Trust centre
Data Protection Policy
This policy describes the principles and safeguards that guide how MyEstateManager handles account, tenant, owner, property, rent, maintenance, document, and communication data.
The essentials at a glance
- Protection is built around clear purpose, limited access, and responsible retention.
- Customers control their workspace users and the records they choose to manage.
- Security safeguards are reviewed as the platform and risks evolve.
Our data-protection principles
We aim to apply recognised data-protection principles throughout the information lifecycle, from collection and access to retention and deletion.
- Lawfulness, fairness, and transparency.
- Clear purposes and limits on incompatible reuse.
- Data minimisation and accuracy.
- Defined retention and secure disposal.
- Integrity, confidentiality, and accountability.
Roles and responsibilities
Customers decide what property-management information is entered into their workspace, why it is needed, and who should have access. MyEstateManager operates the platform and processes customer data to provide the contracted service.
- Customers should provide appropriate notices and establish a lawful basis for workspace data.
- Workspace administrators should regularly review users, roles, permissions, and exported data.
- MyEstateManager personnel and service providers should access customer data only where needed for authorised operational purposes.
Access and authentication
Access controls are designed to limit information to authorised users and functions. Security is shared: platform safeguards work best when customers manage their users and credentials carefully.
- Role-based access and administrative boundaries.
- Password and session protections.
- Verification and rate controls for sensitive public forms.
- Processes for removing access when a user changes role or leaves an organisation.
Technical and organisational safeguards
Safeguards are selected according to the type of information, service architecture, and relevant risks. They are reviewed as the platform and threat landscape evolve.
- Encryption in transit for supported production connections.
- Secure configuration, dependency maintenance, logging, monitoring, and vulnerability remediation.
- Backups and recovery processes appropriate to service continuity needs.
- Confidentiality expectations and access limitation for personnel and providers.
Security reduces risk but cannot remove it entirely. Customers should also protect endpoints, accounts, exports, and integrations under their control.
Privacy by design and change management
New features and material changes should be reviewed for their data needs, access implications, retention effects, and potential risks before or during implementation.
- Collect only information reasonably needed for the feature or workflow.
- Prefer privacy-supportive defaults and understandable user controls.
- Assess providers and integrations before introducing new data flows.
- Document and test changes that affect authentication, permissions, or sensitive records.
Service providers and transfers
Providers may support hosting, communication, monitoring, support, and related operations. They should be selected with regard to service purpose, security, confidentiality, location, and contractual protections.
- Provider access should be limited to the service being supplied.
- Material providers should be reviewed periodically and when risk changes.
- Cross-border transfers should use appropriate safeguards where applicable.
Retention, deletion, and recovery
Data should not be kept indefinitely without a purpose. Retention depends on the active service, customer instructions, backup cycles, security needs, and legal obligations.
- Customers should remove records they no longer need and export necessary data before account closure.
- Deleted data may remain temporarily in protected backups until the relevant backup cycle expires.
- Legal holds, fraud prevention, billing, or security investigation may require limited records to be retained longer.
Incident management and individual rights
Suspected security or privacy incidents should be assessed, contained, documented, and remediated. Where notification is required, affected customers or authorities should be informed according to applicable obligations.
- Customers should report suspected compromise promptly and preserve useful details.
- Requests for access, correction, deletion, restriction, portability, or objection are handled according to the requester’s relationship with MyEstateManager and applicable law.
- Identity and authority may be verified before data or account actions are completed.
Use the contact page for a security concern or data-protection request. Do not include passwords, verification codes, or unnecessary sensitive information in the initial message.
Questions about this policy?
Contact our team for privacy requests, account-specific questions, or clarification about how this policy applies.