Privacy Policy

Letalife - Privacy Notice

Last updated: 2026-07-25

1. Who we are

Letalife is operated by Jotnar Systems Ltd, company number 11982020, of 5 Brayford Square, London, E1 0SG ("we", "us"). We are the controller of the personal data described in this notice. Contact: privacy@letalife.com

2. Summary

  • We collect only what the Service needs: account details, the content of adverts and enquiries, saved searches, and technical logs.
  • We do not sell personal data, we do not use third-party advertising or analytics services, and we do not build advertising profiles.
  • Our bot protection is self-hosted and cookie-free; we set strictly necessary cookies only, so there is no cookie banner (see section 9).
  • You can export your data and delete your account yourself, from your account settings, at any time.
  • No decisions with legal or similarly significant effects are made about you by automated means; every advert is reviewed by a human moderator.

3. What we collect

Account data — email address, display name, password (stored as a salted hash; we never see or store your plaintext password), account type (private individual / business landlord / letting agent).

Business identity data — for business landlords and letting agents, the details you supply on each advert so that the law's trader-disclosure requirements are met: trading or business name, business address, legal form (individual/sole trader, partnership, LLP, or limited company), company registration number where incorporated, redress scheme and membership number for agents, a client money protection declaration for agents (the scheme you belong to, or a statement that you do not hold client money), permitted fees information, and a record of the declarations you make when placing the advert. To save you re-typing, we prefill these from your most recent business advert; check them each time. Your business address is displayed on your adverts only where you are an incorporated entity (a company or LLP). For unincorporated listers, the address is held for our records and dispute handling and is never displayed publicly.

Advert content — property details, descriptions, photographs, and the material-information fields completed at ad creation. Published adverts, including any lister details displayed on them, are public.

Advert contact email and verification — every advert carries a contact email address, which must be confirmed before the advert can be published: we email the address a short-lived confirmation code and record when it was confirmed. Codes are stored only as cryptographic hashes, expire after 30 minutes, and we keep send and attempt counters to prevent abuse of the code system.

Enquiries and messages — when you contact a lister through the Service, we process your message and the contact details you choose to share so that we can relay them to the lister.

Saved searches and favourites — the search criteria and listings you save, used to operate your account hub and, if you enable them, daily email digests.

Moderation, safety, and audit data — reports you submit about listings, moderation decisions, and administrative audit logs recording actions taken on accounts and adverts.

Technical data — server logs including IP address, user-agent, and request data, used for security, abuse prevention, and service operation. Our proof-of-work bot protection runs entirely on our own infrastructure and involves no third-party service and no cookies or tracking.

Rights-request records — records of data-export and deletion requests, held in an auditable erasure queue so we can demonstrate that requests were honoured.

We do not intentionally collect special category data, and you should not include it in adverts or messages.

4. What we use it for, and our lawful bases

Purpose

Lawful basis (UK GDPR Art. 6(1))

Operating your account, publishing your adverts, relaying enquiries, providing saved searches and favourites

(b) performance of a contract — the Terms of Use

Sending service emails: password reset, email-change verification, advert contact-email confirmation codes, deletion/export notifications

(b) performance of a contract

Saved-search email digests you set up

(b) performance of a contract — sent only where you have created a saved search with digests enabled; disable at any time in your account or via the link in each email

Displaying business and agent identity details on listings — trading name, legal form, registration number, redress membership, fees information, and (for incorporated listers only) business address

(b) contract with the lister; (f) our legitimate interest in a transparent, lawful marketplace; and (c)/(f) supporting compliance with consumer protection law, which requires traders to be identifiable on their adverts

Pre-publication moderation, scam prevention, report handling, security logging, bot protection, audit logs

(f) our legitimate interests in operating a safe, lawful, trustworthy platform — and in some cases (c) legal obligation, including our duties under consumer protection law

Maintaining erasure-queue and rights-request records

(c) legal obligation — demonstrating compliance under UK GDPR Art. 5(2)

Responding to regulators, law enforcement, and legal claims

(c) legal obligation and/or (f) legitimate interests

We do not use your data for third-party marketing and we do not carry out solely automated decision-making within the meaning of UK GDPR Article 22.

5. Who we share it with

Other users. Published adverts are public (including on search engines — see section 8). When you enquire about a listing, your message and the contact details you include are passed to the lister; the lister then holds your details as a separate, independent controller and is responsible for their own compliance in using them. Enquire with that in mind, and share only what is needed.

Service providers. Our hosting provider Hetzner, located in Germany; our email provider 20i Ltd, located in the UK. Providers act on our documented instructions under UK GDPR Article 28 contracts.

Regulators and authorities. We may disclose data to Trading Standards, the CMA, the ICO, redress schemes, Rent Smart Wales, Scottish local authorities, the police, or a court where we reasonably consider it necessary to comply with the law, to support enforcement against unlawful listings, or to protect users.

Business transfer. If the Service is sold or transferred, personal data may pass to the successor operator on terms preserving this notice's protections.

We do not sell personal data.

6. How long we keep it

  • Account data: for the life of your account. When you request deletion, a 72-hour cooling-off period applies during which you can cancel the request; your account is then placed in an erasure queue and erased within 14 days of the cooling-off period ending.
  • Published adverts: removed from public view when you remove them or your account is deleted; retained internally for 12 months for audit, fraud-prevention, and legal purposes, then erased.
  • Advert verification codes: stored hashed, expire after 30 minutes, and are cleared on confirmation; the confirmation timestamp and send/attempt counters are retained with the advert.
  • Moderation, report, and audit records: 6 years, reflecting limitation periods and regulatory look-back.
  • Rights-request (erasure/export) records: 6 years, kept as minimal metadata to demonstrate compliance.
  • Technical/security logs: 180 days.

7. Your rights

You have the rights under UK GDPR to access your data, rectify it, erase it, restrict or object to processing, and receive a copy of data you provided in a portable format.

Two of these are self-service, available now in your account settings:

  • Export — download a complete copy of your data in JSON (machine-readable) and HTML (readable) formats.
  • Deletion — delete your account, subject to the 72-hour cooling-off period described in section 6.

For anything else — or if you prefer not to use self-service — contact privacy@letalife.com. We respond within one month. We may retain limited data after erasure where the law permits, for example fraud-prevention and audit records, and a minimal record that your erasure request was completed.

You also have the right to complain to us about our processing of your personal data, under section 164A of the Data Protection Act 2018 — our Data Protection Complaints Procedure explains how, and what we will do in response — and the right to complain to the Information Commissioner's Office under section 165 (ico.org.uk, 0303 123 1113). You can use either route, but the ICO will generally expect us to have had the opportunity to address your concern first.

8. Public listings and search engines

Adverts are published openly and are indexed by search engines through our sitemaps and structured data. Anything you include in an advert — including photographs and, for business and agent listers, your trading name and regulatory details — should be treated as public. The one exception is the business address: it appears on your adverts only if you are an incorporated entity (company or LLP); unincorporated listers' addresses are never published. When an advert is removed, we remove it from our sitemaps, but search engines and third-party sites may retain cached copies outside our control; you can request removal of cached copies from the search engine concerned.

9. Cookies

We use strictly necessary cookies only: a session cookie that keeps you signed in and protects forms against cross-site request forgery. These are exempt from the consent requirement in regulation 6 of the Privacy and Electronic Communications Regulations 2003 because they are essential to provide the service you request, which is why you will not see a cookie banner. We set no analytics, advertising, or third-party cookies of any kind, and our bot-protection system is deliberately cookie-free.

10. Security

Adverts are approved by human moderators before publication; administrative access is segregated in a separate application with least-privilege database roles and audit logging; passwords are stored only as salted hashes; password resets are single-use, time-limited, and revoke existing sessions. No system is perfectly secure, but if we become aware of a breach affecting your rights we will notify the ICO and, where required, you, in accordance with UK GDPR Articles 33–34.

11. Changes

We will publish any revised notice here with a new date and, for material changes, notify account holders by email or on the Service.