Privacy Policy
Last updated: 19 February 2026
1. Introduction
LeaseSwift ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.
By using LeaseSwift, you consent to the data practices described in this Privacy Policy. If you do not agree with the practices described in this policy, please do not use the Service.
2. Information We Collect
2.1 Personal Information
We collect personal information that you provide directly to us, including:
- Name and contact information (email address, phone number)
- Company name and business information
- Payment information (processed securely through Stripe)
- Property addresses and lease information
- Document uploads (lease documents, certificates, etc.)
2.2 Automatically Collected Information
When you use the Service, we automatically collect certain information, including:
- IP address and device information
- Browser type and version
- Usage data and analytics
- Cookies and similar tracking technologies
3. How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve the Service
- Process pack requests and payments
- Generate management packs using AI technology
- Communicate with you about your account and requests
- Send email notifications and updates
- Detect, prevent, and address technical issues
- Comply with legal obligations
- Protect the rights and safety of users and third parties
3.1 Legal Basis for Processing (GDPR Article 6)
Under UK GDPR, we process your personal data based on the following legal bases:
Contract Performance (Article 6(1)(b))
We process your personal data to fulfill our contract with you and provide the Service. This includes:
- Processing your account information (email, company name, contact details) to create and manage your account
- Processing property data and documents to generate management packs
- Processing payment information to complete pack requests
- Communicating with you about your pack requests and account
Legitimate Interest (Article 6(1)(f))
We process your data based on our legitimate interests in providing and improving our Service. This includes:
- Processing documents using AI technology to extract lease information (essential for core service functionality)
- Sending service-related emails (notifications, updates about your pack requests)
- Security monitoring and fraud prevention
- Service analytics and improvement
We have balanced our legitimate interests against your privacy rights and believe our processing is necessary and does not override your rights.
Consent (Article 6(1)(a))
Where we process data based on consent (e.g., marketing communications), you have the right to withdraw your consent at any time by contacting us at privacy@leaseswift.co.uk.
4. Data Processing and AI
LeaseSwift uses artificial intelligence (AI) to process lease documents and generate management packs. This involves:
- Uploaded documents are processed using AI services (OpenAI API) to extract lease information
- Document content is analyzed to generate LPE1 forms and management packs
- Data is processed securely and in accordance with this Privacy Policy
- We do not use your data to train AI models for purposes other than providing the Service
By uploading documents, you consent to this AI processing of your data for the purpose of generating management packs.
5. Data Sharing and Disclosure
We may share your information in the following circumstances:
5.1 Service Providers
We share information with third-party service providers who perform services on our behalf, including:
- Payment processing (Stripe)
- Email delivery (Resend)
- AI processing (OpenAI API)
- Cloud hosting and storage (AWS)
- Authentication (Clerk)
5.2 Legal Requirements
We may disclose your information if required by law or in response to valid requests by public authorities (e.g., a court or government agency).
5.3 Business Transfers
If we are involved in a merger, acquisition, or asset sale, your information may be transferred as part of that transaction.
5.4 Data Processing Agreements
All third-party service providers who process personal data on our behalf are required to enter into Data Processing Agreements (DPAs) that comply with UK GDPR requirements. These agreements ensure that:
- Processors only process data for specified purposes
- Appropriate security measures are in place
- Data is not used for purposes other than providing the Service
- Processors assist us in fulfilling data subject rights requests
Our key data processors include:
- AWS (Amazon Web Services): Cloud hosting and storage (EU region: eu-west-2) - DPA in place
- OpenAI: AI document processing (US, with data processing safeguards) - DPA verification in progress
- Stripe: Payment processing (US/EU) - DPA in place
- Clerk: Authentication services (US) - DPA verification in progress
- Resend: Email delivery (US) - DPA verification in progress
If you would like to request a copy of any Data Processing Agreement, please contact us at privacy@leaseswift.co.uk.
6. Data Storage and Security
We implement appropriate technical and organizational measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. This includes:
- Encryption of data in transit and at rest
- Secure cloud storage on AWS
- Access controls and authentication
- Regular security assessments
However, no method of transmission over the Internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your information, we cannot guarantee absolute security.
7. Data Retention
We retain your personal information for as long as necessary to provide the Service and fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law.
When you delete your account, we will delete or anonymize your personal information, except where we are required to retain it for legal, regulatory, or business purposes.
8. Your Rights (GDPR)
If you are located in the European Economic Area (EEA) or UK, you have certain data protection rights:
- Right to Access: Request copies of your personal data
- Right to Rectification: Request correction of inaccurate data
- Right to Erasure: Request deletion of your personal data
- Right to Restrict Processing: Request restriction of processing your data
- Right to Data Portability: Request transfer of your data to another service
- Right to Object: Object to processing of your personal data (including processing based on legitimate interests)
- Right to Withdraw Consent: Withdraw consent at any time (where processing is based on consent)
To exercise these rights, please contact us at privacy@leaseswift.co.uk. We will respond to your request within 30 days. If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at https://ico.org.uk/make-a-complaint/.
8.1 Data Breach Notification
In the event of a personal data breach that is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay and within 72 hours of becoming aware of the breach, where feasible.
Our notification will include:
- A description of the nature of the breach
- The categories and approximate number of data subjects concerned
- The likely consequences of the breach
- The measures we have taken or propose to take to address the breach
- Contact details for our Data Protection Contact if you need more information
We will also notify the Information Commissioner's Office (ICO) within 72 hours if the breach is likely to result in a risk to individuals' rights and freedoms.
If you suspect a data breach or have concerns about the security of your data, please contact us immediately at privacy@leaseswift.co.uk.
9. Cookies and Tracking Technologies
We use cookies and similar tracking technologies to track activity on our Service and store certain information. Cookies are files with a small amount of data that may include an anonymous unique identifier.
You can instruct your browser to refuse all cookies or to indicate when a cookie is being sent. However, if you do not accept cookies, you may not be able to use some portions of our Service.
10. Children's Privacy
Our Service is not intended for children under the age of 18. We do not knowingly collect personal information from children. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately.
11. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence. These countries may have data protection laws that differ from those in your country.
We ensure that appropriate safeguards are in place to protect your information in accordance with this Privacy Policy, including standard contractual clauses and other legal mechanisms.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date.
You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page.
13. Contact Us
If you have any questions about this Privacy Policy or our data practices, please contact us at:
Email: info@leaseswift.co.uk
Data Protection Contact: privacy@leaseswift.co.uk
For data protection inquiries, GDPR rights requests, or to report a data breach, please contact our Data Protection Contact at privacy@leaseswift.co.uk. We will respond to your inquiry within 30 days.