Privacy policy
Last updated: 5 August 2026
This policy explains how Vault collects, uses, stores and protects personal data when you use our self-storage management software, whether as an operator (our customer), as a member of an operator's staff, or as a storage tenant using an operator's Vault-powered storefront or portal. It is written for the UK GDPR and the Data Protection Act 2018.
1. Who we are
Vault is operated by [Vault Storage Software Ltd], a company registered in England and Wales under company number [00000000], with its registered office at [Loc It Up Limited, 4 Glass House Studios, Fordingbridge, SP6 1QX] ("Vault", "we", "us"). Our demo deployment runs under the trading name "Loc It Up".
You can reach our data protection contact at [[email protected]] or by post at the address above, marked "Data Protection".
2. Controller & processor roles
Vault is software for self-storage operators. Two different data-protection roles apply, and being clear about them matters:
- Operator account and billing data (the business that signs up, its staff logins, its subscription): Vault is the data controller.
- End-customer data stored in the product (storage tenants, leads, agreements, invoices, access events that an operator records about its own customers): the operator is the data controller and Vault acts as its data processor, processing that data only on the operator's documented instructions and under our data processing terms (section 6 of the Terms & conditions).
If you are a storage tenant, your operator's own privacy notice applies first; this policy describes what Vault does on their behalf.
3. Data we collect
| Category | Examples | Source |
|---|---|---|
| Account data | Name, work email, password hash, role, two-factor secret/recovery-code hashes | You / your organisation |
| Operator business data | Organisation name, sites, billing details, VAT settings, API keys (hashed) | You |
| Tenant & CRM data (as processor) | Customer names, contact details, agreements, invoices, payments, stored-asset details, communications log | The operator and its customers |
| Usage & audit data | Sign-in events, audit log of record changes, security events (failed 2FA attempts, lockouts) | Generated by the service |
| Technical data | IP addresses in server logs, browser/user-agent, strictly-necessary cookies (see cookie policy) | Your device |
We do not collect special-category data, and we do not run analytics, advertising or tracking technologies on the service today.
4. Purposes & lawful bases
| Purpose | Lawful basis (UK GDPR Art. 6) |
|---|---|
| Provide the service, run your account and sites | Contract (6(1)(b)) |
| Billing, subscription administration, debt recovery | Contract (6(1)(b)); legal obligation (6(1)(c)) for tax/accounts records |
| Security: authentication, two-factor, audit trails, abuse prevention | Legitimate interests (6(1)(f)): keeping the service and your data secure |
| Service announcements and essential operational emails | Legitimate interests (6(1)(f)) |
| Complying with law (court orders, HMRC, regulators) | Legal obligation (6(1)(c)) |
| Improving the product using aggregated, de-identified statistics | Legitimate interests (6(1)(f)) |
Where we rely on legitimate interests we have balanced them against your rights; you may object (see "Your rights"). Where the operator is the controller, we process personal data only as a processor on the operator's instructions.
5. Subprocessors
We use a small number of suppliers to run the service. The current list for this deployment (placeholders for the demo/beta product) is:
| Supplier | Function | Location |
|---|---|---|
| [Hosting provider, e.g. Hetzner/AWS] | Application hosting and database | [UK/EU] |
| [Payment processor, e.g. Stripe] | Card payment processing for tenants and subscriptions | [UK/EU/US, SCCs] |
| [Email provider, e.g. Postmark] | Transactional email delivery | [UK/EU/US, SCCs] |
| [SMS provider, e.g. Twilio] | Operational SMS (dunning/access notifications) | [UK/EU/US, SCCs] |
Each subprocessor is bound by a written contract with data-protection obligations no less protective than ours. Operators will be notified of changes to this list and may object where the change materially affects them.
6. Retention
- Account data: kept while your account is active and deleted or anonymised within [90 days] of account closure, except where the law requires longer.
- Financial records (invoices, payments, ledger): retained for 6 years from the end of the financial year they relate to, to meet UK tax and accounting obligations.
- Audit and security logs: retained for [12 months], then deleted or aggregated.
- Backups: encrypted backups roll off within [30 days]; deleted data disappears from backups on that cycle.
7. International transfers
We aim to keep personal data in the UK and EEA. Where a supplier processes data outside the UK/EEA (for example a US-headquartered provider), the transfer is made under a valid safeguard: the UK Addendum to the EU Standard Contractual Clauses, the UK International Data Transfer Agreement, or an adequacy regulation.
8. Security
We apply proportionate technical and organisational measures: encrypted transport (TLS), hashed passwords (bcrypt), optional TOTP two-factor authentication with single-use recovery codes, hashed API keys, role-based access control, per-organisation data separation, audit logging of sign-ins and record changes, and rate limiting on sensitive endpoints. No system is perfectly secure; if a personal-data breach risks your rights and freedoms we will notify the ICO and affected individuals as the law requires.
9. Your rights
Under the UK GDPR you have the right to:
- be informed about how your data is used (this policy);
- access a copy of your personal data;
- have inaccurate data rectified;
- have your data erased in certain circumstances;
- restrict or object to processing, including processing based on legitimate interests;
- data portability for data you provided, in a structured, machine-readable format;
- not be subject to solely-automated decisions with legal or similarly significant effect (we do not make any);
- withdraw consent where processing is based on consent (we rarely rely on consent).
To exercise any of these, email [[email protected]]. If your data is held by a storage operator (you are a tenant), contact the operator first; as their processor we will assist them in responding. We respond within one month.
10. Complaints (ICO)
If you are unhappy with how we handle your data, please contact us first so we can put it right. You also have the right to complain to the UK supervisory authority:
Information Commissioner's Office (ICO), Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF · ico.org.uk · 0303 123 1113.
11. Changes & contact
We may update this policy as the product evolves; material changes will be flagged in the app or by email to account owners, and the "last updated" date (5 August 2026) at the top will change. Questions: [[email protected]].
