Legal
Privacy Policy
Last updated: 6 June 2026
Factorly Ltd (“Factorly”, “we”, “us”, “our”) operates the Factorly property management platform. This Privacy Policy explains how we collect, use, disclose, and protect personal data when you use our services, in compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Data controller
Factorly Ltd is the data controller for personal data processed through the Factorly platform. If you have questions about this policy or your data rights, contact us at contact@factorly.co.uk.
2. Data we collect
Account data
When you register, we collect your name, email address, and (if applicable) a hashed password. We never store plain-text passwords.
Property and tenancy data
Property factors may enter data about properties, units, and residents as part of their normal factoring operations. This may include names, contact details, ownership records, and payment history of third parties (property owners and tenants).
Payment data
We process payments through a PCI-DSS-compliant payment provider. We do not store card numbers or payment credentials — these are handled entirely by that provider in accordance with PCI DSS standards.
Usage data
We collect usage data (page views, feature interactions, browser type, IP address) for security, performance monitoring, and product improvement.
Communications
Messages sent through the platform (direct messages, announcements) are stored to provide the service. We do not read message content unless required for a support request or legal obligation.
3. How we use your data
- To provide and maintain the Factorly platform
- To process and record payments on your behalf
- To send service notifications (charges raised, meeting invites, poll deadlines)
- To fulfil our legal and regulatory obligations
- To detect and prevent fraud and abuse
- To improve the platform through aggregated, anonymised analytics
4. Legal basis for processing
We process personal data under the following legal bases:
- Contract performance — to provide the service you or your employer has contracted for
- Legitimate interests — for security monitoring, fraud prevention, and product improvement
- Legal obligation — to comply with applicable law, including HMRC requirements and the Property Factors (Scotland) Act 2011
- Consent — for marketing communications (you can withdraw consent at any time)
5. Data sharing
We share personal data only with the service providers that help us run the platform, under contracts that require them to protect it:
- Amazon Web Services — cloud hosting, database and file storage (UK region)
- Anthropic (via AWS Bedrock) — AI features, processed within the AWS UK/EU region
- A transactional email-delivery provider
- Real-time messaging and error-monitoring providers
- PCI-DSS-compliant payment and Direct Debit processors (only where you enable payments)
A complete, current list of our named sub-processors is available on request and is set out in the Data Processing Agreement we execute with customer firms.
We do not sell personal data to third parties. We do not use personal data for advertising purposes.
6. Data retention
We retain account and property data for the duration of your subscription plus 7 years, to meet legal and accounting obligations. You may request deletion of your account at any time — we will delete personal data within 30 days, subject to legal retention requirements.
7. Your rights under UK GDPR
You have the right to:
- Access the personal data we hold about you
- Correct inaccurate data
- Request deletion of your data (right to erasure)
- Restrict or object to processing
- Receive a copy of your data in a portable format
- Withdraw consent at any time (where processing is based on consent)
To exercise any of these rights, email contact@factorly.co.uk. We will respond within 30 days.
8. Security
All data is encrypted in transit (TLS 1.2+) and at rest. Access to production systems is restricted to authorised personnel. We conduct regular security reviews. If you believe you've found a security vulnerability, please email contact@factorly.co.uk.
9. Marketing telemetry
When you visit the Factorly marketing site, we emit a small number of named events to our error-monitoring and analytics provider to understand how visitors navigate the site and convert to enquiries. No separate analytics vendor is used.
Events collected
marketing.page_view— recorded on each marketing page visitmarketing.cta_click— recorded when you click a primary call-to-action (e.g. “Book a demo”, “Sign in”)marketing.pricing_view— recorded when you view the pricing pagemarketing.contact_form_open— recorded when the contact form loadsmarketing.contact_form_submit_success— recorded on a successful enquiry submissionmarketing.contact_form_submit_error— recorded if a submission fails
Consent and opt-out
Marketing telemetry is opt-in. Events are only emitted after you click “Accept” on the cookie banner. If you click “Decline”, no events are sent for the duration of your browser session and beyond (your choice is persisted in browser local storage under the key marketing_consent). You can revoke consent at any time by clearing marketing_consent from your browser's local storage (DevTools → Application → Local Storage).
If your browser has “Do Not Track” enabled, all marketing events are suppressed regardless of consent state.
IP address handling
Server-side events (e.g. contact form submissions reaching our API) include a hashed IP address. We apply HMAC-SHA256 with a per-month rotating salt before transmission, so the raw IP address is never sent to our provider. The same IP hashes identically within a given calendar month and differently across months, making cross-month correlation infeasible.
Client-side events (page views, CTA clicks) do not include an IP address — the browser SDK does not transmit the visitor's IP.
10. Cookies
We use a single authentication cookie (authjs.session-token) that is strictly necessary for login. We do not use tracking or advertising cookies. You cannot opt out of the session cookie as it is required for the application to function.
11. Changes to this policy
We may update this policy periodically. Material changes will be notified via email or in-app notice. The date at the top of this page reflects the most recent revision.
12. Complaints
If you are unhappy with how we handle your data, you may lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.