Privacy policy

Last updated 11 September 2026

PROVIA is the software; OPSERION is the company that builds and operates it, and is the organisation named in this policy. It explains what OPSERION does with personal data in connection with PROVIA, and it covers two different relationships — it matters which one you are in.

Two roles, and which applies to you

If you are a PROVIA customer — a landlord or agency with an account — OPSERION is the controller of your account data: your name, email, phone number and billing details.

If you are a tenant whose details appear in a landlord’s PROVIA account, that landlord is the controller. OPSERION is only the processor, acting on their instructions. We do not decide what is held about you or how long it is kept.

That distinction decides who you ask. Tenants should contact their landlord or agency first; if you cannot reach them, write to us at george@opserion.uk and we will help you reach the right person. The terms on which we act as a processor are in the data processing agreement.

What we hold about customers

DataWhyLawful basis
Name, email, phoneRunning your account and contacting you about itContract
Password (hashed, never stored in readable form)Signing you inContract
Organisation name, address, currencyConfiguring your accountContract
Sign-in times and actions taken in the appSecurity, and the audit trail your account relies onLegitimate interests
Billing recordsTaking payment and meeting tax obligationsContract, and legal obligation
Support correspondenceAnswering youLegitimate interests

What is held on behalf of landlords

When a landlord uses PROVIA, the following may be stored in their account. We process it only to provide the service to them:

  • Tenant names, phone numbers, email addresses and dates of birth
  • Identification details and uploaded ID documents
  • Employment and emergency contact details
  • Tenancy terms, rent, deposits and payment history
  • Uploaded documents — contracts, receipts, photographs
  • Records of text messages and emails sent, and their delivery status
  • Whether an email we sent was opened, where the landlord’s deployment has that switched on — see below
  • Maintenance requests and their resolution
  • Tenancy agreements, and the name, date and time a tenant typed when signing one
  • What a tenant says about a standing order they have set up with their own bank
  • Lines from a bank statement the landlord has chosen to import — a date, an amount, a description and a reference

Imported bank statement lines are the landlord’s own statement, uploaded by them as a file. OPSERION has no connection to anybody’s bank account, cannot see one, and cannot move money. Only credits are kept; what a landlord spends is their business and is discarded on import.

Uploaded identification documents can contain special category data — for example a photograph revealing ethnicity, or a document showing nationality. Landlords are responsible for deciding whether to upload such documents and for having a lawful basis to do so. We do not inspect, index or analyse their contents.

Knowing whether an email was opened

Email can be sent with a small tracking image that reports back when a mail client loads it. OPSERION keeps this switched off by default. Where it is switched on, we record the first time a message was opened, how many times the image was fetched, and whether a link in it was followed.

It is a poor measurement and we would rather say so than imply otherwise: some mail clients fetch the image the moment a message arrives, before anybody has read anything, and others never fetch it at all. It is not evidence that a person read a message, and nothing in PROVIA treats it as such — a message read in the tenant portal is recorded separately, because that one actually happened.

Delivery and failure are recorded whether or not tracking is on. Those are facts about whether mail arrived rather than about what anybody did, and they are what answers “they say they never got it”.

What we never do

  • We do not sell personal data, and never have.
  • We do not use customer or tenant data to train machine learning models.
  • We do not use tracking or advertising cookies. See the cookies page.
  • We do not read your documents or your tenants’ documents except where you ask us to for support, and then only with your agreement at the time.

Suppliers

We use a small number of suppliers to run the service — for hosting, storage, text messaging, email and the optional live chat on our own help page. Each is bound by a written contract that permits them to process data only on our instructions. Customers can see the current list, and are told before it changes, under the data processing agreement.

Where data is held

Data is held on servers in the United Kingdom and the European Economic Area where possible. Some suppliers process data in the United States; where they do, transfers are covered by the UK International Data Transfer Addendum or by the supplier’s certification under the UK extension to the EU–US Data Privacy Framework.

How long we keep it

  • While your account is open — for as long as you keep it, because it is the record you are relying on.
  • When you delete your organisation — records are removed immediately. Uploaded documents are moved to a recovery area and destroyed within 30 days, so a mistake is not irreversible on the day it is made.
  • Backups — deleted data may persist in backups for up to 90 days before being overwritten.
  • Billing records — kept for six years, as UK tax law requires.

Your rights

Under UK GDPR you have the right to access your data, to have it corrected or erased, to restrict or object to processing, and to receive it in a portable form. You can also withdraw consent where consent is the basis we rely on.

To exercise any of these, write to george@opserion.uk. We will respond within one month. If you are a tenant, please contact your landlord first — see the top of this page.

If you are unhappy with how we have handled your data you can complain to the Information Commissioner’s Office at ico.org.uk, or by calling 0303 123 1113. We would rather you told us first so we can put it right.

Security

Passwords are stored only as salted, iterated hashes and cannot be read back. Sessions are signed and expire. Uploaded documents are stored privately and served only through the application’s own permission checks — never as a public link. Tenants see only what their landlord has explicitly shared with them. Access to production systems is limited to those who need it.

No system is perfectly secure. If we discover a breach affecting your data we will tell you, and the ICO where the law requires it, without undue delay.

Changes

If we change this policy in a way that materially affects you, we will email account owners at least 30 days beforehand. The date at the top always reflects the current version.

Contact

OPSERION.

Data protection enquiries: george@opserion.uk