STEMHQ
Legal

Privacy Policy

Last updated: 28 June 2026 · Version 1.0

1. Who we are

STEMHQ is operated by STEMHQ Ltd, a company registered in England and Wales. For the purposes of UK GDPR, STEMHQ Ltd is the data controller of personal data collected through our platform and website. Contact us regarding this policy at hello@stemhq.co.uk.

2. What personal data we collect

Account and identity data

Your full name, email address, account password (stored as a one-way bcrypt hash), account type, and subscription tier. Collected at registration.

Property and tenancy data

Property addresses, postcodes, rental amounts, tenancy start dates, and other property information you enter. This is your operational data.

Tenant data

Names, contact details, National Insurance numbers, payment records, arrears history, and case notes for tenants you manage. You are the data controller of your tenants’ personal data; STEMHQ processes it as your data processor under the Data Processing Agreement incorporated into our Terms. You are responsible for having a lawful basis to process it.

Compliance and document data

Gas Safety certificate dates, EPC ratings, EICR records, deposit protection details, and documents you upload (tenancy agreements, ID copies, legal notices).

Payment and billing data

Subscription status, billing interval, and Stripe customer reference. We do not store card numbers; payment processing is handled by Stripe Payments Europe Ltd under their own privacy policy.

Usage and technical data

Pages visited, features used, browser type, IP address, and session identifiers. Used to maintain security, diagnose errors, and improve the product.

Communications

If you contact us by email or our contact form, we retain those communications to respond to your enquiry.

3. Legal basis for processing

We rely on the following lawful bases under UK GDPR Article 6:

  • Contract performance (Art. 6(1)(b)): processing your account and billing data to provide the service.
  • Legitimate interests (Art. 6(1)(f)): usage analytics and security monitoring to maintain platform integrity and improve the product, subject to a legitimate interests assessment concluding these do not override your rights.
  • Legal obligation (Art. 6(1)(c)): retaining financial records as required by HMRC and applicable law.
  • Consent (Art. 6(1)(a)): for optional analytics cookies, where given via our cookie banner.

4. How we use your data

  • To create and manage your STEMHQ account.
  • To provide the property management, compliance tracking, and legal document features of the platform.
  • To process your subscription payments via Stripe.
  • To send transactional emails (account confirmation, password reset, feature notifications) via Resend.
  • To maintain platform security and detect fraudulent or abusive activity.
  • To improve the platform through aggregated, anonymised usage analysis.
  • To comply with legal obligations including lawful requests from regulatory authorities.

We do not sell your personal data, use it for advertising, or profile you for automated decision-making that produces legal or significant effects.

5. Data sharing and third-party processors

We share data only with trusted processors necessary to operate the platform, each bound by data processing agreements under equivalent data protection standards:

ProcessorPurposeLocation
Stripe Payments Europe LtdSubscription billing and payment processingEU / UK
Resend Inc.Transactional email deliveryUSA (SCCs)
Infrastructure providerCloud hosting and database storageEU

We may disclose personal data to law enforcement or regulatory authorities where required by law.

6. International data transfers

Where personal data is transferred outside the UK or EU (for example to Resend Inc. in the USA), we rely on Standard Contractual Clauses approved by the UK ICO or European Commission, supplemented by transfer impact assessments where appropriate.

7. Data security

  • All data is encrypted in transit using TLS 1.2 or higher (HTTPS enforced site-wide).
  • Passwords are hashed using bcrypt with a per-user salt. Plain-text passwords are never stored or transmitted.
  • Session tokens are cryptographically random and stored in HttpOnly, Secure, SameSite=Lax cookies.
  • CSRF protection is enforced on all state-changing API endpoints.
  • Tenant data is isolated from other operators at the database level using row-level security. No operator can access another’s data.
  • Database backups are encrypted and stored in a separate geographic region.
  • Access to production systems is restricted to authorised personnel via SSH key authentication only.

In the event of a data breach posing a risk to your rights and freedoms, we will notify you and the ICO within 72 hours of becoming aware, as required by UK GDPR Article 33.

8. Data retention

  • Account and operational data: retained while your account is active.
  • On account deletion: personal and tenant data permanently and irreversibly deleted within 30 days, except where retention is required by law.
  • Payment records: retained for 7 years to comply with HMRC requirements.
  • Security and access logs: retained for 90 days.
  • Support communications: retained for 2 years after resolution.
  • Standalone Form 3A Notice Generator submissions: highly sensitive data, encrypted at rest. Submissions never attached to an account are permanently deleted 90 days after the packet is released (or, if never completed, 90 days after creation). Once you claim a notice into your STEMHQ account, it is kept until you delete it, which you can do from your account at any time.

9. Your rights under UK GDPR

To exercise any right, contact hello@stemhq.co.uk. We respond within one calendar month.

  • Access: a copy of the personal data we hold about you.
  • Rectification: correction of inaccurate or incomplete data.
  • Erasure: deletion where there is no compelling reason to continue processing.
  • Restriction: restricting processing while a dispute is resolved.
  • Portability: a machine-readable export of the data you provided.
  • Objection: to processing based on legitimate interests.
  • Automated decision-making: we do not carry out automated decisions producing legal or significant effects.

You may also lodge a complaint with the Information Commissioner’s Office if you believe we have not handled your data lawfully.

10. Cookies

Essential cookies (always active)

Session authentication token, CSRF token. Required for the platform to function. No consent required.

Functional cookies (default on, can be disabled)

Dark-mode preference, sidebar state, display settings, stored in localStorage and not transmitted to our servers.

Analytics cookies (default off, consent required)

Aggregate usage data. No advertising cookies are used, and no data is sold or shared with advertising networks.

Manage cookie preferences at any time via Cookie Settings in your account menu. See our Cookie Policy for detail.

11. Children

STEMHQ is a professional business tool intended for adults. We do not knowingly collect personal data from anyone under 18. If you believe we have, contact hello@stemhq.co.uk immediately.

12. Changes to this policy

We may update this policy to reflect changes in law, our practices, or the platform. Material changes will be notified by email at least 14 days before they take effect. Continued use after the effective date constitutes acceptance. The date above always reflects the most recent revision.

13. Contact and complaints

For any privacy query, request, or complaint, contact hello@stemhq.co.uk. If you are not satisfied with our response, you may complain to the ICO at ico.org.uk/make-a-complaint or by calling 0303 123 1113.