked after Google, on our key, on the same terms. | United Kingdom |
| Stripe Payments Europe, Ltd. | Taking subscription payments from customer companies, and holding the card and invoice records that go with them. This concerns the person who pays for a Mendlet account — never a tenant or a contractor. | Ireland, with onward transfer to Stripe, Inc. in the United States |
We never see or store a card number. Card details are entered on Stripe’s own pages and stay with Stripe; what Mendlet keeps is a reference to the customer, which plan they are on, and whether the subscription is in good standing.
Behind those, when neither has placed the building, the product falls back to public services that we do not have a contract with, and we say so rather than list them alongside the ones we do. What reaches them is a property address, a postcode or a map tile request — never a person’s name, and never the contents of a repair report. The request is made either by our servers or by the browser of the office user looking at the map, in which case that user’s IP address reaches the service too.
| Service | What for | Relationship |
|---|---|---|
| OpenStreetMap Foundation (Nominatim, map tiles) | Turning an address into a map pin; map imagery | Public service, no contract with us |
| postcodes.io (Ideal Postcodes) | UK postcode lookup | Public service, no contract with us |
| Google Fonts (Google LLC) | The two typefaces on our public web pages, fetched by your browser when you read them. Nothing from a customer’s account is involved. Google LLC is separately a sub-processor for address lookup and map imagery, in the table above. | Google’s own terms |
A customer who would rather no address left the product for any of them can turn the map off — Settings → Maps and address lookup. With it off, nothing is sent to any of these services by our servers or by the office user’s browser, and a property simply has no pin. Everything else works as before.
Beyond these, we disclose personal data only where the law requires it — to a court, regulator or law-enforcement body with proper authority — or, with notice to customers, to a buyer of our business who takes on these commitments. We never sell personal data and never share it for advertising.
6. Where it is processed
Our hosting provider runs a global network, and email and text messages are delivered by providers based partly in the United States. This means personal data may be processed outside the United Kingdom. Where it is, we rely on a safeguard recognised under UK GDPR: the UK's adequacy regulations where they apply (including the UK–US Data Bridge for certified organisations), or the UK International Data Transfer Agreement or Addendum. You can ask us at privacy@mendlet.co.uk which safeguard applies to a particular provider.
7. How long we keep it
| Data | Kept |
|---|---|
| Customer Data (everything in a company's account) | For the life of the account, then deleted within 30 days of closure; removed from backups as they cycle out |
| Items a customer moves to Trash | Until the customer restores or permanently deletes them, or the account closes |
| Customer account and billing records | Life of the account, then six years for tax and accounting law |
| Office and contractor sign-in sessions | 12 hours, or until signed out |
| Tenant portal sessions | 90 days, or until signed out — a tenant should not have to sign in every time a repair moves |
| Tenant sign-in codes | 10 minutes, single-use |
| Password-reset links | 1 hour, single-use |
| Email-confirmation links (proving a new account's address) | 7 days, single-use |
| Tenant sign-out markers (a hash of the address, kept so that "sign out everywhere" and erasure keep every device signed out) | 180 days, then removed |
| Contractor job links | 60 days, or until revoked — see section 8 |
| Links to view a photograph | 15 minutes |
| The activity log in a customer’s account — who did what, when, and the IP address the action was taken from. Unlike the rate-limiting counters below, this is the address itself and not a hash of it, and it is included when the customer exports their data. | 730 days (two years), then deleted automatically. Destroyed sooner if the account is closed, with the rest of the account. |
| Send receipts — one row for each email or text message the service sends on a customer’s behalf, so the office can answer “did they get it?”. It records what the message was about, a masked recipient (the first letter and domain of an address, the last three digits of a number), the subject line of an email, which job and tenancy it belonged to, and what Postmark or Twilio said about delivery. It never holds the body of the message, and the subject it records is a short description of the message’s kind rather than the subject line sent, so a receipt does not place a person at an address. | Eighteen months, then deleted. Erased earlier with the tenant when a customer erases a tenant’s details, and destroyed with the organisation when the account is closed. |
| Rate-limiting counters (kept against a hash of the IP address or identifier, never the value itself) | Fifteen minutes to a few hours |
| Billing records for a customer account — the plan, the subscription state, and a reference to the Stripe customer. Card numbers are never seen or stored by Mendlet; Stripe holds them. | Life of the account, then six years for tax and accounting law (held by Stripe, our payment processor) |
| A note that you asked not to receive Mendlet announcements, stored as a one-way hash of your address and never as the address itself | Kept, so the request keeps being honoured |
| Messages you send us (the contact form, or the Help screen inside the app) — your name, address, what you wrote, the topic you chose, and the reference we gave it | 12 months, then deleted automatically. A message sent from inside a company's account is also deleted when that account is closed. |
| Server logs | As set by Cloudflare's retention, typically days to weeks |
8. How we protect it
Every connection to Mendlet is encrypted. Each customer's data is kept apart from every other customer's, and every request is checked against the company it belongs to. Passwords are stored only as salted, iterated hashes. Sign-in attempts are rate-limited by account and by address.
Links we email are of two kinds, and the difference is deliberate. A password-reset link, an email-confirmation link and a tenant’s six-digit sign-in code are single-use and short-lived — one hour, seven days and ten minutes respectively. A contractor’s job link is different on purpose: it is a long, unguessable address that keeps working for sixty days, because asking a plumber to create an account before they can read a job is how jobs stop getting done. It opens the job it was sent for. It stops working the moment that job is handed to a different contractor, the contractor’s account is deactivated or removed, the job is deleted, the office revokes it, or sixty days pass. Anyone holding that link can see that job, which is why it is sent to the contractor and to no one else.
And it can be exchanged for a sign-in, deliberately. A contractor reading a live job from that link can press through to their own portal without typing a password, which gives them a twelve-hour session showing the work that contractor account is entitled to see — their own jobs for the customer who sent the link, and nothing belonging to any other contractor or any other customer. It is refused if the job is finished or cancelled, if nobody is assigned, or if the contractor’s account has been switched off. We say this plainly because it is a decision rather than an oversight: a tradesperson should not need to create an account before they can be told about a repair, and the same reasoning applies to the second screen as to the first.
Access to production systems is limited to the people who run the service. We keep backups for disaster recovery. No system is perfectly secure; if we become aware of a breach affecting your data we will tell the customer without undue delay and, where the law requires, the ICO and the people affected.
9. Cookies and local storage
We do not use cookies for tracking, advertising or analytics, and we do not use third-party cookies at all. The product uses your browser's own storage for things it needs to work:
| Stored | Why | Type |
|---|---|---|
| Your sign-in session (office, contractor or tenant) | So you stay signed in | Strictly necessary |
| Your light/dark preference | So the page looks the way you chose | Preference, set only when you choose |
| Which settings panels you left open; a repair report you started but did not send | Convenience — it is your own browser remembering | Preference |
| Cloudflare security cookies | Telling people from bots | Strictly necessary |
Because none of this is used to track you, no consent banner is required and we do not show one. You can clear it all with your browser's normal controls; the only effect is that you will be signed out.
10. Your rights
Under UK GDPR you have the right to ask for access to your personal data; to have it corrected; to have it erased; to restrict or object to processing; to have it moved to another provider; and, where processing is based on consent, to withdraw consent. You also have the right not to be subject to a decision based solely on automated processing that has a legal or similarly significant effect on you — the urgency the tenant portal suggests for a report is not such a decision: it is a sorting aid for the office, and a person decides what happens.
Where we are the controller (customers, website visitors, enquirers), write to privacy@mendlet.co.uk. We will respond within one month, and we will not charge you unless the law allows and the request is manifestly unfounded or excessive.
Where we are the processor (tenants, contractors, landlords in a customer's account), contact the customer; section 4 explains why. If you write to us we will forward your request to them the same working day where we can.
What the product can actually do, so that neither of us is promising something that has to be done by hand. A customer can erase a tenant’s details from their account in one action: the name, email address, phone number, access notes, messages and photographs go, and so do the send receipts for messages that were sent to them, and what remains is the repair history with the person taken out of it — because the record that a leak was fixed at a property is the landlord’s, and is not the tenant’s to remove. A customer can also close their account from within the product: that sets a date thirty days out, leaves the account working until then so they can export everything and change their mind, and destroys the data on the day. Both actions are recorded, and what is recorded is that they happened and when — not another copy of what was deleted.
11. Children
Mendlet is a business service and is not directed at children. A customer must not add a person under 16 as a tenant portal user; where a household includes children, the portal user should be an adult member of the household.
12. Changes to this notice
We will update this notice when what we do changes — for example if we add a service provider. The date at the top is the date of the current version, and material changes will be announced in the product and, for customers, by email.
13. Contact and complaints
Questions and requests: privacy@mendlet.co.uk, or by post to Mendlet Ltd, [REGISTERED OFFICE ADDRESS — fill in on incorporation].
If you are unhappy with how we have handled your personal data you have the right to complain to the Information Commissioner's Office: ico.org.uk/make-a-complaint, or 0303 123 1113. We would appreciate the chance to put things right first.