Privacy Policy
Who we are
Property Vault ("we", "us") provides a secure platform that gives residential properties a permanent, professionally verified history. This policy explains what personal information we collect, why, and the choices you have. It is written to be read — no legal maze. For anything unclear, email hello@propertyvault.ai.
What we collect, and why
Professional accounts. If your organisation uses Property Vault to create records, we hold your name, work email, job title and login credentials (passwords are stored only as secure hashes). We use these to operate your account and keep an audit trail of who sealed which documents — that trail is a core feature of the service.
Property records. Records contain information about properties and the work done to them: addresses, UPRNs, documents (certificates, drawings, reports), and the names, firms and registration details of contributing professionals. Documents are cryptographically fingerprinted when uploaded and held in secure UK cloud storage. They are never published; they are visible only to people who hold a valid access link.
Homeowner links. Homeowners access their record through a secure link with no account or password. When a record is opened we log the time, a coarse device type (phone / tablet / computer) and, at most, the country the visit came from. We do not store IP addresses, we do not use fingerprinting, and no third-party analytics or advertising scripts run anywhere on record pages. This first-party measurement exists to understand whether records are useful — opens, revisits, document views and shares.
Enquiries. If you book a demo or request an account, we receive the details you send (name, work email, company, message) and use them solely to respond.
Our lawful bases
- Contract — operating accounts and records for the organisations we serve.
- Legitimate interests — first-party usage measurement, service security, and maintaining the integrity audit trail that the product exists to provide.
- Consent — where you ask us to contact you (e.g. demo requests, newsletters).
Sharing
We do not sell personal information, ever. Records are shared only through the scoped links their owners create — a solicitor link, an agent link and so on — each of which controls exactly what is visible. Service infrastructure (UK-based hosting and storage) processes data on our behalf under contract.
Retention
Property records are designed to be permanent — that is the product. Access links expire (shared links after 90 days) and can be withdrawn. Usage logs are kept for the duration of the pilot plus 12 months, then aggregated or deleted. Account data is deleted when an organisation leaves the service, except the sealed-document audit trail, which persists as part of the records themselves.
Your rights
Under UK GDPR you can ask for access to, correction of, or deletion of your personal information, object to or restrict processing, and take your data elsewhere. Email hello@propertyvault.ai and we will respond within one month. You can also complain to the Information Commissioner's Office (ico.org.uk) — though we'd appreciate the chance to fix things first.
Security
Documents are sealed with SHA-256 fingerprints at upload and cannot be altered afterwards — corrections create new versions with a visible audit trail. Access tokens are cryptographically random, stored hashed, expiring and revocable. Data is hosted in the UK.