> ## Documentation Index
> Fetch the complete documentation index at: https://help.propops.app/llms.txt
> Use this file to discover all available pages before exploring further.

# Privacy Policy

> How PropOps collects, uses, stores, and protects your personal data — including cookies, third-party sharing, retention periods, and your rights.

<Info>
  **Effective date:** 5 April 2026\
  **Last updated:** 5 April 2026
</Info>

## 1. Introduction

PropOps Technologies Ltd ("PropOps", "we", "us", "our") develops two separate products:

* **PropOps Web** — a self-hosted property-operations platform for small and medium-sized businesses (SMBs), distributed as a Docker image.
* **PropOps iOS** — a native iOS application for solo contractors, distributed via the Apple App Store.

These are independent products with different technology stacks, target audiences, and data architectures. This Privacy Policy explains how each product collects, uses, and safeguards your information.

By accessing or using either product you agree to the collection and use of information in accordance with this policy.

***

***

## Part A — PropOps Web

<Note>
  PropOps Web is deployed on infrastructure provided and controlled by you (the operator). PropOps Technologies Ltd has no access to, backdoors into, or monitoring of your PropOps Web instance. The only outbound communication is a periodic licence validation check.
</Note>

## 2. Information We Collect (PropOps Web)

### 2.1 Information You Provide

* **Account data** — name, email address, phone number, job title, and organisation details provided during registration or onboarding.
* **Job & property data** — addresses, case notes, photos, documents, and any other content you upload or create within the Service.
* **Payment data** — invoice and billing details processed through our payment providers. We do not store full card numbers.
* **Communications** — emails, case notes, WhatsApp messages, and feedback submitted through the Service.

### 2.2 Information Collected Automatically

* **Usage data** — pages visited, features used, timestamps, and interaction patterns.
* **Device data** — browser type, operating system, screen resolution, and IP address.
* **Cookies & local storage** — session tokens, preference flags, and analytics identifiers (see our [Cookie Policy](/legal/cookie-policy)).

### 2.3 Information from Third Parties

* **Weather & mapping services** — location-based data used to display weather and maps within the Service.

***

## 3. How We Use Your Information (PropOps Web)

We use collected information to:

* Provide, maintain, and improve the Service.
* Authenticate users and manage sessions.
* Process jobs, assignments, and contractor workflows.
* Send transactional notifications (email, push, WhatsApp).
* Generate analytics, reports, and operational insights.
* Detect and prevent fraud, abuse, and security incidents.
* Comply with legal obligations.

***

## 4. Legal Basis for Processing (UK GDPR)

| Basis                   | Examples                                                   |
| ----------------------- | ---------------------------------------------------------- |
| **Contract**            | Account management, job processing, contractor assignments |
| **Legitimate interest** | Analytics, security monitoring, product improvement        |
| **Legal obligation**    | Tax records, regulatory compliance, breach notification    |
| **Consent**             | Marketing communications, optional analytics cookies       |

***

## 5. Data Sharing & Disclosure (PropOps Web)

We do **not** sell your personal data. We may share data with:

* **Your infrastructure** — PropOps Web runs entirely on your own server or VPS. All data remains within your environment. PropOps Technologies Ltd does not host, access, or monitor your instance.
* **Your organisation** — other users within your tenant/agent organisation as required by the platform's role-based access controls.
* **Third-party integrations** — if you configure integrations (email delivery, push notifications, WhatsApp), data may be shared with those providers under your control.
* **Licence validation** — a periodic check transmits your licence key, domain, and instance identifier to PropOps Technologies Ltd. No personal data is transmitted during this check.
* **Legal authorities** — when required by law, court order, or to protect rights and safety.

As a self-hosted product, you (the operator) are the data controller. PropOps Technologies Ltd does not process your instance data.

***

## 6. Data Retention (PropOps Web)

| Data Category         | Retention Period                                                                |
| --------------------- | ------------------------------------------------------------------------------- |
| Active account data   | Duration of account plus 84 months                                              |
| Activity & audit logs | 84 months (encrypted at rest)                                                   |
| Email logs            | 84 months (encrypted at rest)                                                   |
| Archived jobs         | 84 months after archival                                                        |
| Deleted jobs          | 30 days (soft delete), then permanent removal                                   |
| Session data          | Cleared on logout or after idle timeout                                         |
| Backups               | Managed by you — the operator is responsible for backup schedules and retention |

***

## 7. Data Security (PropOps Web)

We employ industry-standard measures including:

* **Encryption at rest** — PII fields encrypted with modern authenticated encryption.
* **Encryption in transit** — TLS 1.2+ for all connections.
* **Access controls** — role-based permissions with 402 API permission keys, 103 page permission keys, and 45 document permission keys.
* **Session security** — IP and user-agent binding, session blacklisting, forced logout.
* **File integrity monitoring** — continuous hash-based integrity checks.
* **Password breach scanning** — automated checks against known breach databases.

***

## 8. Your Rights (PropOps Web)

Under the UK GDPR and Data Protection Act 2018 you have the right to:

* **Access** your personal data.
* **Rectify** inaccurate data.
* **Erase** data ("right to be forgotten").
* **Restrict** processing.
* **Data portability** — receive data in a machine-readable format.
* **Object** to processing based on legitimate interest.
* **Withdraw consent** at any time for consent-based processing.

PropOps Web includes built-in tools to help the operating organisation fulfil these rights (data export, account deletion, record correction).

<Warning>
  PropOps Technologies Ltd **does not hold, store, or have access to** any personal data within your PropOps Web instance — including data relating to users, tenants, landlords, letting agents, and contractors.

  To exercise any data subject right, contact the **company or organisation operating the PropOps Web instance** that holds your data. PropOps Technologies Ltd cannot retrieve, modify, export, or delete data from any customer instance.
</Warning>

***

## 9. International Transfers (PropOps Web)

PropOps Web is self-hosted — your data resides wherever you deploy your instance. If you deploy outside the United Kingdom, it is your responsibility to ensure appropriate safeguards are in place for any international data transfers. PropOps Technologies Ltd does not transfer or access your instance data.

***

***

## Part B — PropOps iOS

<Note>
  PropOps iOS is a native iOS application for solo contractors. All user data is stored exclusively in **Apple CloudKit** and **iCloud**, secured by Apple's infrastructure. PropOps Technologies Ltd does not operate servers, databases, or backend systems for PropOps iOS.
</Note>

## 10. Information We Collect (PropOps iOS)

### 10.1 Information You Provide

* **Job data** — job details, notes, photos, and documents you create within the app.
* **Business data** — your business name, contact details, and any client information you choose to record.

### 10.2 Information Collected Automatically

* **Device identifiers** — only as required by Apple for App Store functionality and push notifications.
* **Crash data** — anonymised crash reports via Apple's standard crash reporting, if you opt in through iOS settings.

### 10.3 Information We Do Not Collect

PropOps Technologies Ltd does **not** collect, receive, store, or have access to:

* Your personal data, job data, photos, documents, or any content created within PropOps iOS.
* Your Apple ID, iCloud credentials, or CloudKit data.
* Analytics, usage patterns, or behavioural data from the app.
* Location data, contacts, or any other device data.

***

## 11. Data Storage & Security (PropOps iOS)

All data created within PropOps iOS is stored in your personal **Apple CloudKit** container, secured by Apple's infrastructure:

* **Encryption at rest** — data is encrypted by Apple on their servers.
* **Encryption in transit** — all CloudKit communication uses TLS.
* **Access control** — only your Apple ID can access your data. PropOps Technologies Ltd has no access to your CloudKit container.
* **Sync** — data syncs across your Apple devices via iCloud, managed entirely by Apple.
* **Backups** — data is backed up as part of your iCloud backup, managed by Apple.

For full details of Apple's security practices, see [Apple Platform Security](https://support.apple.com/en-gb/guide/security/welcome/web).

***

## 12. Payment (PropOps iOS)

* Subscriptions and purchases are processed entirely by **Apple** via the App Store and **StoreKit**.
* PropOps Technologies Ltd does not receive, process, or store any payment card details, Apple ID credentials, or billing information.
* Subscription management, cancellations, and refunds are handled through your Apple ID settings.

***

## 13. Your Rights (PropOps iOS)

Since PropOps Technologies Ltd does not hold any of your personal data from PropOps iOS:

* **Data access, correction, deletion** — your data is stored in your iCloud account. You can view, edit, or delete it directly within the app or via iCloud settings.
* **Data portability** — you can export data from within the app.
* **Account deletion** — deleting the app and clearing iCloud data removes all PropOps iOS data. No data is retained by PropOps Technologies Ltd.

<Warning>
  PropOps Technologies Ltd **does not hold, store, or have access to** any data from PropOps iOS. All data resides in your personal Apple iCloud / CloudKit account. To manage or delete your data, use the app or your Apple iCloud settings.
</Warning>

***

## Part C — General

## 14. Children's Privacy

Neither product is directed at individuals under 18. We do not knowingly collect data from children.

***

## 15. Changes to This Policy

We may update this policy from time to time. Material changes will be communicated via in-app notice or email. The "Last updated" date at the top indicates the latest revision.

***

## 16. Contact Us

For privacy-related enquiries:

<Card>
  **PropOps Technologies Ltd**\
  Email: [privacy@propops.app](mailto:privacy@propops.app)
</Card>
