Testing-stage privacy notice

Yental is currently in a closed testing phase and is not yet open to external customers. This privacy notice is published to satisfy requirements of the Google OAuth verification process and to be transparent about how data is handled during testing. Several details — including company registration information, formal lawful bases, data retention periods, and international transfer mechanisms — will be confirmed and completed before Yental launches commercially. This document is not final legal documentation.

Legal

Privacy Policy

Applies to: yental.co.uk and Yental platform services
Last updated: 18 September 2026 (testing stage)

Who we are

Yental is a physical asset management platform for UK rental property, operated by Yental Ltd, a company registered in England and Wales. Company registration details and registered office address will be added here prior to commercial launch.

References to "Yental", "we", "us", or "our" in this policy are references to Yental Ltd.

Questions about this policy may be sent to hello@yental.co.uk. Yental has not appointed a formal Data Protection Officer at this stage. Data protection queries should be directed to the email address above.

Data controller and data processor

Summary: Yental is the data controller for its own business operations (accounts, waitlist, platform administration). For property and portfolio data that subscribing organisations enter into the platform, Yental is likely to act as a data processor on the subscribing organisation's behalf.

Where Yental is the data controller

Yental determines the purposes and means of processing for:

  • User account creation, authentication, and management
  • Waitlist sign-up and related notifications
  • Platform security, abuse prevention, and audit logging
  • Yental's own business administration, billing, and communications

Where Yental is a data processor

When a subscribing organisation (a landlord, letting agent, or property management company) uses Yental to record and manage their property portfolio, the subscribing organisation is the data controller for any personal data relating to their tenants, contractors, or third parties that they enter into the platform. Yental processes that data solely on the controller's instructions in accordance with its obligations under UK GDPR Article 28.

A formal Data Processing Agreement covering the terms on which Yental processes data as a processor will be put in place with subscribing organisations before Yental opens to external customers.

Account and identity data

What we collect

  • Email address
  • Display name (from your Google or Microsoft account profile, or entered by you at sign-up)
  • A unique account identifier (Firebase UID) generated at account creation
  • Your role within the platform, subscription tier, and subscription status
  • Account creation timestamp

Why we collect it

This data is necessary to create and maintain your Yental account and to provide you with access to the platform. It is also used for platform security, access control, and support.

Lawful basis

We process account data in order to provide you with access to the Yental platform you have requested. The specific lawful basis under UK GDPR Article 6 is being confirmed as part of pre-commercial compliance work and will be documented here before Yental launches commercially.

How long we keep it

Retention periods for account data are being established as part of pre-launch compliance work. We do not retain data beyond what is necessary to provide the service. Specific periods will be documented here before commercial launch.

Sign-in methods

Yental supports sign-in via email and password, Google Sign-In, and Microsoft sign-in. If you use a federated sign-in method, Google or Microsoft will provide us with your name and email address. We do not receive or store your Google or Microsoft account password.

Portfolio and property data

Subscribing organisations enter and manage property and asset data through the platform. As described in Section 2, Yental processes this data as a data processor on the subscribing organisation's behalf.

Data categories entered by subscribing organisations

  • Property names, addresses, and style classifications
  • Unit names and identifiers
  • Asset records: category, name, brand, model, serial number, purchase date, purchase cost, condition, materials, and estimated useful life
  • Lifecycle events: maintenance, repair, inspection, compliance check, and retirement records — including dates, engineer names, costs, and free-text notes
  • Certification documents: uploaded PDFs or images such as EPC certificates, EICR reports, gas safety certificates, and EPD/sustainability evidence
  • Compliance deadlines: inspection, warranty, compliance, and replacement dates
  • Issue and maintenance reports raised against specific assets
  • Asset movement history (relocation records)

Document uploads

Documents (PDF, JPEG, PNG, WEBP) uploaded through the platform are stored in Google Cloud Storage within the europe-west1 (Belgium) region. Uploaded files are scanned server-side before being made available; files containing executable content or embedded scripts are quarantined automatically. Document storage is a Blaze-plan feature and may not be active in all deployment stages.

How long we keep it

Retention periods for portfolio and document data are being established as part of pre-launch compliance work. Specific periods will be documented here before Yental launches commercially.

AI assistant

Important: When you use the Yental AI assistant, your messages and relevant portfolio context are sent to a third-party AI provider (currently Groq, used for testing). Do not include sensitive personal data in AI chat messages beyond what is necessary to describe your Yental assets.

What is sent to the AI

When you send a message to the Yental AI assistant, the following data is transmitted:

  • Your typed message
  • Relevant portfolio context automatically injected by the platform (such as property names, asset categories, condition scores, and lifecycle data)
  • Text extracted from any document you scan using the AI document import feature

Your Firebase identity token is verified by Yental's Cloudflare Worker before the request is forwarded to the AI provider, but the token value itself is not sent to the AI provider.

Current AI provider (testing stage)

During the current testing phase, the AI assistant uses the Groq inference API (Groq Inc., a US company), via a Cloudflare Worker operated by Yental. The model currently in use is openai/gpt-oss-120b.

The production AI provider has not yet been finalised. The provider and model used in the commercial product may differ from those used during testing. This policy will be updated to reflect the confirmed production AI provider before Yental launches commercially. Any change in AI provider will be communicated to users before it takes effect.

Data sent outside the UK/EEA

Groq is based in the United States. Messages and portfolio context sent to the AI assistant may therefore be processed outside the UK and EEA. See Section 10 for further detail on international transfers.

Scope restriction

The AI assistant is technically restricted by a server-enforced scope guard to respond only to questions about your Yental portfolio and platform features. It is not a general-purpose AI. This restriction is implemented in Yental's Cloudflare Worker and cannot be overridden by users.

Calendar integrations

Yental offers optional integrations that push asset deadline events (inspection, warranty, compliance, and replacement dates) from your Yental portfolio into a connected external calendar. These integrations are optional and user-initiated.

Microsoft 365 / Outlook Calendar (live)

If you connect a Microsoft 365 account, Yental will:

  • Request read/write access to your Outlook calendar via Microsoft's OAuth 2.0 service
  • Store your OAuth access token and refresh token in Yental's database, encrypted using AES-256-GCM
  • Create, update, and delete calendar events in your Outlook calendar corresponding to your Yental asset deadlines
  • Only delete events that Yental itself created — it will never touch unrelated calendar events

Yental communicates with Microsoft's Graph API (graph.microsoft.com) to write and manage these events. Disconnecting the integration removes all events Yental created and revokes Yental's access to your calendar locally. Microsoft's own token revocation is not available via the Microsoft delegated permissions model.

Google Calendar (in testing setup — not yet open to external users)

Status: The Google Calendar integration is implemented in Yental's codebase and is currently being configured for testing. It has not been deployed or made available to external users. This section describes how it will operate and what Google user data it will access when released.

Google user data accessed

When the Google Calendar integration is enabled and a user connects their Google account, Yental will request and use the following Google user data:

  • Google Calendar events — via the https://www.googleapis.com/auth/calendar.events scope. Yental uses this scope to create, update, and delete calendar events on the user's primary Google Calendar corresponding to asset deadlines (inspection dates, warranty expiry, compliance deadlines, and replacement dates) stored in the user's Yental portfolio. Yental only manages events it has itself created; it will never read, modify, or delete unrelated calendar events.
  • Basic profile information — name and email address, via the openid, profile, and email scopes, used to identify the connected Google account.

OAuth access tokens and refresh tokens issued by Google will be stored in Yental's database, encrypted at rest using AES-256-GCM. Tokens will not be accessible to any client application; they are stored and used exclusively by Yental's server-side Cloud Functions.

Disconnecting the integration will revoke Yental's Google access (via Google's token revocation endpoint) and delete all calendar events Yental created. Yental does not retain Google OAuth tokens after a user disconnects.

Google user data accessed via the calendar.events scope is used solely to write and manage the calendar events described above. It is not used for any other purpose, not shared with third parties, and not used to train AI models.

Lawful basis for calendar processing

Both calendar integrations are explicitly user-initiated: you choose to connect your calendar account and can disconnect at any time. The specific lawful basis under UK GDPR Article 6 is being confirmed as part of pre-commercial compliance work and will be documented here before this feature is made available to external customers.

Waitlist

Yental operates a pre-launch waitlist. If you submit your name and email address via the waitlist form on this website:

  • Your submission is stored in Yental's Firestore database
  • An internal notification email is sent to Yental via Gmail (Google's email service), containing your name and email address — it is not sent to any third-party marketing platform
  • Yental may contact you at the email address provided to inform you when access is available or to share relevant platform updates

You may request removal from the waitlist at any time by emailing hello@yental.co.uk.

Lawful basis

You provide your contact details voluntarily for the specific purpose of being informed when Yental access becomes available. The specific lawful basis under UK GDPR Article 6 is being confirmed as part of pre-commercial compliance work.

Browser storage (cookies and local storage)

Yental does not use third-party advertising or analytics cookies. The following browser storage is used solely to make the platform function and to remember your preferences on your own device. Nothing stored here is shared with any third party.

Strictly necessary storage

Firebase Authentication stores session credentials in your browser's local storage to keep you signed in between visits. This is technically necessary to operate the platform; you can clear it at any time by signing out.

localStorageFirebase session token and authentication state (managed by Firebase SDK)
localStorageUser preferences: interface theme (light/dark), sound setting, notification-seen timestamps, voice assistant settings — stored per device and never sent to Yental servers
sessionStorageTemporary OAuth flow state (yental_oauth_intent, yental_oauth_pending) — cleared when you close the browser tab; also unit deep-link state for QR-code flows

No tracking cookies, advertising cookies, or fingerprinting scripts are used on this website. No cookie consent banner is displayed because the storage described above falls within the strictly necessary and user-preference exemptions under the UK Privacy and Electronic Communications Regulations (PECR).

Third-party services

The following third-party services are used in the current production platform. Each has its own privacy policy linked below.

Service Purpose Data involved Privacy policy
Google Firebase (Auth, Firestore, Cloud Functions, Hosting) Core platform infrastructure: authentication, database, server functions, and web hosting All account and portfolio data; function execution logs firebase.google.com/support/privacy
Google Cloud Storage Storage for uploaded property documents and certificates Uploaded PDFs and images cloud.google.com/terms/cloud-privacy-notice
Google Fonts Typography (Plus Jakarta Sans typeface) IP address and user-agent on font load — standard CDN request developers.google.com/fonts/faq/privacy
Groq (AI inference — testing stage) Currently powers the Yental AI assistant and document text extraction during testing. The production AI provider has not yet been finalised. AI chat messages and portfolio context injected into prompts; extracted document text groq.com/privacy-policy
Google Calendar API (testing setup — not yet open to external users) Will be used to create, update, and delete calendar events in a user's primary Google Calendar, corresponding to Yental asset deadlines, once this integration is released Google OAuth tokens (encrypted at rest); calendar event data written on the user's behalf; basic profile (name, email) used to identify the connected account policies.google.com/privacy
Cloudflare Workers AI request proxy and rate-limiting layer between the platform and Groq All AI requests pass through this worker; IP address and verified Firebase token visible to Cloudflare cloudflare.com/privacypolicy
Cloudflare CDN (cdnjs) Delivery of open-source JavaScript libraries (PDF.js, QRCode.js, Three.js, GSAP) IP address and user-agent on script load — standard CDN request cloudflare.com/privacypolicy
Microsoft (Azure AD / Graph API) Microsoft sign-in authentication and optional Outlook Calendar integration OAuth tokens (if connecting Microsoft); calendar event data written on your behalf privacy.microsoft.com
Gmail (Google SMTP) Internal waitlist notification emails sent to Yental Waitlist submitter's email address and name — used only for Yental's internal notification policies.google.com/privacy

Yental does not use Stripe or any other payment processor at this time. Billing infrastructure will be added before the platform launches commercially; this policy will be updated accordingly.

Yental does not use advertising networks, tracking pixels, or behavioural analytics services. No data is sold to third parties.

International transfers

Yental's primary database and Cloud Functions infrastructure is hosted in the europe-west1 (Belgium) region, which is within the EEA.

The following processing involves transfers of personal data outside the UK and EEA:

  • Groq (United States): AI chat messages and portfolio context are sent to Groq's US-based inference infrastructure when you use the AI assistant.
  • Cloudflare (United States): All AI requests pass through a Cloudflare Worker. Cloudflare also processes CDN requests (scripts and fonts) from edge nodes which may be located globally.

The appropriate transfer mechanisms for these services (such as a UK International Data Transfer Agreement or standard contractual clauses) are being identified and documented as part of pre-commercial compliance work. Yental is not currently operating as a commercial service open to the general public; appropriate transfer safeguards will be in place before external customers are onboarded.

Security

Yental applies a range of technical and organisational measures to protect personal data, including:

  • All data in transit is encrypted via HTTPS (TLS). The platform enforces HTTP Strict Transport Security (HSTS) with a one-year policy.
  • Calendar OAuth tokens (for Microsoft and Google integrations) are encrypted at rest using AES-256-GCM before being stored in Firestore.
  • Firestore security rules enforce strict per-user data isolation: users can only access their own organisation's data.
  • Uploaded documents are scanned server-side for executable content and active scripts before being served.
  • Audit logging is maintained for account creation and administrative actions.
  • Firebase App Check is used to restrict platform API access to authorised clients.

No security measures are perfect. If you believe you have identified a security vulnerability in the Yental platform, please contact us at hello@yental.co.uk.

Your rights

Under UK GDPR and the Data Protection Act 2018, you have the following rights in relation to personal data for which Yental is the data controller (see Section 2). For data processed by Yental as a processor on behalf of a subscribing organisation, rights requests should be directed to that organisation.

Right of access

Request a copy of the personal data Yental holds about you.

Right to rectification

Ask us to correct inaccurate or incomplete personal data.

Right to erasure

Request deletion of your personal data where there is no overriding legitimate reason to retain it.

Right to data portability

Receive your personal data in a structured, commonly used, machine-readable format where processing is based on consent or contract.

Right to restriction

Ask us to restrict processing of your data in certain circumstances.

Right to object

Object to processing based on legitimate interests.

To exercise any of these rights, please contact us at hello@yental.co.uk. We will respond within one calendar month in most cases. We may need to verify your identity before processing a request.

Right to complain

If you are unhappy with how we handle your data, you have the right to lodge a complaint with the UK's supervisory authority:

Information Commissioner's Office (ICO)

Website: ico.org.uk

Helpline: 0303 123 1113

Yental's ICO registration status and reference number will be confirmed and added here prior to commercial launch.

Changes to this policy

We may update this privacy policy from time to time as the platform evolves or as legal requirements change. Material changes will be communicated to registered users by email before they take effect. The "Last updated" date at the top of this policy indicates when it was most recently revised.

Continued use of the Yental platform after the effective date of a revised policy constitutes acceptance of the changes, to the extent permitted by applicable law.

Contact us

For any questions, concerns, or rights requests relating to this privacy policy or to the personal data Yental holds about you, please contact us using the details below.

Yental Ltd

Email: hello@yental.co.uk

Registered address: to be confirmed prior to commercial launch.

ICO registration: to be confirmed prior to commercial launch.