← Back to YourBuilding

Data Processing Agreement

Between RTM companies and YourBuilding

Last updated: 15 May 2026

Introduction

This Data Processing Agreement (DPA) sets out the obligations of YourBuilding (yourbuilding.uk) as a data processor when acting on behalf of an RTM company as the data controller.

This agreement applies automatically when an RTM company is formed through the YourBuilding platform and uses the platform to manage its building and associated leaseholder data.

By continuing to use YourBuilding after forming an RTM company, the RTM company agrees to the terms of this agreement.

The parties

Data Controller: The RTM company formed by qualifying tenants at the relevant building, as registered with Companies House.

Data Processor: YourBuilding, operated at yourbuilding.uk. Contact: hello@yourbuilding.uk

What data is processed

YourBuilding processes the following categories of personal data on behalf of the RTM company:

  • Names and correspondence addresses of qualifying tenants, retrieved from HM Land Registry
  • Contact details (email address, phone number) of leaseholders provided by the RTM company's directors
  • Survey responses collected from leaseholders during the consensus-building process
  • Director information including names, roles and digital signatures
  • Service charge data and financial information relevant to the RTM process
  • Correspondence and notices generated and sent through the platform

The data subjects are qualifying tenants and leaseholders at the building managed by the RTM company.

Purpose and duration

YourBuilding processes this data solely for the purpose of providing the Right to Manage platform services to the RTM company, including eligibility checking, document generation, leaseholder outreach, and building management tools.

Processing continues for as long as the RTM company uses the platform and for six years thereafter, in line with standard legal document retention requirements.

Processor obligations

YourBuilding agrees to:

Process personal data only on documented instructions from the RTM company, as set out through use of the platform.

Ensure that all personnel with access to personal data are subject to appropriate confidentiality obligations.

Implement appropriate technical and organisational security measures to protect personal data, including encrypted data storage, access controls and secure data transmission.

Not engage any sub-processors without informing the RTM company. Current sub-processors are listed in the YourBuilding Privacy Policy at yourbuilding.uk/privacy-policy.

Assist the RTM company in responding to data subject rights requests within the required timeframes.

Notify the RTM company without undue delay, and within 72 hours where possible, of any personal data breach affecting data processed under this agreement.

Delete or return all personal data at the end of the service relationship, subject to any legal retention requirements.

Make available all information necessary to demonstrate compliance with this agreement and with Article 28 of UK GDPR.

Controller obligations

The RTM company as data controller agrees to:

Ensure it has a lawful basis for all personal data it instructs YourBuilding to process.

Provide clear and accurate privacy information to leaseholders whose data is processed through the platform, including the notice contained in the YourBuilding Privacy Policy at yourbuilding.uk/privacy-policy.

Handle any data subject rights requests it receives and seek YourBuilding's assistance where needed.

Security

YourBuilding maintains the following security measures:

  • All data stored in Supabase (EU region) with encryption at rest and in transit
  • Access to personal data restricted to authorised platform administrators only
  • Admin access protected by secure authentication
  • Regular review of access controls

Sub-processors

YourBuilding uses the following sub-processors. The RTM company consents to their use by agreeing to this DPA:

  • Supabase - database hosting (EU region)
  • Resend - email delivery
  • Vercel - platform hosting

YourBuilding will notify RTM companies of any changes to sub-processors by updating this page and emailing registered directors.

Data subject rights

Where a leaseholder contacts the RTM company to exercise their UK GDPR rights (access, rectification, erasure, objection), the RTM company should notify YourBuilding at hello@yourbuilding.uk. YourBuilding will provide all necessary assistance within 14 days.

Governing law

This agreement is governed by the laws of England and Wales. Any disputes arising from this agreement are subject to the exclusive jurisdiction of the courts of England and Wales.

Contact

For any questions about this agreement, contact YourBuilding at hello@yourbuilding.uk.

This agreement applies to yourbuilding.uk. This is not legal advice.