Skip to main content

NORTHVANE Property

Privacy Notice

Secure Portfolio Platform, operated by NORTHVANE Property. Last updated 8 October 2026.

This notice explains how NORTHVANE Property handles personal information in Secure Portfolio Platform, a service for property organisations in England. It is written for the people who use the service and for individuals whose details may appear in a customer's records.

If you have a question about this notice or about your personal information, contact us at [email protected].

1. Who operates the service

Secure Portfolio Platform is operated by NORTHVANE Property, part of NORTHVANE. You can reach us at [email protected] or through the contact page.

Secure Portfolio Platform is not a government service. We are not part of, and are not endorsed by, any government body.

2. Our role, and your organisation's

Different information is handled in different capacities. For the details we need to run accounts, billing, security and support, we decide how and why the information is used.

For the property, landlord, ownership and compliance records that a customer organisation puts into the service, that organisation decides what to record and why, and we handle those records on its behalf to provide the service. The roles that apply to particular processing can depend on the circumstances and may be set out in the agreement with a customer.

If your details appear in a customer's records and you want to exercise a right over them, you can contact the organisation concerned, or contact us and we will help direct your request.

3. Information we may process

Depending on how the service is used, this may include:

  • Account and user details, such as name, email address and sign-in identifiers.
  • Organisation details, such as the organisation's name, its members and their roles.
  • Landlord and ownership information, including details of individuals connected to an ownership entity, such as directors, trustees and contacts.
  • Property records, such as addresses, identifiers and portfolio groupings.
  • Tenancy information where supplied, such as occupancy numbers, rent, dates and deposit protection facts. The service is designed so that tenant names, contact details and dates of birth are not required.
  • Compliance information, such as gas, electrical, energy performance and licence records and their dates.
  • Uploaded documents, such as certificates and supporting evidence.
  • Registration and workflow information, such as readiness assessments, registration packs and recorded outcomes.
  • Billing and subscription information, such as plan, billing history and payment status, and reference identifiers from our payment provider. Card details are entered on our payment provider's secure pages and handled by them; we do not receive or store full card numbers. Where we show the card on file (its brand, last four digits and expiry date), we retrieve it from the payment provider when you view it rather than storing it.
  • Audit and security records, such as a record of changes made to data and of sign-in and access activity.
  • Technical and service logs needed to run and secure the service.
  • Support communications, such as the emails you send us.

Most of this information is provided by users, or by their organisation, when they use the service. Some is created by the service, for example readiness assessments and audit records.

4. Why we use information

  • Providing the service you or your organisation asked for.
  • Authenticating users and administering accounts.
  • Managing customer organisations, members and roles.
  • Storing and processing property, landlord and compliance records.
  • Supporting compliance and regulatory administration, including preparing registration packs.
  • Generating exports of an organisation's records.
  • Billing and subscription administration.
  • Keeping the service secure and preventing fraud and misuse.
  • Giving support and responding to enquiries.
  • Meeting legal and regulatory obligations.

We rely on lawful bases that depend on the activity, such as performing our contract with a customer, our legitimate interests in running and securing the service, complying with legal obligations and, where we ask for it, consent.

5. Service providers

We use carefully selected providers to operate the service. They process information for us only to provide their service. They currently include:

  • Clerk, for authentication and sign-in.
  • Railway, for application hosting and the database.
  • Cloudflare R2, for private document storage.
  • Stripe, for payments and subscription billing.
  • Resend, for sending email.

We may use other providers where needed to run the service, and may change providers over time. We do not sell personal information.

6. Where information is processed

Some of our providers may process information outside the United Kingdom. Where that happens we expect appropriate safeguards to be in place, as required by data protection law.

7. Security

We use measures designed to protect information, including separated organisation workspaces enforced in the database, role-based access, private document storage, short-lived secure links for downloads, and an audit history of changes. No system is completely secure, and we cannot guarantee absolute security.

8. How long we keep information

We keep information for as long as it is needed to provide the service and to meet our legal, accounting and security obligations. Compliance and audit records are kept as historical records.

When a paid service ends, the organisation's account stays available for a retrieval period of 30 days so that its records can be viewed and exported. We will tell customers if we change how long information is kept after that.

9. Exporting and deleting information

Organisation owners can request an export of their organisation's records and documents. To ask about deleting information, contact us at [email protected]. We will consider each request, and some information may need to be kept to meet legal or security obligations.

10. Your rights

Under data protection law you may have the right to be informed about, access, correct, erase, restrict and object to the use of your personal information, and to data portability, in some circumstances. To use a right, contact us at [email protected]. We may need to confirm who you are.

11. Complaints

Please contact us first so we can try to put things right. You also have the right to complain to the UK Information Commissioner's Office (ICO) at ico.org.uk.

12. Changes to this notice

We may update this notice as the service develops. The date at the top shows when it was last updated. Where a change is significant, we will take reasonable steps to tell customers.