Document Version: 2.0 (Updated July 2026)
Effective Date: December 2012
This Privacy Policy covers the collection, use, disclosure, and overall processing of personal information collected by TouchRight Software Limited (hereinafter, “TouchRight”) whenever you interact with our platform, website, or mobile applications. TouchRight is committed to ensuring that your privacy is protected. Any information provided by which you can be identified will be utilised strictly in accordance with applicable UK data protection laws and this privacy policy.
TouchRight is formally registered with the Information Commissioner’s Office (ICO) under registration number ZC126654. We may update this policy from time to time by updating this page, and we encourage you to review it periodically to ensure you are satisfied with any changes.
1. Scope of Applications & Data Categorisation
We collect, store, and process distinct categories of information to reliably operate our property software platform, applications, and services:
- Identity and Contact Data: Full name, job title, email address, telephone number, and business demographic details such as postcodes.
- Technical and Usage Data: We collect system interactions to assist users with technical queries. This includes diagnostic app telemetry collected via Crashlytics (which contains no personally identifiable information) and application navigation telemetry captured through our digital adoption provider, Product Fruits.
- Location Data: Our native mobile application includes a Lone Worker protection feature that relies on active device location services. TouchRight requests limited access to your geographic location data only while the application is actively in use. This data is stored within your private account for your exclusive operational use. The feature is an efficiency aid designed to accompany, not replace, your existing corporate lone worker procedures. TouchRight accepts no liability for localized technology or connection failures.
- Portfolio and Content Data (Client Uploaded): When a client takes out a software subscription, they upload property portfolio files to their dashboard. This data includes landlord names, property addresses, landlord email addresses, landlord telephone numbers, tenant names, tenant email addresses, tenant telephone numbers, and property inspection photographs. This data has a specified, explicit, and legitimate purpose; TouchRight processes it strictly as a Data Processor on behalf of the client and will never pass this data to unapproved third parties.
2. How We Collect Personal Data
We collect personal information through the following touchpoints:
- When you directly input details to set up or upgrade your platform account.
- When you actively utilise the TouchRight Service and navigate our desktop or mobile software builds.
- When you communicate directly with our customer support teams over the telephone, via live chat, or through an online contact form.
- Indirectly, when a registered TouchRight client inputs your personal information (e.g., as a landlord, tenant, or occupant) into their private dashboard to facilitate an inventory report.
3. Purposes and Lawful Bases for Processing
We require this data to understand your operational requirements and provide a more resilient software service. In compliance with the UK GDPR, we map our processing activities to the following approved lawful bases:
| Processing Purpose / Activity |
Data Type Involved |
Lawful Basis for UK GDPR Compliance |
| Core provisioning of our SaaS tools, user logins, and daily commercial platform requirements. |
Identity, Contact, and Portfolio Data |
Contractual Necessity: Necessary to perform our core software service agreement with you. |
| Setting up a trial environment or a paid subscription account. |
Identity, Contact, and Demographic Data |
Contractual Necessity: Actively submitted by the user to activate specific account features. |
| Routine internal record keeping, corporate administration, invoicing, and billing structures. |
Identity, Contact, and Transactional Data |
Contractual Necessity & Legal Obligation: Crucial for contract execution and compliance with UK corporate financial reporting rules. |
| Platform performance monitoring, bug identification, and software safety upgrades. |
Technical and Usage Data (Crashlytics/Product Fruits) |
Legitimate Interests: To continuously improve our systems, protect account security, and prevent platform abuse. |
| Sending periodic marketing communications, software updates, and product feature announcements. |
Contact Data (Email Addresses) |
Consent: Collected via explicit opt-in checkboxes upon account activation. This consent can be entirely withdrawn at any time. |
4. Artificial Intelligence Processing Safeguards (ReportAssist)
Our platform features an integrated ReportAssist module that utilises enterprise-grade Application Programming Interfaces (APIs) powered by third-party large language models (such as OpenAI architecture) to analyse property indicators and compile automated textual property descriptions.
To maintain strict data confidentiality, the following system rules are enforced:
- Zero Model Training: Data, text, and property images transmitted to our AI sub-processors via the API are processed exclusively for real-time descriptive generation. They are never stored, harvested, or repurposed by third-party providers to train public models.
- Human-in-the-Loop Accountability: ReportAssist functions solely as an efficiency tool. The final responsibility for checking data accuracy and signing off the property report rests entirely with the registered human operator. TouchRight accepts no liability for errors, omissions, or deposit claim disputes arising from AI-generated text.
- Media Guidelines: TouchRight customers must ensure they have robust data controller procedures in place and warrant that they have obtained all necessary consents before uploading third-party information. Users must avoid uploading property photographs containing clear, identifiable personal data (such as sensitive financial documents or family portraits) into the AI generation queue.
5. Security & Data Breach Protocols
TouchRight implements appropriate technical and organisational measures to protect personal data from accidental or unlawful destruction, loss, alteration, or unauthorised disclosure. We have put in place suitable physical, electronic, and managerial procedures to safeguard our online environments. We do not sell or rent your contact information to third-party marketers.
- Access Key Protection: TouchRight monitors and controls the use and distribution of its AWS access keys. Account Owners are solely responsible for managing the user profiles within their subscription, and must immediately disable access credentials whenever an employee leaves the firm to prevent unauthorized entry.
- Breach Notification: In the highly unlikely event of a security compromise that is likely to adversely affect individuals’ rights and freedoms, TouchRight will inform all impacted customers immediately and notify the Information Commissioner’s Office (ICO) within 72 hours of becoming aware of the incident. We maintain a comprehensive internal log of all personal data breaches, regardless of whether statutory notification is mandated.
6. Data Retention, Account Closure, and Deletion
We will only retain personal data for as long as is reasonably necessary to fulfil the business purposes it was collected for, including satisfying any legal, regulatory, tax, accounting, or statutory reporting requirements.
Upon the official termination of your software subscription:
- Live Environment Boundary: Active personal data, user profiles, and associated property media are systematically removed from our active, live platform databases 90 days following the contract termination date. Following this 90-day window, standard data accessibility terminates and recovery cannot be contractually guaranteed.
- Deactivation of Shared Assets: From the immediate date of contract termination, all external web links to historical inspection reports previously shared with third parties (such as landlords or tenants) will be instantly deactivated, and enhanced media functionalities (including click-to-enlarge photo features) will be disabled.
- The Hibernate Exception: Where a client actively elects to transition to our Hibernate Plan, personal data and historical report profiles are securely maintained in an active, read-only state. This preserves active data access, report downloads, and third-party web link continuity for the duration of the hibernate agreement.
- Customer-Initiated Data Erasure: If a customer manually deletes files within an active account, landlord/tenant profiles are logically deleted immediately upon request and personally identifiable information (PII) is fully removed after 12 months. Property records and completed reports are logically deleted and stored for 24 months before final PII removal. Full, comprehensive data destruction can be executed upon written request.
7. Your Statutory Rights Under UK GDPR
You can contact our teams at any time to exercise your statutory rights under the UK GDPR and Data Protection Act 2018:
- Right to Withdraw Consent: Cancel previously granted permissions to receive marketing updates or product development announcements.
- Right of Access (Subject Access Requests): You may request details of the personal data we hold about you. Requests must be made via email to info@touchrightsoftware.com, stating your full name, email address, and account name for verification. Information will be provided electronically and free of charge within the statutory UK limit of one calendar month of receipt.
- Right to Rectification: Mandate the immediate correction of inaccurate or outdated contact information.
- Right to Erasure ("Right to be Forgotten"): Request the deletion of personal records where there is no overriding legal or contractual reason for TouchRight to continue processing it.
- Right to Restrict Processing: Suspend active data handling while we establish accuracy or investigate processing objections.
- Right to Data Portability: Receive a copy of your account data in a structured, commonly used, and machine-readable format. Requests will be completed free of charge within 30 working days. PDF reports remain freely downloadable by active customers at any time.
- Right to Object: Challenge how your data is handled, including objecting to analytics, market research, or profiling activities.
8. Cloud Infrastructure & Sub-Processors
As a cloud-based Software-as-a-Service provider, we store platform data inside secure virtual environments managed by Amazon Web Services (AWS) servers. AWS maintains zero operational visibility over our database content and treats all customer uploads with identical, best-in-class infrastructure security controls.
- Geographic Sovereignty: Our primary data storage region is hosted securely within the AWS Ireland (Dublin) zone. AWS does not move content outside our chosen boundaries unless severe localized server faults impact data availability.
- International Transfer Protections: To protect data flows across international borders, TouchRight utilises approved Standard Contractual Clauses (SCCs) embedded within the AWS Data Processing Addendum alongside the UK International Data Transfer Agreement (IDTA) where data moves to third countries outside the UK and EEA.
- Core Sub-Processors: We share defined components of data with trusted operational partners to maintain day-to-day services.
Explicit list naming our core sub-processing partners is available upon request. Additionally, clients may choose to grant third-party applications access to their data by enabling our API. TouchRight controls the API connection but is not responsible for the privacy policies or data-handling methods utilised by those external platforms. All API usage is governed by our separate TouchRight API Terms.
9. Backups and Data Restoration
All TouchRight system directories, account configurations, and property databases stored within the AWS environment are backed up daily every night. In the event of an enterprise-level infrastructure fault or a physical data incident, our operational continuity protocols ensure that this daily backup can be successfully restored into a live environment within 24 hours, mitigating the risk of long-term data loss or platform unavailability.
10. How We Use Cookies
To ensure our web services remain reliable, secure, and user-friendly, navigating our online interface involves placing small text identifiers known as cookies onto your device. Cookies cannot be used to identify you personally.
We utilise cookies for the following operational workflows:
- Strictly Necessary Cookies: Essential for platform security. These recognize your device, maintain your active login status, and validate secure data routing so you do not have to re-enter credentials on every web page request.
- Performance & Telemetry Cookies: We use traffic log cookies to monitor page traction, evaluate system loading speeds, and tailor web performance. These are used for statistical analysis before being removed. This category also includes Product Fruits scripts to deliver interactive, contextual user guides across your dashboard.
A cookie does not grant us access to your computer or pass us any information other than the specific data you actively choose to share. Most web browsers automatically accept cookies, but you can modify your browser parameters to decline them. Because our software relies on session cookies for authentication, blocking essential functional cookies will break user authorization and prevent access to the online dashboard.
11. Links to Other Websites
Our public marketing website may contain links to external web spaces of interest. Once you utilise these links to leave the TouchRight environment, you acknowledge that we maintain no operational control over that external website. Consequently, TouchRight cannot be held responsible for the protection and privacy of any information you submit while visiting external sites, which are governed by their own independent privacy notices.
12. Connect with Us & Complaints
TouchRight Software Ltd is a registered company in England and Wales (Company Registration Number: 8019321). Our registered office is located at 349 Regents Park Road, London, England, N3 1DH. If you have any questions regarding your data protection rights, please contact our support desk directly at info@touchrightsoftware.com.
You retain the statutory right to raise a formal complaint at any time with the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection issues (www.ico.org.uk). We would, however, welcome the opportunity to investigate and address your compliance concerns internally before you approach the regulator, and ask that you contact us in the first instance.
Copyright © 2026 TouchRight Software Ltd. All rights reserved.