Privacy, security & AI
How we protect your data
The principles behind how Propvora keeps workspace data separate, controls access and handles security incidents.
- Updated
- Reading time
- 2 min read
On this page
Propvora holds information that matters to you and to the people you work with: tenancies, contacts, documents and money. This article explains the principles we follow to protect it. The governing detail is in our Security overview and Privacy Policy.
Who is responsible
Propvora is run by Blackwellen Limited, a company registered in England and Wales (company number 16482166) and registered with the Information Commissioner's Office (ICO) under registration number ZB905402.
For data that a business stores in its own workspace, such as tenant or contractor details, that business is usually the controller and we act as its processor under the Data Processing Agreement. For account, billing, website and partner data, we are the controller.
Workspaces are kept separate
Each organisation works in its own workspace, which is isolated from every other workspace. Requests are checked against your membership and role, so being signed in to Propvora does not give you access to anyone else's workspace.
Portal users, such as tenants or contractors, only see the portal they were invited to, and the property team controls what each portal shows. See Portal access and permissions.
The principles we follow
- Least privilege: people get the access they need for their role and no more, and that applies to our own staff too.
- Strong sign-in for platform administrators: Propvora administrator accounts must use multi-factor authentication with an authenticator app.
- Passwords handled securely: we never ask you to send your password by email, and password resets use a secure link.
- Careful choice of suppliers: we use established providers for hosting, storage, email, payments and AI, under written contracts, listed in our Subprocessor register.
- Incident response: if something goes wrong, we investigate, contain it and notify the people and regulators we are required to.
The Privacy Policy and Security overview describe the specific technical measures in place. We do not claim certifications we do not hold, and we will update those documents as our measures change.
What you can do
- Use a strong, unique password and keep it to yourself.
- Only tick Remember me on a device you trust. It remembers your email address on that device, not your password.
- Give team members and portal users only the access they need.
- Follow our Acceptable Use Policy, and store only the personal data you need.
Quick answers
Can other Propvora customers see my data?
No. Each workspace is isolated, and access is checked against your membership and role.
Is Propvora ISO 27001 or SOC 2 certified?
We do not claim those certifications. Our Security overview at /legal/security describes the measures we use.