Rose & Co Lettings Ltd
Privacy Policy
Company Name: Rose & Co Lettings Ltd
Company Number: 16820372
Registered Address: 14 Laurel Road, Lowestoft, Suffolk, NR33 0NG
ICO Registration Number: ZC039715
Email: info@roseandcolettings.co.uk
Effective Date: 30th October 2025
Rose & Co Lettings Ltd (“we”, “us”, “our”) is committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, store, and share your personal information, and your rights in relation to that data, in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, Propertymark, and The Property Ombudsman (TPO).
1. Data Protection Officer
Lauren Copping – Director and Data Protection Officer (DPO)
Email: info@roseandcolettings.co.uk
The DPO oversees all data protection activities, monitors compliance, and acts as the main point of contact for any privacy-related questions or requests.
2. Personal Data We Collect
We may collect the following personal data:
Landlords
Full name, address, and contact details
Bank account and mortgage details
Identification documents (e.g., passport, driving licence)
Insurance and property ownership documentation
Correspondence and communication records
Tenants / Applicants
Full name, date of birth, and contact details
Current and previous addresses
Identification documents (e.g., passport, driving licence)
Employment, income, and financial information
Credit and reference check information
Bank account details
Emergency contact information
Tenancy agreements and related correspondence
Contractors / Third Parties
Business name and contact details
Insurance and certification documents
Payment and invoicing information
3. How We Use Personal Data
We use personal data to:
Manage tenancy agreements and property management services
Conduct referencing, Right to Rent checks, and credit checks
Communicate with landlords, tenants, contractors, and service providers
Process rent payments, deposits, and invoices
Ensure compliance with legal obligations
Provide services requested by landlords or tenants
Send marketing communications (with consent)
4. Lawful Basis for Processing
We process personal data under the following legal bases:
Contractual necessity – to perform tenancy agreements and property management contracts
Legal obligation – including deposit protection, Right to Rent checks, and statutory compliance
Legitimate interests – for effective property management and business operations
Consent – for marketing communications (withdrawable at any time)
5. Data Sharing
We only share personal data where necessary and lawful, including with:
Referencing agencies
Deposit protection schemes
Maintenance contractors
Utility companies and local authorities (when required)
HMRC or legal bodies when legally obliged
All third parties are required to handle data securely and in accordance with data-protection laws.
6. Data Retention
We retain personal data only as long as necessary for legal, contractual, and business purposes:
Data Type
Retention Period
Tenancy documentation
6 years after tenancy ends
Financial records
6 years (HMRC requirement)
Identification documents
12 months after tenancy application decision
General enquiries
12 months
Data is securely destroyed or anonymised once the retention period expires.
7. Data Security
We implement appropriate technical and organisational measures to keep personal data safe, including:
Password-protected systems and encrypted storage
Secure cloud-based storage
Restricted access to personal data
Safe disposal of paper and electronic records
Regular staff training on data handling and confidentiality
No personal data is stored on personal devices without prior written approval from the Director.
8. Your Rights
You have the following rights under UK GDPR:
Access your personal data
Rectify inaccurate or incomplete data
Request erasure (“right to be forgotten”)
Restrict processing
Object to processing, including marketing
Data portability
Requests should be sent to: info@roseandcolettings.co.uk. We will respond within 1 calendar month, which may be extended by up to 2 months for complex requests.
9. Automated Decision-Making
We do not make decisions based solely on automated processing, except for referencing or credit checks, in which case you have the right to challenge the decision and request human review.
10. Data Breaches
All personal data breaches are reported immediately to the Data Protection Officer. If a breach poses a high risk to individual rights, affected parties and the ICO will be informed without undue delay.
11. Transfers Outside the EEA
We may transfer personal data outside the EEA only when:
The country provides adequate data protection
Appropriate safeguards are in place (e.g., standard contractual clauses)
The transfer is necessary for contract performance or legal obligations
12. Complaints
If you have concerns about our handling of personal data:
Contact our Data Protection Officer: info@roseandcolettings.co.uk
If unresolved, you may lodge a complaint with the Information Commissioner’s Office (ICO): https://ico.org.uk
13. Website & Legal Compliance
For transparency, our website should display:
Company Name: Rose & Co Lettings Ltd
Registered Office: 14 Laurel Road, Lowestoft, Suffolk, NR33 0NG
Company Number: 16820372
ICO Registration Number: ZC039715
Professional Memberships: Propertymark, The Property Ombudsman
Client Money Protection: CMP
This Privacy Policy is effective from 30th October 2025, the date Rose & Co Lettings Ltd was incorporated. The Company is fully registered with the ICO, a member of Propertymark, regulated by The Property Ombudsman (TPO), and holds Client Money Protection (CMP). All personal data processing activities are carried out in compliance with applicable regulations.

