Skip to main content
Legal

UK GDPR and Data Rights

Version 1.0Draft prepared 13 July 2026 — not yet effective

Draft — legal review required — not yet effective. This document has been drafted to reflect ConditionVault's actual product, data processing, and technology stack. It is a draft and is not legally binding. It must be completed with verified company information, approved by the authorised business owner, reviewed by a qualified UK solicitor, and explicitly published before it becomes effective.

1. UK GDPR and Data Protection Act coverage

This page explains your rights under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. It complements our Privacy Policy by providing detailed information about your data-protection rights and how to exercise them.

2. ConditionVault's roles

ConditionVault acts as a data controller for account administration, authentication, billing, security, and lead enquiries. ConditionVault acts as a data processor for customer-directed processing of property, inspection, and tenant/landlord data. Where ConditionVault is the processor, the customer organisation is the controller and is primarily responsible for responding to data-subject requests from tenants, landlords, and other contacts.

3. Your rights

  • Right of access — You can request a copy of the personal data we hold about you.
  • Right to rectification — You can ask us to correct inaccurate or incomplete data.
  • Right to erasure — You can request deletion of your personal data (also known as the "right to be forgotten"). This right is not absolute.
  • Right to restriction — You can ask us to limit how we use your data in certain circumstances.
  • Right to object — You can object to processing based on legitimate interests or for direct marketing.
  • Right to data portability — You can receive your data in a structured, machine-readable format where processing is based on consent or contract and carried out by automated means.
  • Right to withdraw consent — Where processing is based on consent, you can withdraw it at any time.
  • Rights regarding automated decision-making — ConditionAI does not make solely automated decisions with legal or significant effects. AI output is always reviewed by a human user before inclusion in a report.

4. How to make a request

You can submit a request using the form at the bottom of this page, or by emailing us at [privacy contact to be confirmed]. Please include your name, email, the type of request, and a description of what you need.

5. Identity verification

We will verify your identity before disclosing personal data. If you are making a request on behalf of someone else, we will require evidence of your authority to act on their behalf.

6. Response time and deadlines

Data-subject rights requests. We will respond without undue delay and within one calendar month of receipt. In complex cases or where numerous requests are made, we may extend this period by up to two additional months where legally permitted. If we extend, we will notify you of the extension and the reasons within the original one-month period. We do not promise that every request will be fulfilled in full — some rights are not absolute and may not apply in certain circumstances (see below).

Internal service target. Our internal service target is to acknowledge requests within 72 hours. This is an internal target and is not a statutory deadline. The statutory deadline for substantive response is one calendar month.

Data-protection complaints. Complaints are handled as a separate workflow. We will acknowledge a complaint within 30 days (internal service target), investigate it appropriately, communicate the outcome, and inform you of your right to escalate to the ICO. The 30-day acknowledgement is an internal target, not a statutory deadline.

7. When a right may not apply

Some rights are not absolute. For example, we may need to retain data to comply with legal obligations, for the establishment or defence of legal claims, or to protect the rights of others. We will explain our reasons if we cannot fully action your request.

8. If ConditionVault is the processor

If your request relates to property, tenancy, or inspection data processed on behalf of a customer organisation, the customer is normally the controller. We will route your request to the relevant organisation and assist them in responding. We will not make an independent decision outside the customer's instructions unless required by law.

9. Complaints and ICO escalation

Data-protection complaints are treated as a separate workflow from rights requests. If you wish to make a complaint about how we handle personal data, you can submit it using the form below by selecting "Data protection complaint" as the request type. We will record the received date, acknowledge it within 30 days (internal service target), investigate it, communicate the outcome, and inform you of your right to escalate to the ICO.

If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk or by calling 0303 123 1113. We encourage you to contact us first so we can address your concerns.

10. Submit a request

We do not accept file attachments through this form. If you need to provide documents, we will contact you with a secure process.

Contact us

For questions about this document, please contact us at [privacy contact to be confirmed]