Skip to content
LatchFlowThe AI Lettings Platform
SecurityPrivacyTermsDPA
Privacy

Privacy Policy

Last updated: 8 July 2026

Who we are

LatchFlow(“LatchFlow”, “we”, “us”) provides an AI operations platform for lettings and property-management agencies. This policy explains how we handle personal data, and it distinguishes two very different situations:

  • Where we are the controller — the personal data of website visitors, enquirers, and the staff users who administer an agency account. We decide how and why that data is used, and this policy governs it.
  • Where we are the processor— the tenant, landlord, contractor, and operational data an agency loads into, or connects to, its LatchFlow workspace. The agency is the controller of that data; we process it only on the agency’s documented instructions under our Data Processing Agreement.

Personal data we handle

  • Website & enquiry data — name, email, agency, and anything you include in a booking or contact form.
  • Account data — the names, work emails, and roles of the staff who use the dashboard, plus authentication and audit records.
  • Workspace data (as processor) — records an agency manages: properties, tenancies, and the contact details and correspondence of tenants, landlords, and contractors, including messages handled across email, SMS, WhatsApp, and the AI phone line, and any operational notes the agency records.
  • Technical data — the request and security logs needed to operate and protect the service.

An agency may choose to record sensitive notes (for example, a tenant’s vulnerability or accessibility needs) to deliver a duty of care. Where it does, that is special-category or safeguarding-relevant data and is handled under the agency’s instructions and the additional safeguards in our Data Processing Agreement.

Why we use it, and our lawful bases

  • To respond to enquiries and assess fit — legitimate interests in answering and qualifying business enquiries.
  • To provide the service — performance of our contract with the agency.
  • To keep the service secure and reliable — legitimate interests in security, fraud prevention, and diagnostics.
  • To meet legal obligations — where the law requires us to retain or disclose information.

For workspace data we process as processor, the lawful basis for the underlying processing is the agency’s to determine as controller. We do not sell personal data, and we do not use workspace data to train third-party AI models. Our language-model provider processes prompts via its API and, under its API terms, does not use that content to train its models.

AI processing

The product uses AI to draft replies, summarise cases, triage maintenance, and answer calls. AI-generated output that is customer-facing is held behind human approval where the agency’s settings require it, and every material action is written to an audit trail. Caller identity on the phone line is always re-verified from the caller’s own number on our servers — never taken on trust from the AI.

Who we share it with (subprocessors)

We use a small set of vetted providers to run the service. Each processes data only to provide its function and under contractual data-protection terms:

  • Vercel Inc. — Application hosting and content delivery (EU/US (region-configured)).
  • Supabase — Managed PostgreSQL database and encrypted file storage (Project-configured region).
  • OpenAI — Large language model that drafts replies, summaries and triage (no training on your data via the API) (US).
  • ElevenLabs — Voice synthesis and telephony transcription for the AI phone line (US/EU).
  • Twilio — Telephony, SMS and WhatsApp message transport (EU/US).
  • Microsoft 365 — Your own connected mailbox, accessed under your OAuth grant (your tenant, your data) (Your Microsoft tenant).

We do not add or change subprocessors that handle workspace data without notice to the agency and a right to object, as set out in the Data Processing Agreement.

International transfers

Some subprocessors are based outside the UK. Where personal data is transferred internationally, we rely on UK-approved safeguards — the UK International Data Transfer Agreement or the EU Standard Contractual Clauses with the UK Addendum — together with additional technical measures. The specific hosting region for an agency’s workspace is confirmed in its Data Processing Agreement.

Security

Data is encrypted in transit (TLS) and at rest. Each agency’s workspace is logically isolated and every query is scoped to that agency. Access is least-privilege and audited. Full detail is on our Security page.

Retention

Enquiry data is kept only as long as needed to follow up and for reasonable business records. Workspace data is retained for the life of the agency’s account and then deleted or returned on the timetable set in the Data Processing Agreement. We retain limited records where the law requires it.

Your rights

Under UK data-protection law you may have the right to access, correct, delete, restrict, object to, or port your personal data. If your data sits inside an agency’s workspace (where we are processor), we will refer your request to that agency as the controller and support them in responding. You can also complain to the Information Commissioner’s Office (ico.org.uk), though we’d appreciate the chance to help first.

Cookies and analytics

The site uses no advertising cookies. Vercel Web Analytics and Speed Insights record anonymous, aggregate page and performance data without cookies and without identifying individual visitors. Essential browser storage may hold interface state; the booking form keeps no local copy of your details after submission.

Contact

Privacy questions and rights requests: support@latchflow.co.uk.

LatchFlow
support@latchflow.co.ukPricingIntegrationsSecurityPrivacyTermsDPA
ResourcesOperations ScorecardOperations Audit Pack

© 2026 LatchFlow. The AI-powered lettings platform.