Privacy notice

How Tekniti processes your data

Last updated: 5 May 2026 · Review cycle: every 12 months or on material change.

Who we are

Tekniti AI is a property management platform for UK letting agents and landlords, operated by Tekniti.AI Ltd, a company registered in England and Wales (registered address: 30 Aldwych, London WC2B 4BG, United Kingdom). We are the data processor for tenant and property data uploaded by our customers, and the data controller for the customer's own account information (name, email, login credentials, billing).

Contact for privacy enquiries: legal@tekniti.ai.

What data we hold

For each customer organisation, we may process:

  • Property data — addresses, EPC ratings, planning constraints, certificate metadata
  • Tenancy data — start/end dates, rent amounts, deposit status, agreement PDFs
  • Tenant and contact data — names, contact details, right-to-rent status, visa expiry where applicable
  • Compliance evidence — gas safety / EICR / EPC certificates, tenant correspondence, maintenance records
  • Payment metadata — rent due/received amounts and dates (we do not store card or bank account numbers)
  • Account data — your name, email, role, organisation, hashed password, session tokens
  • Audit log — a hash-chained record of every compliance-relevant action you take in the platform

Why we hold it

The lawful bases under UK GDPR Article 6 are:

  • Contract (Art 6(1)(b)) — to provide the platform you have subscribed to
  • Legal obligation (Art 6(1)(c)) — to meet our own obligations under the Money Laundering Regulations and HMRC record-keeping rules
  • Legitimate interests (Art 6(1)(f)) — to detect fraud, prevent unauthorised access, and improve the product. You can object to processing on this basis at any time

We do not rely on consent for the core operation of the platform — withdrawing consent in this context is achieved by ending your subscription and exercising your right to erasure.

Where data is held

All customer data is stored in AWS eu-west-2 (London). The relevant services and what they hold:

  • RDS Postgres (encrypted at rest, in private subnet) — structured tenancy / property / contact records
  • S3 — uploaded documents and generated PDFs. Tenancy agreements and maintenance evidence sit in an Object-Locked bucket with 7-year retention to meet statutory obligations under HA 2004 and HMRC record-keeping
  • Secrets Manager — API tokens and DB credentials
  • CloudWatch — application logs (30-day retention)

No customer data leaves the UK except for the AI processing described below.

AI processing — Bedrock and the agreement audit

When you ask the assistant a question, request the agreement audit, or generate a Form 4A rationale, we send the relevant excerpt to AWS Bedrock in eu-west-2, calling Anthropic Claude (Sonnet and Haiku). The data leaves our database briefly, is processed by the model, and the response comes back.

AWS Bedrock does not use your data to train models, per the AWS Service Terms (section 50.1). We do not send tenant personal data into the model unless it is intrinsic to the query (e.g. you ask the assistant to draft a notice naming the tenant). Where possible we redact or generalise.

Per-call telemetry — model, token counts, latency, estimated cost — is logged in our own database for cost management. The query and response themselves are not persisted server-side beyond the duration of the request, with one exception: the agreement-audit findings are saved to the tenancy record so you can review them again without paying for re-inference.

You can disable AI features for your organisation by emailing support@tekniti.ai. Compliance tracking continues to work — only the AI features (chat, agreement audit, recommender) become unavailable.

Sub-processors

Tekniti uses the following sub-processors. Their role, location and our reason for choosing them:

Sub-processorPurposeRegion
Amazon Web ServicesCompute, storage, database, emaileu-west-2 (London)
Anthropic (via Bedrock)Claude language model inferenceeu-west-2 (London)
gov.uk EPC serviceEPC rating + expiry lookupUK
Companies HouseOrganisation lookup at signupUK
postcodes.ioPostcode → local authority lookupUK
planning.data.gov.ukArticle 4 / conservation / flood dataUK

We notify you of any change to this list at least 30 days before it takes effect, by email and by updating this page.

How long we hold it

  • Active customer data — for the lifetime of your subscription
  • Tenancy agreements and maintenance evidence 7 years from end of tenancy, locked under S3 Object Lock to meet HA 2004 and HMRC requirements; this is required by statute and overrides erasure requests
  • Audit log entries — 7 years (same reason)
  • Account data — deleted within 30 days of subscription cancellation, except where required for outstanding invoicing
  • System logs — 30 days

Your rights

Under UK GDPR you have the right to:

  • Access the personal data we hold about you (Subject Access Request)
  • Have inaccurate data corrected
  • Request erasure (subject to the statutory retention exceptions above)
  • Object to processing on the basis of legitimate interests
  • Receive your data in a structured, machine-readable format (portability)
  • Lodge a complaint with the Information Commissioner's Office

Request any of the above by emailing legal@tekniti.ai. We respond within 30 calendar days, free of charge unless the request is excessive or repetitive.

Security

  • All traffic is TLS 1.2+; HSTS enabled. Connections to the database are TLS-only and never traverse the public internet
  • Database, S3 and Secrets Manager are all encrypted at rest with AWS-managed KMS keys
  • Authentication uses bcrypt-hashed passwords and short-lived JWTs. Magic-link sign-in is supported for invited users
  • Every compliance-relevant action is logged to a hash-chained audit trail; tampering breaks the chain and is detectable
  • Access to production systems is restricted to a small number of named engineers. AWS access is OIDC-federated through GitHub Actions for deploys; no long-lived AWS keys exist
  • We have not had a notifiable personal-data breach. We will report any future breach to affected customers and the ICO within 72 hours per UK GDPR Art 33

Data Protection Impact Assessment (DPIA)

Because Tekniti processes tenant personal data and uses AI on tenancy agreements (which can name a data subject), we maintain a DPIA covering:

  • The purpose, lawful basis and necessity of each processing activity
  • Risks to data-subject rights — particularly around AI inference, cross-border transfer, and statutory retention overriding erasure
  • Mitigations — see the Security section above
  • Residual risk assessment — currently rated low

Customers acting as data controllers (i.e. letting agents and landlords using Tekniti to manage tenant data) can request a copy of our DPIA to inform their own assessment. Email legal@tekniti.ai.

Changes to this notice

We update this page when our processing changes materially. We will email all account holders when we do. Historical versions are retained on request.