Draft — pending legal review. This page has not yet been reviewed by a solicitor and should not be relied on as final.

Privacy Policy

Draft — last updated 7 September 2026

1. Who we are

DomusAI ("we", "us") provides a property management platform for UK letting agencies and landlords. [Registered company name, company number, and registered address to be added here.] This policy explains what personal data we process, why, and who we share it with.

2. Who this applies to

We process data about several categories of people: organisation admins and staff (letting agencies and portfolio landlords using DomusAI), landlords, tenants, contractors, and — for anti-money-laundering purposes — the directors and beneficial owners of organisations that sign up.

3. Identity verification (KYC/AML)

Before an organisation can transact on DomusAI, we verify the identity of its directors and beneficial owners through our verification provider, Veriff, as part of our anti-money-laundering obligations. This involves submitting identity documents and biometric checks directly to Veriff via a hosted verification link; we receive and store the verification outcome (approved, declined, or under review), not the underlying documents themselves.

4. Right to Rent checks

UK law requires landlords to check a tenant's right to rent in England. Where this check is done digitally through DomusAI, it is performed by Veriff's Right to Rent verification service embedded in the tenant portal. We store the outcome of the check and the date it was carried out and is next due for follow-up, not the underlying identity documents.

5. Payments and banking data

We use GoCardless to collect rent by Direct Debit and to bill organisations their DomusAI subscription; this involves sharing bank account details (sort code and account number) directly with GoCardless to set up a Direct Debit mandate — DomusAI does not store full bank account details itself. We use Stripe to pay contractors for completed maintenance work and to store landlords' card details for contractor payments; Stripe collects and stores this payment data directly. Where an organisation connects its own bank account for management-fee reconciliation, we use TrueLayer's open banking service to read transaction data (read-only access, re-authorised periodically) — DomusAI does not hold client funds at any point in this process.

6. Contractors and cross-organisation data

Contractors are not tied to a single organisation on DomusAI. A contractor's profile — company details, trade, qualifications, insurance status, rating, and job history — can be visible to and used by any organisation on the platform that assigns work to them, not only the organisation that first added them. This lets contractors work across multiple letting agencies and landlords through a single DomusAI profile rather than maintaining separate records with each.

7. Documents

Tenancy agreements, compliance certificates, mortgage statements, and other property documents you upload are processed to extract relevant data (using AI-based document extraction) and stored in Google Drive under our account. Signed agreements (tenancy renewals, management agreements) are processed through DocuSeal for e-signature.

8. Messaging (WhatsApp, SMS, and phone verification)

A significant part of DomusAI's service runs over WhatsApp and SMS rather than email — for example, confirming a payment claim, dispatching a maintenance job to a contractor, asking a landlord to approve a contractor or confirm a deposit has been protected, reminding a tenant about a rent payment, and sending one-time verification codes to organisation staff who choose to verify a phone number for WhatsApp-based actions.

These messages are sent using Twilio's WhatsApp Business API integration, which in turn relies on WhatsApp's underlying infrastructure, operated by Meta, to deliver them. Sending a message this way means the recipient's phone number and the content of the message pass through both Twilio and Meta as part of delivery. Media sent to us over WhatsApp — for example, a photo of a maintenance issue — is downloaded and stored as part of the relevant job or claim record, in the same way as a photo uploaded through the app directly.

One-time verification codes are generated and checked server-side; the plaintext code itself is never stored, only a hashed version used to confirm a match, and it expires shortly after being sent. [Confirm with your solicitor whether any additional consent or opt-in language is needed for specific message types under UK PECR, beyond the transactional service messages described here.]

9. Where your data is stored and processed

Our core database and authentication are hosted with Supabase. Automated workflows (reminders, document processing, payment orchestration, and the messaging described above) run through n8n. We rely on these and the providers named above as data processors acting on our instructions.

10. Cookies

DomusAI's website and app use only the cookies needed to keep you signed in and protect your account, managed by our authentication provider, Supabase. We do not currently use analytics, advertising, or tracking cookies. If that changes, we'll update this section and, where required, ask for your consent first.

11. International transfers

Some of the providers named in this policy are based outside the UK, or may store data outside the UK — most notably Twilio (United States). Where we transfer personal data outside the UK, we do so on the basis of an approved transfer mechanism, such as the UK International Data Transfer Addendum or equivalent Standard Contractual Clauses with that provider. [Confirm which safeguard is actually in place with each non-UK/EU provider before relying on this section — it should reflect your real contractual position with Twilio and any other non-UK/EU processor, not a generic statement.]

12. Data retention

We keep personal data for as long as it's needed for the purpose it was collected, and no longer. As a starting point to be confirmed with a solicitor: tenancy and compliance records — retained for the applicable statutory limitation period after a tenancy ends [period to be confirmed]; KYC/AML verification records — retained per applicable Money Laundering Regulations requirements [period to be confirmed]; account and profile data, including verified phone numbers — retained while your account is active and for a defined period after closure [period to be confirmed]. [This section still needs a solicitor-confirmed retention schedule for each data category before publishing.]

13. Your rights

Under UK GDPR, you have the right to access, correct, delete, or export your personal data, and to object to or restrict certain processing. To exercise any of these rights, contact us using the details below. You also have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk if you believe we haven't handled your data properly.

14. Contact

Questions about this policy or how we handle your data: support@domusai.co.uk.

15. Changes to this policy

We may update this policy as the product changes. Material changes will be flagged on this page.