Legal · Data resilience
Subscriber data backup & recovery
Where your data lives, how it is backed up and how it would be recovered — plus the exports you can take yourself at any time.
Last updated:
1. Scope
This policy explains how LetCompliance backs up subscriber data and how it would be recovered after a data-loss event. It supplements — and does not replace — our Privacy Policy, Terms of Service and Data Processing Agreement.
2. Where your data is stored
Your account, property, tenancy, compliance and finance records are held in a managed PostgreSQL database hosted in the European Union. Uploaded documents (certificates, tenancy agreements and similar) are kept in encrypted object storage. Data is encrypted in transit (TLS) and at rest (AES-256). Card and bank details are handled by Stripe and are never stored on our systems.
3. Backups
Our database is backed up automatically every day by our managed database provider and retained on a rolling cycle. The platform also supports point-in-time recovery, so the database can be rolled back to a specific moment within the retention window. Backups inherit the same AES-256 encryption and EU data-residency as the live database.
4. Recovery
If data is corrupted or lost, we restore from the most recent healthy backup or, where point-in-time recovery applies, to the last consistent state before the incident. We aim to restore service as quickly as is safely possible. Because recovery time depends on the nature and scale of an incident and on our providers' platforms, we do not commit to a fixed recovery-time guarantee on current plans.
5. Your own exports and copies
You can export your own data at any time — for example transaction and accountant CSV exports, compliance packs and individual document downloads. We strongly encourage you to keep independent copies of business-critical records such as Gas Safety, EICR and EPC certificates and signed tenancy agreements. Your own exports are the simplest and fastest recovery path for your records.
6. Retention and deletion
While your subscription is active we retain your data so the Service works. After cancellation we keep your data for 30 days so you can reactivate or export it, then permanently delete it from the live database; backup copies then age out on the provider's standard backup-retention cycle. You can ask us to delete your data sooner.
7. Incidents and continuity
Security incidents and personal-data breaches are handled under our security process. Where a breach is likely to affect your rights, we notify affected customers and, where the law requires it, the ICO. You can report a suspected vulnerability via the contact in our security.txt or on our Security page.
8. Limitations
No backup or recovery system is infallible. This policy describes our current practices; it is not a warranty of uninterrupted availability or zero data loss. For your most critical records, keep your own copies in addition to using the Service.
9. Contact
Questions about this policy: letcomplianceuk@gmail.com.