These documents are being prepared for launch. Our Stairwell Ltd has not yet been incorporated. Customer subscriptions will open only after incorporation and completion of the supplier details and launch terms. This draft does not offer a subscription from an existing limited company.
Our Stairwell Ltd has not yet been incorporated and there are no customer subscriptions. Before incorporation, the individual operating Our Stairwell is responsible for personal information used for website enquiries and other pre-launch activities. The operator's full identity and contact address must be completed in this notice before public use. Contact privacy@ourstairwell.uk. Before customers join, this notice will identify the incorporated company and its contact details for activities where it decides why and how personal information is used. No statutory data protection officer has been appointed; this mailbox is the privacy contact.
1. Scope and our different roles
This notice covers visitors to our websites; prospective customers and their contacts; customer administrators and billing contacts; account holders and invited users; people who contact support; people who open an invitation or public sale-pack link; contractors and professional advisers; and other people whose information we use for our own business purposes.
A customer association normally decides why resident, owner, tenant, building, governance, finance, contractor and workspace records are used. It is the controller for those records and we operate the platform as its processor, under the Data Processing Agreement. If your question is about information in an association workspace, contact the association first. We will help it answer requests.
We act as a separate controller when we decide to use information for our website and enquiries, contracting, account and service administration, billing, fraud and misuse prevention, security, support operations, legal compliance, complaints and legal claims. Support content about a customer's residents or records may still be processed on that customer's instructions even though we control the limited ticket, security and service-management records around it.
2. Information we receive
Depending on how you interact with us, we may receive:
- name, email address, postal address, telephone number, role, organisation and unit relationship;
- account, authentication, invitation, permission and profile identifiers;
- customer setup, contract acceptance, authority, plan, billing and payment-status information;
- messages, support correspondence, attachments, feedback and complaint information;
- public sale-pack link details and records of link views or downloads;
- IP address, browser and device details, request identifiers, timestamps, security events and audit records;
- information a customer or another authorised user enters about you in its workspace; and
- other information you choose to give us or that is needed to deal with a request.
We receive information directly from you; from the customer association and its authorised users; from identity, email, payment and integration providers; and, where relevant, from public registers such as Companies House. If another person provides your information, the relevant customer should also give you its own privacy information.
Please do not put special-category information, criminal-offence information or unnecessary information about other people into a contact or support message. Customer workspace content may contain such information only where the customer has decided it is necessary and lawful.
3. Why we use information and our lawful bases
| Purpose | Typical information | Lawful basis when we are controller |
|---|---|---|
| Answer enquiries, arrange demonstrations and take requested pre-contract steps | Contact details, role, organisation, unit count and message | Steps at your request before a contract and our legitimate interests in responding and developing customer relationships |
| Set up and administer customers, accounts, subscriptions, contracts and payments | Identity, organisation, authority, acceptance, billing contact, plan and payment status | Contract where you are the contracting individual; otherwise our and the customer's legitimate interests in performing the business contract; legal obligation for tax and accounting records |
| Authenticate users, control access, protect the service and investigate misuse or incidents | Account identifiers, roles, IP, device, browser, request, event and audit information | Our and customers' legitimate interests in providing a secure service, and compliance with legal security obligations |
| Provide support, diagnose faults and improve service reliability | Contact details, ticket content, relevant account context and diagnostic information | Contract or legitimate interests in supporting and improving the service; legal obligation where a request concerns data-protection rights |
| Handle privacy requests, complaints, disputes and legal claims | Identity, request, evidence, correspondence and outcome | Legal obligation and legitimate interests in establishing, exercising or defending legal claims |
| Send genuinely optional direct marketing | Name, business contact details, preferences and suppression status | Consent where electronic-marketing law requires it; otherwise legitimate interests after the required balancing assessment. You may object at any time |
Where we process customer workspace information only on the association's instructions, its lawful basis applies rather than one chosen by us. You are not generally required by law to give us information, but required form, account, contract or payment details are needed to provide the requested service. If they are not provided, we may be unable to respond, create an account or supply the service.
4. Contact forms, invitations and public links
The contact form sends the details you enter to our support system. We and Cloudflare use your IP address, a short-lived Turnstile token and browser signals to distinguish people from bots and rate-limit misuse. Turnstile tokens expire after five minutes. Contacting us does not by itself add you to a marketing list.
Invitation pages use the invitation code, email address, account details and security information to validate and accept an invitation. Invitation links normally expire after 30 days. Public sale-pack pages use the access token and record limited view, download, IP, browser and audit information to protect the link and give the customer an access record. Public sale-pack links expire no later than 30 days after creation unless revoked sooner. The customer association is normally controller for the invitation, sale-pack content and viewer details.
5. Cookies and similar technology
We currently use only storage and access technology needed to authenticate users, preserve security, prevent fraud or technical faults, remember an action you request, and provide features you choose to use. We do not currently load advertising technology, optional audience analytics or browser session replay. Our Cookies and Storage Notice identifies the technology currently in use, its purpose and normal duration. If our use changes, we will update that notice and provide the consent or objection control required by law before enabling the new technology.
6. Who receives information
We disclose information only as needed to:
- the relevant customer association and its authorised users;
- hosting, content-delivery, security, authentication, storage, search, support, email, monitoring and backup providers;
- payment providers and customer-selected accounting or calendar integrations;
- professional advisers, insurers, auditors and prospective purchasers under appropriate confidentiality controls; and
- regulators, courts, law-enforcement bodies or other recipients where disclosure is required or legally justified.
Important providers and their functions are listed on our Subprocessor List. GoCardless and some customer-selected integrations may act as independent controllers under their own privacy notices. We do not sell personal information.
7. International transfers
Our core production hosting is intended to be in the United Kingdom, but providers including Cloudflare, Resend, Google and OpenAI may process information in the United States or other countries. Where a restricted transfer requires a safeguard, we use an applicable UK adequacy regulation, the UK Extension to the EU-US Data Privacy Framework, the UK International Data Transfer Agreement, the UK Addendum to EU Standard Contractual Clauses, or another lawful mechanism. We assess the transfer and use supplementary security measures where appropriate. Contact us for information about a relevant safeguard.
8. How long we keep information
| Record | Normal retention |
|---|---|
| Uncompleted onboarding draft | Up to 90 days after it was last saved |
| Contact and sales enquiry | Until resolved and normally up to 24 months after the last meaningful contact; longer if it becomes a customer, complaint or legal record |
| Support ticket | Normally up to 24 months after closure; material contract, security, complaint or legal correspondence may be kept for up to six years |
| Contract acceptance, invoice, payment and tax record | Normally six years after the end of the customer relationship or relevant accounting period |
| Central operational logs | Normally three days; separately retained error or incident evidence may be kept for up to 90 days or longer while an investigation or claim requires it |
| Live customer workspace | For ordinary paid or trial access and normally 90 days after that access ends following voluntary cancellation; for qualifying non-payment, normally 90 days from the payment failure or mandate loss, subject to the customer contract and instructions |
| Protected backups and restricted compliance archive | Until the applicable backup deletion cycle; selected records may be retained for up to six years where a documented legal, tax, accounting, regulatory or claims purpose requires them |
| Marketing suppression record | Minimal contact and objection details for as long as needed to honour the objection |
We may keep a record longer where a legal hold, active dispute, regulator or law requires it, and may delete it sooner when it is no longer needed. Customer associations set retention for workspace content; after live deletion, backup copies are put beyond ordinary use until their deletion cycle. A six-year archive is not intended to include an entire workspace by default: only records justified by the specific legal or business-record purpose should be selected.
9. Your rights
Depending on the circumstances and lawful basis, you may ask for access to your information, correction, erasure, restriction, or portability; object to processing based on legitimate interests or to direct marketing; and withdraw consent without affecting earlier processing. You also have rights concerning decisions made solely by automated means that have legal or similarly significant effects.
We use automated security checks to validate requests and rate-limit suspected misuse. They may temporarily reject or delay a request, but we do not use solely automated decisions that produce legal or similarly significant effects. Contact privacy@ourstairwell.uk to exercise a right. We may need proportionate information to confirm your identity. If the information is controlled by a customer association, we will normally refer the request to that association and assist it.
10. Data-protection complaints
You may make a data-protection complaint in plain language by emailing privacy@ourstairwell.uk. Tell us what happened, which information or right is involved, the outcome you want and any relevant dates or evidence. We will acknowledge a data-protection complaint within 30 days, make appropriate enquiries, keep you informed about progress and tell you the outcome without undue delay.
You may also complain to the Information Commissioner's Office at ico.org.uk/make-a-complaint, telephone 0303 123 1113, or write to Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF. We would appreciate the opportunity to address the issue first, but you do not have to contact us before seeking regulatory assistance.
11. Changes to this notice
We will update this notice when our identity, services, providers or processing materially changes. When a limited company takes over the business, this notice must be updated to name the company, company number and registered office, explain any transfer of existing records and identify the effective date. Material changes will be brought to affected people’s attention where appropriate.