Legal
Privacy Policy
Who we are
Yental is a physical asset management platform for UK rental property, operated by Yental Ltd, a company registered in England and Wales. Company registration details and registered office address will be added here prior to commercial launch.
References to "Yental", "we", "us", or "our" in this policy are references to Yental Ltd.
Questions about this policy may be sent to hello@yental.co.uk. Yental has not appointed a formal Data Protection Officer at this stage. Data protection queries should be directed to the email address above.
Data controller and data processor
Where Yental is the data controller
Yental determines the purposes and means of processing for:
- User account creation, authentication, and management
- Waitlist sign-up and related notifications
- Platform security, abuse prevention, and audit logging
- Yental's own business administration, billing, and communications
Where Yental is a data processor
When a subscribing organisation (a landlord, letting agent, or property management company) uses Yental to record and manage their property portfolio, the subscribing organisation is the data controller for any personal data relating to their tenants, contractors, or third parties that they enter into the platform. Yental processes that data solely on the controller's instructions in accordance with its obligations under UK GDPR Article 28.
A formal Data Processing Agreement covering the terms on which Yental processes data as a processor will be put in place with subscribing organisations before Yental opens to external customers.
Account and identity data
What we collect
- Email address
- Display name (from your Google or Microsoft account profile, or entered by you at sign-up)
- A unique account identifier (Firebase UID) generated at account creation
- Your role within the platform, subscription tier, and subscription status
- Account creation timestamp
Why we collect it
This data is necessary to create and maintain your Yental account and to provide you with access to the platform. It is also used for platform security, access control, and support.
Lawful basis
We process account data in order to provide you with access to the Yental platform you have requested. The specific lawful basis under UK GDPR Article 6 is being confirmed as part of pre-commercial compliance work and will be documented here before Yental launches commercially.
How long we keep it
Retention periods for account data are being established as part of pre-launch compliance work. We do not retain data beyond what is necessary to provide the service. Specific periods will be documented here before commercial launch.
Sign-in methods
Yental supports sign-in via email and password, Google Sign-In, and Microsoft sign-in. If you use a federated sign-in method, Google or Microsoft will provide us with your name and email address. We do not receive or store your Google or Microsoft account password.
Portfolio and property data
Subscribing organisations enter and manage property and asset data through the platform. As described in Section 2, Yental processes this data as a data processor on the subscribing organisation's behalf.
Data categories entered by subscribing organisations
- Property names, addresses, and style classifications
- Unit names and identifiers
- Asset records: category, name, brand, model, serial number, purchase date, purchase cost, condition, materials, and estimated useful life
- Lifecycle events: maintenance, repair, inspection, compliance check, and retirement records — including dates, engineer names, costs, and free-text notes
- Certification documents: uploaded PDFs or images such as EPC certificates, EICR reports, gas safety certificates, and EPD/sustainability evidence
- Compliance deadlines: inspection, warranty, compliance, and replacement dates
- Issue and maintenance reports raised against specific assets
- Asset movement history (relocation records)
Document uploads
Documents (PDF, JPEG, PNG, WEBP) uploaded through the platform are stored in
Google Cloud Storage within the europe-west1 (Belgium) region.
Uploaded files are scanned server-side before being made available; files
containing executable content or embedded scripts are quarantined automatically.
Document storage is a Blaze-plan feature and may not be active in all
deployment stages.
How long we keep it
Retention periods for portfolio and document data are being established as part of pre-launch compliance work. Specific periods will be documented here before Yental launches commercially.
AI assistant
What is sent to the AI
When you send a message to the Yental AI assistant, the following data is transmitted:
- Your typed message
- Relevant portfolio context automatically injected by the platform (such as property names, asset categories, condition scores, and lifecycle data)
- Text extracted from any document you scan using the AI document import feature
Your Firebase identity token is verified by Yental's Cloudflare Worker before the request is forwarded to the AI provider, but the token value itself is not sent to the AI provider.
Current AI provider (testing stage)
During the current testing phase, the AI assistant uses the Groq
inference API (Groq Inc., a US company), via a Cloudflare Worker operated by Yental.
The model currently in use is openai/gpt-oss-120b.
The production AI provider has not yet been finalised. The provider and model used in the commercial product may differ from those used during testing. This policy will be updated to reflect the confirmed production AI provider before Yental launches commercially. Any change in AI provider will be communicated to users before it takes effect.
Data sent outside the UK/EEA
Groq is based in the United States. Messages and portfolio context sent to the AI assistant may therefore be processed outside the UK and EEA. See Section 10 for further detail on international transfers.
Scope restriction
The AI assistant is technically restricted by a server-enforced scope guard to respond only to questions about your Yental portfolio and platform features. It is not a general-purpose AI. This restriction is implemented in Yental's Cloudflare Worker and cannot be overridden by users.
Calendar integrations
Yental offers optional integrations that push asset deadline events (inspection, warranty, compliance, and replacement dates) from your Yental portfolio into a connected external calendar. These integrations are optional and user-initiated.
Microsoft 365 / Outlook Calendar (live)
If you connect a Microsoft 365 account, Yental will:
- Request read/write access to your Outlook calendar via Microsoft's OAuth 2.0 service
- Store your OAuth access token and refresh token in Yental's database, encrypted using AES-256-GCM
- Create, update, and delete calendar events in your Outlook calendar corresponding to your Yental asset deadlines
- Only delete events that Yental itself created — it will never touch unrelated calendar events
Yental communicates with Microsoft's Graph API (graph.microsoft.com)
to write and manage these events. Disconnecting the integration removes all events
Yental created and revokes Yental's access to your calendar locally. Microsoft's
own token revocation is not available via the Microsoft delegated permissions model.
Google Calendar (in testing setup — not yet open to external users)
Google user data accessed
When the Google Calendar integration is enabled and a user connects their Google account, Yental will request and use the following Google user data:
-
Google Calendar events — via the
https://www.googleapis.com/auth/calendar.eventsscope. Yental uses this scope to create, update, and delete calendar events on the user's primary Google Calendar corresponding to asset deadlines (inspection dates, warranty expiry, compliance deadlines, and replacement dates) stored in the user's Yental portfolio. Yental only manages events it has itself created; it will never read, modify, or delete unrelated calendar events. -
Basic profile information — name and email address, via the
openid,profile, andemailscopes, used to identify the connected Google account.
OAuth access tokens and refresh tokens issued by Google will be stored in Yental's database, encrypted at rest using AES-256-GCM. Tokens will not be accessible to any client application; they are stored and used exclusively by Yental's server-side Cloud Functions.
Disconnecting the integration will revoke Yental's Google access (via Google's token revocation endpoint) and delete all calendar events Yental created. Yental does not retain Google OAuth tokens after a user disconnects.
Google user data accessed via the calendar.events scope is used
solely to write and manage the calendar events described above. It is not used
for any other purpose, not shared with third parties, and not used to train
AI models.
Lawful basis for calendar processing
Both calendar integrations are explicitly user-initiated: you choose to connect your calendar account and can disconnect at any time. The specific lawful basis under UK GDPR Article 6 is being confirmed as part of pre-commercial compliance work and will be documented here before this feature is made available to external customers.
Waitlist
Yental operates a pre-launch waitlist. If you submit your name and email address via the waitlist form on this website:
- Your submission is stored in Yental's Firestore database
- An internal notification email is sent to Yental via Gmail (Google's email service), containing your name and email address — it is not sent to any third-party marketing platform
- Yental may contact you at the email address provided to inform you when access is available or to share relevant platform updates
You may request removal from the waitlist at any time by emailing hello@yental.co.uk.
Lawful basis
You provide your contact details voluntarily for the specific purpose of being informed when Yental access becomes available. The specific lawful basis under UK GDPR Article 6 is being confirmed as part of pre-commercial compliance work.
Browser storage (cookies and local storage)
Yental does not use third-party advertising or analytics cookies. The following browser storage is used solely to make the platform function and to remember your preferences on your own device. Nothing stored here is shared with any third party.
Strictly necessary storage
Firebase Authentication stores session credentials in your browser's local storage to keep you signed in between visits. This is technically necessary to operate the platform; you can clear it at any time by signing out.
yental_oauth_intent, yental_oauth_pending) — cleared when you close the browser tab; also unit deep-link state for QR-code flowsNo tracking cookies, advertising cookies, or fingerprinting scripts are used on this website. No cookie consent banner is displayed because the storage described above falls within the strictly necessary and user-preference exemptions under the UK Privacy and Electronic Communications Regulations (PECR).
Third-party services
The following third-party services are used in the current production platform. Each has its own privacy policy linked below.
| Service | Purpose | Data involved | Privacy policy |
|---|---|---|---|
| Google Firebase (Auth, Firestore, Cloud Functions, Hosting) | Core platform infrastructure: authentication, database, server functions, and web hosting | All account and portfolio data; function execution logs | firebase.google.com/support/privacy |
| Google Cloud Storage | Storage for uploaded property documents and certificates | Uploaded PDFs and images | cloud.google.com/terms/cloud-privacy-notice |
| Google Fonts | Typography (Plus Jakarta Sans typeface) | IP address and user-agent on font load — standard CDN request | developers.google.com/fonts/faq/privacy |
| Groq (AI inference — testing stage) | Currently powers the Yental AI assistant and document text extraction during testing. The production AI provider has not yet been finalised. | AI chat messages and portfolio context injected into prompts; extracted document text | groq.com/privacy-policy |
| Google Calendar API (testing setup — not yet open to external users) | Will be used to create, update, and delete calendar events in a user's primary Google Calendar, corresponding to Yental asset deadlines, once this integration is released | Google OAuth tokens (encrypted at rest); calendar event data written on the user's behalf; basic profile (name, email) used to identify the connected account | policies.google.com/privacy |
| Cloudflare Workers | AI request proxy and rate-limiting layer between the platform and Groq | All AI requests pass through this worker; IP address and verified Firebase token visible to Cloudflare | cloudflare.com/privacypolicy |
| Cloudflare CDN (cdnjs) | Delivery of open-source JavaScript libraries (PDF.js, QRCode.js, Three.js, GSAP) | IP address and user-agent on script load — standard CDN request | cloudflare.com/privacypolicy |
| Microsoft (Azure AD / Graph API) | Microsoft sign-in authentication and optional Outlook Calendar integration | OAuth tokens (if connecting Microsoft); calendar event data written on your behalf | privacy.microsoft.com |
| Gmail (Google SMTP) | Internal waitlist notification emails sent to Yental | Waitlist submitter's email address and name — used only for Yental's internal notification | policies.google.com/privacy |
Yental does not use Stripe or any other payment processor at this time. Billing infrastructure will be added before the platform launches commercially; this policy will be updated accordingly.
Yental does not use advertising networks, tracking pixels, or behavioural analytics services. No data is sold to third parties.
International transfers
Yental's primary database and Cloud Functions infrastructure is hosted in the europe-west1 (Belgium) region, which is within the EEA.
The following processing involves transfers of personal data outside the UK and EEA:
- Groq (United States): AI chat messages and portfolio context are sent to Groq's US-based inference infrastructure when you use the AI assistant.
- Cloudflare (United States): All AI requests pass through a Cloudflare Worker. Cloudflare also processes CDN requests (scripts and fonts) from edge nodes which may be located globally.
The appropriate transfer mechanisms for these services (such as a UK International Data Transfer Agreement or standard contractual clauses) are being identified and documented as part of pre-commercial compliance work. Yental is not currently operating as a commercial service open to the general public; appropriate transfer safeguards will be in place before external customers are onboarded.
Security
Yental applies a range of technical and organisational measures to protect personal data, including:
- All data in transit is encrypted via HTTPS (TLS). The platform enforces HTTP Strict Transport Security (HSTS) with a one-year policy.
- Calendar OAuth tokens (for Microsoft and Google integrations) are encrypted at rest using AES-256-GCM before being stored in Firestore.
- Firestore security rules enforce strict per-user data isolation: users can only access their own organisation's data.
- Uploaded documents are scanned server-side for executable content and active scripts before being served.
- Audit logging is maintained for account creation and administrative actions.
- Firebase App Check is used to restrict platform API access to authorised clients.
No security measures are perfect. If you believe you have identified a security vulnerability in the Yental platform, please contact us at hello@yental.co.uk.
Your rights
Under UK GDPR and the Data Protection Act 2018, you have the following rights in relation to personal data for which Yental is the data controller (see Section 2). For data processed by Yental as a processor on behalf of a subscribing organisation, rights requests should be directed to that organisation.
Right of access
Request a copy of the personal data Yental holds about you.
Right to rectification
Ask us to correct inaccurate or incomplete personal data.
Right to erasure
Request deletion of your personal data where there is no overriding legitimate reason to retain it.
Right to data portability
Receive your personal data in a structured, commonly used, machine-readable format where processing is based on consent or contract.
Right to restriction
Ask us to restrict processing of your data in certain circumstances.
Right to object
Object to processing based on legitimate interests.
To exercise any of these rights, please contact us at hello@yental.co.uk. We will respond within one calendar month in most cases. We may need to verify your identity before processing a request.
Right to complain
If you are unhappy with how we handle your data, you have the right to lodge a complaint with the UK's supervisory authority:
Information Commissioner's Office (ICO)
Website: ico.org.uk
Helpline: 0303 123 1113
Yental's ICO registration status and reference number will be confirmed and added here prior to commercial launch.
Changes to this policy
We may update this privacy policy from time to time as the platform evolves or as legal requirements change. Material changes will be communicated to registered users by email before they take effect. The "Last updated" date at the top of this policy indicates when it was most recently revised.
Continued use of the Yental platform after the effective date of a revised policy constitutes acceptance of the changes, to the extent permitted by applicable law.
Contact us
For any questions, concerns, or rights requests relating to this privacy policy or to the personal data Yental holds about you, please contact us using the details below.
Yental Ltd
Email: hello@yental.co.uk
Registered address: to be confirmed prior to commercial launch.
ICO registration: to be confirmed prior to commercial launch.