Key points
- Blackwellen Limited runs Propvora. We are the controller for account, billing, website, marketing, security and partner data, and we are registered with the ICO (ZB905402).
- Information that property businesses put into their workspaces (for example about tenants, landlords and contractors) belongs to them. We process it only on their instructions, so if you are a tenant or contractor, contact your managing agent or landlord first.
- We do not sell your personal data, and we do not use cookies for advertising or analytics.
- AI features send only the content needed to answer a request to our AI providers. A person stays in control, and we make no automated decisions about you that have legal or similarly significant effects.
- Product data is kept in the UK or EEA by default where our providers offer it. Any transfer outside the UK is protected by a recognised safeguard.
- You can access, correct, delete, restrict, object to and port your data. We usually reply within one month. Please complain to us first; you can also go to the ICO.
This summary is for convenience only. The full text below is what governs.
1.Who we are
Propvora is a property operations platform provided by Blackwellen Limited ("Blackwellen", "we", "us" or "our"), a private company limited by shares registered in England and Wales under company number 16482166. Our registered office is 61 Bridge Street, Kington, Herefordshire, HR5 3DJ, United Kingdom.
We are registered with the Information Commissioner's Office (ICO) as a data controller under registration number ZB905402. We have not appointed a statutory data protection officer under Article 37 of the UK GDPR, as we are not required to. Our data protection lead is responsible for privacy matters and can be contacted at info@blackwellen.com or by post at our registered office, marked "For the attention of the Data Protection Lead".
This policy is our privacy information under Articles 13 and 14 of the UK GDPR. Read it with our Cookie Policy, our Data Processing Agreement, our Subprocessor register, our AI Disclaimer and our Security overview.
2.Definitions
In this policy the following words have these meanings:
- Account Data means information about a person who registers for, or is invited to, Propvora, such as name, email address, password credentials (held only in hashed form by our authentication provider), role, workspace membership and settings.
- Customer means the business or individual that subscribes to Propvora and controls a Workspace, for example a letting agent, property manager, landlord, HMO operator or block management company.
- Authorised User means an individual a Customer permits to use the Service under its account.
- Customer Data means all data, content and files (including personal data) that a Customer, its Authorised Users or its Portal Users upload to, create in or transmit through the Service.
- Customer Personal Data means personal data within Customer Data, such as details of tenants, applicants, guarantors, landlords, leaseholders, owners, contractors and the Customer's own staff.
- Data Protection Law means the UK GDPR, the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations 2003 (PECR), each as amended (including by the Data (Use and Access) Act 2025), and any other law relating to personal data that applies to us.
- Portal means one of the external portals (tenant, landlord, owner or investor, applicant, guarantor, contractor and leaseholder) through which a Customer gives limited access to people it deals with, and Portal User means a third party a Customer invites to a Portal.
- Service means the Propvora website at https://propvora.com, the Propvora application, its Portals, the Propvora Agent, the partner programme and related support.
- Workspace means a logically separated area of the Service in which a Customer's Customer Data is held (including supplier workspaces and customer homes).
Words such as controller, processor, personal data, processing and special category data have the meanings given to them in Data Protection Law.
3.Scope of this policy
This policy covers personal data that Blackwellen processes in connection with Propvora: when you visit https://propvora.com, make an enquiry or ask for a demo, open or use an account, are invited into a Workspace or Portal, apply to or take part in the partner programme, or supply goods or services to us.
It does not cover the corporate website at https://blackwellen.com except where that site links to Propvora. It also does not cover how a Customer uses Propvora for its own purposes. Each Customer decides why and how it processes Customer Personal Data, and is responsible for giving its own privacy information to its tenants, landlords, contractors and other contacts (see section 4).
Third-party websites and services linked from the Service, such as Stripe-hosted payment pages, have their own privacy notices.
4.Our role: controller or processor
Data Protection Law gives different responsibilities to a controller (who decides the purposes and means of processing) and a processor (who processes on a controller's behalf). Our role depends on the data.
Where we are the controller
Blackwellen is the controller for: Account Data; billing and subscription records; website and enquiry data; marketing preferences; support and complaints correspondence; security, audit and service logs that we use to run and protect the Service; partner and affiliate programme data; supplier data; and any job applicant data. This policy explains how we handle that data.
Where we are a processor
For Customer Personal Data, the Customer is the controller and Blackwellen is its processor. We process that data only on the Customer's documented instructions, under our Data Processing Agreement, which forms part of our Terms of Service. We do not use Customer Personal Data for our own marketing, we do not sell it, and we do not combine it across Workspaces.
Where we act independently for limited purposes
For a few purposes needed to run a lawful, secure service we act as a controller even for Customer Data: preventing fraud, abuse and security incidents; keeping service and audit logs; meeting our own legal obligations; and producing aggregated, de-identified statistics. Section 7 sets out the lawful bases.
5.The personal data we collect
We collect only what we need for the purposes in section 7. The data we hold depends on how you interact with us.
Website visitors
When you browse https://propvora.com, our hosting and security providers process technical data needed to deliver pages and protect the site: IP address, browser and device type, the pages requested, referring URL, the date and time, and security signals (for example whether a request looks automated). We do not use analytics or advertising cookies. The small number of cookies and browser storage items we use are listed in our Cookie Policy.
Enquiries, demo requests and contact forms
Your name, work email address, phone number (if given), company name and website, role, portfolio size, the topic of your enquiry and the content of your message, together with our replies.
Account holders and workspace members
Name, email address, credentials (passwords are hashed and we cannot read them), role, Workspace memberships, profile picture, preferences, onboarding answers (such as portfolio size, regions and modules), consents given, and activity records such as sign-ins and audit-trail entries. For account owners we also hold plan, billing contact and address, VAT details where relevant, and invoice and payment history. Card details are held by Stripe; we see only the card brand, last four digits and expiry date.
Portal Users
If a Customer invites you to a Portal, we process your name, contact details, the role the Customer has given you, and the information you view, submit or upload in the Portal (for example a repair request, a document or a message). That information is Customer Personal Data and the Customer is the controller (see section 4). Your sign-in details and security logs are Account Data, which we control.
People whose details are stored in a Workspace
Customers may store information about tenants, applicants, guarantors, occupiers, landlords, owners, leaseholders, contractors and their own staff: for example names, contact details, addresses, tenancy dates, rent and payment history, deposit information, references, identity and right-to-rent checks, maintenance requests, access arrangements, photographs, inspection notes, correspondence and compliance certificates. We process it as a processor only.
Partners and affiliates
Name, email address, company and website, the audiences and channels you intend to use, your application answers, referral links and codes, referral and conversion records, commission calculations, payout details and tax information (collected through Stripe Connect, which carries out its own identity checks), and our correspondence with you.
Suppliers and service providers to us
Contact names, business contact details, contract and invoice records and payment details.
Job applicants
We do not currently run open recruitment through the Service. If we do, we will give applicants specific privacy information at the time, and we will process CVs, application answers, interview notes and right-to-work information only for recruitment and to meet legal requirements.
Communications and support
Your messages to us, our replies, any attachments you send and, for problem reports, technical details of the error.
6.Where we get personal data from
- From you directly, when you fill in a form, register, complete onboarding, use the Service, contact us or apply to the partner programme.
- From a Customer or a colleague, when a Customer invites you to a Workspace or Portal or stores your details in its Workspace. In that case the Customer is responsible for telling you about it and for having a lawful basis.
- From our service providers, such as Stripe (payment status, fraud signals and, for partners and suppliers, the outcome of identity and business verification, not the identity documents themselves), our authentication provider (sign-in events) and our security and error-monitoring providers (technical logs).
- From partners and referrers, if you sign up through a partner's referral link. We record the referral so that commission can be calculated. We do not receive any other data about you from the partner.
- From publicly available sources, such as a business website or professional profile, when we research a business that has asked us for a demo.
Where we obtain personal data other than from you, this policy is our privacy information under Article 14 of the UK GDPR. We give it to you within a reasonable period, and in any event within one month, or when we first contact you if earlier.
7.Why we use personal data and our lawful bases
We must have a lawful basis under Article 6 of the UK GDPR for each purpose. The list below sets out each purpose, the data used and the basis relied on.
- Providing the Service and your account (accounts, Workspaces, sign-in, roles, settings, onboarding). Basis: contract (Article 6(1)(b)); for invited users who are not party to our contract, legitimate interests (Article 6(1)(f)) in providing the service the Customer has paid for.
- Processing Customer Personal Data (storage, search, documents, communications, automations and AI within a Workspace). Basis: determined by the Customer as controller; we act as processor under the Data Processing Agreement.
- Billing and subscriptions (payments, invoices, trials, renewal reminders, cancellations and refunds). Basis: contract, and legal obligation (Article 6(1)(c)) for consumer subscription information duties.
- Accounting and tax records. Basis: legal obligation under company and tax law.
- Service messages (security alerts, password resets, invitations, notifications and changes to our terms). Basis: contract and legitimate interests.
- Support, complaints and data rights requests. Basis: contract, legitimate interests, and legal obligation where the law requires us to handle the request.
- Security, fraud prevention and enforcing our [Acceptable Use Policy](/legal/acceptable-use) (monitoring, rate-limiting, audit logs, incident investigation). Basis: legitimate interests, and legal obligation under Article 32 of the UK GDPR.
- Error monitoring and service improvement, using technical data and aggregated, de-identified statistics. Basis: legitimate interests.
- Propvora Agent (see section 10). Basis: the Customer's instructions for Customer Data; contract for Account Data.
- Enquiries and demos. Basis: legitimate interests, and steps taken at your request before a contract.
- Marketing to business contacts (see section 19). Basis: legitimate interests, subject to PECR; consent (Article 6(1)(a)) where PECR requires it.
- Partner programme (applications, referral tracking, commission, payouts, preventing self-referrals and checking advertising disclosures under the Partner Terms). Basis: contract, legitimate interests in preventing fraud, and legal obligation for tax records.
- Supplier identity and business verification through Stripe when a supplier completes payout setup. Basis: contract, legitimate interests in preventing fraud and legal obligation.
- Legal claims and lawful requests from courts, regulators and law enforcement. Basis: legal obligation, legitimate interests or a recognised legitimate interest (see section 8).
- Business reorganisation or sale, sharing information with a prospective buyer under confidentiality. Basis: legitimate interests.
Where we rely on consent, you can withdraw it at any time without affecting earlier processing. If you do not provide information we need under a contract or by law (such as a valid email address), we cannot provide the relevant Service; our forms show which fields are required.
8.Legitimate interests and recognised legitimate interests
Where we rely on legitimate interests, we have carried out a balancing test. We identified the interest, checked that the processing is necessary for it, and weighed it against your interests, rights and reasonable expectations. In summary:
- Running and securing the Service. Users of business software reasonably expect sign-ins and actions to be logged for security and audit. Logs are access-restricted, kept for limited periods (see section 13) and never used for advertising.
- Improving the Service. We use technical data and aggregated, de-identified statistics, not individual profiles.
- Business-to-business marketing. Direct marketing is recognised in Data Protection Law as capable of being a legitimate interest. We contact only relevant business contacts, every message has an opt-out, and your objection is absolute (see section 15).
- Enquiries, fraud prevention and partner integrity. You expect a reply when you contact us, and preventing self-referrals and fraudulent payouts protects Customers, honest partners and us.
Recognised legitimate interests
The Data (Use and Access) Act 2025 introduced a short list of recognised legitimate interests that do not need a separate balancing test. We rely on one only where it genuinely applies, chiefly:
- disclosing information to a public authority that tells us it needs the information to carry out a public task;
- detecting, investigating or preventing crime, or apprehending or prosecuting offenders;
- safeguarding a child or an adult at risk; and
- responding to an emergency.
Even in these cases we disclose only what is necessary and proportionate, we record what we disclosed and why, and, where Customer Personal Data is involved, we tell the Customer unless the law prevents us from doing so.
You can ask us for more detail about any balancing test by writing to info@blackwellen.com.
9.Special category and criminal offence data
Blackwellen does not ask for special category data (such as health, ethnicity, religion or sexual orientation) or criminal offence data for its own purposes, and we ask you not to include it in enquiries or support messages.
Customers may, however, record such information in a Workspace. Examples include notes on a tenant's vulnerability or health needs (for example to prioritise a repair or make a reasonable adjustment), information relevant to safeguarding, disability adaptations, or the outcome of a criminal record or identity check for a contractor. When this happens:
- the Customer is the controller and must identify both an Article 6 lawful basis and an Article 9 condition (or, for criminal offence data, an Article 10 condition under Schedule 1 to the Data Protection Act 2018), and must hold any appropriate policy document that law requires;
- the Customer must limit what is recorded to what is necessary, use the access controls in the Service so that only authorised staff can see it, and tell the individuals concerned;
- we process it only as the Customer's processor, under the Data Processing Agreement, with the same security measures as all Customer Data; and
- Customers should think carefully before submitting such data to the Propvora Agent, since using it is optional (see section 10).
10.AI features and automated decision-making
Propvora includes an AI assistant, the Propvora Agent, currently offered as a Beta, which can draft messages, summarise records, suggest next steps and answer questions about information in your Workspace. Our AI Disclaimer explains its limits.
What is sent to AI providers
When you use an AI feature, we send the AI provider your instruction and the parts of your Workspace that are needed to answer it (for example the text of a work order, a tenancy summary or a document you have selected), together with system instructions that we write. We do not send whole Workspaces, passwords, or payment card details. The providers we use are OpenAI, Microsoft (Azure OpenAI Service) and NVIDIA, as listed in our Subprocessor register.
No training of general AI models on Customer Data
We use AI providers through business APIs, with the provider acting as our subprocessor. We do not permit our AI subprocessors to use Customer Data to train their general models, and we have opted out of such use wherever a provider's terms offer it; under the API terms we currently use, such data is not used for training by default. Providers may keep inputs and outputs for up to 30 days to detect abuse, unless the law requires longer. We do not use Customer Data to train generally available AI models.
Human review and automated decision-making
AI output is a suggestion. The Agent is designed so that its drafts are not sent, saved as final records or used to trigger actions until a person has reviewed them. AI output can be wrong, and the Customer remains responsible for decisions such as arrears steps, possession action, compliance sign-off or tenant selection.
We make no decision about you based solely on automated processing (including profiling) that produces legal or similarly significant effects, within Articles 22A to 22D of the UK GDPR. Automations a Customer sets up (such as a certificate-expiry reminder) apply the Customer's own rules, and the Customer must ensure meaningful human involvement in any significant decision about an individual.
Using the Agent is optional. If you are a tenant or other individual and do not want your information processed with AI, please tell the Customer that holds your data.
12.International transfers
Our aim is to keep product data in the UK or the European Economic Area (EEA) by default, where our providers offer it. The Subprocessor register shows the processing region for each provider, and where a region is not yet confirmed it says so.
Several providers are US-headquartered, and their teams may access data from outside the UK. For any transfer outside the UK, one of these safeguards applies:
- the destination is covered by UK adequacy regulations, which include the EEA countries and Switzerland;
- for the United States, the recipient is certified under the UK Extension to the EU–US Data Privacy Framework (the "UK–US Data Bridge"), which we check before relying on it; or
- the transfer is covered by the International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses issued by the ICO, together with a transfer risk assessment and, where appropriate, extra technical measures such as encryption in transit and at rest.
You can ask for more information about the safeguard for a particular transfer, or a copy of the relevant clauses (with commercial terms removed), by writing to info@blackwellen.com.
13.How long we keep personal data
We keep personal data only as long as needed for the purposes in section 7, legal requirements and limitation periods, then delete or anonymise it:
- Account Data: while the account is open, then [Blackwellen to confirm: 12 months] after closure (to deal with questions or restore an account closed by mistake).
- Customer Data (including Customer Personal Data): for the term of the Customer's subscription. After the subscription ends, the Customer has a 30-day Exit Period to export it (see the Terms); we then delete it from live systems within Blackwellen to confirm: 30 days] after the Exit Period ends, as set out in the [Data Processing Agreement. The Customer can delete individual records at any time.
- Backups: encrypted backups containing deleted data are overwritten within [Blackwellen to confirm: 35 days] after deletion from live systems.
- Billing, invoices and accounting records: 6 years from the end of the financial year to which they relate, to meet tax and company law requirements.
- Partner programme records: for the duration of the partnership, then commission and payout records for 6 years from the end of the financial year of the last payment; application data for unsuccessful applicants for [Blackwellen to confirm: 12 months].
- Enquiries and demo requests that do not lead to a subscription: [Blackwellen to confirm: 24 months] after our last contact.
- Marketing preferences: until you unsubscribe. We then keep your email address on a suppression list for as long as we send marketing, so that we do not contact you again.
- Support correspondence: for [Blackwellen to confirm: 3 years] after the issue is closed.
- Complaints and data rights requests: 3 years after the matter is closed, or longer if a claim is brought.
- Security and audit logs: [Blackwellen to confirm: 12 months], unless needed for an ongoing investigation. Workspace audit-trail entries are Customer Data and follow the Customer Data period above.
- Error-monitoring events: [Blackwellen to confirm: 90 days].
- Email delivery logs: [Blackwellen to confirm: 30 days].
- AI requests: AI prompts and responses that you save become part of Customer Data. Our AI providers may retain inputs and outputs for up to 30 days for abuse monitoring (see section 10).
- Records needed for legal claims: up to 6 years after the relevant event, in line with the Limitation Act 1980, or longer where a claim is ongoing.
- Browser storage on your device: see the Cookie Policy.
Where we anonymise data so that it can no longer identify anyone, we may keep it indefinitely for statistics.
14.How we protect personal data
We use technical and organisational measures appropriate to the risk, as required by Article 32 of the UK GDPR. These include:
- encryption in transit (TLS 1.2 or higher) and at rest (AES-256) through our hosting and storage providers;
- row-level security in our database, isolating each Workspace and checking every request against the user's membership and role;
- hashed passwords and short-lived session tokens through our authentication provider, with role-based permissions and limited Portal access;
- least-privilege staff access to production data;
- web application firewall, DDoS protection and rate-limiting;
- due diligence on, and written contracts with, every subprocessor; and
- an incident response process.
No system is completely secure. If a personal data breach affects data we control, we will notify the ICO within 72 hours where required, and tell you without undue delay if it is likely to result in a high risk to you. Breaches affecting Customer Personal Data are handled under the Data Processing Agreement. See also our Security overview. Please tell us at once at info@blackwellen.com if you think your account has been compromised.
15.Your rights
Under Data Protection Law you have the following rights, subject to some conditions and exemptions:
- To be informed about how your data is used, which this policy does.
- Access: a copy of your personal data and information about our use of it, found by a reasonable and proportionate search.
- Rectification: correction of inaccurate or incomplete data. You can update most account details in your settings.
- Erasure: deletion where, for example, the data is no longer needed or you withdraw consent, unless we must keep it (for example invoices required by tax law).
- Restriction: limiting our use of your data while accuracy or an objection is resolved, or where you need it kept for a legal claim.
- Portability: data you gave us, processed by consent or contract by automated means, in a machine-readable format, or sent to another controller where feasible.
- Objection: to processing based on legitimate interests (including recognised legitimate interests), on grounds relating to your situation. We will stop unless we have compelling overriding grounds or need the data for a legal claim. You can object to direct marketing at any time, and we will always stop.
- Automated decisions: we make none with legal or similarly significant effects (see section 10). If that changes, you will be able to make representations, obtain human intervention and contest the decision.
- Withdrawing consent at any time, where we rely on consent.
Where we process your data as a processor for a Customer, these rights are exercised against the Customer. We will help the Customer respond (see section 4).
16.How to exercise your rights
Email info@blackwellen.com with the subject line "Data protection request", or write to the Data Protection Lead at our registered office. You do not need to use a particular form or wording, and you can make a request verbally, although putting it in writing helps us to deal with it accurately.
- Identity. We may ask for reasonable information to confirm your identity, or the authority of anyone acting for you.
- Time limit. We respond without undue delay and within one month of receiving the request (or, if later, the information we need to confirm identity).
- Clarification. If we reasonably need you to clarify your request, the time limit pauses until you reply.
- Extensions. For complex or numerous requests we may extend by up to two further months, telling you why within the first month.
- Fees. Requests are free. We may charge a reasonable fee or refuse only where a request is manifestly unfounded or excessive, and will explain why.
- Refusals. If we refuse, we will explain why and tell you about your right to complain to us and the ICO and to go to court.
17.Complaints
If you are unhappy with how we have handled your personal data, please complain to us first at info@blackwellen.com or by post to our registered office. We will acknowledge your complaint within 30 days, investigate it without undue delay, and tell you the outcome. Our general Complaints Policy also applies.
You also have the right to complain to the Information Commissioner's Office, the UK supervisory authority for data protection, at ico.org.uk, by telephone on 0303 123 1113, or by post to Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF. The ICO will usually expect you to have raised the matter with us first. Making a complaint does not affect your right to go to court.
18.Children
Propvora is a business tool and is not directed at people under 18. We do not knowingly allow anyone under 18 to create an account, and we do not knowingly collect their personal data for our own purposes. If you believe a child has given us personal data, please contact us and we will delete it.
Customers may record information about children within a Workspace (for example household members named in a tenancy or a children's safeguarding note). That information is Customer Personal Data, and the Customer is responsible for having a lawful basis and for taking extra care with it.
19.Marketing preferences
We send marketing emails about Propvora, such as product updates, guides and offers, only in line with PECR:
- to corporate subscribers (for example an email address at a limited company), on the basis of our legitimate interests, with an opt-out in every message;
- to individual subscribers (including sole traders and partnerships) only if you have consented, or if you are an existing customer or gave us your details while enquiring about our services and did not opt out when we collected them (the "soft opt-in"); and
- never to Portal Users or people whose details are held in a Customer's Workspace, because we hold that data as a processor.
You can opt out at any time using the unsubscribe link, your notification settings or by emailing us. Opting out does not stop essential service messages such as security alerts, invoices and notices of changes to our terms. We do not use advertising cookies or third-party ad networks. Partners promoting Propvora must follow PECR, the CAP Code and the CMA's guidance on hidden advertising (see the Partner Terms).
20.Changes to this policy
We update this policy when our processing or the law changes; the version and effective date above show the latest change. Before a material change takes effect (such as a new purpose or a new category of recipient), we will tell account holders by email or in the application and, where Data Protection Law requires, ask for consent.
Changes to the list of subprocessors are announced through the Subprocessor register and the notice process in the Data Processing Agreement.
21.Contact us
Data protection lead, Blackwellen Limited, 61 Bridge Street, Kington, Herefordshire, HR5 3DJ, United Kingdom. Email: info@blackwellen.com. Company number 16482166. ICO registration ZB905402.