A short plain-English summary
- We only collect personal data that we actually need to run our business and help you.
- We never sell your data.
- We use a small number of reputable service providers (Cloudflare, Stripe, GoCardless) to run the service, send email and take payments.
- If you are a tenant whose landlord uses PropertyManager360, your landlord decides how your tenancy data is used — we process it on their behalf. Contact your landlord first about that data; we'll help where we can.
- If a landlord connects the optional HMRC Making Tax Digital feature, UK law requires certain technical data to be sent to HMRC with each request — see section 4.1.
- You can ask for a copy, correction or deletion of your data at any time using the contact details at the end.
- You can complain to the UK Information Commissioner's Office if you're not happy with how we've handled your data.
1. Introduction
This Privacy Policy explains how 360PropertyLabs Ltd ("we", "us" or "our"), trading as PropertyManager360, collects, uses, discloses and safeguards your personal information when you:
- visit our website at propmgr360.com;
- create an account on, or use, the PropertyManager360 software service — the landlord dashboard (app.propmgr360.com) or the tenant portal (tenant.propmgr360.com);
- sign up for a free trial or request a demo;
- contact us by email or through any of our online forms; or
- otherwise interact with our brand or services.
This policy is written to meet our obligations under the UK GDPR, the Data Protection Act 2018 (the "DPA 2018") and the Privacy and Electronic Communications (EC Directive) Regulations 2003 (the "PECR").
Please read this policy carefully. If you do not agree with any part of this policy, please do not use our website or services.
2. Who we are (the data controller)
The data controller responsible for your personal information is:
- Legal name
- 360PropertyLabs Ltd
- Trading as
- PropertyManager360
- Company number
- 17390622
- Registered office
- 66 Paul Street, London, England, EC2A 4NA
- ICO registration
- Registration pending
- General contact
- hello@propmgr360.com
- Privacy contact
- privacy@propmgr360.com
We are not required under UK GDPR to appoint a Data Protection Officer ("DPO"), but you can reach our designated privacy contact at the email address above for any questions about how we handle your data.
2.1 When we are the controller — and when we are not
We act in two different capacities, and it matters which one applies to you:
- We are the controller for the personal data described in this policy: website visitors, demo requests, our customers' own account, billing and usage data, and tenants who sign up for our standalone tenant tools directly (without a landlord on the platform).
- We are a processor for the tenancy data that landlords and letting agents manage inside the service — tenant names and contact details, tenancy and rent records, maintenance requests, documents and messages. For that data the landlord (or agent) is the controller and decides how it is used; we process it on their instructions under a Data Processing Agreement that reflects Article 28 UK GDPR. If you are a tenant and want to exercise your data rights over your tenancy records, your landlord is the right first contact — though the tenant portal also gives you tools to download your own data, and you can always ask us for help at privacy@propmgr360.com.
3. Personal data we collect
We only collect personal data that we genuinely need. The categories below cover the data for which we are the controller (see section 2.1). Tenancy data you process through the platform as a landlord or agent is covered by the Data Processing Agreement, not this section.
3.1 Information you give us directly
- Account registration: your name, email address, company name and password (stored only as a one-way hash) when you sign up; your phone number and two-factor authentication enrolment if you add them; and the optional business details (such as company number and correspondence address) you record in settings.
- Billing: your subscription plan and billing history. Card details are collected and held by our payment processor, Stripe — we never see or store your full card number.
- Demo requests and enquiries: the details you submit through our forms — name, email, company, phone and portfolio size where you provide them.
- Correspondence: any information you choose to share when you email us, reply to our emails or contact us through a form or support ticket — including your name, email address, company and the content of your message.
3.2 Information collected automatically
- Technical data: your IP address, approximate location derived from that IP, browser type, operating system, device type and language preference.
- Usage data: pages visited, referring URL, time spent on pages, links clicked and similar interaction events.
- Security data: rate-limit counters keyed to your IP address; sign-in events, including a coarse device fingerprint used to alert you when your account is accessed from a new device; and audit logs of actions taken in the service (who did what, and when), kept for security and accountability.
3.3 Information from third parties
We may receive limited information about you from the service providers we use to run our site and deliver emails, including:
- Cloudflare — request logs, bot-detection signals and security analytics for our website and API.
- Cloudflare (email) — email delivery status (delivered / bounced / complained) for messages we send you.
4. How we use your personal data
The tables below set out each purpose for which we process personal data, the data categories involved and the lawful basis we rely on under Article 6 UK GDPR.
| Purpose | Data categories | Lawful basis |
|---|---|---|
| Provide the PropertyManager360 service — accounts, sign-in, the features you use | Account data, security data, usage data | Contract (Art. 6(1)(b)) — performing our agreement with you |
| Take payment for subscriptions and manage billing | Account data, plan and billing history (card details held by Stripe) | Contract (Art. 6(1)(b)); legal obligation for tax/accounting records |
| Submit your Making Tax Digital data to HMRC, with the legally required fraud-prevention data — see 4.1 | Tax records you keep in the service; device, browser and network data | Contract (Art. 6(1)(b)) — you asked us to connect; legal obligation (Art. 6(1)(c)) for the fraud-prevention data |
| Respond to demo requests and contact prospects who ask to hear from us | Email address, name, company, timestamp, source page | Consent (Art. 6(1)(a)) — you positively submitted the form |
| Operate, secure and monitor our website and API | IP address, user-agent, request logs | Legitimate interests (Art. 6(1)(f)) — running our business securely |
| Send transactional emails (waitlist confirmation, replies to enquiries) | Email address, name | Contract (Art. 6(1)(b)) and/or legitimate interests |
| Respond to your enquiries | Everything you share with us in your message | Legitimate interests — replying to you is expected |
| Prevent fraud, abuse and security incidents | IP, request logs, rate-limit counters | Legitimate interests — protecting our systems and other users |
| Comply with legal obligations (tax, accounting, requests from authorities) | Whatever the specific obligation requires | Legal obligation (Art. 6(1)(c)) |
| Send direct marketing (only if you have opted in) | Email address, name | Consent (Art. 6(1)(a)) and PECR reg. 22 |
We do not engage in "soft opt-in" marketing to contacts who have not explicitly asked to hear from us. You can withdraw consent at any time — see Section 11 (Your rights).
4.1 Making Tax Digital (HMRC) and fraud-prevention data
If you connect your account to HM Revenue & Customs for Making Tax Digital ("MTD"), the following processing happens — only for accounts that use this optional feature:
- Connection details. We collect your National Insurance number to identify your HMRC record, and store the access tokens HMRC issues when you authorise the connection through your own Government Gateway sign-in. Both are encrypted at rest. We never see or store your Government Gateway password, and tokens are deleted when you disconnect.
- Submission data. The income and expense figures submitted to HMRC are derived from the records you keep in the service, and each submission is made only when you trigger it.
- Fraud-prevention headers (a legal requirement). UK law requires software that communicates with HMRC's MTD APIs to send HMRC certain technical data with every request, which HMRC uses to detect and prevent fraud. For each MTD request made from your account this includes: your IP address and the time we observed it; a random identifier stored in your browser to recognise the device; your browser's user-agent string, screen and window dimensions and timezone; your user ID in our system; whether your session used two-factor authentication (with the time of the check — never the code itself); and details of our software and servers. We send this data to HMRC only when you use the MTD features, on the lawful basis of legal obligation (Article 6(1)(c) UK GDPR). HMRC is the controller of the data it receives; its own privacy information is at gov.uk.
If you do not want this data shared with HMRC, simply don't connect the MTD feature — the rest of the service works without it.
5. Our legal bases explained
The lawful bases we rely on (from Article 6 UK GDPR) are:
- Consent — where you have given us clear consent to process your personal data for a specific purpose. You can withdraw consent at any time.
- Contract — where processing is necessary to perform a contract with you, or to take steps at your request before entering into one (for example, responding to a sales enquiry).
- Legal obligation — where we need to process data to comply with a legal or regulatory obligation under UK law (for example, keeping accounting records under the Companies Act 2006).
- Legitimate interests — where processing is necessary for our or a third party's legitimate interests and those interests are not overridden by your rights and freedoms. Before relying on this basis we balance our interests against your rights and only proceed where we think a reasonable person would expect the processing.
6. Cookies and similar technologies
Cookies are small text files placed on your device when you visit a website. The Privacy and Electronic Communications Regulations 2003 require websites to obtain your consent before setting any cookies or similar technologies that are not strictly necessary for the service you have asked for.
Our pages serve their fonts, stylesheets and images from our own servers rather than from a third-party content delivery network. Simply opening a page therefore discloses your IP address only to us and our hosting provider (Cloudflare, see section 7). The advertising tag described below is the only third-party request we make on arrival, and it is consent-gated; where a form shows an anti-spam challenge, that check is served by Cloudflare.
We use Google Ads conversion measurement on our marketing website so we can see which of our adverts lead people to start a trial, and spend our advertising budget responsibly. This is provided by Google (see section 7). We do not use Meta Pixel, LinkedIn Insight Tag or any similar third-party tracker.
We load Google's tag through Google Consent Mode with advertising and analytics storage set to denied by default, so no advertising or analytics cookies are set when you first arrive. A banner asks for your choice:
- If you accept, Google sets cookies (for example
_gcl_*) to measure ad conversions. - If you decline (or before you choose), no such cookies are set — Google receives only aggregated, cookieless signals used to model conversions.
Our lawful basis for advertising cookies is your consent (Article 6(1)(a) UK GDPR and PECR). You can change or withdraw it at any time: reopen cookie settings, or clear this site's storage in your browser.
Cloudflare may set a short-lived technical cookie (for example __cf_bm)
to distinguish humans from bots. This is a "strictly necessary" cookie under PECR,
does not identify you and does not require consent.
When you sign in to the service itself (the landlord dashboard or tenant portal), we set a session cookie that keeps you signed in. It is HttpOnly and Secure, is essential to providing the service you asked for ("strictly necessary" under PECR, so no consent banner is needed for it), and is cleared when you sign out. The application sets no advertising or analytics cookies.
7. Who we share your data with
We never sell your personal data. We share personal data only in the limited circumstances below:
7.1 Our service providers (processors)
We use the following data processors to run our business. Each is bound by a written data processing agreement that reflects the requirements of Article 28 UK GDPR.
| Provider | Purpose | Data location |
|---|---|---|
| Cloudflare, Inc. | Website hosting, DDoS protection, edge compute (Workers), KV storage, DNS, transactional email delivery | Global edge network with UK / EU regional processing |
| GitHub, Inc. (a Microsoft company) | Source code hosting and deployment pipeline (no customer data) | United States |
| Google Ireland Limited / Google LLC | Advertising conversion measurement on the marketing site (consent-based; see section 6) | Ireland / United States (with UK GDPR-compliant safeguards) |
| Stripe Payments Europe, Ltd / Stripe, Inc. | Subscription payment processing and billing | Ireland / United States (with UK GDPR-compliant safeguards) |
| GoCardless Ltd | Direct Debit collection where a landlord enables rent collection | United Kingdom |
| Microsoft Ireland Operations Ltd | Outlook calendar sync — only if you connect your Microsoft account | EU / United States (with UK GDPR-compliant safeguards) |
AI-assisted features (the in-app assistant and document analysis) run on Cloudflare's Workers AI infrastructure under the Cloudflare engagement above; the content you submit to them is not used to train third-party foundation models.
7.2 Professional advisers
We may share personal data with our accountants, auditors and lawyers where it is necessary for them to provide their services to us, subject to confidentiality.
7.3 Law enforcement and regulators
We may share personal data where we are required to do so by law, court order or by a regulator (such as HMRC, the police or the ICO), or where we believe disclosure is necessary to protect our rights, property or safety, or those of our users or the public.
Separately, if you use the Making Tax Digital feature we send HMRC your tax submissions and the legally required fraud-prevention data described in section 4.1. HMRC receives that data as a controller in its own right, not as our processor.
7.4 Business transactions
If we are involved in a merger, acquisition or sale of all or part of our business or assets, personal data may be transferred to the acquiring entity. Where this happens, we will notify you and make sure the recipient is bound by equivalent data protection commitments.
8. International transfers of personal data
Some of our service providers are based in, or process data in, the United States and other countries outside the UK. Where personal data is transferred outside the UK we ensure at least one of the following safeguards is in place:
- An adequacy regulation made by the UK government, meaning the recipient country provides an essentially equivalent level of protection;
- The UK's International Data Transfer Agreement (IDTA), or the European Commission's Standard Contractual Clauses together with the UK Addendum; or
- Another valid transfer mechanism permitted under Chapter V of the UK GDPR.
You can request a copy of the specific safeguards applying to a transfer by contacting us at privacy@propmgr360.com.
9. How long we keep your data
We only keep personal data for as long as is necessary for the purposes we collected it for, or for a legal or regulatory reason. Typical retention periods:
| Category | Retention period |
|---|---|
| Account data (customers) | For the life of your account, then deleted or anonymised after closure — subject to the 30-day post-subscription export window and any legal retention duties (e.g. accounting records below). |
| HMRC connection tokens and National Insurance number | Until you disconnect the MTD feature (tokens are then deleted) or your account is closed. Records of submissions made to HMRC are kept with your financial records. |
| Demo requests and prospect enquiries | Until 24 months after our last meaningful contact, after which unconverted entries are deleted; earlier if you ask us to remove your entry. |
| Email correspondence | Up to 3 years from our last meaningful contact, to handle follow-up questions and disputes. |
| Audit logs (actions taken in the service) | Up to 6 years, reflecting limitation periods for disputes and the evidential purpose of the log. |
| Security logs (IP, user-agent, request logs) | Up to 90 days, then deleted or irreversibly anonymised. |
| Rate-limit counters | Up to 1 hour (automatically expired). |
| Accounting records (for paying customers) | 6 years from the end of the relevant accounting period, per the Companies Act 2006 and HMRC requirements. |
When retention periods expire we either delete the data or irreversibly anonymise it so that it can no longer be associated with you.
10. How we protect your data
We use industry-standard technical and organisational measures to protect your personal data against unauthorised access, accidental loss, alteration and disclosure. These include:
- TLS (HTTPS) encryption for all data in transit.
- Encrypted storage for personal data at rest.
- Strict access controls — only authorised personnel can access personal data, and only on a need-to-know basis.
- Multi-factor authentication on administrative accounts.
- Application-layer rate limiting and abuse protection.
- Regular security reviews and dependency patching.
No online service can be guaranteed to be 100% secure, but we take our security obligations seriously. If we become aware of a personal data breach that is likely to result in a risk to your rights and freedoms we will notify the ICO within 72 hours and you without undue delay, as required by Articles 33 and 34 UK GDPR.
11. Your rights under UK data protection law
Under the UK GDPR and the DPA 2018 you have the following rights in relation to your personal data:
- Right to be informed — to be told how your data is used, which this policy is designed to do.
- Right of access — to request a copy of the personal data we hold about you (a "subject access request" or "SAR").
- Right to rectification — to have inaccurate data corrected, or incomplete data completed.
-
Right to erasure — the "right to be forgotten", where a number of
conditions apply. Erasure removes your identifying details — name, email, phone,
date of birth, nationality, emergency contacts and any identity document — and
revokes portal access. Two categories of record are kept, because Article 17(3)
permits it:
- Financial and tenancy records, in anonymised form, where we have a legal obligation to retain them (Art. 17(3)(b)) — see the retention schedule above.
- Free-text records written by or about you — a message you sent, a report about conduct at a property, a support thread — where they are needed for a legal obligation (Art. 17(3)(b)) or for the establishment, exercise or defence of legal claims (Art. 17(3)(e)). Your landlord can review these after an erasure and redact any that are not needed on that basis. If you believe a specific record is being kept without justification, contact us and we will look at it.
- Right to restrict processing — to ask us to stop actively using your data in certain circumstances, while still storing it.
- Right to data portability — to receive data you have provided to us in a structured, machine-readable format.
- Right to object — to object to processing we carry out based on legitimate interests, and an absolute right to object to direct marketing.
- Right to withdraw consent — where processing is based on consent, you can withdraw it at any time without affecting the lawfulness of earlier processing.
- Rights relating to automated decisions and profiling — see Section 13.
To exercise any of these rights, email privacy@propmgr360.com. We aim to acknowledge requests within 5 working days and respond substantively within one month (extendable by up to two further months for complex requests, as permitted by Article 12(3) UK GDPR — we will tell you if that applies). To request deletion of your account specifically, you can also use our dedicated account deletion page.
We may need to verify your identity before acting on a request. Requests are free of charge unless they are manifestly unfounded or excessive, in which case we may charge a reasonable fee or refuse the request (as allowed under Article 12(5)).
12. Children's data
Our services are aimed at UK landlords, letting agents and their authorised staff. They are not directed at children. We do not knowingly collect personal data from anyone under the age of 18 on the marketing website. If you believe a child has provided us with personal data, please contact us and we will delete it.
13. Automated decision-making and profiling
We do not carry out any solely automated decision-making within the meaning of Article 22 UK GDPR on our marketing website (i.e. decisions that produce legal or similarly significant effects on you without any meaningful human involvement).
The PropertyManager360 platform may use automated features such as AI-assisted triage of maintenance requests, but any decision with significant effects on a data subject is reviewed by a human. Full details are provided in the customer-facing Data Processing Agreement.
14. Changes to this policy
We may update this policy from time to time to reflect changes in our practices, technology, legal requirements or other factors. When we do so we will update the "Last updated" and "Version" fields at the top of this page.
For material changes we will take reasonable steps to notify you in advance — for example by email (where we have a relationship with you) or by a prominent notice on the site. Continuing to use our website after a change takes effect means you accept the updated policy.
15. Complaints and the ICO
If you are unhappy with the way we have handled your personal data we would like to hear from you first — please email privacy@propmgr360.com and we will do our best to resolve the matter.
You always have the right to lodge a complaint with the Information Commissioner's Office ("ICO"), the UK's independent supervisory authority for data protection:
Information Commissioner's Office
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Helpline: 0303 123 1113
Website: ico.org.uk
16. Contact us
For any questions about this policy or your personal data, please contact:
- By email
- privacy@propmgr360.com
- By post
- 360PropertyLabs Ltd, 66 Paul Street, London, England, EC2A 4NA
This Privacy Policy is governed by the laws of England and Wales.