Version 2.5 Last reviewed: 9 June 2026 Next review due: June 2027
AboveBoard Homes Ltd, also known as AboveBoard, and our team are committed to protecting your personal data. This privacy policy governs how AboveBoard collects and uses personal data. Personal data is information that relates to you and that may identify you as an individual.
We use your personal data in line with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Data (Use and Access) Act 2025, and the Privacy and Electronic Communications Regulations (PECR), together with all other applicable laws. To keep our promise of trust and transparency, we review how we handle data as part of our ongoing privacy programme.
This policy explains how we collect and use your personal data, so that you can be confident you know what your data is used for and that it is kept safe and secure.
Please read it alongside any other privacy notice we give you on specific occasions when we collect or process your data, so that you are fully aware of how and why we are using it. This policy supplements those other notices and does not override them.
This policy applies to AboveBoard Homes Ltd (“AboveBoard”), a company incorporated and registered in Scotland (company number SC644426), registered with the Property Factor Register under PF000861.
AboveBoard Homes Ltd, 5 South Charlotte Street, Edinburgh, EH2 4AN
AboveBoard is the data “controller” for the personal data you provide to us. This means we decide the purposes for which, and the way in which, your personal data is processed.
AboveBoard is registered with the Information Commissioner’s Office under data protection fee registration number ZA797125.
We welcome questions, comments, and requests about this policy. Please contact us in the first instance:
by email at data@aboveboard.homes
through the customer portal; or
by post to the address above.
Day-to-day responsibility for data protection sits with our Data Protection Lead, who you can reach at data@aboveboard.homes.
We are not required to appoint a statutory Data Protection Officer, and our Data Protection Lead acts as your point of contact for any data protection question or concern.
If you want to make a complaint about how we handle your data, we will:
acknowledge your complaint within 3 working days;
carry out an initial assessment within 14 working days to check we have the information we need to progress it (we may ask you for more detail at this stage);
investigate once we have a complete view of the issue; and
aim to resolve it within 30 working days. If we cannot, we will give you regular updates and a target date for our response.
If we do not resolve your complaint to your satisfaction, you can raise it with the Information Commissioner’s Office (ICO), the UK supervisory authority:
We record complaints in our data protection log and use them to improve our services and measure how well we meet our obligations. We would always appreciate the chance to put things right before you contact the ICO.
AboveBoard provides residential property factoring services, focusing on the careful management and administration of the communal areas of residential developments. Our goal is to keep those shared spaces well maintained, safe, and enjoyable for everyone who lives there.
Directly from you: when you fill in forms or contact us through our website or portal, by email, phone, or post, or otherwise.
Automatically: as you use our website, we may collect technical data about your device and browsing activity through cookies and similar technologies. Please see our cookie policy and website privacy policy. Data may also be generated while we deliver services to you.
From third parties or public sources: such as previous property factors, contractors, insurers, letting agents, debt recovery and tracing agents, and public sources such as Registers of Scotland.
Customer data: title, full name, occupancy status, contact details (email, phone, property address, correspondence address), and an emergency contact.
Correspondence data: a record of contact from you or anyone authorised to act for you, such as a letting agent, relative, or solicitor.
Property data: information about your managed property, including location, property type, communal areas, number and type of units, repair and maintenance history, and value for insurance purposes.
Financial data: information about the activity on your account, such as payment history and any matters relating to disputed invoices or arrears.
Operational data: information exchanged with our business partners to deliver services, such as insurance policies, work orders, and debt recovery instructions.
Business partner data: contact details and a history of transactions with our contractors, insurers, letting agents, and debt recovery and tracing agents.
Prospect data: contact details and a record of our interactions where you contact us as a prospective customer.
Job applicant data: the information you provide so we can assess your application.
Technical data: data we collect automatically when you visit our website, such as IP address, device, and browser.
In limited circumstances we may need to handle more sensitive information, known as special category data. For example, we may record information about a health condition or disability where you ask us to make a reasonable adjustment to how we communicate with you or deliver services, or where it is relevant to a vulnerable owner’s needs.
We only process special category data where we have a lawful condition to do so. Where we hold information about a health condition or disability, for example to make a reasonable adjustment, we rely on your explicit consent.
You can withdraw that consent at any time; please note that without it we may not be able to fully assist you or provide the adjustment you have asked for. In an emergency, we may also rely on the need to protect someone's vital interests. We collect the minimum needed, restrict who can see it, and do not use it for any other purpose.
Occasionally, while managing a development, we may record information that relates to alleged or actual criminal offences. For example, we may hold reports of antisocial behaviour, records of incidents in communal areas, or correspondence with the police.
We treat this information as sensitive. We only process it where we have a lawful basis and, where required, a condition under Schedule 1 of the Data Protection Act 2018. We collect only what is necessary, restrict access to it, and share it only where the law allows or requires, for example with the police or a relevant authority.
Our customers are property owners, who are adults, so we do not usually process children’s data. We may occasionally hold limited information about children or vulnerable residents, for example where it is relevant to a safeguarding concern, a reasonable adjustment, or access to a communal area.
Where we do, we take particular care: we collect the minimum needed, limit who can see it, and where there is a safeguarding risk we share information proportionately with the appropriate authority and record our reasons for doing so.
We only use your personal data where the law allows us to. We do not rely on consent for everything we do; instead we use the lawful basis that fits the purpose. In general we use your data:
to manage your property and deliver services under the contract we have, or are about to enter into, with you, including communicating with you, keeping accurate records, and sharing data with business partners such as contractors, insurers, debt recovery agents, and solicitors so those services can be delivered;
to monitor and improve the performance of our services and internal processes; and
to manage and audit our business, meet our legal and regulatory obligations, and, where necessary, share data with bodies such as the police for the prevention or detection of crime.
Each category of data has a main lawful basis, and more than one basis may apply depending on the circumstances. The lawful bases we rely on are:
Consent: where we ask your permission for a specific purpose, such as sending you marketing or using non-essential cookies. You can withdraw consent at any time.
Contract: where we need your data to deliver the factoring services you have signed up for.
Legal obligation: where the law requires us to use your data, for example for tax or regulatory reporting.
Legitimate interests: where we use your data for a genuine business interest, provided this is not overridden by your rights. Our legitimate interests include: managing and administering your development; recovering sums due and protecting other owners from shortfall; preventing fraud and crime and keeping our systems secure; improving and training on our services; running our business efficiently, including audit and record keeping; and bringing or defending legal claims. Where we rely on legitimate interests, we carry out a balancing assessment, and you can ask us for a summary of it.
Recognised legitimate interests: in limited cases we may rely on the recognised legitimate interests basis introduced by the Data (Use and Access) Act 2025, for example to disclose data to a public authority, to prevent crime, or to safeguard someone at risk.
Where we process special category data or criminal offence data, we identify and document the additional condition required under Article 9 or Article 10 of the UK GDPR and, where relevant, Schedule 1 of the Data Protection Act 2018. We do not rely on the recognised legitimate interests basis unless it is available in law and applies to the specific processing.
We freely use aggregated or anonymised data, which can no longer identify you, for various purposes, provided we are satisfied that re-identifying you is not reasonably likely.
| Data | Why we use it | Lawful basis |
| Customer | To maintain an effective relationship with you, to deal with questions and issues about the services we provide, and to share data with our business partners so those services can be delivered. | Contract; legitimate interests. |
| Correspondence | To respond to enquiries, deal with issues, and keep a record of the progress and history of tasks carried out. | Contract; legitimate interests. |
| Property | To manage your development effectively and to support insurance cover for the building. | Contract; legitimate interests. |
| Financial | To keep accurate accounts, pay business partners for work carried out, recover sums due, and meet our audit, tax, and regulatory obligations. | Contract; legitimate interests; legal obligation. |
| Operational | To deliver our services, improve them, and meet our internal governance and external legal and regulatory obligations. | Contract; legitimate interests; legal obligation. |
| Business partner | To maintain effective working relationships with the contractors, insurers, and others who help us deliver services. | Contract; legitimate interests. |
| Prospect | To respond to enquiries about our services and to follow up with prospective customers. | Legitimate interests; consent (for marketing). |
| Job applicant | To assess your application and meet employment-related obligations. | Legitimate interests; legal obligation. |
| Technical | To keep our website secure and working, and to understand and improve how it is used. | Legitimate interests; consent (non-essential cookies). |
We may share your data with the following types of organisation for the purposes set out above:
Business partners: contractors who may need to contact you to arrange access, and insurers, solicitors, bankers, auditors, and debt recovery agents who support our services and operations.
Your development’s committee or residents’ association: where you have asked us to, we may share your contact details, such as your email address, with the owners’ committee for your development so they can coordinate with you on shared matters. We only do this with your consent, and you can withdraw it at any time.
Your letting agent or appointed representative: where you have authorised it, we may deal directly with your letting agent, solicitor, or another representative acting on your behalf.
Government and regulatory bodies: such as HMRC, the Financial Conduct Authority, the Information Commissioner’s Office, and the First-tier Tribunal for Scotland (Housing and Property Chamber), and other regulators or authorities that require reporting.
Technology providers: organisations that provide our server hosting, IT software, analytics, and back-office functions, acting as our processors.
We do not, and will not, sell your personal data to anyone. We require all third parties to protect your data and to use it only for the specific purposes we instruct, not for their own.
Where a data-sharing arrangement is routine, sensitive, or higher risk, we put a written data-sharing agreement or equivalent arrangement in place. This sets out the parties, the purpose, the lawful basis, the data involved, security, retention, how individual rights are handled, and how any breach is reported.
Where another organisation processes data on our behalf, we have a written contract requiring it to act only on our instructions and to keep your data secure.
We keep your data within the UK wherever possible. If we ever need to transfer data outside the UK, we will make sure it has a level of protection that is not materially lower than under UK law. We do this by relying on UK adequacy regulations for the destination country, or by putting an approved transfer mechanism in place, such as the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the European Commission’s standard contractual clauses.
Where the law requires it, we complete and keep a transfer risk assessment before transferring data, and we keep a record of the categories of recipients, the destination countries, and the safeguards we rely on.
We also check that the providers we use meet recognised security standards, for example through independent certifications such as ISO 27001.
We use appropriate technical and organisational measures to protect your data against loss, misuse, and unauthorised access. These include access controls so that staff and partners only see the data they need, secure and reputable systems for storage and communication, supplier due diligence and contractual safeguards, regular backups, and staff awareness of their data protection responsibilities.
We keep a record of any personal data breach, whether or not it is reportable. If a breach is likely to result in a risk to your rights and freedoms, we will report it to the ICO without undue delay and, where required, within 72 hours of becoming aware of it. If a breach is likely to result in a high risk to you, we will also tell you without undue delay. Our contracts require the providers who process data for us to tell us promptly if they become aware of a breach.
Behind this notice we keep the records that let us show how we protect your data. These include a record of our processing activities, our lawful basis and legitimate interests assessments, a retention schedule, our contracts with the providers who process data for us, and, where a new activity could be higher risk, a Data Protection Impact Assessment. We review these as part of our annual privacy review, and we train our team on their responsibilities.
We keep your data only for as long as we have a genuine business or legal reason to. When our relationship ends, our standard retention periods are set out below. As a Scottish company, we use a six-year period as a safe margin around the five-year prescriptive period for most contractual claims under Scots law, and to meet HMRC requirements.
| Type of data | Retention period | Why |
| Customer and property records | Up to 6 years after our relationship ends | To deal with any legal claim about services provided |
| Financial and accounting records | 6 years after the relevant financial year | To comply with tax law and HMRC requirements |
| Correspondence and case records | Up to 6 years after the matter closes | To evidence what was done and deal with later queries or claims |
| Prospect and enquiry data | Up to 2 years from last contact, then deleted | We no longer need it once a lead is inactive |
| Unsuccessful job applicants | 6 months after the decision | To deal with queries and equal-opportunities monitoring |
| Website technical and analytics data | Up to 26 months | In line with standard analytics retention |
We review our retention periods regularly and delete data that is no longer needed as soon as we reasonably can. Where we anonymise data, we remove everything that could identify you and may keep and use the anonymised data for research and statistical purposes, for as long as we are satisfied that re-identifying you is not reasonably likely, in line with data minimisation and purpose limitation.
We do not make decisions about you, or about the management of your account, based solely on automated processing that produce legal or similarly significant effects.
We do profile the performance of our contractors using customer feedback from surveys and direct feedback, together with internal metrics such as timeliness, quality, value, and satisfaction scores. This profiling can affect which jobs a contractor is offered. It is about our contractors, not about you as an owner. We aim to be fair, and a contractor can ask us to review a decision that affects them, make representations, and ask for a person to look at it.
Where a contractor is an individual or sole trader, this performance information is their personal data, and we apply the same fairness, transparency, and review safeguards to it.
If you have any concern about how our profiling affects you, please contact us at data@aboveboard.homes or through the portal. You can ask for human involvement, give us your point of view, and challenge the outcome.
Our website uses cookies and similar technologies. Essential cookies keep the site working; for non-essential cookies, such as analytics, we act in line with the law, relying on the limited exemptions allowed under the Data (Use and Access) Act 2025 or asking for your consent where it is needed. You can manage your choices through our cookie banner and the cookie policy linked in the site footer.
We will only send you marketing where you have agreed to receive it, or where the law otherwise allows. You can opt out at any time using the unsubscribe link in any message or by contacting us at data@aboveboard.homes.
Where you have agreed to receive our newsletter or updates, we use MailerLite to send them and to measure whether messages are opened and links are clicked. This helps us understand what is useful and improve what we send. You can opt out at any time, and opting out stops this measurement.
You have a number of rights over your personal data. To exercise any of them, simply contact us at data@aboveboard.homes. Requests are free of charge in all but exceptional cases, and we will respond within one month. If your request is complex, we may extend this by up to two further months and will let you know. Where we reasonably need more information to deal with a request, we may ask you for it and pause the time limit until you reply.
Access: ask for a copy of the data we hold about you (a subject access request).
Correction: ask us to correct data that is inaccurate or incomplete.
Deletion: ask us to delete your data where it is no longer needed. Some legal limits may apply, and we will tell you if they do.
Object: object to our use of your data for certain purposes, including direct marketing, which we will always stop on request.
Restriction: ask us to pause our use of your data while a query is resolved.
Portability: ask us to provide certain data in a commonly used electronic format, or to send it to another provider.
Withdraw consent: where we rely on consent, withdraw it at any time. This does not affect anything we did before you withdrew it.
You also have the right to complain to the ICO at any time, as set out above. We would welcome the chance to address your concern first.
So that our records stay accurate, please tell us as soon as you can about any change to your details, by email, letter, through the portal or website, or by phone.
We review this policy regularly and will update it to reflect changes in the law or in how we work. The version number and review dates at the top of this document show when it was last updated. Where a change is significant, we will bring it to your attention.