Legal

Privacy Policy

How KeyLedger collects, uses, shares and protects personal data in KeyLedger.

Last updated: 20 August 2026

This policy covers two different relationships. When you visit our site or manage your own KeyLedger account, we are the data controller. When your organization stores tenant, lease and payment records in KeyLedger, your organization is the controller and we act as its processor — we handle that data only on your instructions.

1. Data we collect as controller

For account holders and site visitors:

  • Account data — name, work email, phone number, organization name, and the password hash used to authenticate you.
  • Billing data — plan, subscription status and billing history. Card numbers never reach our servers; they are handled by our payment processor.
  • Usage and device data — pages visited, features used, IP address, browser, operating system and device type, plus session records so you can review and revoke your own logins.
  • Support correspondence — messages you send us and our replies.

2. Data we process on your behalf

When your organization uses KeyLedger, it puts records into the system that typically include tenant names and contact details, lease terms, rent and payment history, maintenance requests, documents and messages. We process this only to run the Service for you, to provide support, and to meet legal obligations.

We do not sell this data, use it to build advertising profiles, or use it to train machine-learning models.

3. Why we process data

  • To perform our contract — creating your account, providing the Service, taking payment, and supporting you.
  • Legitimate interests — securing the platform, preventing abuse and fraud, and improving the product in aggregate.
  • Legal obligation — keeping financial records and responding to lawful requests.
  • Consent — optional communications such as product announcements. You can withdraw consent at any time.

4. Tenant isolation

Every record in KeyLedger is bound to the organization that owns it, and that boundary is enforced in the database itself through row-level security — not only in application code. One customer's data is not visible to another, and our own staff access is limited to what is needed for support and operations.

5. Sharing and sub-processors

We share data only with service providers who help us run KeyLedger, each bound by contract to protect it:

  • Payment processors — to take subscription and rent payments.
  • Cloud hosting and object storage — to run the application and store uploaded documents and images.
  • Email delivery — to send transactional mail such as invitations, receipts and reminders.
  • Product analytics and error monitoring — to understand usage and diagnose faults.

We may also disclose data where required by law, or in connection with a merger or acquisition — in which case we will notify you before your data becomes subject to a different policy.

6. International transfers

Our providers may process data outside your country. Where that happens, transfers are covered by an appropriate safeguard such as the Standard Contractual Clauses or an adequacy decision.

7. Retention

We keep account data for as long as your subscription is active. After termination, Customer Data remains available for export for 30 days and may then be deleted. Audit logs are retained for the period configured by your organization; financial records are kept for as long as tax law requires. Backups are cycled out on a rolling schedule.

8. Security

Passwords are stored using industry-standard hashing, traffic is encrypted in transit, and access to production systems is limited and logged. Sessions are listed in-app so you can revoke a device you no longer recognise. No system is perfectly secure, but we will notify you and any applicable regulator without undue delay if a breach affects your data.

9. Your rights

Depending on where you live, you may have the right to access, correct, delete, restrict or object to the processing of your personal data, and to receive it in a portable format. To exercise a right relating to your own account, email [email protected].

If you are a tenant and your data was entered by a landlord or property manager, that organization is the controller — contact them first, and we will support them in responding. You also have the right to complain to your local data-protection authority.

10. Cookies

We use strictly necessary cookies to keep you signed in and to protect against cross-site request forgery; these cannot be turned off without breaking the Service. We also use a small number of analytics cookies to understand product usage. We do not use advertising or cross-site tracking cookies.

11. Children

KeyLedger is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child's data has been provided to us, contact [email protected] and we will delete it.

12. Changes and contact

We will post any changes to this policy on this page and update the date above. Material changes are announced by email or in-app before they take effect.

Contact us at [email protected]. See also our Terms of Service.