LEGAL
Data Processing Addendum
Effective 28 September 2026 · Version 2026-09-28
This Data Processing Addendum (“DPA”) forms part of the contract between a Customer and LET NEXUS LTD whenever LET NEXUS processes personal data on that Customer's behalf. It is intended to satisfy Article 28 of the UK GDPR.
1. Parties, status and application
1.1 LET NEXUS LTD is a company registered in England and Wales under company number 17404019 with registered office at 190 Park Road, Dukinfield, England, SK16 5LP (“LET NEXUS” or “Processor”).
1.2 The “Customer” is the person or organisation identified in the LET NEXUS account or Order and is the controller of Customer Personal Data, or a processor acting for another controller, as applicable.
1.3 This DPA applies automatically whenever LET NEXUS processes Customer Personal Data on the Customer's behalf in providing the service. No separate signature is required, although either party may sign a copy for its records.
1.4 Each party remains independently responsible for personal data it processes as a controller. This DPA does not apply to LET NEXUS controller processing described in the Privacy Policy.
2. Definitions and interpretation
- Applicable Data Protection Law: the UK GDPR, Data Protection Act 2018 and other UK law applying to the processing, including the Data (Use and Access) Act 2025 and PECR where relevant.
- Customer Personal Data: personal data contained in Customer Content that LET NEXUS processes on behalf of the Customer.
- Data Subject, Personal Data Breach, process/processing, controller and processor: have the meanings given in Applicable Data Protection Law.
- Restricted Transfer: a transfer of personal data subject to the UK GDPR to a separate organisation in a country outside the UK that is not covered by applicable UK adequacy regulations.
- Subprocessor: another processor engaged by LET NEXUS to process Customer Personal Data.
- Terms: the LET NEXUS Terms of Service and any Order incorporating them.
References to Articles are to the UK GDPR. “Including” does not limit what follows. This DPA must be interpreted to achieve compliance with Applicable Data Protection Law.
3. Processing instructions and scope
3.1 The Customer instructs LET NEXUS to process Customer Personal Data to provide, host, secure, maintain and support the service; operate Customer-selected functions; comply with the Terms and Order; and follow further lawful written instructions accepted by LET NEXUS.
3.2 The Customer's configuration and ordinary use of the service are documented instructions. A further instruction must be in a durable written form, such as email, and be consistent with the contract. If it would require a material change or cost, the parties will agree scope, timing and reasonable charges before implementation unless the law requires otherwise.
3.3 LET NEXUS will process Customer Personal Data only on documented instructions, including for a Restricted Transfer, unless UK law requires other processing. Where permitted, LET NEXUS will tell the Customer before processing required by law.
3.4 LET NEXUS will inform the Customer if, in its reasonable opinion, an instruction infringes Applicable Data Protection Law and may suspend the affected processing until a lawful instruction is agreed. This does not make LET NEXUS responsible for the Customer's controller duties.
3.5 Schedule 1 describes the subject matter, duration, nature, purpose, data types, data subjects and controller rights and obligations.
4. Customer rights and obligations
4.1 The Customer determines the purposes and lawful basis for Customer Personal Data and retains the rights and obligations of controller, including the right to issue lawful documented instructions, configure the service, grant and withdraw User access, obtain an export and choose return or deletion when processing ends.
4.2 The Customer warrants that:
- its instructions and use comply with Applicable Data Protection Law;
- it has a lawful basis and every additional condition required for the processing;
- it gives complete and timely privacy information to data subjects;
- Customer Personal Data is adequate, relevant, limited to what is necessary, accurate and retained no longer than needed;
- it applies appropriate User, device, credential and endpoint security;
- it does not upload special-category, criminal-offence or identity data unless necessary, lawful and appropriately protected; and
- it will provide information and cooperation reasonably needed for LET NEXUS to meet processor obligations.
4.3 If the Customer is itself a processor, it confirms that the relevant controller has authorised its instructions, LET NEXUS and the approved Subprocessors, and that it will pass through assistance and information as required.
5. Confidentiality and authorised personnel
LET NEXUS will ensure that any person it authorises to process Customer Personal Data is bound by an appropriate contractual or statutory duty of confidentiality, receives access only where needed for their role and processes the data only on documented instructions unless law requires otherwise.
6. Security
6.1 Taking account of the state of the art, implementation cost, the nature, scope, context and purposes of processing and the risk to individuals, LET NEXUS will maintain appropriate technical and organisational measures designed to meet Article 32.
6.2 The baseline measures are in Schedule 4. LET NEXUS may update them where the update maintains an appropriate and materially equivalent level of protection.
6.3 The Customer acknowledges that security also depends on its Users, permissions, devices, integrations, data choices and credentials and will implement the measures allocated to it by the Terms and its own risk assessment.
7. Subprocessors
7.1 The Customer gives general written authorisation for LET NEXUS to use the approved Subprocessors listed in Schedule 5 for the described processing.
7.2 Before a Subprocessor processes Customer Personal Data, LET NEXUS will enter into a written contract imposing data-protection obligations that provide an equivalent level of protection for the relevant processing, including the applicable Article 28 obligations. LET NEXUS remains liable to the Customer for that Subprocessor's performance of those obligations as required by law.
7.3 LET NEXUS will give at least 14 days' advance notice by email, account notice or an update-notification mechanism before a material new or replacement Subprocessor starts processing Customer Personal Data. Where an urgent legal or security need makes prior notice impracticable, notice will be given as soon as reasonably possible.
7.4 The Customer may object within the notice period on reasonable and documented data-protection grounds. The parties will work in good faith on a reasonable mitigation, alternative configuration or replacement. If none is reasonably available, either party may terminate the affected feature or service before the change and any refund is limited to the unused prepaid period for the affected service. An objection is not a right to require an economically or technically unreasonable bespoke service.
7.5 Stripe is identified separately in the Privacy Policy because payment processing concerns LET NEXUS controller data and Stripe may act as a processor or independent controller depending on the activity. Stripe is not approved by this DPA to receive tenant/applicant Customer Personal Data unless Schedule 5 is expressly updated.
8. Data-subject rights
8.1 Taking account of the nature of processing, LET NEXUS will provide appropriate technical and organisational assistance to help the Customer respond to requests under Chapter III of the UK GDPR.
8.2 If LET NEXUS receives a request relating to Customer Personal Data, it will normally refer the requester to the Customer, notify the Customer where appropriate and not respond substantively unless authorised by the Customer or required by law.
8.3 The Customer is responsible for deciding the response, verifying identity and meeting applicable time limits. LET NEXUS may request the information reasonably needed to locate relevant data.
9. Personal Data Breaches
9.1 LET NEXUS will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data.
9.2 As information becomes reasonably available, LET NEXUS will provide a description of the nature of the breach, affected data and data subjects, likely consequences, measures taken or proposed and a contact point. Information may be supplied in stages.
9.3 LET NEXUS will take reasonable steps to contain, investigate and remediate the breach and preserve relevant evidence. A notification is not an admission of fault or liability.
9.4 The Customer remains responsible for deciding whether and how to notify the ICO or data subjects, with LET NEXUS's assistance under clause 10.
10. Assistance with Articles 32 to 36
Taking account of the nature of processing and the information available, LET NEXUS will provide reasonable assistance to the Customer with:
- security of processing under Article 32;
- assessment and notification of Personal Data Breaches under Articles 33 and 34;
- data-protection impact assessments under Article 35; and
- prior consultation with the ICO under Article 36.
Ordinary compliance information and reasonable routine assistance are included. LET NEXUS may charge reasonable, pre-agreed costs for exceptional, repetitive or Customer-specific work that exceeds its legal obligations or selected plan, unless the need was caused by LET NEXUS's breach.
11. International transfers
11.1 LET NEXUS will not make or permit a Restricted Transfer of Customer Personal Data except on documented instructions and using a lawful transfer mechanism applicable to the actual recipient and processing.
11.2 Depending on the circumstances, the mechanism may be applicable UK adequacy regulations, the UK International Data Transfer Agreement, or approved EU standard contractual clauses with the UK Addendum. Where required, LET NEXUS will assess transfer risk and apply supplementary measures.
11.3 On reasonable request, LET NEXUS will provide information about the mechanism relevant to the Customer's processing, subject to redaction of other customers' data and confidential commercial or security information.
11.4 LET NEXUS must not state that a particular safeguard or provider certification applies until the relevant provider, account, processing scope and contract have been verified in the vendor register.
12. Return and deletion
12.1 At the end of processing, the Customer may choose:
- return through LET NEXUS's standard available export, followed by deletion; or
- deletion without return.
12.2 The Customer must communicate its choice by the deadline in the applicable account-closure notice. If it gives no instruction by that deadline, it instructs LET NEXUS to delete Customer Personal Data.
12.3 LET NEXUS will delete existing copies after return or deletion unless UK law requires retention. Where law requires retention, LET NEXUS will isolate and protect the data and process it only for that legal purpose.
12.4 Customer Personal Data in protected backups may remain until overwritten through the documented cycle where immediate deletion is not technically practicable, provided it is put beyond ordinary business use, remains protected and is deleted at the next applicable cycle.
13. Compliance information, audits and inspections
13.1 LET NEXUS will make available information reasonably necessary to demonstrate compliance with Article 28 and this DPA and will allow for and contribute to audits and inspections by the Customer or its appointed independent auditor.
13.2 The Customer should first use current contractual information, security documentation, certifications and written responses where these reasonably address the request.
13.3 Unless a regulator, Personal Data Breach, material breach or substantiated security concern requires otherwise, an audit will be limited to once in any 12-month period, on at least 20 Business Days' notice, during normal business hours, by an auditor bound by confidentiality, without access to another customer's information and without unreasonable disruption.
13.4 The Customer bears its audit costs and LET NEXUS's reasonable pre-agreed cost of assistance beyond ordinary compliance information, unless the audit identifies a material breach by LET NEXUS. These conditions do not restrict the lawful powers of the ICO or another regulator.
13.5 LET NEXUS will maintain records required of a processor under Article 30(2) where applicable and will inform the Customer if it can no longer comply with this DPA.
14. Term, termination, liability and hierarchy
14.1 This DPA begins when LET NEXUS first processes Customer Personal Data and continues until that processing ends and return/deletion obligations are completed.
14.2 A material breach of this DPA is a material breach of the Terms. Termination rights in the Terms apply. If an instruction is unlawful, LET NEXUS may suspend the affected processing while the parties seek a lawful solution.
14.3 Liability arising under this DPA is governed by the liability clause in the Terms. This does not limit an individual's rights or a regulator's lawful powers.
14.4 If this DPA conflicts with the Terms about controller-to-processor processing, this DPA prevails. The rest of the Terms continues to apply. A mandatory transfer instrument prevails only to the extent required for the relevant transfer.
14.5 Notices under this DPA may be sent to the Customer's account contact and to LET NEXUS at support@letnexus.co.uk.
Schedule 1 — Processing details
| Item | Details |
|---|---|
| Subject matter | Provision, hosting, administration, maintenance, support and security of LET NEXUS, including Customer-selected property and tenancy records, compliance reminders, inspections, maintenance, documents, screening, communications, exports and optional AI-assisted features. |
| Duration | The contract term and the limited return, deletion and protected-backup period after processing ends, unless UK law requires longer retention. |
| Nature of processing | Collection, recording, organisation, structuring, storage, retrieval, consultation, transmission, restriction, support access, backup, export, deletion and other operations required for selected functions. |
| Purpose | To provide, secure, maintain and support the service and carry out lawful documented Customer instructions. General improvement must use aggregated/effectively anonymised data unless supported by a separate lawful role and notice. |
| Frequency | Continuous or as initiated/configured by the Customer during the contract. |
| Controller rights | To configure processing, manage Users and permissions, give lawful instructions, receive compliance information and assistance, object to Subprocessor changes on reasonable grounds, audit under clause 13, export data and choose return or deletion. |
| Controller obligations | Lawful basis and conditions, transparency, minimisation, accuracy, retention, rights handling, secure configuration, lawful instructions and compliance with Applicable Data Protection Law. |
Schedule 2 — Categories of data subjects
- Customers, Authorised Users, landlords, property owners, letting agents and property managers.
- Tenants, former tenants, prospective tenants, applicants, permitted occupiers, guarantors, dependants and emergency contacts.
- Referees, employers and other people supplying screening information.
- Contractors, tradespeople, inspectors, advisers and supplier contacts.
- Other individuals whose information the Customer lawfully places in the service.
Schedule 3 — Types of personal data
- Identity and contact details.
- Account identifiers, roles and permissions relating to Customer-controlled Users.
- Property, tenancy, occupancy, deposit and compliance records.
- Applicant, screening, affordability, employment and rental-history information chosen by the Customer.
- Referee identities, responses, opinions and correspondence.
- Identity/right-to-rent documents and verification records where the Customer lawfully chooses to collect them.
- Certificates, inspection and maintenance records, photographs, documents, signatures, notes and communications.
- Contractor and service-provider information.
- IP address, device/browser details, access and security logs where they form Customer Personal Data.
- AI prompts, selected context and outputs where the Customer chooses an AI-assisted feature.
- Other Customer Content selected and lawfully provided by the Customer.
Special-category and criminal-offence data: not required as a standard service category. It may be processed only where the Customer deliberately and lawfully includes it, has the required Article 6 basis and additional condition/authority, provides instructions and safeguards, and uses an appropriate policy document where required.
Schedule 4 — Technical and organisational measures
The following are LET NEXUS's baseline technical and organisational measures.
A. Access and identity
- Authentication through the configured Supabase service, currently offering password and email login-link flows.
- Organisation-scoped access design and role-based permissions for Customer Users.
- Least-privilege access for LET NEXUS personnel and providers, with prompt removal when no longer required.
- Protection of administrator credentials and secrets; multi-factor authentication for privileged provider/admin access where supported.
B. Encryption and transport
- HTTPS/TLS for public network connections.
- Encryption at rest for database and stored files to the extent supplied and contractually committed by the verified hosting providers.
- Controlled management of credentials, secrets and encryption keys; no secrets in public client code.
C. Data separation and documents
- Database policies and application checks designed to enforce organisation separation and role permissions.
- Private document storage by default; access through authenticated requests or time-limited signed links where external access is required.
- Screening links designed for a specific purpose, with appropriate entropy, expiry, revocation and protection against unintended reuse.
D. Availability, resilience and recovery
- Resilience features included in the contracted Supabase/Vercel plans, with backup coverage reviewed as the service grows.
- A documented incident-response and recovery procedure.
- No recovery-time, recovery-point or backup-frequency promise.
E. Logging, monitoring and incident response
- Security and access logging proportionate to risk, with restricted access and a documented retention period.
- Procedures to identify, triage, contain, investigate and remediate suspected incidents.
- Processor-to-controller Personal Data Breach notification workflow consistent with clause 9.
F. Secure development and operations
- Change review, dependency and vulnerability management, timely security patching and separation of production secrets from source code.
- Testing of organisation separation, authorisation and external one-time-link behaviour before material releases.
- Data minimisation, retention and secure-deletion procedures aligned to the documented lifecycle.
G. People and suppliers
- Confidentiality obligations and access limited to people with a business need.
- Due diligence and appropriate contracts for Subprocessors; review of current DPA, region, subprocessor and transfer information.
- Physical/infrastructure security delegated to verified hosting providers under contract.
H. Customer responsibilities
- Secure devices and email accounts, individual credentials, appropriate User roles and prompt offboarding.
- Lawful data selection, minimisation, accurate records, retention decisions and exports of critical records.
- Prompt reporting of suspected unauthorised access.
Schedule 5 — Approved Subprocessors
LET NEXUS currently uses the following Subprocessors for Customer Personal Data.
| Provider | Service and Customer Personal Data | Processing location/transfer position | Notes |
|---|---|---|---|
| Supabase | Managed database, authentication and private file storage; account identifiers and Customer Content required for these functions | Database and file storage hosted in London, United Kingdom (eu-west-2). Provider support and its own subprocessors may involve access from outside the UK | Transfers protected as described in clause 11 |
| Vercel | Application hosting/delivery; request, technical and Customer Personal Data handled by server functions as required | Server functions run in London; responses are delivered through Vercel's global network. US-headquartered provider | Transfers protected as described in clause 11 |
| Resend | Transactional email delivery; recipient, subject/body, attachments if any, delivery and event data | Emails sent from Resend's Ireland (EU) region. US-headquartered provider | Transfers protected as described in clause 11 |
| Anthropic | Optional AI prompt/output processing; only selected context and Customer Personal Data supplied to the feature | US-based provider | Not currently active: no Customer Personal Data is sent. At least 14 days' notice under clause 7.3 will be given before activation |
Not listed as a Customer-Content Subprocessor: Stripe is used for LET NEXUS subscription billing and may be a processor or independent controller for that controller processing. Do not send tenant/applicant Customer Personal Data to Stripe unless Schedule 5 is updated and the processing is lawful.
Stop wondering what you’ve forgotten.
Try LET NEXUS free for 7 days. No card needed, then £10 a month.
Start your free trial