Privacy policy

Last updated: 5 August 2026

This policy explains how Vault collects, uses, stores and protects personal data when you use our self-storage management software, whether as an operator (our customer), as a member of an operator's staff, or as a storage tenant using an operator's Vault-powered storefront or portal. It is written for the UK GDPR and the Data Protection Act 2018.

1. Who we are

Vault is operated by [Vault Storage Software Ltd], a company registered in England and Wales under company number [00000000], with its registered office at [Loc It Up Limited, 4 Glass House Studios, Fordingbridge, SP6 1QX] ("Vault", "we", "us"). Our demo deployment runs under the trading name "Loc It Up".

You can reach our data protection contact at [[email protected]] or by post at the address above, marked "Data Protection".

2. Controller & processor roles

Vault is software for self-storage operators. Two different data-protection roles apply, and being clear about them matters:

  • Operator account and billing data (the business that signs up, its staff logins, its subscription): Vault is the data controller.
  • End-customer data stored in the product (storage tenants, leads, agreements, invoices, access events that an operator records about its own customers): the operator is the data controller and Vault acts as its data processor, processing that data only on the operator's documented instructions and under our data processing terms (section 6 of the Terms & conditions).

If you are a storage tenant, your operator's own privacy notice applies first; this policy describes what Vault does on their behalf.

3. Data we collect

CategoryExamplesSource
Account dataName, work email, password hash, role, two-factor secret/recovery-code hashesYou / your organisation
Operator business dataOrganisation name, sites, billing details, VAT settings, API keys (hashed)You
Tenant & CRM data (as processor)Customer names, contact details, agreements, invoices, payments, stored-asset details, communications logThe operator and its customers
Usage & audit dataSign-in events, audit log of record changes, security events (failed 2FA attempts, lockouts)Generated by the service
Technical dataIP addresses in server logs, browser/user-agent, strictly-necessary cookies (see cookie policy)Your device

We do not collect special-category data, and we do not run analytics, advertising or tracking technologies on the service today.

4. Purposes & lawful bases

PurposeLawful basis (UK GDPR Art. 6)
Provide the service, run your account and sitesContract (6(1)(b))
Billing, subscription administration, debt recoveryContract (6(1)(b)); legal obligation (6(1)(c)) for tax/accounts records
Security: authentication, two-factor, audit trails, abuse preventionLegitimate interests (6(1)(f)): keeping the service and your data secure
Service announcements and essential operational emailsLegitimate interests (6(1)(f))
Complying with law (court orders, HMRC, regulators)Legal obligation (6(1)(c))
Improving the product using aggregated, de-identified statisticsLegitimate interests (6(1)(f))

Where we rely on legitimate interests we have balanced them against your rights; you may object (see "Your rights"). Where the operator is the controller, we process personal data only as a processor on the operator's instructions.

5. Subprocessors

We use a small number of suppliers to run the service. The current list for this deployment (placeholders for the demo/beta product) is:

SupplierFunctionLocation
[Hosting provider, e.g. Hetzner/AWS]Application hosting and database[UK/EU]
[Payment processor, e.g. Stripe]Card payment processing for tenants and subscriptions[UK/EU/US, SCCs]
[Email provider, e.g. Postmark]Transactional email delivery[UK/EU/US, SCCs]
[SMS provider, e.g. Twilio]Operational SMS (dunning/access notifications)[UK/EU/US, SCCs]

Each subprocessor is bound by a written contract with data-protection obligations no less protective than ours. Operators will be notified of changes to this list and may object where the change materially affects them.

6. Retention

  • Account data: kept while your account is active and deleted or anonymised within [90 days] of account closure, except where the law requires longer.
  • Financial records (invoices, payments, ledger): retained for 6 years from the end of the financial year they relate to, to meet UK tax and accounting obligations.
  • Audit and security logs: retained for [12 months], then deleted or aggregated.
  • Backups: encrypted backups roll off within [30 days]; deleted data disappears from backups on that cycle.

7. International transfers

We aim to keep personal data in the UK and EEA. Where a supplier processes data outside the UK/EEA (for example a US-headquartered provider), the transfer is made under a valid safeguard: the UK Addendum to the EU Standard Contractual Clauses, the UK International Data Transfer Agreement, or an adequacy regulation.

8. Security

We apply proportionate technical and organisational measures: encrypted transport (TLS), hashed passwords (bcrypt), optional TOTP two-factor authentication with single-use recovery codes, hashed API keys, role-based access control, per-organisation data separation, audit logging of sign-ins and record changes, and rate limiting on sensitive endpoints. No system is perfectly secure; if a personal-data breach risks your rights and freedoms we will notify the ICO and affected individuals as the law requires.

9. Your rights

Under the UK GDPR you have the right to:

  • be informed about how your data is used (this policy);
  • access a copy of your personal data;
  • have inaccurate data rectified;
  • have your data erased in certain circumstances;
  • restrict or object to processing, including processing based on legitimate interests;
  • data portability for data you provided, in a structured, machine-readable format;
  • not be subject to solely-automated decisions with legal or similarly significant effect (we do not make any);
  • withdraw consent where processing is based on consent (we rarely rely on consent).

To exercise any of these, email [[email protected]]. If your data is held by a storage operator (you are a tenant), contact the operator first; as their processor we will assist them in responding. We respond within one month.

10. Complaints (ICO)

If you are unhappy with how we handle your data, please contact us first so we can put it right. You also have the right to complain to the UK supervisory authority:

Information Commissioner's Office (ICO), Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF · ico.org.uk · 0303 123 1113.

11. Changes & contact

We may update this policy as the product evolves; material changes will be flagged in the app or by email to account owners, and the "last updated" date (5 August 2026) at the top will change. Questions: [[email protected]].

Vault is in demo/beta. This document is a carefully prepared template for a UK self-storage SaaS and is provided for transparency and product evaluation: it is not legal advice. Before relying on it in production, have it reviewed by a qualified solicitor and adapt the bracketed placeholders (company details, contacts, subprocessors) to your organisation.

We use essential cookies only: they keep you signed in and make the site work. No analytics, no tracking. See our cookie policy.