Data Processing Addendum
Version 1.0. Last updated: 26 August 2026. Applies to Reqzi Go.
This addendum applies automatically when you use Reqzi Go to manage tenancies. It forms part of the Terms of Service and needs no separate signature. If your organisation needs a countersigned copy on your own paper, email hello@reqzi.com and we will provide one.
1. Parties and roles
This addendum is between you, the landlord, letting agent or other business using Reqzi Go (the controller), and Reqzi Limited, a company registered in England and Wales, company number 16858392, at 124 City Road, London EC1V 2NX, United Kingdom (the processor). It gives effect to Article 28 of the UK GDPR.
It covers only the data you control: the tenancy records you create in Reqzi Go and the people in them. It does not cover the data Reqzi Limited controls in its own right, such as your account, your subscription and our security logs. That is described in the Privacy Policy, where we are the controller and this addendum does not apply.
2. Subject matter of the processing
| Item | Detail |
|---|---|
| Subject matter | Providing the Reqzi Go property management service to you |
| Duration | For as long as your account is open, plus the retention periods in section 9 |
| Nature and purpose | Storing, organising, transmitting and displaying tenancy data so you can manage tenancies, collect rent, handle maintenance, track compliance and communicate with tenants |
| Types of personal data | Names, contact details, addresses, tenancy terms, rent and arrears records, payment records and status, maintenance requests and photographs, compliance certificates, inventories, documents, electronic signatures, messages |
| Categories of data subject | Your tenants and their household members, applicants, guarantors, contractors, and your own staff |
| Special category data | Not requested by the service. If you choose to record health or vulnerability information in a tenancy record, you are responsible for the Article 9 condition that permits it |
3. Our obligations
- We process the data only on your documented instructions. Using the service is an instruction: what you enter, what you ask us to send, and the settings you choose. We will tell you if an instruction appears to breach data protection law.
- We do not use your tenancy data for our own purposes, do not sell it, and do not use it to train AI models.
- Everyone we authorise to access the data is bound by confidentiality obligations and gets access only where their role requires it.
- We help you meet your own obligations under Articles 32 to 36, including security, breach notification, data protection impact assessments and prior consultation, taking into account the nature of the processing and the information available to us.
- Where the law requires us to process data for a reason other than your instruction, we will tell you first unless that law forbids it.
4. Your obligations
- You confirm you have a lawful basis for the personal data you put into Reqzi Go, and an Article 9 condition for any special category data.
- You are responsible for telling your tenants how their data is used, including that you use Reqzi Go to manage their tenancy.
- You control who in your organisation has access, and what role each person holds. Remove people who leave.
5. Security
We keep appropriate technical and organisational measures under Article 32. These currently include:
- Encryption in transit and at rest, with message content encrypted separately.
- Workspace isolation enforced in the database itself, so one customer’s data cannot be read by another even if application code is wrong.
- Role-based access control inside each workspace.
- Screening of uploads for unsafe content before they can be downloaded, and short-lived signed download links.
- An append-only audit trail of changes, and a fresh sign-in requirement for sensitive administrative actions.
- Automated backups, and monitoring and alerting on errors and failures.
- Least-privilege access for our staff, and secrets held outside the codebase.
Measures evolve as threats do. We will not make a change that materially reduces the security of the service.
6. Sub-processors
You give general authorisation for us to use sub-processors. The current list, with what each one does and where it processes data, is in section 5 of the Privacy Policy and is kept up to date there.
We impose data protection obligations on every sub-processor that are no less protective than this addendum, and we remain liable for their performance. We will give at least 30 days’ notice before adding or replacing one. Email hello@reqzi.com to be added to the notification list. If you reasonably object on data protection grounds within that period, we will work with you to find an alternative, and if we cannot, you may terminate the affected part of the service and get a refund of any unused paid period.
7. International transfers
Data is stored in the United Kingdom. Where a sub-processor processes data outside the UK, we rely on UK adequacy regulations where they apply, the UK extension to the EU-US Data Privacy Framework where the provider is certified, and otherwise the UK International Data Transfer Agreement or the EU Standard Contractual Clauses with the UK Addendum, supported by a transfer risk assessment. Those terms are incorporated into this addendum by reference for any transfer they cover.
8. Data subject requests and personal data breaches
Requests from individuals
The service lets you find, correct, export and delete tenancy records yourself, which is normally enough to answer a request. If an individual contacts us directly about data you control, we will not respond substantively; we will tell them to contact you and pass the request on. We will help you answer it, taking into account the nature of the processing.
Breaches
If we become aware of a personal data breach affecting your data, we will notify you without undue delay and in any event within 48 hours, with what we know at the time: the nature of the breach, the categories and approximate number of records and people affected, the likely consequences, and the measures taken or proposed. We will keep you updated as we learn more, and help you meet your own notification duties.
9. Deletion and return
You can export your data at any time from Settings, in a machine-readable format. On termination, or on your instruction, we delete the personal data we process for you, except where UK law requires us to keep it: financial records for up to 7 years, tenancy documents for up to 6 years and audit records for up to 3 years, as set out in the Privacy Policy. Retained data stays protected by this addendum and is not processed for any other purpose. Backups are cycled out on their normal schedule.
10. Audit
We make available the information needed to show we meet Article 28, including this addendum, the security measures in section 5 and answers to reasonable written questions. Where that is not enough, you may audit us, or appoint an independent auditor who is not a competitor of ours, on 30 days’ notice, no more than once a year unless a regulator requires more or there has been a breach affecting your data. Audits happen in working hours, must not disrupt the service or affect other customers’ data, and are subject to confidentiality. Each party bears its own costs.
11. Liability and precedence
Liability under this addendum is subject to the limits in the Terms of Service, except where data protection law prevents that. If this addendum conflicts with the Terms of Service on the processing of personal data you control, this addendum prevails.
12. Contact
Data protection queries, sub-processor notifications and audit requests: hello@reqzi.com. Reqzi Limited, 124 City Road, London EC1V 2NX, United Kingdom.